Privacy
Privacy Policy
How Cookhouse collects, uses, discloses, and retains personal information.
Effective September 15, 2026 · Version 2026-09-15
Scope and controller
This Privacy Policy describes how ScreenSense Studios LLC (Cookhouse, we, us, or our) handles personal information in the Cookhouse Service. ScreenSense Studios LLC is the controller or business responsible for this information unless another notice says otherwise. This Policy does not govern independent retailers, group members, app stores, or third-party sites.
Information we collect
- Account and profile: email address, authentication identifiers, username, display name, biography, avatar, account dates, country and age-band attestations, policy acceptances, and account status.
- Groups and social activity: groups, roles, memberships, invitations, join requests, messages, replies, mentions, reactions, blocks, read state, leaderboards, moderation actions, and Discord connection or server-link information.
- Store and collecting activity: stores, products, tracked items, historical store checks, availability and quantity estimates, observation times, notes, photos, online links, purchase or secured-bag quantities, edits, reports, and related audit history.
- Location: approximate location inferred from network data and, only with device permission, precise foreground or background coordinates used to find nearby stores, validate store proximity, and refresh nearby results. Coordinates may be transmitted to our backend or mapping provider for processing but are not retained as the reporter’s permanent store observation.
- Devices and communications: device and push tokens, platform, app version, notification preferences, support requests, emails, diagnostics you choose to share, and related correspondence.
- Safety and legal: reports, preserved evidence, case history, appeals, enforcement, identity snapshots, access audits, copyright notices, legal requests, fraud signals, and records needed to protect people or rights.
- Payments and creators, when enabled: RevenueCat app-user and entitlement identifiers, product and transaction metadata, subscription status, token grants and uses, group charges, creator identity and eligibility, tax details, payout allocations, PayPal identifiers, payout history, refunds, chargebacks, and fraud or sanctions reviews. Apple or Google processes mobile payment credentials; Cookhouse does not receive full card numbers.
- Technical use: IP address, request and security logs, cookie or local-storage identifiers, session state, crash or performance information, feature interactions, and abuse-prevention signals.
- Public-source intelligence: public retailer, catalog, release, price, resale, website, and social-post information and the source, retrieval, confidence, and review records used to produce release intelligence.
Sources
We receive information from you; your device; other users and group administrators; Apple, Google, Discord, RevenueCat, PayPal, and other connected services; retailers and catalog providers; public websites and public social sources; safety reporters; and vendors that help us operate Cookhouse. We may infer approximate area, likely interests, store trends, release timing, abuse risk, and de-identified or aggregated patterns from these sources.
How and why we use information
We use information to create and secure accounts; provide profiles, groups, invitations, chat, store reports, media, maps, search, drops, alerts, scoring, and notifications; process subscriptions, tokens, creator allocations, refunds, and payouts when enabled; personalize and improve Cookhouse; develop de-identified or aggregated Cookhouse-only insights; provide support; detect bugs, fraud, abuse, and security incidents; moderate content and handle appeals; enforce agreements; preserve evidence; comply with law; and protect users, the public, and legal rights.
Where applicable, our legal bases are performance of our contract, your consent (including optional location and certain device permissions), our legitimate interests in operating and securing Cookhouse and improving its usefulness, and compliance with legal obligations. Where we rely on consent, you may withdraw it, but that does not affect earlier processing. We will identify another basis where local law requires it.
Public and private groups
Any eligible account may join a public group. Public-group metadata and member-accessible content carry no confidentiality guarantee and may be copied or reshared by members. If Cookhouse proposes making that content openly visible on the web, we will provide advance notice and obtain consent where required.
We do not directly publish private-group source messages, media, identities, or group attribution. Authorized users, ScreenSense personnel, and service providers may nevertheless access or process them to operate, secure, support, moderate, and improve Cookhouse; investigate reports; respond to legal process; prevent fraud; or protect safety and rights. De-identified or aggregated private-group observations may be used inside Cookhouse to create public catalog facts, restock trends, predictions, and alerts without identifying the source content, user, or group. We do not currently license those derived private-group insights outside Cookhouse or use them to train third-party general-purpose AI models.
When we disclose information
- Other users: according to group visibility, membership, profile, posting, and sharing features you use.
- Group administrators: membership and local moderation information; report views omit reporter identity where our policy specifies.
- Processors and vendors: Supabase (database, authentication, storage, functions), Vercel (web hosting), Apple (App Store, APNs, MapKit), Google (Google Play, Firebase/FCM, Maps/Places), Discord, GIPHY, Resend, RevenueCat, PayPal, Scrydex, Browserless, OpenAI, and public-source intelligence providers, only where used for the purposes described here. Provider availability may change; the current Service determines which receive data.
- Business transfers: in diligence, financing, reorganization, bankruptcy, or sale, subject to appropriate confidentiality and applicable law.
- Legal, safety, and rights: when we believe disclosure is required or permitted by valid legal process, law, an emergency, fraud or security prevention, child safety, enforcement, or protection of a person’s safety, property, or legal rights. We may preserve records and may disclose them to law enforcement or regulators. We do not promise advance notice.
- With direction or consent: when you connect or direct a sharing feature.
We do not currently sell personal information, share it for cross-context behavioral advertising, use targeted advertising, or license member information or private-group-derived insights to third parties. If that changes, we will update this Policy and provide required choices before the change.
Cookies and local storage
Our websites and apps use essential cookies, local storage, session storage, secure device storage, and local caches for authentication, security, preferences, media performance, and app operation. We do not currently use advertising cookies. See the Cookie and Local Storage Notice.
Retention
We retain account and profile information while the account is active and ordinarily delete or de-identify it within 30 days after a valid deletion request. Messages, replies, reactions, mentions, personal media, Discord credentials, push devices, and ordinary revisions are removed through the deletion process. Historical shouts may be converted into private de-identified store observations containing store, item, availability or quantity, and time without user or group attribution.
Closed safety reports, evidence, actions, and appeals are ordinarily retained for 24 months after closure. We may retain narrowly scoped copyright, fraud, security, legal-hold, dispute, tax, creator, and payment records for the period required by law or reasonably needed for those purposes. Backups expire through provider backup cycles. Retention may be longer where law requires preservation and shorter where law requires deletion.
Security
We use administrative, technical, and physical safeguards designed to protect information, including access controls, row-level authorization, encrypted transport, restricted service credentials, media re-encoding and metadata removal, audit records, and limited moderator access. No system is perfectly secure, and we cannot guarantee that unauthorized access or loss will never occur. Protect your credentials and report suspected compromise promptly.
International transfers
Cookhouse is operated from the United States, and information may be processed in the United States and other countries where our providers operate. Those countries may have different privacy laws. Where required, we use approved transfer mechanisms, contractual protections, and supplementary safeguards. Cookhouse will not launch in a country until required transfer, representative, child-safety, and local-law measures are in place.
Your privacy rights
Depending on where you live, you may request access, confirmation, correction, deletion, portability, restriction, or objection; withdraw consent; opt out of certain sale, sharing, profiling, or targeted advertising; and appeal a denied request. Cookhouse does not discriminate for exercising a right. An authorized agent may submit a request where law permits, but we will verify identity and authority. We usually respond within one month or the shorter period required by law and may extend where legally permitted.
Email support@getcookhouse.com with “Privacy request” or use the account-deletion process. You may complain to your local data-protection, privacy, consumer-protection, or attorney-general authority. EEA/UK users may contact the competent supervisory authority. If we deny an appealable U.S. state request, our response will explain how to appeal.
U.S. state notices
The categories collected are identifiers; customer records; protected age-band and country characteristics; commercial and subscription information; internet or network activity; approximate and precise geolocation; audio/visual content; user communications; and inferences. We collect, use, disclose, and retain them for the purposes and periods described above. We do not knowingly sell or share personal information of any age for targeted advertising. Precise geolocation, account credentials, private communications, and certain payment or identity records may be treated as sensitive information and are used only for permitted operational purposes unless we obtain any consent required by law.
Children and teens
Cookhouse is not directed to children under 13 in the United States or under 16 elsewhere. We request country and age-band attestations rather than a full birth date. If we learn an account is below the applicable minimum, we restrict group access and delete the account subject to legally required preservation. Users below local adulthood need parent or guardian permission where required. We apply heightened defaults and avoid targeted advertising, sale, or unnecessary profiling of teens.
Changes
We may update this Policy as Cookhouse changes. We will post the new version and give prominent notice or request acknowledgement when a change is material. The effective date identifies the current version. We will not materially expand use of previously collected private information without any notice or consent required by law.
Contact
ScreenSense Studios LLC
1 Chestnut Hill Plaza #1032
Newark, DE 19713, United States
support@getcookhouse.com