Legal
Privacy policy
Your data stays on your device. Here is exactly what goes where, and when.
Last updated: 18 August 2026
Quirl is an offline-first cookbook app. It works without an account, without a backend, and without tracking. Your recipes and data stay on your device by default.
Controller
Van Cheng · Stikelkamper Straße 6, 26835 Hesel, Germany · bdgraue@gmail.com
What data is processed
Locally on your device (never leaves the device):
- Recipes, ingredients, steps, shopping lists, meal plans, cooking history, settings, and your dietary profile — stored in a local database.
- Photos you take or select (cover, gallery, and step images). On import, EXIF metadata is stripped (including GPS location) before the image is stored.
- Text recognition (OCR) for photographed recipes runs entirely on-device; photos are never sent to any service.
- API keys for the optional AI features are kept in the **operating system's secure storage** (Android Keystore or the system keychain).
No analytics, no tracking, no ads. No usage or telemetry data is collected, and no data is sold or shared.
Permissions
- Camera / photos: only when you take or select a recipe photo, or scan a QR code.
- Internet: only for the optional features listed below, and only after an explicit action by you.
- Multicast (local network): only for syncing between your own devices on your Wi-Fi (see below).
Sync between your devices
Quirl can sync recipes (including categories and photos) and your meal plans directly between your own, explicitly paired devices:
- Sync runs exclusively over your local network (mDNS/Bonjour and a direct device-to-device connection). There is no server and no cloud; your data never leaves your network.
- The transfer is end-to-end encrypted (X25519 key exchange, XChaCha20-Poly1305). During pairing you compare a verification code on both devices.
- The only identifiers visible on the network are a randomly generated device ID and the device name you choose — no hardware identifiers.
Optional online features (opt-in)
These features send data to third parties only when you actively use them. The privacy policy of the respective provider then applies; with every request, your IP address becomes visible to the contacted server.
- Shopping list connections (test mode): During setup and list selection, Quirl contacts Bring! or your KitchenOwl/Grocy instance. Selected item names, quantities and units are sent when you transfer them. Optional Grocy/KitchenOwl list views also read and locally cache their contents. Supported edits send names, amounts, descriptions or checked states; removal sends the provider's item identifier. Offline changes are sent during later synchronization attempts while Quirl is open and active. Optional automatic updates send changes from explicitly adopted sources to the selected list; new plan entries are not automatically adopted. Recipe contents and Quirl-internal item identifiers are not sent. Bring! receives your email and password during login; afterwards only session tokens and user identifiers are kept locally in the OS secure store. Instance credentials and API keys are also stored there and excluded from Quirl backups. Disconnecting removes the local connection, not previously transferred items. Cached data and pending local changes are included in shopping backups; restored changes remain paused and automatic following remains off. Source bindings and purchased quantities are included. During explicitly initiated Quirl device sync, execution ownership and its source state travel encrypted between paired devices; executable external operations are not copied. After disconnecting, old changes can be inspected and discarded under “Local changes”. Bring! and Listonic remain handoff destinations. For Listonic, pressing the handoff button sends the list name and displayed items to its link service, together with the fixed source URL `https://quirl.vancheng.de`. Quirl then opens the generated link. Listonic stores the handoff data behind this link; anyone who knows the link can access it. Quirl receives no import confirmation.
- Recipe discovery: search terms are sent to the online sources you have enabled (TheMealDB; Edamam only with your own credentials, in which case your Edamam app ID is sent as an identifier). The bundled sources "Public domain recipes" and "OpenRecipes" are searched locally — nothing goes online for them. Preview images of search results are loaded from the servers of the respective recipe source.
- URL import: the address you paste or share is fetched to read the recipe from the page; the cover image is downloaded from the address given there.
- AI features: only if you add your own API key, data is sent to the provider you choose (e.g. Anthropic, OpenAI, Google, Perplexity, OpenRouter, or a server you specify yourself — including a local one). In detail:
- Recipe structuring and translation: the recipe text in question (title, description, ingredients, steps) or the recognized OCR text. Photos are never transmitted.
- Ingredient classification: ingredient names or the text of a photographed label (only the recognized text).
- Meal plan suggestions: titles, nutrition values, and season information of the recipes in your library, the days and meals to plan, and — if you provide them — your nutrition targets. Without a key, an offline heuristic runs on the device instead.
- The "Automatically translate imports" setting, once enabled, sends every imported foreign-language recipe to the chosen provider without further confirmation. It is off by default.
- Nutrition data comes from a bundled database or from you — nothing goes online for it.
Without these actions, no data is transmitted.
Retention & deletion
All data is stored locally and remains until you delete it in the app or uninstall the app. You can export your recipes as open files at any time (data sovereignty).
Contact
Privacy questions: bdgraue@gmail.com