Privacy Policy
Updated September 24, 2026
Grave Danger Media operates Daily Spatula. This policy explains what we collect, why we collect it, and the choices you have. It covers the website at dailyspatula.com and the same app wherever it is hosted.
Data we collect
- Account data: email, optional name, a bcrypt password hash (never the raw password), the time you accepted the Terms, and whether you opted into recipe email.
- Preferences: diets and allergens you ask us to remember, favorites, and, on a paid plan, shopping lists, item notes, and a country or region code.
- Plan flag: free or paid. We do not collect card numbers on this site. Checkout is not live.
- Security data: IP address used in memory for sign-in rate limits, and a salted hash of the IP address (not the raw address) on the contact and copyright forms, kept so we can limit repeat submissions.
- Messages you send: the contact form and the copyright claim form store what you submit, such as your email, the message, and recipe links.
- Cookie preference: your choice about analytics and marketing cookies, stored in this browser.
Auth.js and cookies
Sign-in uses Auth.js. The session cookie and the CSRF cookie are necessary. They are HttpOnly, SameSite=Lax, and marked Secure in production. We use them to keep you signed in and to reject cross-site form posts to the auth routes. Necessary cookies stay on. Analytics and marketing cookies stay off unless you opt in on the cookie settings page. We do not load an analytics or advertising script today.
Where the data lives
Account and recipe data are stored in Postgres hosted by Neon. The application is hosted on Railway or a similar host we choose. Those companies process data so we can run the service. We do not sell personal information.
Marketing
If you check the recipe-email box, we may send occasional cooking notes. You can turn that off on the account page or through the contact form. We do not use a marketing cookie for that choice. It is stored on your account.
Third parties
- Cloudflare Turnstile, when keys are configured, checks that a signup is from a person. Cloudflare receives the verification token and technical data described in Cloudflare’s own policy. The Turnstile secret stays on our server.
- Google, if you use Google sign-in, receives the fact that you chose that button and shares the email and name already on your Google account. Google sign-in is optional and may be off.
- Neon hosts the database. Railway or the current host runs the application.
- We do not currently send data to an analytics vendor. If we add one, it will load only after the analytics cookie preference is on, and we will update this page.
Why we use the data
We use it to run accounts, remember preferences, show the right recipe tools, keep the site secure, and send email you asked for. We also use it to honor deletion requests and to keep a short audit trail of admin changes.
Your choices and rights
You can review and change preferences, favorites, email consent, and shopping lists from your account. You can request deletion there or through the contact form. We will disable the account and then remove personal data, keeping security audit logs where we need them. Depending on where you live, you may have rights to access, correct, or delete personal information, or to appeal a denial. Write to us through the contact form and we will respond.
Children
Daily Spatula is family-safe reading. It is not directed at children under 13, and we do not knowingly create accounts for them. If you believe a child gave us personal information, use the contact form and we will delete it.
Changes and contact
We will update the date at the top when this policy changes. The terms of service are separate: Terms.
Contact Grave Danger Media through the contact form. Copyright notices go through the copyright claim form.