Privacy Policy
The short version
Your recipes, photos, grocery lists and meal plans live on your phone. Sorrel has no ads, no analytics and no tracking SDKs, and it never needs an account. A few features do use Sorrel's own server: when a web page hides its recipe, Sorrel sends the page's text to the server to read it; Sorrel Pro's video import sends the video's link and lets the server watch it for you; a scanned page your phone couldn't read is sent only if you say so; asking Sorrel to arrange your week sends recipe titles from your library, never the recipes themselves; and if you turn on sync or start a household, your library is stored on the server so your other phone, or the people you cook with, can see it. Those are the only times anything you create leaves your device, and this page describes each of them in full.
Who this policy covers
This policy applies to the Sorrel app for Android (com.burnsoft.sorrel), to the Sorrel app for iPhone, to the Sorrel server at api.sorrelapp.io that some of their features use, and to this website. "Sorrel", "we" and "us" mean the developer of the Sorrel app.
What Sorrel stores on your device
Everything you create in Sorrel is written to private app storage on your phone:
- Recipes you import, scan, type in or edit — titles, ingredients, steps, times, tags, source links, and the original text they were read from
- Recipe photos, saved as files on your device
- Your cook journal: how many times you have made a recipe, when, your rating and your notes
- Grocery lists, collections, meal plans and the aisle corrections you make
- App settings, such as your units and whether crash reporting is on
Unless you turn on sync (below), this data is not uploaded anywhere, and we have no ability to read it. Sorrel requests the Android permissions it can explain: INTERNET, Google Play billing, and — for cook timers — showing notifications, vibrating, and keeping a timer counting after you leave the app. It never asks for your location, contacts, camera, microphone, call logs or files outside its own storage. Scanning a recipe card uses a scanner screen provided by Google Play services (or your photo picker), which hands Sorrel the finished pages; Sorrel does not hold camera permission itself.
What leaves your device, and when
Importing a recipe from a web link
When you paste or share a link, your phone fetches that page directly from the website that hosts it. The website sees your IP address, the page you asked for and a standard mobile browser user-agent string — exactly as if you had opened the link in Chrome — and its own privacy policy governs what it does with that. Sorrel then reads the recipe out of the page on your phone, and in most cases that is the end of it: nothing is sent to us.
Some pages hide the recipe in ways Sorrel cannot read on its own. When a page looks like a recipe but Sorrel cannot find both its ingredients and its steps, it sends the page's address, title and visible article text (never the raw HTML, and capped at roughly 10,000 characters) to our server, which asks an AI model run by Anthropic to pick out the recipe. The model receives the text, the title and the page address without its query string. It does not receive anything that identifies you. Our server keeps the recipe it read, filed under the page's address, for up to 90 days so the next person who imports the same page gets it instantly.
Importing from a video (Sorrel Pro)
When you share a TikTok, Instagram or YouTube link, your phone sends only the link to our server. The server fetches the video from that platform itself — the platform sees our server's address, not yours — and works up a ladder until it has a recipe:
- It reads the video's caption and any recipe page the caption links to, and asks the Anthropic model to turn that into a recipe.
- If the caption is not enough, it extracts the audio and has it transcribed by Groq (a Whisper speech-recognition service); YouTube's own captions are used instead where they exist.
- If the words are still not enough, it takes a handful of still frames from the video and sends them, with the caption and transcript, to the Anthropic model to read what is shown.
The downloaded video, audio and frames are deleted as soon as the import finishes, on every outcome. The server keeps the transcript and the finished recipe, filed under the video's id, for up to 90 days (24 hours if the result needed your review), so a popular video is only ever read once. Your phone also sends the Google Play purchase token that proves your Pro subscription (see "Google Play" below).
Scanning a recipe card (Sorrel Pro)
Scanning starts, and usually ends, on your phone. The pages come from a scanner screen provided by Google Play services or from your photo picker; text recognition runs on-device with a bundled model; the photos and the recognised text are stored with the recipe in Sorrel's private storage. If that reading comes back incomplete, Sorrel asks whether to send the scan — the photos, or just the recognised text — to our server, which asks the Anthropic model to read it. Nothing is sent unless you agree, the pages are discarded as soon as they have been read, and the server keeps only the finished recipe, filed under a fingerprint of the scan rather than under you, for up to 90 days. (If sync is on, the recognised text travels with the recipe like any other recipe text; the photos do not.)
Letting Sorrel plan the week (Sorrel Pro)
The free planner fills your week on the phone, offline. If you ask Sorrel to arrange the week instead, your phone sends our server a list of candidates from your library — titles, tags, times and how often you've made them, identified by ids — and the Anthropic model picks and orders them. The server answers with those ids and forgets the request: nothing about it is cached or stored.
Sync (Sorrel Pro)
Sync is off until you turn it on in Settings. When you do, Sorrel creates an account for you on our server:
- By default the account is anonymous. It is a random identifier with no name, email or phone number attached. To add a second phone you enter a six-character code that works once and expires after ten minutes.
- If you choose "Sign in with Google" — or, on iPhone, "Sign in with Apple" — so you can find the account again later, we store the account id the provider gives us and, if it is reported as verified, your email address. We do not receive your name, photo or contacts.
- For each phone we store a device id, the device's model name (for example "Google Pixel 8"), when it was added and when it last synced.
Sync uploads your recipes (including the cook journal, notes, ratings, tags and the original text they were read from), collections, grocery items, meal plans and aisle corrections. Photos stay on the phone they were taken on and are not uploaded. Your phone syncs a few seconds after you change something, roughly every six hours in the background, and while a household's grocery list is open.
This data is stored on a server we run on Microsoft Azure, in a database only our server software can reach, over encrypted connections. It is stored so that it can be delivered to your other phones and your household; we do not read it, analyse it, sell it or use it for anything else. Alongside the account we store the Google Play purchase token that proves your subscription, so that a household you own stays unlocked for its members.
"Sign out" in Settings stops the phone syncing and forgets its access token; your library stays on the phone, and so does the copy on the server, ready for your other phones. To erase the account itself, use Settings → Your data → Delete account and synced data: it deletes the account and everything stored under it immediately, and a lapsed subscription never blocks it. See Delete your Sorrel account.
Household sharing (Sorrel Pro)
A household is a group of sync accounts that share one cookbook and one grocery list. Starting a household requires Pro; joining one does not — the owner's subscription covers everyone. Within a household:
- Members see each other's recipes, collections and grocery items, live. Meal plans and aisle corrections stay personal and are never shared.
- Members can see who else is in the household. Each member is shown by their Google email address if they signed in with Google, otherwise by their phone's model name. Nothing else about a member is shared.
- An invite is a link (
https://www.sorrelapp.io/join/…) or QR code containing a random token. It works once and stops working after a day. It contains no information about you or the household. - Leaving a household, or being removed, keeps everything already on your phone and re-files it as your own. Deleting a household stops all sharing; each member keeps what is on their phone.
Loading recipe photos
Photos for imported recipes are fetched from the website or platform the recipe came from, then cached on your device.
Crash reports — only if you turn them on
Sorrel asks you once, on first launch, whether it may send a report when it crashes. The answer defaults to no; dismissing the question counts as declining. The setting lives under ⋮ → Settings → Send crash reports, and turning it off stops reporting immediately.
If you turn it on, then when the app crashes it sends the error and stack trace, your device model, and the Android and Sorrel version numbers — and only at the moment of a crash, never on launch or while you use the app. Your recipes, photos and lists are never included; Sorrel explicitly disables the parts of the crash reporter that would attach a screenshot, a view hierarchy, your IP address or any identifier for you or your device. Reports are processed on our behalf by Sentry and used for one thing: finding and fixing bugs.
What our server keeps about requests
Requests your phone makes to our server carry a random install token, created once when Sorrel is installed and not derived from your device or account. Two do not: signing out and deleting your account send the account's access token alone, because both exist to wind something down rather than to use the service. The server never stores the install token; it keeps only a short one-way hash of it, which it uses to apply fair-use limits and to count how many imports succeed or fail. For each import it records how it went — the platform, the outcome, how long it took, what it cost us — for 90 days, and never the address, title, caption or recipe. Usage counts are kept for seven days. Our hosting provider and web server may keep standard connection logs, including IP addresses, for security and reliability.
Google Play and the App Store
- Sorrel Pro subscriptions are sold and billed by Google Play. We never see your payment details. To confirm a subscription is active, Sorrel sends Google Play's purchase token to our server, which checks it with Google. For import requests the token is held in memory only for the length of the check; for sync accounts it is stored with the account, as described above.
- On iPhone, Sorrel Pro is sold and billed by Apple's App Store, and we never see your payment details there either. Sorrel sends the App Store transaction id to our server, which confirms the subscription with Apple.
- Review prompt. Sorrel may occasionally ask you to rate it using Google Play's built-in in-app review flow, which Google handles.
- Android backup. Sorrel allows Android's standard Auto Backup, so your recipes, meal plan, grocery list and settings can be restored to a new phone. That backup is yours and goes to your Google account, not to us; you can turn it off in your device's system backup settings. Sorrel deliberately holds four things back from it — your sync credentials, your sync progress, your Play entitlement and the install's fair-use token — so a backup can never carry a login, a claim to a subscription, or one install's identity onto another phone.
These interactions are covered by Google's Privacy Policy and Apple's Privacy Policy.
What we do not collect
- No analytics or telemetry SDK — nothing measures how you use the app
- No advertising, ad networks or advertising identifiers
- No name, email or phone number unless you choose to sign in with Google for sync
- No access to your location, contacts, camera, microphone, call logs or files outside Sorrel's own storage
Files you export
Sorrel can export recipes and create backup files. These are written only when you ask, only to the location you choose, and the app never transmits them anywhere. Once exported, a file is yours to manage.
Keeping and deleting your data
- Delete any recipe, list, plan or note inside the app at any time. If sync is on, the deletion syncs too.
- Clear everything on the phone with Android's "Clear storage" option for Sorrel, or by uninstalling.
- Anything our server cached while reading a page, a video or a scan for you expires within 90 days and is not tied to you.
- Delete your sync account and everything stored under it from Settings → Your data → Delete account and synced data. It takes effect immediately and does not need a live subscription. See Delete your Sorrel account.
- To have crash reports already sent removed, write to us at the address below. We will do it promptly and confirm.
Children
Sorrel is not directed at children under 13 and does not knowingly collect personal information from anyone, including children.
This website
This site is a set of static pages hosted on Vercel. It sets no advertising cookies and has no login. Two things are worth naming:
- Vercel Web Analytics records how the page is used, in aggregate, so we can tell whether it is working. That is: page views; clicks on the download and call-to-action buttons; clicks on links that leave the site, and on the support email address; which sections of the page you reached; and how far down the page you scrolled, to the nearest quarter. No text you type, no precise location and nothing that identifies you personally is collected, and none of it is joined up into a profile. It is cookie-free and does not follow you across other websites; Vercel processes it as described in Vercel's privacy policy.
- Google Fonts are loaded from Google's servers, which means Google receives your IP address when the page loads.
Household invite links open a page on this site that hands the invite to the Sorrel app; the page itself stores nothing.
Changes to this policy
When Sorrel gains a feature that changes how data is handled, this policy is updated before the feature ships and the "last updated" date above changes. Material changes are also noted in the app's release notes. This revision adds the Sorrel app for iPhone, scanning's ask-first cloud fallback, meal plans arranged on the server, and the cook-timer permissions.
Contact
Questions about this policy, or anything else about privacy in Sorrel, can go to sorrelapp@burnsforce.com.