Last Updated: 1 February 2026
This Privacy Policy explains how Carbonara, operated by Christos Sotirelis, based in Greece ("we", "us", "our"), collects, uses, stores, and protects your personal data when you use the Carbonara mobile application ("the App") or visit our website.
We are committed to protecting your privacy and complying with all applicable laws, including the EU General Data Protection Regulation (GDPR).
By using Carbonara, you agree to the practices described in this Privacy Policy.
The Data Controller for your personal data is:
Christos Sotirelis
Greece
Contact us
We collect personal data in the following categories:
All stored securely in Supabase.
When you use the contact form on our website, we receive:
Used only to respond to your inquiry; sent via our email provider (Resend).
If you submit feedback from within the App (Settings → Feedback), we store your message linked to your account in Supabase to improve the service and respond where appropriate.
We collect event-level usage data such as:
All data sent to PostHog is pseudonymous (no name or email unless explicitly configured).
Carbonara uses external AI and extraction services to import and structure recipes:
We send only the necessary content, such as:
We never send:
AI providers process data temporarily for output generation. They do not store your data for training unless you opt in (we do not enable this).
To manage Pro subscriptions, we share:
We never receive your credit card information—payments are handled by:
Your recipe data and images are stored in Supabase, located in EU data centers when available. Supabase maintains industry-standard security and encryption.
We use your data to:
We do not sell your personal data.
We process data based on:
To provide the core functions of Carbonara:
You may object to processing under legitimate interest (see Section 8).
For:
To comply with EU or Greek law.
We share data only with trusted service providers:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database, auth, storage | Account & recipe data |
| PostHog | Analytics & error tracking | Pseudonymous event data |
| RevenueCat | Subscription validation | App user ID & receipt tokens |
| OpenAI / Gemini | Recipe extraction | Uploaded text/video/image content |
| Apify | Scraping TikTok/Instagram | Public video metadata |
| Apple/Google | Payments | Purchase information |
| Resend | Contact form delivery | Name, email, message |
We do not share your personal data with advertisers.
We retain data for as long as your account is active.
Carbonara is not intended for children under 16 years old. We do not knowingly collect personal data from children.
If we discover such data has been collected, we will delete it immediately.
You have the right to:
To exercise your rights, contact us at: our contact form
We use:
However, no online service can guarantee 100% security.
We aim to store and process data within the EU whenever possible.
Some providers (e.g., OpenAI, Google) may process data outside the EU. In those cases, transfers are protected by:
The Carbonara website may use:
You can manage cookie preferences via your browser settings.
We may update this Privacy Policy to reflect changes in:
We will notify users when required by law.
If you have questions about this Privacy Policy or your data rights:
Christos Sotirelis
Greece
Contact us