Evoked
Privacy Policy
The Kitchen Table
Version 1.3 · Effective December 14, 2024 · Last Updated February 6, 2026
Introduction
The Kitchen Table ("we," "us," "our," or the "Company"), operated by Evoked, is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services (collectively, the "Services").
Your privacy is not just a legal obligation — it's a core value. We believe your data belongs to you, and we design our systems to respect your autonomy and sovereignty over your personal information.
Please read this Privacy Policy carefully. By using The Kitchen Table, you consent to the practices described herein.
1. Information We Collect
1.1 Information You Provide Directly
Account Information:
- Email address
- Password (stored securely hashed, never in plain text)
- First and last name
- Family name
Profile Information:
- Date of birth or age group
- Dietary restrictions and allergies
- Food preferences
- Health goals (optional)
- Profile photo (optional)
Family Data:
- Family member profiles
- Meal plans and recipes
- Inventory items
- Grocery lists
- Cooking session records
- Family journal entries
- Heritage recipes and food stories
Communication Data:
- Support requests and correspondence
- Feedback and suggestions
- Survey responses
1.2 Information Collected Automatically
Device Information:
- Device type and model
- Operating system and version
- Unique device identifiers
- Mobile network information
Usage Information:
- Features used and actions taken
- Time spent in the application
- Screens viewed
- Search queries within the app
Log Data:
- IP address
- Access times and dates
- App crashes and errors
- Referring URLs (web access)
Location Information:
- General location (city/region) derived from IP address
- Precise location only if you explicitly enable it (optional, for local grocery store features)
1.3 Information from Third Parties
Payment Processors:
- Transaction confirmations (we do not store full payment card details)
- Billing address
- Payment status
Social Login (if enabled):
- Basic profile information from authentication providers
- Email address
2. How We Use Your Information
2.1 To Provide and Improve Services
| Purpose | Data Used |
|---|---|
| Create and manage your account | Email, name, password |
| Generate personalized recipes | Dietary restrictions, preferences, family profiles |
| Track kitchen inventory | Inventory items, expiration dates |
| Plan meals for your family | Profiles, preferences, meal history |
| Calculate nutritional information | Age groups, dietary needs |
| Coordinate cooking sessions | Family member profiles, skills |
| Improve our AI recommendations | Anonymized usage patterns |
2.2 To Communicate With You
- Send service-related notifications (password reset, security alerts)
- Respond to support requests
- Provide updates about new features
- Send marketing communications (with your consent, opt-out available)
2.3 To Ensure Security
- Detect and prevent fraud
- Monitor for suspicious activity
- Enforce our Terms and Conditions
- Protect the rights and safety of users
2.4 To Comply With Legal Obligations
- Respond to legal requests
- Comply with applicable laws and regulations
- Protect our legal rights
2.5 AI-Powered Features
We use your information to power AI features, including:
- Recipe generation based on your preferences and inventory
- Meal plan suggestions tailored to your family
- Nutritional recommendations by age group
Important: Your personal data is used only to personalize your experience. We do not use your data to train AI models or share it with AI providers in identifiable form.
3. How We Share Your Information
3.1 We Do NOT Sell Your Data
We never sell, rent, or trade your personal information to third parties for their marketing purposes.
3.2 Service Providers
We share information with trusted service providers who help us operate our Services:
| Provider Type | Purpose | Data Shared |
|---|---|---|
| Cloud Hosting | Data storage and processing | All data (encrypted) |
| Payment Processing | Handle subscriptions | Payment info (not stored by us) |
| Email Services | Send notifications | Email address, name |
| Error Tracking | Fix bugs and issues | Anonymized error data |
| Analytics | Improve user experience | Anonymized usage data |
All service providers are bound by data processing agreements and are prohibited from using your data for their own purposes.
3.3 Legal Requirements
We may disclose your information if required by law or in response to:
- Court orders or legal process
- Government or regulatory requests
- To protect our rights, privacy, safety, or property
- To protect against fraud or security threats
3.4 Business Transfers
If The Kitchen Table is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
3.5 With Your Consent
We may share your information for other purposes with your explicit consent.
4. Family Data Sharing
4.1 How Family Sharing Works
The Kitchen Table is designed for families. When you join a family group, certain data becomes visible to other family members:
Shared Within Your Family:
- Meal plans and calendar
- Kitchen inventory
- Grocery lists
- Family recipes (not personal favorites)
- Cooking sessions and task assignments
- Family journal entries (as designated)
- General family preferences
Kept Private (Not Shared with Family):
- Your login credentials
- Your personal account settings
- Your email address (unless you choose to share)
- Your individual favorites and bookmarks
- Your private notes
4.2 Controlling Family Data Sharing
- You can control profile visibility in your settings
- The Table Keeper (family admin) manages family-wide settings
- You can leave a family at any time
- When you leave, your shared contributions remain with the family (you cannot delete others' data)
4.3 Family Admin Responsibilities
If you are the Table Keeper (family administrator):
- You can invite and remove family members
- You can manage subscription and billing
- You cannot access other members' private data or passwords
- You are responsible for ensuring family members consent to data sharing
5. Data Storage and Security
5.1 Security Measures
We implement industry-standard security measures to protect your data:
Technical Safeguards:
- Encryption of data in transit (TLS/HTTPS)
- Encryption of sensitive data at rest
- Secure password hashing (bcrypt)
- Regular security assessments
- Access controls and authentication
Operational Safeguards:
- Limited employee access to personal data
- Security training for staff
- Incident response procedures
- Regular security audits
5.2 Data Location
Your data is stored on secure servers located in the United States. We use reputable cloud service providers with robust security certifications.
5.3 Security Incidents
In the event of a data breach that affects your personal information:
- We will notify you within 72 hours of discovery
- We will provide details about what data was affected
- We will explain what steps we are taking
- We will offer guidance on protecting yourself
5.4 Your Role in Security
You can help protect your account by:
- Using a strong, unique password
- Enabling two-factor authentication (when available)
- Not sharing your login credentials
- Logging out on shared devices
- Keeping your app updated
6. Your Privacy Rights
6.1 Rights for All Users
Regardless of your location, you have the right to:
| Right | Description |
|---|---|
| Access | Request a copy of your personal data |
| Correction | Update or correct inaccurate data |
| Deletion | Request deletion of your data |
| Portability | Export your data in a standard format |
| Opt-Out | Unsubscribe from marketing communications |
6.2 California Residents (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to Know: What personal information we collect and how we use it
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: We do not sell personal information, but you may opt out of certain data sharing
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
To exercise your CCPA rights, contact passionevoked@icloud.com or use the in-app privacy controls.
6.3 European Users (GDPR)
If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):
- Legal Basis: We process your data based on consent, contract performance, legitimate interests, or legal obligations
- Right to Object: Object to processing based on legitimate interests
- Right to Restrict: Request restriction of processing
- Right to Withdraw Consent: Withdraw consent at any time
- Right to Lodge Complaint: File a complaint with your local data protection authority
Data Controller: The Kitchen Table (Evoked)
Contact: passionevoked@icloud.com
6.4 How to Exercise Your Rights
In-App Controls:
- Account Settings > Privacy > Manage My Data
- Export your data in JSON or CSV format
- Delete your account
Contact Us:
- Email: passionevoked@icloud.com
- We will respond within 30 days (or sooner as required by law)
- We may need to verify your identity before processing requests
7. Data Retention
7.1 Retention Periods
| Data Type | Retention Period | Reason |
|---|---|---|
| Account data | Duration of account + 14 days grace period | Service provision |
| Meal plans & recipes | Duration of account | Service provision |
| Family data | Duration of family membership | Service provision |
| Transaction records | 7 years | Legal/tax requirements |
| Security logs | 1 year | Security and fraud prevention |
| Support communications | 3 years | Service improvement |
| Anonymized analytics | Indefinitely | Service improvement |
7.2 After Account Deletion
When you delete your account:
- You have a 14-day grace period during which you can change your mind and restore your account
- After 14 days, personal data is permanently deleted from active systems (not just anonymized — truly removed)
- Shared family content may be retained for other family members
- Legal/compliance data is retained as required by law
Backup Retention: We maintain rolling backups for disaster recovery:
- Daily backups: purged within 30 days
- Weekly backups: purged within 90 days
- Monthly backups (for catastrophic recovery): purged within 1 year
Maximum deletion timeline: Your data is permanently deleted from active systems after 14 days, and will naturally age out of all backup systems within 90 additional days. This means complete removal from all systems occurs within 105 days maximum of your deletion request.
If we ever need to restore from backup, we will filter out any accounts that requested deletion before the backup date.
7.3 Right to Be Forgotten
You may request complete deletion of your data. We will:
- Provide a 14-day grace period in case you change your mind
- After 14 days, permanently delete all identifiable personal data from active systems
- Filter your data from any backup restoration
- Complete purge from all systems (including backup aging) within 105 days maximum
- Retain only what is legally required
8. Children's Privacy
8.1 Age Requirements
- You must be at least 18 years old to create a Kitchen Table account
- Child profiles can be created by adult family members for meal planning purposes
8.2 Children's Profiles
When an adult creates a profile for a child:
- We collect minimal information (name, age group, dietary restrictions)
- We do not collect email addresses or contact information for children
- Child profiles cannot log in independently
- Child data is managed by the adult family member
8.3 COPPA Compliance
We comply with the Children's Online Privacy Protection Act (COPPA):
- We do not knowingly collect personal information from children under 13 without parental consent
- Parents can review, update, or delete their child's information through their account
- If we learn we have collected information from a child without proper consent, we will delete it promptly
8.4 Parental Rights
Parents and guardians can:
- Review their child's profile information
- Update or correct their child's data
- Delete their child's profile
- Contact us at passionevoked@icloud.com with concerns
9. Health Data and HealthKit
9.1 Health Data We Collect
The Kitchen Table may collect and store health-related information to provide personalized meal planning and nutrition features:
| Health Data Type | Purpose | Storage |
|---|---|---|
| Allergies | Prevent allergen exposure in recipes | Encrypted (AES-256-GCM) |
| Dietary Restrictions | Filter recipes and ingredients | Encrypted |
| Medical Conditions | Customize nutritional recommendations | Encrypted |
| Medications | Check for food-drug interactions | Encrypted |
| Growth Measurements | Age-appropriate portion sizing (for children) | Encrypted |
| Nutritional Goals | Personalize meal plans | Standard |
9.2 Apple HealthKit Integration
If you choose to connect The Kitchen Table with Apple HealthKit:
What We May Read (With Your Permission):
- Dietary energy consumed
- Active energy burned
- Weight and body measurements
- Nutritional intake data
What We May Write (With Your Permission):
- Nutritional information from logged meals
- Calorie and macronutrient data
Important HealthKit Disclosures:
- We do not sell HealthKit data. Your health information will never be sold to advertisers, data brokers, or any third party.
- We do not use HealthKit data for advertising. Health data is used solely to improve your meal planning experience.
- We do not share HealthKit data with third parties except as required to provide our Services (and only with your explicit consent).
- HealthKit data is stored securely using AES-256-GCM encryption on our servers.
- You control your data. You can revoke HealthKit access at any time through iOS Settings > Privacy > Health.
9.3 Your Health Data Rights
You have complete control over your health data:
| Action | How to Do It |
|---|---|
| View your data | Settings > Privacy & Security > View My Health Data |
| Export your data | Settings > Privacy & Security > Export Data |
| Delete your data | Settings > Privacy & Security > Delete Health Data |
| Revoke HealthKit access | iOS Settings > Privacy > Health > The Kitchen Table |
| Disable health features | Settings > Preferences > Disable Health Features |
9.4 Granular Consent
We request permission for each type of health data separately. You can:
- Grant access to some data types while denying others
- Change your consent preferences at any time
- See exactly what data we have collected
- Delete specific data types without deleting your entire account
10. Device Permissions
10.1 Permissions We Request
The Kitchen Table requests the following device permissions to provide our Services:
| Permission | Purpose | Required? |
|---|---|---|
| Camera | Scan barcodes, photograph recipes and ingredients | Optional |
| Photo Library | Save recipe photos, add profile pictures | Optional |
| Notifications | Meal reminders, cooking timers, family updates | Optional |
| Location | Find local grocery stores, regional recipe suggestions | Optional |
| HealthKit | Sync nutrition data, personalize meal plans | Optional |
| Siri & Shortcuts | Voice commands for hands-free cooking | Optional |
10.2 Permission Details
Camera Access:
- Used only when you actively scan a barcode or take a photo
- Photos are stored locally until you choose to upload
- We do not access your camera in the background
Photo Library Access:
- Read access: Only to photos you select to add to recipes
- Write access: To save recipe images to your library
- We do not scan or analyze your photo library
Heritage Recipe Photos (Server Storage):
We intentionally limit photo storage to Heritage Recipes only — photos of culturally significant family recipes passed down through generations. This is a deliberate privacy choice:
- What we store: Photos attached to Heritage Recipes (grandmother's recipe card, traditional dishes)
- What we don't store: Daily meal photos, journal entry images — these are not uploaded to our servers
- Encryption: Heritage photos are encrypted at rest using AES-256-GCM
- Storage limits: 5MB per photo, 50MB total per family
- Deletion: Photos are securely deleted (overwritten before removal) when you delete them or your account
- Why this limit: We minimize data collection. Daily meal photos don't warrant the storage and breach risk; heritage recipes do because they preserve family culture.
Push Notifications:
- You choose which notifications to receive
- Categories include: meal reminders, timer alerts, family activity, shopping lists
- You can customize or disable notifications at any time
- Device Identifier: When you enable push notifications, we collect your device identifier (Expo push token) to deliver notifications to your specific device. See Section 10.4 for details.
Location Services:
- Used only when you request local features (store finder)
- We store only general location (city/region), not precise GPS coordinates
- You can use the app fully without location access
10.3 Managing Permissions
You can change permissions at any time:
On iOS: Settings > The Kitchen Table > [Permission Name]
On Android: Settings > Apps > The Kitchen Table > Permissions
In-App: Profile > Preferences > App Permissions
We will never require a permission that isn't essential for the feature you're using.
10.4 Device Identifiers and Persistent Identifiers
What We Collect:
| Identifier Type | When Collected | Purpose | Retention |
|---|---|---|---|
| Expo Push Token | When you enable notifications | Deliver push notifications to your device | Until notifications disabled |
| Device ID | When you enable notifications | Correlate push tokens with your account for debugging | Until notifications disabled |
| IP Address | On each request | Security (fraud detection, anomaly monitoring) | 1 year (security logs) |
| User Agent | On each request | Device type identification for security | 1 year (security logs) |
How Device Identifiers Are Used:
Our use of device identifiers falls under COPPA's "internal operations" exception:
- Push Notification Delivery: We need to know which device to send notifications to. The Expo push token and device ID enable this functionality.
- Security and Fraud Prevention: IP addresses and device information help us detect impossible travel, identify credential stuffing attacks, block suspicious access patterns, and maintain audit trails for security incidents.
- Session Management: You can view active sessions (devices logged into your account) in Settings > Security > Active Sessions.
What We Do NOT Do:
- We do NOT use device identifiers for advertising or behavioral profiling
- We do NOT share device identifiers with advertisers or data brokers
- We do NOT track users across other apps or websites
- We do NOT use device fingerprinting for purposes beyond security
Child Profiles and Device Identifiers:
When a child profile (under 13) is active on a device:
- Push notification device IDs are still collected (to deliver meal reminders to the family device)
- This collection is disclosed to parents during the Parental Consent (VPC) process
- Parents can disable notifications for child profiles
Your Control:
- Disable notifications to stop device ID collection for push notifications
- View and terminate active sessions to remove device associations
- Delete your account to remove all associated device data
11. International Data Transfers
11.1 Data Location
Our primary servers are located in the United States. If you access our Services from outside the U.S., your data will be transferred to and processed in the United States.
11.2 Transfer Mechanisms
For users in the EEA, UK, or other regions with data transfer restrictions, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Your explicit consent (where applicable)
- Adequacy decisions (where applicable)
11.3 Your Consent
By using The Kitchen Table, you consent to the transfer of your data to the United States, understanding that U.S. data protection laws may differ from those in your country.
12. Third-Party Services
12.1 Services We Use
| Service | Purpose | Privacy Policy |
|---|---|---|
| Anthropic (Claude) | AI recipe generation | anthropic.com/privacy |
| Stripe | Payment processing | stripe.com/privacy |
| Sentry | Error tracking | sentry.io/privacy |
| Cloud Provider | Data hosting | Varies by provider |
12.2 AI Processing
When you use AI features:
- Your preferences and context are sent to our AI provider
- We do not share your name, email, or directly identifying information
- AI providers are prohibited from using your data to train their models
- Responses are generated in real-time and not stored by the AI provider
12.3 Links to Other Sites
Our Services may contain links to third-party websites. We are not responsible for the privacy practices of other sites. We encourage you to read their privacy policies.
13. Cookies and Tracking
13.1 Mobile Application
Our mobile app does not use traditional browser cookies. We use:
- Local Storage: To save your preferences and session data
- Secure Storage: To store authentication tokens securely
- Analytics SDKs: To collect anonymized usage data
13.2 Website (If Applicable)
If you access The Kitchen Table via web browser, we may use:
| Cookie Type | Purpose | Duration |
|---|---|---|
| Essential | Authentication, security | Session |
| Functional | Preferences, settings | 1 year |
| Analytics | Usage statistics | 1 year |
13.3 Managing Tracking
- Disable analytics in app settings
- Use browser privacy settings for web access
- Opt out of personalized recommendations
14. Changes to This Policy
14.1 Updates
We may update this Privacy Policy from time to time. When we make changes:
- We will update the "Last Updated" date
- For material changes, we will notify you via email or in-app notification
- We will provide at least 30 days' notice for significant changes
14.2 Review History
| Version | Date | Changes |
|---|---|---|
| 1.0 | December 14, 2024 | Initial release |
| 1.1 | January 13, 2026 | Added HealthKit and Device Permissions sections (Apple compliance) |
| 1.2 | January 27, 2026 | Honest deletion timeline: true deletion (not anonymization) |
| 1.3 | February 6, 2026 | Added Section 10.4: Device Identifiers and Persistent Identifiers (COPPA compliance) |
14.3 Your Continued Use
Continued use of our Services after changes become effective constitutes acceptance of the updated Privacy Policy.
15. Contact Us
15.1 Privacy Questions
For questions or concerns about this Privacy Policy or our data practices:
Email: passionevoked@icloud.com
Subject Line: Privacy Inquiry
15.2 Data Requests
To exercise your privacy rights:
Email: passionevoked@icloud.com
Subject Line: Data Rights Request - [Your Request Type]
We will respond within 30 days.
15.3 General Contact
The Kitchen Table
Operated by Evoked
Support: evokesupports@icloud.com
Legal: passionevoked@icloud.com
Privacy: passionevoked@icloud.com
Mailing Address:
Evoked
Nampa, Idaho
United States
Your data belongs to you. We're just helping you cook with it.
Document Version: 1.3 · Effective Date: December 14, 2024 · Last Reviewed: February 6, 2026
The Kitchen Table - Bringing Families Together, One Meal at a Time