TerraSpoon
Sign inAdd recipe
Privacy & safety

Privacy at TerraSpoon

This notice describes the current test service operated by Gamma Meon Ltd. It is intentionally specific about what the product does today and does not claim legal compliance that has not been independently verified.

Service notice · 19 August 2026

Data we keep

Account contact and profile details, sign-in-provider links, recipes and media, cookbook activity, ratings, follows, blocks, reports, planning data, approximate security metadata and operational logs. If you explicitly use protected cloud photo capture when it is enabled, we also keep the submitted page unchanged in private storage, its embedded metadata (which may include precise location), integrity and storage facts, source details, consent record, extracted draft and model provenance.

Why we use it

To authenticate you, provide recipe and planning features, calculate and sync your data, protect the service, investigate reports and operate backups.

Recipe photos and AI

The ordinary scanner performs OCR on your device and does not upload scan pages. Protected cloud photo capture is a separate opt-in. Before upload, you must acknowledge that TerraSpoon keeps the submitted file unchanged for administrator review and that embedded EXIF, IPTC or XMP may include precise location. TerraSpoon rebuilds a separate metadata-free JPEG for analysis. Hetzner's experimental Inference API receives only a short-lived signed URL for that preview and the extraction prompt; it does not receive the original or its metadata. Model output is untrusted, cannot publish and must be reviewed by an administrator before it can become a private recipe draft. Hetzner describes this API as experimental, without production availability guarantees.

Sharing and visibility

Public recipes and profiles can be viewed by others. Unlisted recipes require their secret URL. Private recipes and planning data are account-only. Blocking creates a two-way interaction boundary for signed-in users.

Exports

Your Account page provides a portable JSON export of current profile, recipe, photo-capture, cookbook, community and planning records. It includes retained photo metadata and extraction records but not temporary object-storage keys or download signatures. Passwords, tokens, provider claims, integration credentials and internal audit logs are excluded.

Deletion and retention

After recent sign-in verification, account deletion immediately revokes sessions, removes private collections and active application access to uploaded media and recipe-photo captures, hides recipes and de-identifies the account. An application download URL issued earlier may remain valid for up to five minutes; a provider-only preview URL may remain valid for up to ten minutes. A direct-upload signature may remain usable for up to fifteen minutes, but it can write only to private staging. Exact media and capture keys are committed to the durable deletion queue, retried if storage is unavailable and swept again five days later. Abandoned captures are scheduled for deletion after 7 days; every new upload grant resets a collecting capture's seven-day stale deadline. Rejected captures are scheduled for deletion after 30 days. Metadata-free AI preview bytes have a conservative object-storage cleanup backstop of up to 47 days, including noncurrent-version expiry; private approved originals remain until account deletion. Moderation, ingestion, security and audit records may be retained in de-identified form. Encrypted backup copies expire under the configured backup rotation schedule.

Reports and moderation

Signed-in users can report a profile or recipe. Administrators can dismiss or resolve a report, or suspend the reported account. Decisions are recorded in an internal audit log. Reports are not public.

Contact

Questions, access requests or deletion concerns can be sent to spoon@laurson.net. Identity verification may be required before account-specific information is disclosed.

Version 20260824-01feef998b9921