Support → The privacy notice

The privacy notice

What Vurna keeps, what leaves your phone, who else touches it, and what you can switch off. Written against the app itself rather than from a template — every switch named here is a switch that exists, in the place it says.

Who we are

Vurna is made by CRAGG Studios. Write to support@vurna.app about anything on this page, including a request to see, correct or erase what we hold. Most days you'll hear back within one working day, and never longer than three.

What we keep

  • Recipes and photos — what you wrote, imported or scanned, and the pictures with them.
  • Plans, lists and kitchen — weeks you planned, what you shopped for, what's in the fridge and pantry.
  • Household — names, allergies and dislikes of the people you cook for. They are your records, not accounts: they cannot sign in, and we never contact them.
  • Your conversations — what you and Vurna said, so she can remember.
  • Name, email and Kitchen № — how you sign in, and how other kitchens find yours.
  • Subscription status — whether you're on Premium. Payment details stay with Apple or Google; we never see a card.

All of it is stored in the EU. None of it is sold, and none of it is shared with advertisers. The same list is in the app, under Privacy → What Vurna keeps.

The three switches, and what they really do

Profile → Privacy has three, and they are the whole of it. Each takes effect straight away, on that device and every other one you sign in to.

  • Usage analyticsoff unless you turn it on. Which screens get used, never what you cook. Every event in the app passes through one function, and when the switch is off that function stops before sending. There is no second route.
  • Crash reportson by default, and you can turn it off. When something breaks, a report goes to our error tracker so we can fix it. With the switch off the report is dropped at the last moment before it would leave the phone, rather than merely being ignored once it has arrived.
  • Email from usoff unless you turn it on.

Your answers are held on the device so they are already correct the instant the app opens — there is no window at the start of a session where a setting hasn't loaded yet — and kept on our side too, so a phone you sign in to later starts from the same answers.

Allergies never go to analytics. Allergies, dietary rules and anything that could reveal a religious practice are the most sensitive things in a recipe app, and they stay in your kitchen. Nothing of that kind is attached to a usage event — the app is built to refuse it rather than to remember not to — and your name and email are never sent to the error tracker either.

What leaves your phone, and when

Reading a recipe card starts on the phone. The text is recognised by Apple's own recogniser on an iPhone and Google's on an Android, and that step needs no connection and sends nothing anywhere.

What comes after does leave. Turning recognised text into a recipe, translating one, talking with Vurna, drafting a week, and drawing a photograph are all done by language and image models we don't run ourselves. We send them the recipe text or your question; we use OpenAI, Google and Anthropic directly, and OpenRouter when one of those can't answer. We also keep a record of those requests, tagged with your account id — an identifier, not your name — so that when she gets something wrong we can find the one that went wrong.

Who else touches it

  • Supabase — the database and the file storage, in the EU. This is where your kitchen actually lives.
  • RevenueCat — tells us whether you're on Premium. Card details never reach it, and never reach us; they stay with Apple and Google.
  • PostHog — usage analytics, and only if you turned that switch on.
  • Sentry — crash reports, and only while that switch is on.
  • OpenAI, Google, Anthropic, OpenRouter — the models described above.
  • Langfuse — the record of those model requests.
  • Apple and Google — they take the payment. We are told the outcome, never the card.

Taking it with you, and getting rid of it

Both live in Profile → Privacy, and neither needs to go through us. Download your data writes the whole account onto your phone. Delete your account removes it, immediately and completely — the photographs first, then everything else, and your Kitchen № is retired and never given to anybody again. There is no grace period and no way back, and nothing derived from your email address survives it, so a later sign-up is a new person with a new number.

Your rights

You can ask to see what we hold, to have it corrected, to have it erased, and to take it elsewhere in a form a machine can read. The first and the last two are buttons in the app. For anything else, or if a button doesn't do what you needed, write to support@vurna.app — a person reads it.

When this changes

If what the app does changes, this page changes with it and the date below moves. It is checked against the app rather than maintained alongside it, which is the only version of this promise that survives contact with a release.

Last checked 19 August 2026 · If any of this doesn't match what you're seeing, write to support@vurna.app and we'll fix the page.

← All support articles