Lutong Bahay

Privacy

How Lutong Bahay currently handles information in this product. Some operator-specific details are still marked as TODO.

Website: https://lutongbahay.online

Effective date and operator details have not been supplied yet.

Introduction

Lutong Bahay is a cookbook app for saving home recipes, sharing public dishes, and taking part in cooking conversations. The public website is the origin configured for this product (see the Website line on this page).

This page describes the current product’s behavior. It is not complete legal advice, and it does not name a finished operator policy where those facts have not been supplied.

TODO. Add the operator identity, any registered business details, and the date this policy becomes effective. Do not publish those details until they are supplied.

Information We Collect

Depending on how you use the app, Lutong Bahay may store the following categories.

  • Account information: email address and a password managed by the authentication service.
  • Profile: username, display name, bio, cooking level, and avatar URL if one is stored.
  • Recipes: titles, descriptions, stories, ingredients, steps, times, servings, difficulty, category, cuisine, privacy, draft/published status, and related metadata.
  • Recipe photos: storage path references for covers you upload. The current JSON download includes those path references, not the image files themselves.
  • Community activity: comments, questions, answers, likes, and saves you create.
  • Cooking history: private cook logs, including recipe title snapshot, rating, notes, and cooked-at time.
  • Notifications: records created when there is activity related to your account or content.
  • Reports: reports you submit about content, used for community safety.
  • Security data: session cookies and Cloudflare Turnstile challenge results on selected forms.
  • Deletion request state: whether you have asked for account deletion and when that request was made.

TODO. Confirm whether any additional categories are collected (for example, support tickets or server logs) and list only those that actually exist.

How We Use Information

The current app uses this information to:

  • Create and keep your cookbook account.
  • Show your recipes, profile, and cooking history to you.
  • Show public recipes in Discover, Search, and public profiles.
  • Support comments, questions, likes, saves, and notifications.
  • Handle reports and moderation tools used by staff.
  • Run security checks on sign-up, sign-in, password reset, and reporting forms.
  • Let you download a copy of your own application data from Account Settings.
  • Record an account deletion request until it is processed.

TODO. Add any other purposes the operator actually uses, such as support or abuse investigation. Do not add marketing or analytics uses unless they exist.

Public Content

When you choose to make something public, other visitors can see it through the product’s public surfaces.

  • Public published recipes, including their ingredients, steps, stories, and cover images when those pages load.
  • Public profile information such as username, display name, bio, and cooking level.
  • Public comments, questions, and answers on public recipes.

Private Content

The following are treated as private under normal application behavior and are not listed in Discover, Search, or another cook’s public profile:

  • Private recipes.
  • Draft recipes.
  • Cooking history.
  • Notifications.
  • Saved and liked state.
  • Deletion request state.

Staff moderation can remove community-facing content from public views. That does not, by itself, describe how long copies are kept.

Recipes and User Content

Recipes, photos, comments, questions, answers, and cooking notes are content you add to the app. You can download your own copy from Account Settings. Public recipes and public community posts can be seen by other visitors.

TODO. Add the operator’s legal treatment of user content, including any license needed to host and display it. Do not invent ownership transfers.

Public vs Private Recipes

Each recipe can be marked public or private. Public, published recipes may appear in Discover, Search, and on a cook’s public profile. Private recipes and drafts are not listed in those public surfaces.

TODO. Clarify any extra rules for changing privacy, unpublishing, or residual copies in backups once those practices are defined.

Account Information

An account uses an email address for sign-in and recovery. Profile usernames and display names can appear with public recipes and community posts.

TODO. Describe how email is used beyond sign-in (for example, confirmation or reset messages) and whether profile fields are optional or required.

Photos and Storage

Recipe photos are stored so the app can show covers on recipe pages. Access to private images is intended for people who are allowed to view that recipe. A personal JSON export includes photo path references only; it does not currently bundle the image files.

TODO. Add storage-provider details, regions, and any signed-URL or access rules the operator wants stated publicly.

Community Activity

If you comment, ask a question, answer, like, save, or report content, that activity is stored so community features can work. Comments, questions, and answers on public recipes can be visible to other people. Likes and saves are stored as your personal interaction state.

Cookies and Security Technologies

The app uses session cookies so a signed-in visit can stay signed in across pages. Selected forms also use Cloudflare Turnstile, a challenge used to reduce automated abuse on sign-up, sign-in, password reset, and content reports.

This page does not describe advertising cookies, analytics pixels, or a cookie-consent banner. Those are not part of the current product UI.

TODO. Publish a complete cookie and similar-technology inventory once reviewed. Do not list tracking products that are not in the app.

Service Providers

The app relies on third-party infrastructure to run authentication, database storage, file storage, hosting, and bot-protection checks.

TODO. Name each processor, its role, and where a reader can find that provider’s own privacy terms. Do not add vendors that are not actually used.

Data Retention

TODO. Add retention periods for accounts, recipes, photos, community posts, reports, deletion requests, and backups. Do not invent time limits until they are decided.

Data Security

Signed-in areas use authenticated sessions. Public pages show only content the app treats as public. This is a description of the current design, not a guarantee against every risk.

TODO. Add any security practices the operator is prepared to state, without over-promising.

User Rights

While you are signed in, you can edit your profile from Profile settings and download a JSON copy of your own application data from Account Settings.

TODO. Describe access, correction, export, and objection rights that actually apply, including the region and process. Do not copy a generic GDPR/CCPA clause until it is reviewed.

Account Deletion

You can request account deletion from Account Settings. Deleting your account is permanent. Recipes, profile, community activity, and other account data may be removed.

For safety, account deletion is reviewed before final removal. A request is not completed instantly, and this page does not promise a specific processing period. You can cancel the request while it is still pending. You stay signed in after requesting deletion so you can cancel it.

Final deletion is processed after necessary operational and security steps, including removing recipe Storage objects and then deleting the authentication user outside the public website.

TODO. Add any residual records that may remain for legal or safety reasons, and any processing timeframe, only after those practices are decided.

Children's Privacy

TODO. State the intended audience and any age limit. Do not claim the service is directed to children, or that it is not, until that decision is made.

International Processing

TODO. Describe where accounts and files may be processed and any transfer safeguards. Do not invent countries or transfer mechanisms.

Changes to This Policy

When this policy is completed, the operator will need a process for updating it and showing readers that it changed.

TODO. Add how changes will be announced and whether continued use counts as acceptance.

Contact

TODO. Provide a privacy contact method (and mailing address if required). Do not invent an email address, form, or company address here.