食万里隐私政策
版本 v2.0 · 更新日期:2026 年 7 月 29 日 · 生效日期:2026 年 7 月 29 日
食万里(英文名 Cookabout,下称"本应用")由长沙市海豚创享科技有限公司(下称"我们")开发运营。我们深知个人信息对你的重要性,并会尽全力保护你的个人信息安全可靠。
本政策的设计原则是尽量少收集:本应用无广告、不含任何广告或第三方统计分析 SDK、不收集位置信息、不读取通讯录、不采集设备唯一标识用于画像、绝不出售你的个人信息。
请你在使用本应用前仔细阅读本政策,特别是加粗的条款。如你不同意本政策的任何内容,应立即停止使用本应用。
- 一、我们如何收集和使用你的个人信息
- 二、个人信息收集清单
- 三、应用权限申请与使用清单
- 四、第三方 SDK 清单
- 五、委托处理与对外提供清单
- 六、共享厨房中的信息可见范围
- 七、信息的存储地域与保存期限
- 八、信息安全保护措施
- 九、你的权利
- 十、未成年人保护
- 十一、本政策的更新
- 十二、如何联系我们
一、我们如何收集和使用你的个人信息
1.1 为实现基本功能,你需要提供的信息
- 账号信息(登录时收集)。本应用按发行渠道提供不同的登录方式:
- 手机号验证码登录——我们收集你的手机号码,仅用于创建账号、登录身份验证与账号找回。手机号码属于个人信息,不提供则无法使用需登录的功能。我们不会将手机号本身作为昵称对外展示,系统会为你生成默认昵称(如"厨友尾号")。
- 华为账号登录(鸿蒙版)——你授权后,我们仅接收华为签发的身份令牌(id_token),并从中解析出你在本应用内的唯一标识(OpenID);若令牌中包含邮箱,我们会用它生成默认昵称。我们不会获得也不会存储你的华为账号密码。
- Google / Apple 登录(海外版)——获得你授权提供的邮箱地址与昵称;我们无法获取、也不存储你的 Google/Apple 账号密码。
- 日志信息(自动收集)。你访问我们的服务时,服务器会按行业通行做法记录访问日志,包含 IP 地址、请求时间、请求的接口路径与结果状态。这些日志仅用于保障服务安全、排查故障与防范滥用,不用于识别你的身份,亦不与你的账号信息关联分析。
1.2 你可以选择提供的信息(拒绝不影响基本功能)
- 储藏室与饮食偏好。若你使用"今晚吃什么"功能,可以填写家中现有食材、饮食目标、食物过敏原或忌口。这些信息保存在我们的服务器并与你的账号关联,以便在你的多台设备间同步。其中过敏原与忌口信息可能构成敏感个人信息:我们仅在你主动填写时收集,仅用于菜品推荐与过敏原提示,不作其他用途,你可以随时在应用内清除。
- 菜单照片("扫菜单"功能)。你在餐厅使用扫菜单时,可以拍摄或从相册选择菜单照片上传。照片仅用于本次菜单识别与点餐建议的生成,解析完成后我们不保存照片本身。本应用不会读取或扫描你相册中的其他内容。
- 语音录音("语音记账/语音入库"功能,Pro 功能)。你可以按住按钮说话把食材加进储藏室。录音仅在你按住按钮期间采集,松手即停,本应用不会在后台录音、不会在你未主动操作时开启麦克风。录音会上传至我们的服务器转写为文字,转写完成后音频不予保存;这句话表达的是"加"还是"删"、命中哪样食材,完全在你的设备本地计算。
- 成品照片("做菜复盘"功能)。你拍摄的成品照片存储在你自己的设备上,不会上传到我们的服务器。
- 推送标识。当你加入共享厨房后,为了在家人向你推荐菜品时通知你,我们会向系统推送服务申请推送令牌(Token)并保存,仅用于向你的设备下发本应用的通知。你可以在系统设置中随时关闭通知。
- 你主动发给我们的信息。你通过邮件向我们反馈或求助时,我们会收到你的邮箱地址与邮件内容。
- 应用内反馈。你在"我的 → 支持与反馈"里写的内容、你自愿留下的联系方式、以及你选择附上的截图(最多 3 张),会提交到我们的反馈收件箱。为了让我们能复现你说的问题,这条反馈会同时带上应用版本号、操作系统名称与版本、以及一个应用内随机生成的安装标识(见下条)。不登录也能提交;已登录时会一并带上你的账号 id,便于我们回头对上你的情况。
- 故障诊断信息(崩溃与异常上报)。本应用崩溃或出现内部异常时,会自动上报错误信息、调用堆栈、出错时所在的页面、应用版本号、操作系统名称与版本、以及安装标识,用于定位并修复问题。不包含你的菜谱内容、储藏室、照片或录音。该上报仅在你同意本政策之后发生。
- 安装标识。上面两项用到的"安装标识"是本应用首次启动时自己随机生成的一串字符,保存在本机,不是设备唯一标识——它与 IMEI/OAID/IDFA 无关、无法用于跨应用追踪,卸载重装即变成新的一串。它的唯一用途是给反馈与故障上报做频次限制,并把同一台设备上的多条上报串起来看。
1.3 我们明确不收集的信息
- 位置信息——本应用不申请任何定位权限,不收集你的地理位置;
- 广告标识符——本应用无广告,不含任何广告 SDK;
- 第三方统计分析数据——本应用不含友盟、GA 等任何第三方统计分析 SDK;
- 通讯录、通话记录、短信内容、日历、剪贴板;
- 设备唯一标识(IMEI/OAID/IDFA 等)——我们不采集设备唯一标识,不做跨应用追踪或用户画像;
- 你相册中除你主动选择上传的菜单照片以外的任何内容。
1.4 关于 AI 生成内容
本应用的制作讲解、菜品推荐、菜单识别与语音转写由 AI 模型能力支持。AI 生成的内容仅供参考,可能存在不准确之处,应用内已作标注。你提交给这些功能的内容(提问文本、菜单照片、语音音频)会传输给我们委托的 AI 服务商,仅用于生成本次结果,且不附带你的账号身份信息,服务商不得用于其自身目的。
二、个人信息收集清单
| 个人信息 | 收集场景 | 使用目的 | 是否必需 | 保存期限 |
| 手机号码 | 手机号验证码登录时 | 创建账号、身份验证、账号找回 | 登录必需 | 账号存续期间 |
| 华为账号唯一标识(OpenID) | 使用华为账号登录时 | 创建并关联账号、身份验证 | 该登录方式必需 | 账号存续期间 |
| 邮箱地址、昵称 | 使用 Google / Apple 登录时(海外版) | 创建账号、生成默认昵称 | 该登录方式必需 | 账号存续期间 |
| 昵称 | 系统自动生成或你主动修改 | 应用内及共享厨房中标识你 | 否 | 账号存续期间 |
| 储藏室食材选择 | 你在储藏室勾选或语音添加食材时 | "今晚吃什么"推荐、购物清单 | 否 | 账号存续期间,可随时清除 |
| 饮食偏好、过敏原与忌口(可能构成敏感个人信息) | 你在引导设置或"我的"中主动填写时 | 菜品推荐过滤、过敏原提示 | 否 | 账号存续期间,可随时清除 |
| 菜单照片 | 你主动使用"扫菜单"并选择照片时 | 识别菜单、生成点餐建议 | 否 | 不保存,识别完成即丢弃 |
| 语音音频 | 你按住按钮说话时 | 转写为文字以添加/移除食材 | 否 | 不保存,转写完成即丢弃 |
| 成品照片 | 你在"做菜复盘"中拍照时 | 记录你的烹饪成长 | 否 | 仅存于你的设备,不上传 |
| 推送令牌(Token) | 你加入共享厨房并同意通知后 | 向你的设备下发本应用通知 | 否 | 至你关闭通知或注销账号 |
| 共享厨房成员关系与点选记录 | 你创建或加入共享厨房、发出推荐/点选时 | 实现家庭点菜功能 | 否 | 至你退出该厨房或注销账号 |
| 服务器访问日志(IP 地址、时间、接口路径) | 你使用需联网的功能时自动记录 | 服务安全、故障排查、防滥用 | 是(技术必需) | 不超过 6 个月 |
| 邮箱地址与邮件内容 | 你主动发邮件联系我们时 | 回复你的反馈与求助 | 否 | 问题解决后即清理 |
| 反馈内容、自愿留下的联系方式、你附上的截图 | 你在应用内提交反馈时 | 了解并解决你反馈的问题 | 否 | 问题解决后即清理 |
| 错误信息、调用堆栈、出错页面 | 应用崩溃或发生内部异常时自动上报 | 定位并修复故障 | 否 | 不超过 6 个月 |
| 应用版本号、系统名称与版本、安装标识 | 随上面两项一并提交 | 复现问题、上报频次限制 | 否 | 随所属记录一并清理 |
三、应用权限申请与使用清单
本应用遵循最小必要原则申请权限。所有权限均在你首次使用对应功能时才动态申请,拒绝授权仅影响该项功能,不影响本应用其他功能的正常使用;授权后你也可以随时在系统设置中关闭。
| 平台 | 权限 | 使用目的 | 申请时机 | 可否拒绝 |
HarmonyOS (鸿蒙版) | 网络访问
ohos.permission.INTERNET | 获取菜谱内容与图片、账号登录、云端同步 | 安装即具备(非敏感权限) | — |
麦克风
ohos.permission.MICROPHONE | "语音入库":按住说话把食材加进储藏室 | 首次按住语音按钮时 | 可拒绝,仅该功能不可用 |
| 鸿蒙版不申请相机与相册权限:扫菜单与做菜复盘的选图通过系统安全选图器完成,你选中哪张我们才拿到哪张,应用无法访问相册中的其他内容。 |
Android (安卓版) | 网络访问
android.permission.INTERNET | 同上 | 安装即具备(非敏感权限) | — |
录音
android.permission.RECORD_AUDIO | "语音入库":按住说话把食材加进储藏室 | 首次按住语音按钮时 | 可拒绝,仅该功能不可用 |
相机 / 读取媒体 (由系统选图组件按需申请) | "扫菜单"拍摄或选择菜单照片、"做菜复盘"拍摄成品 | 首次使用扫菜单或复盘拍照时 | 可拒绝,仅该功能不可用 |
| iOS | 麦克风 | "语音入库" | 首次按住语音按钮时 | 可拒绝,仅该功能不可用 |
| 相机 / 相册 | "扫菜单"、"做菜复盘" | 首次使用对应功能时 | 可拒绝,仅该功能不可用 |
| 通知 | 共享厨房中家人向你推荐菜品时提醒你 | 你加入共享厨房后 | 可拒绝,仅收不到通知 |
本应用不申请以下权限:定位、通讯录、通话记录、短信、日历、身体传感器、悬浮窗、开机自启动、读写系统设置。
四、第三方 SDK 清单
为实现特定功能,本应用嵌入了下列第三方 SDK。它们会在你使用对应功能时收集或处理必要的信息,具体规则以其各自的隐私政策为准。本应用不含任何广告 SDK、统计分析 SDK 或推广类 SDK。
| SDK 名称 | 提供方 | 使用平台 | 使用目的 | 处理的个人信息 | 隐私政策 |
华为账号服务 (Account Kit) |
华为软件技术有限公司 |
HarmonyOS |
华为账号一键登录 |
华为账号身份令牌(id_token),其中包含你在本应用内的唯一标识 |
查看 |
Google 登录 (Google Sign-In) |
Google LLC |
Android(海外版) |
Google 账号登录 |
邮箱地址、昵称 |
查看 |
通过 Apple 登录 (Sign in with Apple) |
Apple Inc. |
iOS(海外版) |
Apple 账号登录 |
邮箱地址(可隐藏)、昵称 |
查看 |
应用内购买 (In-App Purchase) |
Apple Inc. / Google LLC |
iOS / Android |
Pro 订阅的购买与校验 |
由应用商店处理,我们仅接收订阅是否有效的结果,不接触你的支付信息 |
见各应用商店政策 |
五、委托处理与对外提供清单
下列服务由我们在服务器侧调用,属受我们委托处理个人信息的情形。我们会与受托方签订协议,约定其处理目的、期限与保护义务,受托方不得将信息用于本表列明目的以外的用途。
| 受托方 | 服务内容 | 提供的信息 | 目的 |
| 腾讯云计算(北京)有限责任公司 |
短信服务 |
你的手机号码 |
向你发送登录验证码短信(仅在你请求验证码时提供) |
| 北京火山引擎科技有限公司 |
AI 大模型与语音识别服务 |
你提交的提问文本、菜单照片、语音音频 不含你的账号标识、手机号等身份信息 |
生成制作讲解与推荐、识别菜单、将语音转写为文字 |
推送服务提供方 (Apple APNs / 相应终端厂商推送服务) |
消息推送通道 |
推送令牌(Token)与通知内容 |
将共享厨房的推荐通知送达你的设备 |
除上表所列情形,以及法律法规明确要求或取得你另行单独同意的情形外,我们不会向任何第三方提供你的个人信息。我们绝不出售你的个人信息。
六、共享厨房中的信息可见范围
"共享厨房"是供家人之间一起决定吃什么的功能。加入同一个共享厨房后:
- 你的昵称、你发出的菜品推荐与点选记录,对同一厨房内的其他成员可见;
- 你的手机号码、登录方式、过敏原与饮食偏好的具体内容不会展示给其他成员;
- 为孩子创建的成员不需要手机号,也不产生登录凭证,仅有一个昵称;
- 你可以随时退出共享厨房,退出后你的推荐与点选记录不再对其他成员展示。
七、信息的存储地域与保存期限
存储地域。中国大陆版本用户的个人信息存储于位于中华人民共和国境内的服务器。我们不会将中国大陆用户的个人信息传输至境外。如未来确有出境必要,我们将另行取得你的单独同意,并依法完成安全评估或认证等法定程序。
保存期限。各类信息的保存期限见第二节收集清单。总体原则是:账号存续期间保留为提供服务所必需的信息;你注销账号后,你的个人信息将从在用系统中抹除,常规备份中的残留副本随备份周期正常覆盖;法律法规对保存期限另有强制规定的,从其规定。
八、信息安全保护措施
- 全站及全部接口传输使用 HTTPS/TLS 加密;
- 登录凭证存储于设备的系统安全存储区(iOS Keychain / Android Keystore / 鸿蒙对应能力),不以明文写入普通偏好文件;
- 服务端遵循最小权限原则控制数据访问,并保留操作审计;
- 提供"登出全部设备"功能,如你怀疑账号被他人使用,可立即终止所有会话;
- 我们通过"只收集必要的最少数据"从源头控制风险。
请注意:互联网环境并非绝对安全。若不幸发生个人信息安全事件,我们将按法律法规要求,及时以推送通知、应用内公告或邮件等方式告知你事件基本情况、我们已采取的处置措施与你可采取的建议措施,并向监管部门报告。
九、你的权利
- 查阅与复制——你可在应用内查看你的账号信息、储藏室与偏好设置;需要副本的,可通过下方邮箱申请。
- 更正与补充——昵称、储藏室、饮食偏好与过敏原均可在应用内直接修改;其他信息可通过邮箱申请更正。
- 删除——你可在应用内清除储藏室、过敏原等单项信息;也可通过注销账号删除全部个人信息。
- 撤回同意——清除相应设置即撤回对该项信息处理的同意;在系统设置中关闭麦克风、相机、通知权限,即撤回对应授权。撤回不影响此前基于你的同意已进行的处理。
- 注销账号——前往 我的 → 账号 → 注销账号,按提示确认即可。注销将解绑你的登录身份并抹除我们系统中你的个人信息,该操作不可恢复。你也可以使用账号关联的手机号或邮箱发邮件至 support@echohey.com 申请注销,我们将在15 个工作日内完成核验并处理,最长不超过 30 天。
- 获取副本与转移——你可申请获取账号信息与偏好设置的副本;符合国家网信部门规定条件的转移请求,我们将提供转移途径。
- 要求解释说明——你可要求我们对本政策的条款作出解释说明。
我们将在收到你的请求后15 个工作日内作出答复。对于无正当理由重复请求、需要过多技术手段、可能危害他人合法权益或不具可行性的请求,我们可能予以拒绝并说明理由。
十、未成年人保护
本应用主要面向成年人。若你是不满 14 周岁的儿童,请务必在你的父母或其他监护人的陪同下阅读本政策,并在取得监护人同意后使用本应用及向我们提供个人信息。
我们不会主动向不满 14 周岁的儿童收集个人信息。若你是儿童的监护人,对被监护人的个人信息有任何疑问,或希望查阅、更正、删除被监护人的个人信息,请通过下方联系方式与我们联系,我们将在核实身份后优先处理。若我们发现在未事先取得监护人同意的情况下收集了儿童的个人信息,将设法尽快删除相关信息。
共享厨房中为孩子创建的成员不需要手机号、不产生登录凭证,我们仅保存一个由户主填写的昵称。请户主不要将孩子的真实姓名、学校等信息填入昵称。
十一、本政策的更新
我们可能不时更新本隐私政策。发生下列重大变更时,我们会通过应用内弹窗、显著位置公告等方式另行通知你,并在必要时重新征得你的同意:
- 服务模式发生重大变化,如处理个人信息的目的、类型、使用方式发生变化;
- 控制权发生变更,如并购重组引起的所有者变更;
- 个人信息共享、转让或公开披露的主要对象发生变化;
- 你参与个人信息处理方面的权利及其行使方式发生重大变化;
- 个人信息安全影响评估报告表明存在高风险。
我们会在本页顶部标注版本号与更新日期。变更生效后你继续使用本应用,即表示你已充分阅读、理解并同意受更新后的政策约束。
十二、如何联系我们
如你对本政策有任何疑问、意见或建议,或需要行使上述任何权利,可通过以下方式联系我们。我们设有个人信息保护负责人,你的请求将转交其处理。
我们将在收到你的问题、意见或建议后15 个工作日内予以答复。如你对我们的答复不满意,特别是认为我们的个人信息处理行为损害了你的合法权益,你还可以向网信、电信、公安及市场监管等监管部门投诉举报,或向运营者注册地(湖南长沙)有管辖权的人民法院提起诉讼。
Cookabout Privacy Policy
Version 2.0 · Last updated: July 29, 2026 · Effective: July 29, 2026
Cookabout ("we," "us," or "our") is developed and operated by Echohey (Changsha Dolphin Chuangxiang Technology Co., Ltd.). This Privacy Policy explains what information the Cookabout mobile application (the "App") collects, how we use it, and the choices you have.
Cookabout is designed to collect as little personal information as possible: we show no ads, we include no advertising or third-party analytics SDKs, we never collect your location, we never collect device advertising identifiers, and we never sell your data.
1. Information We Collect
1.1 Information required for core functionality
- Account information. Sign-in methods vary by distribution channel:
- Phone number with verification code — we collect your phone number, used only to create your account, verify sign-in, and recover access. Your phone number is never displayed as your public nickname.
- Huawei ID (HarmonyOS build) — with your authorization we receive only an identity token issued by Huawei, from which we derive a unique identifier (OpenID) for your account. We never receive or store your Huawei ID password.
- Google / Apple sign-in (international builds) — we receive the email address and name (or nickname) you authorize them to share. If you use Apple's "Hide My Email," we only receive the private relay address. We never receive or store your Google or Apple password.
- Server logs. Our servers record standard access logs containing IP address, request time, endpoint path, and response status, used solely for security, troubleshooting, and abuse prevention. Logs are retained for no more than 6 months.
1.2 Information you may choose to provide
- Your pantry and dietary preferences. If you use the "What's for dinner tonight" feature, you can tell the App which ingredients you have at home, your dietary goals, and any food allergies or restrictions. Allergy information may constitute sensitive personal information; it is collected only when you enter it, used only for dish filtering and allergen warnings, and can be cleared at any time.
- Menu photos you choose to scan. Each photo is used only to recognize the dishes and generate ordering suggestions for that request; we do not keep the photo afterward. The App never scans or reads other content in your photo library.
- Voice recordings (Pro feature). You can press and hold a button to speak and add ingredients to your pantry. Audio is captured only while you hold the button — the App never records in the background. The audio is uploaded to be transcribed into text and is discarded immediately after transcription.
- Finished-dish photos. Photos you take in the cooking log are stored on your device only and are not uploaded to our servers.
- Push token. After you join a shared kitchen, we request and store a push token so we can notify you when a family member suggests a dish. You can turn notifications off at any time in system settings.
- Information you send us directly. If you email us, we receive your email address and the contents of your message.
- In-app feedback. What you write under "Me → Support & feedback", any contact detail you choose to leave, and up to three screenshots you attach are sent to our feedback inbox. So we can reproduce what you describe, the message also carries the app version, operating system name and version, and a randomly generated install identifier (see below). No sign-in is required; if you are signed in, your account id is included so we can match the report to your situation.
- Diagnostics (crash and error reports). When the app crashes or hits an internal error, it reports the error message, stack trace, the screen you were on, the app version, operating system name and version, and the install identifier so we can find and fix the problem. It never includes your recipes, pantry, photos or recordings, and it only happens after you accept this policy.
- Install identifier. The identifier used by the two items above is a random string the app generates for itself on first launch and stores on your device. It is not a device identifier — unrelated to IMEI/OAID/IDFA, unusable for cross-app tracking, and replaced by a new one if you reinstall. Its only purpose is rate-limiting feedback and crash reports, and grouping reports that came from the same device.
1.3 Information we do NOT collect
- Your location — the App never requests location permissions;
- Advertising identifiers (IDFA/AAID) — the App contains no ads and no advertising SDKs;
- Analytics data — the App contains no third-party analytics SDKs;
- Contacts, call logs, SMS, calendar, or clipboard contents;
- Device unique identifiers for profiling or cross-app tracking;
- Anything in your photo library other than the menu photo you actively select.
2. How We Use Your Information
- Create and maintain your account, and keep you signed in across your devices;
- Provide dish suggestions matching your pantry ingredients, dietary goals, and allergen settings;
- Recognize the menu photos you submit and generate ordering suggestions;
- Transcribe your voice input into pantry changes;
- Deliver shared-kitchen notifications to your device;
- Respond to your support requests and feedback;
- Maintain the security of our service, including "sign out of all devices."
We do not use your information for advertising or for profiling unrelated to the App's cooking features. We never sell your personal information and never share it with third parties for their marketing purposes.
AI processing. The App's AI features (cooking guidance, dish suggestions, menu scanning, and speech-to-text) are powered by third-party AI model providers acting on our behalf. Content you submit for these features is transmitted to the provider solely to generate that response, without your account identity attached, and the provider may not use it for its own purposes. AI-generated content is for reference only and may be inaccurate; it is labeled as such in the App.
3. App Permissions
All permissions are requested only when you first use the corresponding feature. Declining a permission disables only that feature and does not affect the rest of the App.
- Microphone — press-and-hold voice input for the pantry. Captured only while you hold the button.
- Camera / Photos — menu scanning and cooking-log photos. On HarmonyOS the App requests neither permission: photo selection goes through the system's secure picker, so we only ever receive the single image you pick.
- Notifications — shared-kitchen suggestions from family members.
- Network access — recipe content and images, sign-in, and cloud sync.
The App does not request location, contacts, call logs, SMS, calendar, body sensors, overlay, or auto-start permissions.
4. Third-Party SDKs
| SDK | Provider | Platform | Purpose | Data handled |
| Account Kit | Huawei | HarmonyOS | Huawei ID sign-in | Identity token containing your unique identifier |
| Google Sign-In | Google LLC | Android | Google sign-in | Email address, name |
| Sign in with Apple | Apple Inc. | iOS | Apple sign-in | Email address (may be relayed), name |
| In-App Purchase | Apple / Google | iOS / Android | Pro subscription | Handled by the app store; we receive only entitlement status and never see your payment details |
Service providers acting on our behalf on the server side: Tencent Cloud (SMS verification codes — receives your phone number only when you request a code), Volcano Engine (AI models and speech recognition — receives your submitted text/photo/audio without your account identity), and platform push services (Apple APNs and the relevant device vendor's push service).
5. Shared Kitchen Visibility
Within a shared kitchen, your nickname, the dishes you suggest, and the dishes you pick are visible to other members of that kitchen. Your phone number, sign-in method, allergens, and dietary preferences are not. Child members require no phone number and have no sign-in credentials — only a nickname. You may leave a shared kitchen at any time.
6. Data Storage and Security
Personal information of users in mainland China is stored on servers located within the People's Republic of China and is not transferred abroad. All traffic uses HTTPS/TLS encryption. Sign-in credentials are stored in the device's secure storage (iOS Keychain / Android Keystore / the HarmonyOS equivalent), never in plain preference files. We apply least-privilege access control and retain audit logs on the server side.
The App also provides "Sign out of all devices" so you can immediately end all active sessions. No method of transmission or storage is 100% secure, but we limit risk by collecting only the minimum data necessary. In the event of a data breach we will notify affected users and the relevant authorities as required by law.
7. Data Retention
We keep your account information and preferences for as long as your account exists. Menu photos and voice audio are never retained. When you delete your account, your personal information is erased from our active systems; residual copies in routine backups are overwritten in the ordinary course of our backup cycle. Support emails are retained only as long as needed to resolve your request.
8. Your Rights: Access, Correction, Deletion, and Control
Delete your account in the App. Go to Me → Account → Delete Account. This unlinks your sign-in identity and erases your personal information from our systems. This action cannot be undone.
Delete by email. You may also request deletion by emailing support@echohey.com from the address or phone number associated with your account. We will complete it within 30 days.
Access, copy, and correction. Nickname, pantry, dietary preferences, and allergens are editable in the App. For a copy of your data or other corrections, email support@echohey.com. We respond within 15 business days.
Withdraw consent. Clearing a setting withdraws consent for that item; turning off microphone, camera, or notification permissions in system settings withdraws that authorization. Sign out of all devices is available in account settings.
9. Children's Privacy
Cookabout is not directed to children. We do not knowingly collect personal information from children under 13 (or under 14 where local law sets that threshold, including mainland China), and children under that age should use the App only with a parent or guardian's consent. If you believe a child has provided us with personal information, contact support@echohey.com and we will promptly delete it, consistent with COPPA and applicable local law.
Child members in a shared kitchen have no phone number and no credentials — only a nickname chosen by the account holder. Please do not use a child's real name or school in that nickname.
10. Your California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect and how we use it (Sections 1 and 2), access it, delete it, correct it, and to non-discrimination for exercising these rights. We do not sell or "share" (as defined by the CPRA) your personal information, and have not done so in the preceding 12 months. To exercise any right, use in-app account deletion or email support@echohey.com; we verify requests using the email address or phone number associated with your account.
11. Users in the European Economic Area and United Kingdom (GDPR)
- Legal bases. We process account information to perform our contract with you (providing the App), and your pantry, dietary preferences, voice input, and menu photos on the basis of your consent, which you may withdraw at any time.
- Your rights. Access, rectification, erasure, restriction of processing, data portability, and objection — exercise them via in-app deletion or by emailing support@echohey.com.
- International transfer. Data for users outside mainland China may be processed on servers outside the EEA/UK. We protect it as described in this policy regardless of where it is processed.
- Complaints. You have the right to lodge a complaint with your local supervisory authority.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes — to the purposes, types, or methods of processing; to who we share data with; to your rights or how you exercise them; or upon a change of control — we will notify you in the App and, where required, seek your consent again. We update the version number and date at the top of this page. Your continued use of Cookabout after changes take effect constitutes acceptance.
13. Contact Us