Privacy Policy

Who this policy covers

This policy applies to the Sorrel app for Android (com.burnsoft.sorrel), to the Sorrel app for iPhone, to the Sorrel server at api.sorrelapp.io that some of their features use, and to this website. "Sorrel", "we" and "us" mean the developer of the Sorrel app.

What Sorrel stores on your device

Everything you create in Sorrel is written to private app storage on your phone:

Unless you turn on sync (below), this data is not uploaded anywhere, and we have no ability to read it. Sorrel requests the Android permissions it can explain: INTERNET, Google Play billing, and — for cook timers — showing notifications, vibrating, and keeping a timer counting after you leave the app. It never asks for your location, contacts, camera, microphone, call logs or files outside its own storage. Scanning a recipe card uses a scanner screen provided by Google Play services (or your photo picker), which hands Sorrel the finished pages; Sorrel does not hold camera permission itself.

What leaves your device, and when

Importing a recipe from a web link

When you paste or share a link, your phone fetches that page directly from the website that hosts it. The website sees your IP address, the page you asked for and a standard mobile browser user-agent string — exactly as if you had opened the link in Chrome — and its own privacy policy governs what it does with that. Sorrel then reads the recipe out of the page on your phone, and in most cases that is the end of it: nothing is sent to us.

Some pages hide the recipe in ways Sorrel cannot read on its own. When a page looks like a recipe but Sorrel cannot find both its ingredients and its steps, it sends the page's address, title and visible article text (never the raw HTML, and capped at roughly 10,000 characters) to our server, which asks an AI model run by Anthropic to pick out the recipe. The model receives the text, the title and the page address without its query string. It does not receive anything that identifies you. Our server keeps the recipe it read, filed under the page's address, for up to 90 days so the next person who imports the same page gets it instantly.

Importing from a video (Sorrel Pro)

When you share a TikTok, Instagram or YouTube link, your phone sends only the link to our server. The server fetches the video from that platform itself — the platform sees our server's address, not yours — and works up a ladder until it has a recipe:

The downloaded video, audio and frames are deleted as soon as the import finishes, on every outcome. The server keeps the transcript and the finished recipe, filed under the video's id, for up to 90 days (24 hours if the result needed your review), so a popular video is only ever read once. Your phone also sends the Google Play purchase token that proves your Pro subscription (see "Google Play" below).

Scanning a recipe card (Sorrel Pro)

Scanning starts, and usually ends, on your phone. The pages come from a scanner screen provided by Google Play services or from your photo picker; text recognition runs on-device with a bundled model; the photos and the recognised text are stored with the recipe in Sorrel's private storage. If that reading comes back incomplete, Sorrel asks whether to send the scan — the photos, or just the recognised text — to our server, which asks the Anthropic model to read it. Nothing is sent unless you agree, the pages are discarded as soon as they have been read, and the server keeps only the finished recipe, filed under a fingerprint of the scan rather than under you, for up to 90 days. (If sync is on, the recognised text travels with the recipe like any other recipe text; the photos do not.)

Letting Sorrel plan the week (Sorrel Pro)

The free planner fills your week on the phone, offline. If you ask Sorrel to arrange the week instead, your phone sends our server a list of candidates from your library — titles, tags, times and how often you've made them, identified by ids — and the Anthropic model picks and orders them. The server answers with those ids and forgets the request: nothing about it is cached or stored.

Sync (Sorrel Pro)

Sync is off until you turn it on in Settings. When you do, Sorrel creates an account for you on our server:

Sync uploads your recipes (including the cook journal, notes, ratings, tags and the original text they were read from), collections, grocery items, meal plans and aisle corrections. Photos stay on the phone they were taken on and are not uploaded. Your phone syncs a few seconds after you change something, roughly every six hours in the background, and while a household's grocery list is open.

This data is stored on a server we run on Microsoft Azure, in a database only our server software can reach, over encrypted connections. It is stored so that it can be delivered to your other phones and your household; we do not read it, analyse it, sell it or use it for anything else. Alongside the account we store the Google Play purchase token that proves your subscription, so that a household you own stays unlocked for its members.

"Sign out" in Settings stops the phone syncing and forgets its access token; your library stays on the phone, and so does the copy on the server, ready for your other phones. To erase the account itself, use Settings → Your data → Delete account and synced data: it deletes the account and everything stored under it immediately, and a lapsed subscription never blocks it. See Delete your Sorrel account.

Household sharing (Sorrel Pro)

A household is a group of sync accounts that share one cookbook and one grocery list. Starting a household requires Pro; joining one does not — the owner's subscription covers everyone. Within a household:

Loading recipe photos

Photos for imported recipes are fetched from the website or platform the recipe came from, then cached on your device.

Crash reports — only if you turn them on

Sorrel asks you once, on first launch, whether it may send a report when it crashes. The answer defaults to no; dismissing the question counts as declining. The setting lives under ⋮ → Settings → Send crash reports, and turning it off stops reporting immediately.

If you turn it on, then when the app crashes it sends the error and stack trace, your device model, and the Android and Sorrel version numbers — and only at the moment of a crash, never on launch or while you use the app. Your recipes, photos and lists are never included; Sorrel explicitly disables the parts of the crash reporter that would attach a screenshot, a view hierarchy, your IP address or any identifier for you or your device. Reports are processed on our behalf by Sentry and used for one thing: finding and fixing bugs.

What our server keeps about requests

Requests your phone makes to our server carry a random install token, created once when Sorrel is installed and not derived from your device or account. Two do not: signing out and deleting your account send the account's access token alone, because both exist to wind something down rather than to use the service. The server never stores the install token; it keeps only a short one-way hash of it, which it uses to apply fair-use limits and to count how many imports succeed or fail. For each import it records how it went — the platform, the outcome, how long it took, what it cost us — for 90 days, and never the address, title, caption or recipe. Usage counts are kept for seven days. Our hosting provider and web server may keep standard connection logs, including IP addresses, for security and reliability.

Google Play and the App Store

These interactions are covered by Google's Privacy Policy and Apple's Privacy Policy.

What we do not collect

Files you export

Sorrel can export recipes and create backup files. These are written only when you ask, only to the location you choose, and the app never transmits them anywhere. Once exported, a file is yours to manage.

Keeping and deleting your data

Children

Sorrel is not directed at children under 13 and does not knowingly collect personal information from anyone, including children.

This website

This site is a set of static pages hosted on Vercel. It sets no advertising cookies and has no login. Two things are worth naming:

Household invite links open a page on this site that hands the invite to the Sorrel app; the page itself stores nothing.

Changes to this policy

When Sorrel gains a feature that changes how data is handled, this policy is updated before the feature ships and the "last updated" date above changes. Material changes are also noted in the app's release notes. This revision adds the Sorrel app for iPhone, scanning's ask-first cloud fallback, meal plans arranged on the server, and the cook-timer permissions.

Contact

Questions about this policy, or anything else about privacy in Sorrel, can go to sorrelapp@burnsforce.com.