mum's spaghetti — Privacy Policy
Version: 1.4 Effective date: 22 August 2026 Agency: Ohnyx IT Solutions Ltd, a New Zealand company ("Ohnyx", "we", "us") Privacy contact: [email protected]
This policy explains what personal information mum's spaghetti (mumspaghetti.com) collects, why, where it goes, and your rights. We're a New Zealand company and we handle personal information under the New Zealand Privacy Act 2020.
The short version: we collect what we need to run a family recipes app and nothing more. We don't sell your information, we don't run advertising or ad trackers, and we don't use your recipes to train AI models.
1. What we collect
Account information
- Your name and email address
- Your password (stored only as a secure one-way hash — we cannot read it)
- If you enable two-factor authentication: your 2FA secret and recovery codes (stored encrypted)
- Your family group, role in it (owner or member), and invitations you send or receive
Your content
- Recipes, including photos you upload, extracted recipe text, notes, annotations, versions, meal plans, shopping lists, and favourites
Billing information
- Your subscription status, plan, and credit balances
- Payments are handled by our payment processor. We never see or store your card number — card details go to the processor directly, and it sends us only what we need (e.g. that a payment succeeded, and a customer reference)
Usage and technical information
- AI usage records (which AI features were used, when, by which account, and how many tokens they consumed) — used for credit metering, abuse prevention, and cost tracking
- Standard server logs (IP address, browser type, pages requested) — used for security and troubleshooting
- Session cookies needed to keep you logged in (see section 6)
We do not collect anything from your device beyond what you actively upload and what any website receives (like your IP address).
2. Why we collect it (and what we do with it)
We use your information to:
- Provide the Service: store and display your recipes to you and your family group, run invitations and sharing;
- Run the AI features you ask for: when you upload a recipe photo or use chat/substitutions/variations, the relevant recipe content is sent to our AI provider for processing (see section 3);
- Bill you: manage subscriptions, credits, receipts, and payment failures via our payment processor;
- Send you transactional email: invitations, security notices (like 2FA changes), billing notices, and removed-member notices. We don't send marketing email;
- Keep the Service secure: rate-limiting, abuse detection, and investigating security incidents;
- Meet our legal obligations (e.g. tax records for payments).
We do not sell or rent your personal information, use it for advertising, or use your content to train AI models.
3. Who else sees your information (including overseas)
We use a small number of specialist service providers to run mum's spaghetti — the same kinds every online service relies on. Each receives only the information it needs to do its job:
- Payment processing — your name, email, and subscription records. Card details go directly to the payment processor and never touch our systems.
- AI processing — the recipe photos, recipe text, and chat messages you submit when you use an AI feature, and only then. Under our provider's commercial terms, this data is not used to train AI models.
- Email delivery — your email address and the content of the transactional emails we send you.
- Security and content delivery — traffic to the site passes through a protective network (IP address, request metadata, encrypted content in transit) that shields the Service from attacks and keeps it fast.
- Backup storage — nightly backups of the Service's data, encrypted by us before they leave our servers, so the storage provider cannot read them.
Some of these providers operate overseas, mainly in the United States and Australia. The app itself runs on infrastructure we operate in New Zealand.
Where a provider is overseas, we rely on the provider being subject to comparable safeguards (contractual commitments and, for backups, encryption that keeps the data unreadable to the provider). If you'd like more detail about any provider, ask us.
We do not otherwise disclose your personal information unless you ask us to, the law requires it, or it's necessary to protect the safety of a person or the security of the Service.
Within the app, your name and your recipes are visible to your family group, and to other users when you or your family use the sharing features. A recipe forked by another user becomes a copy in their library, including any attribution to you.
4. How we protect it
- All traffic to the site is encrypted (HTTPS).
- Passwords are hashed (bcrypt-class); 2FA secrets and recovery codes are encrypted at rest.
- Access to production systems is restricted to Ohnyx personnel who need it, protected by strong authentication.
- Nightly off-site backups are encrypted before they leave our servers, with the decryption key held separately from the backup provider; backups are also write-locked against tampering or deletion for 90 days.
- Two-factor authentication is available (and encouraged) for your account.
No internet service can promise perfect security, but we treat your family's recipes and details with the same care we'd want for our own.
5. How long we keep it
- Your account and content: for as long as your account exists.
- One number to remember: 90 days. However your data leaves the Service, every remaining copy becomes unrecoverable within 90 days of it leaving the live system.
- If you delete your account (or ask us to): your account and content are removed from the live system straight away. Residual copies in our tamper-locked, encrypted backups age out and become unrecoverable within 90 days. Backups are only ever used for disaster recovery — we don't restore deleted accounts from them except to recover from a system failure.
- If you're removed from a family: your account enters a 90-day window (explained in the Terms) in which you can upgrade to your own plan and keep your recipes. If you don't, your account and content are permanently deleted at the end of the window, with backup copies aging out within a further 90 days as above.
- If your free family goes quiet: where a family has never subscribed and no member signs in for 90 days, we delete the family and its content — after at least 14 days' emailed warning to the owner (see the Terms). Backup copies then age out within a further 90 days as above.
- Billing records: kept for 7 years as required by New Zealand tax law (these live with our payment processor and in our accounting records; they're kept even after account deletion).
- Server logs and AI usage records: kept for a short operational period for security and cost tracking, then deleted or aggregated.
- Our providers retain data per their own policies; we've chosen providers whose retention is limited (see section 3, and section 10 for how to ask us questions).
6. Cookies
We use only the cookies the app needs to work: a session cookie to keep you logged in and a CSRF token to protect forms. No advertising cookies, no cross-site trackers, no analytics cookies from third parties. Because these cookies are strictly necessary, there's no cookie banner nagging you.
7. Your rights
Under the Privacy Act 2020 you can:
- Ask for a copy of the personal information we hold about you;
- Ask us to correct it if it's wrong;
- Ask us to delete your account and information (you can also do this yourself from your profile page) — subject only to what we must keep by law (like billing records) and the backup window in section 5;
- Ask questions or complain about how we've handled your information.
Email [email protected] for any of these. We'll respond as soon as we can, and within 20 working days as the Privacy Act requires.
If you're not happy with our response, you can complain to the Office of the Privacy Commissioner (privacy.org.nz, 0800 803 909).
8. If something goes wrong (data breaches)
If we have a privacy breach that causes, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and the affected people as soon as practicable, as the Privacy Act 2020 requires. Our notice will tell you what happened, what information was involved, and what we're doing about it — plainly, without burying it.
9. Children
mum's spaghetti is a family app, so children may appear as family members invited by the family owner. We require account holders to be 16 or older; younger family members should only use the Service with a parent or guardian's knowledge and consent, arranged through the family owner who invites them. We collect the same minimal information for every member (name, email, and their recipes) and never use any member's information for marketing or profiling.
10. Changes to this policy
We may update this policy as the Service or the law changes. Every version has a version number and effective date, with a version history below. For material changes we'll email account holders before the change takes effect. Questions about this policy or our providers: [email protected].
Version history
| Version | Effective date | Summary of changes |
|---|---|---|
| 1.0 | 22 August 2026 | First published version. |
| 1.4 | 22 August 2026 | Disclosed inactive-free-account deletion (90 days' inactivity, 14 days' warning), matching the Terms. |
| 1.3 | 22 August 2026 | Provider disclosures rewritten as generalised service categories in prose (industry-standard form); payment processor no longer named. No change to what is shared, why, or where. |
| 1.2 | 22 August 2026 | Deletion timeframes aligned on 90 days (removed-member window extended from 60 days); retention section reworded around one rule. |
| 1.1 | 22 August 2026 | Service providers described by category and location rather than by name (payment processing excepted); no change to what is shared or why. |