Legal

Flavonomics Privacy Policy

Last updated: 24/07/2026

This Privacy Policy explains how Flavonomics ("we", "us", or "our") collects, uses, shares, and protects personal data when you use our websites, applications, APIs, model context protocol services, ChatGPT app integrations, developer tools, datasets, and related products.

If you use Flavonomics on behalf of a company or other organization, this policy applies to personal data processed in connection with that organization's use of the Services.

Who We Are

Flavonomics provides flavour pairing, ingredient analysis, cocktail intelligence, developer APIs, and MCP tools for culinary and product development workflows.

For privacy questions or requests, contact us at [email protected].

Personal Data We Collect

The personal data we collect depends on how you use the Services. It may include:

  • account details such as name, email address, login method, and plan status;
  • authentication data such as session identifiers, OAuth tokens, API keys, and MCP keys;
  • billing and subscription data processed through our payment providers;
  • usage data such as pages visited, features used, request timestamps, tool calls, rate-limit events, logs, diagnostics, device data, IP address, and approximate location derived from request metadata;
  • customer content such as prompts, queries, ingredient selections, recipes, feedback, uploaded or submitted text, and other content you provide to the Services;
  • communications you send to us, including support, sales, and feedback messages; and
  • essential cookie, local-storage, and first-party operational data used to keep you signed in, preserve product state, apply usage limits, and protect the Services.

ChatGPT App and MCP Integrations

When you connect to Flavonomics through ChatGPT, another MCP client, or a third-party integration, that client may send us the information needed to authenticate you and run the requested tools. This may include OAuth token claims, account identifiers, email address, scopes, tool requests, prompts, selected conversation context, and technical request metadata.

We use this information to verify access, map the request to an eligible Flavonomics account or plan, execute the requested MCP tools, return results to the client, monitor reliability, detect abuse, and enforce applicable usage limits.

The third-party client remains responsible for its own processing of your data. For example, data handled by ChatGPT or OpenAI is also subject to OpenAI's applicable terms and privacy practices.

Deep Flavour uses OpenAI models to generate responses. When you send a Deep Flavour message in our website or mobile applications, we share the message and relevant recent conversation context with OpenAI so it can generate the requested response. By sending a message you agree to that processing. Do not include sensitive personal data in a prompt unless it is necessary for your request and you are comfortable with this processing.

How We Use Personal Data

We use personal data to:

  • provide, operate, maintain, and improve the Services;
  • authenticate users, manage accounts, subscriptions, and access controls;
  • process payments, invoices, refunds, and tax or accounting records;
  • run API, MCP, and ChatGPT app requests and return outputs;
  • respond to support requests, feedback, and business inquiries;
  • monitor usage, debug errors, protect security, and prevent abuse or fraud;
  • develop new features, recommendations, ranking logic, and product workflows; and
  • comply with legal obligations and enforce our terms.

Cookies and Local Storage

We use cookies, local storage, and similar technologies to keep users signed in, remember product state, maintain security, apply usage limits, and provide features you request.

We may keep first-party operational events, such as a feature request timestamp or quota event, in our own systems for reliability, security, and entitlement enforcement. We do not load third-party behavioural analytics, advertising measurement, or session-recording tools in the Flavonomics web application.

How We Share Personal Data

We do not sell your personal data. We may share personal data with:

  • service providers that host, secure, monitor, analyze, or support the Services;
  • payment processors that process website subscriptions and purchases;
  • authentication, email, infrastructure, and customer support providers;
  • OpenAI, when you send a Deep Flavour request, as described above;
  • third-party clients or integrations you choose to connect, where sharing is needed to provide the integration;
  • professional advisers, auditors, insurers, or legal authorities where reasonably necessary; and
  • another organization in connection with a merger, acquisition, financing, reorganization, or sale of assets.

We require third parties that receive personal data from us to provide the same or an equivalent level of protection described in this Privacy Policy and required by applicable law.

Retention and Account Deletion

We retain personal data for as long as reasonably necessary to provide the Services, maintain accounts, comply with legal and accounting obligations, resolve disputes, enforce terms, protect security, and maintain business records.

You can initiate permanent deletion from the Account area of the website or mobile application. When deletion succeeds, we remove the user profile and directly linked authentication records, sessions, password and verification tokens, saved items, Deep Flavour conversation history, usage records keyed to the account, API and MCP credentials, family membership links and invitations, local Stripe subscription record, and any dormant store-entitlement link associated with the account. We also remove or de-identify your authorship from collaborative flavour-profile records.

Active Stripe billing is cancelled immediately before deletion. Stripe and other payment providers may retain transaction, tax, fraud-prevention, and accounting records under their own policies and legal obligations.

Deleted data may remain temporarily in restricted backups until the applicable backup rotation completes. We may retain records required for legal, tax, accounting, security, fraud-prevention, or dispute purposes, and may retain aggregated or de-identified scientific and product data that can no longer reasonably identify you.

Security

We use reasonable technical and organizational safeguards designed to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure. No online service can guarantee absolute security, so you should keep passwords, API keys, OAuth connections, and MCP credentials confidential.

International Processing

We and our service providers may process personal data in the United Kingdom, European Economic Area, United States, and other countries where we or they operate. These countries may have data protection laws that differ from those in your location.

Your Rights and Choices

Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal data. You may also have the right to withdraw consent where processing is based on consent.

To make a request, contact [email protected]. We may need to verify your identity before responding. You can also manage some account, subscription, and communication preferences through the Services. You can initiate account deletion directly from the Account area in the website or mobile application.

Children

The Services are not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided personal data to us, contact us so we can take appropriate steps.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will post the updated policy on our website and update the "Last updated" date above.

Contact Details

If you have questions about this Privacy Policy, contact:

[email protected]