1. Scope
This policy applies to the Viandly website, installed web application, Help Center, and related account, import, scanner, sharing, cookbook, and cooking-assistance services. It does not replace the privacy terms of an AI provider or another site you choose to use with Viandly.
2. Information we process
Account and authentication information
Viandly processes information such as your display name, email address, public profile slug, profile image, account role and status, email-verification state, and service entitlements. Authentication may also involve provider identifiers, passkey public-key material and counters, short-lived challenges, session data, and hashed verification or invitation tokens. Viandly does not provide password-based accounts and does not receive your Google or Apple password.
Recipe and workspace content
Content you provide can include recipes, ingredients, instructions, source attribution, notes, ratings, collections, shopping lists, cookbooks, uploaded images, import source text, scanned pages, draft revisions, cooking sessions, timers, AI transcripts, and account preferences. Private recipes and private account notes remain restricted to the account unless you deliberately publish or share applicable content.
AI provider configuration and usage
If you configure an AI provider, Viandly stores the provider, model, capability status, encrypted API credential, optional instructions, and feature-level usage estimates. Saved credentials are not returned to your browser after configuration. Provider invoices remain the authoritative source for charges.
Scanner delivery and communications
Scanner intake can process a delivery address, sender address, subject, filenames, attachment metadata, and attached PDF or image content. Support, security, privacy, and invitation messages are also processed through the relevant mail providers.
Technical and usage information
Viandly and its infrastructure providers process information needed to deliver and secure requests, such as timestamps, network information, browser and device characteristics, request identifiers, operation names, error categories, quota use, and background-job status. The public waitlist rate limiter uses a keyed representation of the source address instead of retaining that raw address in the application database.
Viandly currently uses necessary session and security storage. It does not currently use a third-party advertising network, sell personal information, or use cross-site advertising trackers.
3. How information is used
Viandly uses information to:
- create, authenticate, secure, and administer accounts;
- store, organize, search, display, scale, print, share, and export recipe content;
- receive and process files, websites, scanner deliveries, images, and import drafts;
- run optional AI-assisted import, development, cookbook, and cooking workflows;
- send verification, invitation, scanner, security, and service messages;
- apply quotas, entitlements, rate limits, and abuse protections;
- diagnose failures, operate backups, restore service, and complete deletion requests;
- respond to support, privacy, security, and copyright reports; and
- understand aggregate service capacity and reliability without exposing recipe content.
4. Service providers and optional AI processing
Viandly uses service providers to operate the application. Current provider roles include Fly.io for application and database infrastructure, Tigris for object storage, Resend for transactional and scanner email, Google or Apple for configured sign-in, and Google Workspace for human support mail. Viandly may also use Sentry for privacy-filtered application error monitoring and operator alerts. Sentry receives diagnostic error structure and release context, not recipe bodies, scanner content, AI prompts, account credentials, or session replay. Providers process information only in the role needed to deliver their service and under their own terms.
AI features are optional and use the provider account you configure. When you invoke an AI feature, Viandly may send relevant recipe content, source text, images, scanner pages, cookbook material, cooking context, audio, or instructions to that provider. The selected provider controls its own processing, retention, and billing. Do not enable an AI feature unless you are comfortable sending the indicated content to that provider.
Camera and microphone access requires a user action and browser permission. Local photo preparation may remain in your browser. Cook Assist audio is sent to the configured realtime AI provider when a voice session is active; Viandly stores the private cooking session state and transcript needed for that workflow.
6. Retention and deletion
Viandly keeps account and recipe content while your account is active and as needed to provide requested workflows. Temporary scanner deliveries normally expire 14 days after receipt and can be removed sooner through their workflow. Import drafts, source material, completed editions, messages, and operational records follow their product lifecycle, user actions, configured limits, and cleanup schedules.
A deleted recipe normally enters a 30-day recovery period before permanent purge. Account deletion immediately disables normal access and public sharing, then provides a 30-day recovery period unless you request irrevocable immediate purge. Permanent purge removes active relational data and schedules known stored objects for deletion.
If paid access ends, content outside the free allowance can enter the published subscription-retention lifecycle. During that period, you can select archived recipes for available free-library slots, restore the retained library by resuming paid access, or request a portable download. Restored recipes return as private. Temporary generated downloads normally expire after 24 hours; the underlying retained library follows its separate published deadline. Viandly attempts notices when the archive is created, 30 days before expiration, and 7 days before expiration. At the deadline, remaining retained recipe content, archived original images, and identifying catalog entries are permanently removed through retryable background deletion. The account and recipes already restored into its active free library remain.
Encrypted disaster-recovery backups are not ordinary user-accessible archives and are not rewritten for individual deletion requests. Deleted information can remain in those protected recovery points until the applicable backup expires. Restored environments are isolated from public access and outbound processing, and backup data is not used to recreate an ordinarily purged account.
7. Your choices and controls
You can use Viandly controls to:
- edit account, profile, recipe, attribution, and preference information;
- keep recipes private, publish them, or create and revoke private share links;
- configure or remove an optional AI provider;
- create a schema-backed account archive for portability;
- delete recoverable recipes or permanently purge them;
- schedule account deletion, restore during the recovery period, or purge immediately; and
- contact Viandly about access, correction, privacy, or deletion concerns.
8. Security and international processing
Viandly uses access controls, encrypted transport, encrypted AI credentials, scoped storage, private backups, account lifecycle controls, and tested authorization boundaries. No internet service can promise absolute security. Report a suspected vulnerability to security@viandly.com rather than posting private details in the public feedback tracker.
Viandly and its providers may process information in the United States or other locations where they operate. Those locations may have data-protection rules different from your home jurisdiction.
9. Children
Viandly is not directed to children under 13 and does not knowingly collect account information from them. A person below the age of legal majority where they live may use Viandly only with permission and supervision from a parent or legal guardian. Contact Viandly if you believe a child under 13 provided account information.
10. Changes and contact
Viandly may update this policy as the service, providers, or legal obligations change. The policy version and effective date identify the published text. Material changes will be presented through an appropriate service or account notice before they take effect when practical.
Privacy questions and requests can be sent to privacy@viandly.com. General support questions can be sent to support@viandly.com.