In short: cookbook OCR and ingredient understanding run on your device. We do not use advertising, third-party analytics, tracking pixels, or cookies. Optional sync, imports, Apple integrations, support, and sharing transmit only the data needed to provide those features.
Information processed on your device
Crumb processes captured cookbook pages, recognized text, recipes, pantry items, grocery lists, meal plans, and cooking timers on your iPhone. A custom ingredient model and deterministic parsing rules run on-device. Local-only content is not sent to Guhl Design Studio.
Storage choices
Local-only
Your library remains in app storage and is removed when you delete it or uninstall the app, subject to iOS backup behavior you control.
iCloud
If you choose iCloud, Apple processes and stores your recipe data under your Apple account and Apple’s terms. Guhl Design Studio does not receive your iCloud credentials.
Mealie
If you connect a Mealie server, Crumb sends recipe data and credentials to the server address you provide. That operator controls its security, retention, and backups. Crumb avoids publishing private or plain-HTTP Mealie addresses in public shares.
Network features
URL import
When you import a web recipe, Crumb requests the URL from its publisher. The publisher can receive ordinary connection information such as your IP address. Failed imports may remain queued locally until retried.
Private recipe links and App Clips
When you approve a share preview, Crumb sends the recipe title, yield and times, ingredients, method, source attribution, and sharing timestamp to our server. It excludes photos, personal notes, nutrition, ratings, favorites, local identifiers, and synchronization identifiers. New random public identifiers are used for the snapshot.
Shares are immutable and retained for 30 days, then deleted. Revoking removes the payload promptly; a content-free revocation record may remain for seven days. Permanent demonstration content published by Guhl Design Studio does not expire. Shared links are unlisted but are not end-to-end encrypted: anyone who receives the URL can view the recipe.
App Attest
Publishing and revoking use Apple App Attest to help verify that requests come from a genuine Crumb installation. We process an App Attest key identifier, security assertion, app version, one-time challenge, and a device-bound management token hash. These identifiers are linked to share-security records, used only for app functionality, fraud prevention, and security, and are not used for tracking. Inactive attestation records are removed after 90 days.
Apple integrations
Crumb can interact with Reminders, Calendar, Notifications, Live Activities, Spotlight, Shortcuts, widgets, and controls when you enable them. Apple and iOS govern the resulting system data. You can change permissions in iOS Settings.
Server operations
Private recipe routes do not persist request bodies, full IP addresses, or user-agent strings in application logs. In-memory rate limits temporarily inspect network information to protect the service. We do not back up ephemeral recipe payloads. Operational security records are kept only as described above.
Support messages
If you email us, we receive your email address and anything you choose to include. We use it to answer, diagnose problems, and maintain necessary correspondence. Do not send private recipes or security tokens. Email providers process these messages under their own terms.
Children
Crumb is a general-audience cooking utility and is not directed to children under 13. We do not knowingly collect information from children.
Disclosure and legal requests
We do not sell personal information. We may disclose limited information to service providers that operate features you request, to comply with law, or to protect users and the service. We do not permit those providers to use Crumb data for advertising.
Your privacy choices
- Choose local-only, iCloud, or Mealie storage in Crumb.
- Decline optional permissions or disable them in iOS Settings.
- Preview every recipe share before publishing.
- Revoke active shares from the share receipt.
- Delete content inside Crumb and manage synced copies with the selected provider.
- Request help with a lost share receipt by emailing the exact share ID to us.
For access, deletion, correction, or privacy questions, contact design@guhlstudio.com. We may need limited information to verify and fulfill a request; because Crumb has no account system, we may not be able to associate local-only content with you.
Changes
We will update the effective date and this page when practices change materially. App Store privacy disclosures, app privacy manifests, and this policy are maintained together.
Contact
Guhl Design Studio
design@guhlstudio.com