Privacy policy
Staple — last updated 25 August 2026.
This describes what the app actually does, checked against the source rather than written from a template. If a line here and the code disagree, the code is the bug.
The short version
Staple stores your recipes so they reach your other devices. To turn a link into a recipe it sends the page's text to an AI model through a third party. If you share a shopping list, the person you share it with sees your name and what you put on the list — and nothing else of yours. It uses aggregate product analytics and diagnostics to improve the app. It does not sell anything, show ads, or track you across other apps.
What is collected
| what | why | where it goes | |
|---|---|---|---|
| Account | An anonymous account id, created on first launch before you are asked anything | There has to be somewhere to put a recipe you save before you sign in | Firebase Authentication |
| Account, signed in | Your Google account's name, email address and profile picture URL | So the library reaches your other devices, and so the account sheet can show whose it is | Firebase Authentication |
| Your content | Recipe links, text you paste or type, the recipes themselves, your servings and your shopping list | It is the product | Cloud Firestore |
| Pictures | A copy of the photograph the recipe's own page advertises, and any photograph you pick for a recipe out of your own library | Publishers redesign and move pages; a copy is what keeps the card looking right in a year | Cloud Storage |
| Sharing | Only if you share a shopping list or join one: your name and initials, your Google profile picture if your account has one, and which items you added and which you ticked | So the other person can tell whose list it is, and who already got the milk | Cloud Firestore |
| Reports | Only when somebody reports a shared list: who was reported, the name they were going by, and a random pseudonym for each person involved | So the report can be acted on | Cloud Firestore |
| Analytics | An app-instance identifier, device and OS details, approximate location, screens and sessions, and actions such as saving a recipe or starting cook mode | To understand whether the product works and which paths need improvement | Firebase Analytics |
| Diagnostics | Crash reports and non-fatal API failures, with the affected service and operation, a bounded error code, and device and OS details | To find out what broke without collecting the failed request, its content or its error message | Firebase Analytics and Firebase Crashlytics |
| Logs | Your account id, the recipe id, the attempt number and whether you imported a link or pasted text | To trace an import that failed | Google Cloud Logging, 30 days |
Analytics is not given your account id, recipe or list ids, URLs, invite tokens, names, email address, recipe or shopping-list text, report details, or exception messages. Advertising storage and ad features are disabled, no advertising identifier is collected, and there is no cross-app tracking.
The part worth reading twice
Recipe pages are sent to an AI model. When you share a link, our server fetches that page, reduces it to its text, and sends that text to Google's Gemini through OpenRouter, which routes the request. Anything you paste is sent the same way. So:
- Do not paste something into Staple that you would not want a third party to process.
- The request carries no account id and nothing that identifies you — just the page's text.
- OpenRouter and the model provider handle that text under their own terms.
- It is not used to train a model. The request is routed only to providers that do not collect what is sent to them, and if there is no such provider for a model the request fails rather than going to one that does. That is a promise about training, not about storage: it does not say the text is never written down at the provider's end.
A report outlives the thing it reported. A report holds who was reported, the name they were going by, and a random pseudonym for each person involved rather than a name. Once it has been dealt with it is kept for twelve months and then deleted automatically, because a single report is an incident and several are a pattern, and only the second one can be acted on.
The pictures are readable by anyone holding the link. A stored picture gets a Cloud Storage download URL containing a token. That URL is kept only in your own recipe, and it is not guessable — but it keeps working after the recipe is deleted, and removing a photo from a recipe does not delete what was uploaded. For a picture copied off a recipe page that is a small thing; the photograph was already public on the web. For one you picked yourself it is not, so pick one you would be willing to have live at an unlisted URL. Deleting your account deletes the stored pictures themselves.
Choosing a photo does not give the app your library. The picker the app opens is the system's own and runs outside the app; the app receives the one picture you chose and nothing else, which is why it never asks for photo permission.
Who else can see it
Google, as the operator of Firebase, Analytics and Google Cloud, where the data is stored. OpenRouter and the model provider, for the page text described above. Nothing is sold, and nothing is shared for advertising.
A person here reads what you report. A report goes to whoever is on moderation duty, who sees the text complained of and the pseudonyms, and who decides what happens to the content and to the account behind it.
Anyone you share a shopping list with, if you choose to. A shared list is one list on two phones: everyone on it sees your name, your initials, every item on the list, and which items you added and which you ticked. They do not see your library — a shared list carries the items, never the recipes behind them. You can leave whenever you like, and the list comes with you as a copy of your own.
Anyone holding an invite link. Opening one shows who sent it and how many items and recipes are on their list, before anybody signs in — that is what makes a link worth acting on rather than a string to trust blindly. It names nobody else on the list, and it does not show the items themselves to someone who has not signed in. The link stops working the moment the person who made it turns it off.
Data is stored in Google's eur3 multi-region (European Union). The extraction functions run in europe-west4 (Netherlands). The model call leaves that boundary.
Opening an invite link on getstaple.app makes one request from the page to those same functions, to fetch the sender's name and the two counts. It is the only request the site makes to anywhere but itself, and it is the reason the site's content-security policy names an origin at all.
Deleting it
In the app: account sheet → Delete account…. That erases your recipes, your shopping list, your stored pictures and the account itself. It cannot be undone and support cannot reverse it.
By mail: hello@getstaple.app, from the address on the account.
If you are on a shared list when you delete your account, you come off it and everything that identified you goes with you — your name, and the record of which items were yours and which you ticked. The items themselves stay on the other person's list, unattributed, because deleting your own account should not empty somebody else's trolley in the middle of a shop. If the list was yours and other people are on it, it carries on without you and passes to whoever joined first.
A report is the one thing deletion does not erase, and it is not left as it was: your name and every id that pointed at you come out of it, and what stays is the random pseudonym and the text that was reported. Twelve months after that report was resolved, it goes too. Blocks other people hold against you are removed with the account. The reason a report survives at all is that deleting an account is otherwise a way to erase the evidence of what was done with it.
Deleting a single recipe removes it everywhere, and it is immediate. Cloud Logging entries expire on their own schedule (30 days) and are not deleted on request, because they are keyed to an account id that no longer resolves to anybody. Analytics and diagnostic data are not linked to that account id and expire under the retention configured for those services.
Children
Staple is not directed at children and is not designed for anyone under 13.
Changes
The date at the top moves when this changes. A change that affects what is collected or who receives it will be said in the app before it takes effect.