← Back

Pitada Privacy Policy

Last updated: August 28, 2026


In one sentence

Pitada keeps your recipes on your own phone. You only need an account to save recipes from the internet, and even then, we collect the bare minimum to make the app work. We never sell your data.


1. Who we are

Pitada is operated by [COMPANY NAME / YOUR FULL NAME], registered under [CNPJ/CPF], with its place of business at [ADDRESS].

For anything privacy-related, talk to us: support@pitada.app

We are the controller of your personal data under Brazil's General Data Protection Law (LGPD, Law No. 13.709/2018).


2. What stays on your phone only (it never leaves)

This information is stored locally, in the app's storage:

  • Your saved recipes, Cookbooks, Meal Plan, and Grocery List
  • Your preferences (light/dark theme, measurement units, language)
  • Your answers to the welcome quiz

If you uninstall the app, that data goes with it.


3. What we collect (and why)

3.1. Account: optional

You can use Pitada without creating an account. An account is only needed to save recipes from the internet (because that processing happens on our servers).

Data Source Why Legal basis (LGPD)
Email, or an Apple/Google identifier You, when you sign in Authenticate you and recover your access Performance of a contract (Art. 7, V)
Display name You (or your social login) Personalize the app Performance of a contract
Quiz answers (cooking goals, preferred time, age range) You, at the start Tailor suggestions and your reminder time Consent (Art. 7, I)
Language and measurement units Your preference Show the app your way Performance of a contract
About "Sign in with Apple": if you choose to hide your email, we only receive the anonymous address Apple generates. We never see your real one.

3.2. Recipes you save

When you save a recipe (from a video, photo, or website), we store on our servers: the title, ingredients, directions, time, servings, photo, and the source link. This keeps the same recipe from being processed twice (saving your quota) and lays the groundwork for syncing across devices.

If you use the app in another language, the recipe is translated on demand: we send the title, ingredients, and directions to OpenAI and store the translation on our servers, so the same recipe isn't translated twice. The original content is never overwritten: it stays right there, exactly as it came in.

3.3. Usage limit and subscription

We store how many recipes you've saved in the month (to apply the free plan's limit) and how long your Pitada+ stays active. We have no access to your card: payment is processed entirely by Apple or Google Play.

3.4. App usage (analytics)

We use PostHog to understand how the app is used (for example, how many people finish signing up, how many saves fail). These events are anonymous: we don't link them to your account, and we never send the content of your recipes, your photos, or your links. Legal basis: legitimate interest (Art. 7, IX), to improve the product.

On our website (pitada.app), we use analytics and advertising cookies: Google Analytics, Meta Pixel, and TikTok Pixel. They measure visits and clicks (for example, on the download button) and only load after you accept the site's cookie notice. If you decline, none of them loads and the site works just the same. To change your choice later, just clear your browsing data for the site (the notice will appear again). Legal basis: consent (Art. 7, I).

3.5. Crashes and errors

We use Sentry to receive technical reports when the app breaks (details about the error and the device). It's used only to fix the problem. Legal basis: legitimate interest.


4. Phone permissions

We only ask when you use the feature, and you can say no (the app keeps working, just without that feature):

  • Photos: to read the recipe in the image you choose. We never scan

your gallery.

  • Camera: to photograph a recipe from a notebook or a package.
  • Notifications: for the reminder at the time you chose, the heads-up before your

Pitada+ trial ends, and the alert when your monthly saves renew.


5. Who we share it with

We never sell your data. We share it only with the providers the app needs to work (processors, under the terms of the LGPD):

Company What for What it receives
Supabase Database and sign-in Account and recipes
Apify Read the public post you shared The Instagram/TikTok link
Groq Transcribe the speech in the video The audio of the video you saved
OpenAI Turn the content into a structured recipe, and translate it into the app's language The text/caption/images of the content you saved and, for translation, the title, ingredients, and directions
RevenueCat Manage your subscription An identifier for your account
PostHog Usage statistics Anonymous events
Sentry Error reports Technical crash data
Apple Payment and distribution Transaction data (we don't see your card)

These services may process data outside Brazil (mainly in the United States). Transfers are made under Art. 33 of the LGPD and these providers' contractual clauses.

Important: the AI providers we use (OpenAI, Groq) receive the content through commercial APIs and, under their policies, do not use that material to train models.

6. How long we keep it

  • For as long as your account exists: account, recipes, and preferences.
  • Technical logs of your saves (for diagnostics and cost tracking): up to 12 months.
  • When you delete your account: we erase everything from our servers,

permanently. Rotating backups may keep copies for up to 30 days.


7. Your rights (LGPD, Art. 18)

At any time, you can:

  • Confirm whether we process your data and access it
  • Correct incomplete or inaccurate data
  • Delete your data and your account, right in the app:

Profile → Settings → Delete Account

  • Port your data to another provider
  • Withdraw consent (for example, turning off notifications)
  • Object to processing based on legitimate interest

Write to support@pitada.app. We reply within 15 days.


8. Children

Pitada is not intended for children under 13, and we do not knowingly collect data from that age group. If it happens, we will delete it as soon as we're told.


9. Security

We use encrypted connections (HTTPS), row-level access control in the database (each person can only see what's theirs), and we keep API keys only in server-side secret vaults, never inside the app.

No system is 100% fail-proof. If a relevant security incident happens, we will notify you and the ANPD (Brazil's data protection authority), as required by law.


10. Changes to this policy

If we change anything important, we'll let you know inside the app before it takes effect. The date at the top shows the latest revision.


Pitada. Your kitchen, organized in a snap.