Privacy & cookies

Last updated: April 2026. This policy explains what data we collect, why we collect it, the legal basis for processing, and your privacy rights under GDPR/RODO.

1. Data controller

The controller of personal data is Michal Kielkowski (Get Cookin) (the entity operating this website). Contact: [email protected], Rybnik, Poland.

2. What we collect

Account data: email address, password hash, authentication provider (local or Google), login session identifiers.

Content data: recipes, inventory items, profile-related data you create in the app.

Technical data: IP address, request logs, user agent, timestamps, and security/rate-limit events.

Cookie and browser storage: essential authentication cookie, locale preference (`getcookin-locale`), and your optional consent choices stored in browser local storage (`get_cookin_cookie_consent_prefs`).

Optional analytics data (if consented): page views, approximate location, browser/device metadata, engagement metrics from Google Analytics 4.

Optional advertising data (if consented): ad delivery and measurement via Google AdSense (cookies/identifiers used by Google for ads).

3. Why we collect data and legal basis

Provide the service: account login, recipe/inventory features, image handling (GDPR Art. 6(1)(b), contract performance).

Security and abuse prevention: protect accounts, detect attacks, enforce rate limits (GDPR Art. 6(1)(f), legitimate interest).

Legal obligations: where required by law (GDPR Art. 6(1)(c)).

Analytics and ads: improve website quality, traffic analysis, UX decisions, and ad funding only after consent (GDPR Art. 6(1)(a), consent).

4. Cookies and consent

We use strictly necessary cookies for authentication and security. Optional analytics and advertising scripts (Google Analytics 4, Google AdSense) load only if you opt in via the banner or this page. Your choice is stored in browser local storage (not only cookies). You can change your choice at any time below.

4a. Cookie and storage list

Name / keyTypePurposeDurationThird party
token (or configured auth cookie name)HTTP cookie (httpOnly)Logged-in sessionTypically up to 7 daysGet Cookin
google_oauth_stateHTTP cookie (httpOnly)CSRF protection during Google sign-inAbout 10 minutesGet Cookin
getcookin-localeHTTP cookie + local storageLanguage preference (EN/PL)Up to 1 yearGet Cookin
get_cookin_cookie_consent_prefsBrowser local storageStores your optional analytics/ads choicesUntil you clear site dataGet Cookin
Google Analytics / AdSense cookiesHTTP cookies (third party)Measurement and ads (only if you opt in)Set by Google; see Google policiesGoogle

5. Data recipients and international transfers

We use service providers for hosting, logging, and (if you consent) measurement and advertising.

Google Ireland Limited / Google LLC (United States): Google Analytics 4 and Google AdSense when you opt in. Google may process data in the EU and the US under its terms and certification mechanisms (where applicable).

Other infrastructure providers process data only on our instructions and under appropriate safeguards.

6. Retention

We keep personal data only as long as needed for the purposes above, including account operation, legal obligations, and security auditing. Analytics and ad-related data retention depends on your consent status and Google's settings for Analytics and AdSense.

7. Your GDPR/RODO rights

You have the right to access, rectify, erase, restrict processing, object to processing, and request data portability where applicable.

You can withdraw consent at any time for consent-based processing (analytics and advertising), without affecting lawfulness of processing before withdrawal.

You also have the right to lodge a complaint with a competent supervisory authority.

8. Children

This service is not intended for children under 18, and we do not knowingly collect personal data from children.

9. Changes to this policy

We may update this policy from time to time. Material changes will be published on this page with an updated date.

Contact

For privacy requests or questions, contact us at [email protected], Rybnik, Poland.

← Back to home