Legal
Privacy Policy
1. Introduction
Hook Cookbook is a cozy, personal tool for crocheters. It helps you turn patterns into clear, trackable recipes using AI, and keep your crochet world organised in one calm place.
This Privacy Policy explains what data we collect, how we use it, and the choices you have. We wrote it in plain English so it's actually readable.
By using Hook Cookbook, you agree to this policy.
2. Who We Are
Hook Cookbook is operated by N&G LLC, a single-member limited liability company registered in the State of New Mexico, USA.
We act as the data controller for the information we collect directly from you.
Questions? Email us anytime: hello@hook-cookbook.com
3. What Hook Cookbook Is (and Isn't)
Hook Cookbook is a personal crochet companion, not a social network.
- We don't host your content publicly
- We don't sell your data
- We don't run ads or tracking pixels
- Most of your crochet content stays on your device or your Google Drive
4. Data We Collect
We collect only the minimum needed to run the app.
Account Data
- Name
- Email address
Collected through email/password sign-up or Google OAuth.
Marketing Consent (GDPR)
- Optional checkbox at registration — opt-in only, never pre-checked
Usage Data
- Pattern upload count (to manage free/paid limits)
- Subscription status (synced from Stripe)
Optional Analytics (with consent)
- Anonymous usage data to help us understand how the app is used
- You can opt out anytime in Settings
What We Do NOT Collect
- Pattern content (never stored on our servers)
- Your Google Drive files (we only access our own hidden app folder — see Section 10)
- Advertising or third-party tracking data
- Sensitive personal information
5. Legal Basis for Processing (GDPR)
For users in the EU/EEA, we process your data under the following lawful bases (Article 6, GDPR):
- Contract performance — to provide you with the app and the features you signed up for
- Legitimate interests — to improve the app, prevent abuse, and keep it running securely
- Consent — for optional marketing emails and optional analytics (you can withdraw anytime)
- Legal obligation — where required by applicable law
6. Where Your Data Lives
On Your Device
Most of your crochet content (patterns, recipes, notes, progress) is stored locally in your browser's storage. It never leaves your device unless you enable cloud backup.
In Your Google Drive (optional)
If you connect cloud backup:
- We store your patterns in the appDataFolder — a hidden, app-only folder that only Hook Cookbook can access
- We cannot see or access anything else in your Google Drive
- You can revoke access anytime in your Google account settings
On Our Servers
We store only:
- Your account record (via Supabase Auth)
- Pattern upload count
- Subscription status
- Optional anonymised analytics (if you opted in)
7. How We Use Your Data
We use your data to:
- Create and manage your account
- Process patterns using Anthropic's Claude AI
- Track your usage against free/paid plan limits
- Manage your subscription and payments
- Provide cloud backup (if enabled)
- Send transactional emails (receipts, password resets, account alerts)
- Improve the app (if you opted into analytics)
- Send marketing emails — only if you explicitly opted in
We do not use your data for advertising, profiling, or selling to third parties.
8. AI Pattern Processing
When you submit a pattern for processing:
- The pattern text is sent securely to Anthropic's Claude API
- We do not store the pattern text on our servers at any point
- The processed result is saved only on your device or in your Google Drive (if enabled)
Anthropic's own privacy policy governs how they handle data during processing. Hook Cookbook is a tool, not a content host.
9. Google API Services — Limited Use Disclosure
Hook Cookbook's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In plain terms: we only access the drive.appdata scope — the hidden application folder in your Google Drive. We use it solely to store and retrieve your pattern data. We do not read, modify, or transfer any other Google user data.
10. Google Drive Integration
If you enable cloud backup:
- Hook Cookbook requests access to the
drive.appdatascope — a non-sensitive permission that creates a hidden, app-only folder - This folder is invisible in your normal Google Drive interface
- No one, including you, can see this folder in Drive's UI — only Hook Cookbook can read or write to it
- You can revoke Drive access at any time via your Google Account → Security → Third-party apps
You are responsible for managing your own Google Drive storage quota.
11. Third-Party Services We Use
Anthropic (AI processing)
Patterns are sent for processing and are not stored by us. Anthropic's privacy policy governs their handling of this data.
Supabase (authentication)
Handles your account, login sessions, and OAuth flows. Data hosted on Supabase's servers.
Google OAuth + Drive API (sign-in and optional backup)
Used for Google sign-in and, optionally, Drive cloud backup. Governed by Google's privacy policy and the Limited Use Policy described in Section 9.
Meta Graph API — Link Previews (coming soon)
When you save an Instagram, Facebook, or Threads link to your Stash, we request a preview (thumbnail and title) from Meta's oEmbed API. This is a server-to-server request using our own app credentials — it does not require you to log in with Facebook or connect a Meta account, and no Facebook or Instagram account data of yours is accessed. Only the URL you saved is sent to Meta. Governed by Meta's Platform Terms. This feature is pending Meta's review and is not yet active.
Stripe (payments)
Handles all subscription and payment processing. Hook Cookbook does not store your payment card details. Stripe's privacy policy applies to payment data.
Resend (email)
Used for transactional emails only (account alerts, receipts, password resets). No marketing emails are sent via Resend unless you opted in.
Vercel (hosting)
Hosts the Hook Cookbook web app. Vercel's privacy policy applies to hosting-level data.
Each service operates under its own privacy policy. We choose partners carefully and only share the minimum data needed.
12. Cookies
We use only:
- Session and authentication cookies (Supabase) — required for you to stay logged in
- No advertising cookies
- No tracking pixels or third-party analytics cookies (unless you opt into anonymous analytics)
13. Your GDPR Rights
If you are in the EU/EEA, you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and data
- Withdraw consent for marketing or analytics at any time
- Request data portability (your data in a machine-readable format)
- Object to processing based on legitimate interests
- Restrict processing in certain circumstances
- Lodge a complaint with your local Data Protection Authority (DPA)
You can manage most of these directly in your account settings. For anything else, email hello@hook-cookbook.com and we'll respond promptly.
We do not have a formal EU representative or DPA, but we take GDPR compliance seriously and will cooperate with any supervisory authority inquiry.
14. California Privacy Rights (CCPA)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to:
- Know what personal information we collect about you and how it's used
- Delete personal information we hold about you (subject to certain exceptions)
- Opt out of the sale of your personal information — though we do not sell personal information
- Non-discrimination — we will not treat you differently for exercising your privacy rights
To exercise any of these rights, email us at hello@hook-cookbook.com. We will respond within 45 days.
15. Meta / Facebook Data Deletion
Hook Cookbook does not use Facebook Login and does not access, collect, or store any of your Facebook, Instagram, or Threads account data. Our only interaction with Meta's platform is a server-to-server request to fetch a public link preview when you save a Meta-hosted link to your Stash — see Section 11.
If you'd like any data associated with your Hook Cookbook account deleted, you can:
- Delete your account via Settings → Account → Delete Account, or
- Email hello@hook-cookbook.com with "Data deletion" in the subject line
We will process deletion requests promptly.
16. Children's Privacy
Hook Cookbook is available to all ages, but we do not knowingly collect personal data from children under 13 (or under 16 in the EU/EEA) without verifiable parental consent.
If you believe a child has created an account without permission, contact us at hello@hook-cookbook.com and we will delete the account.
17. Data Retention & Deletion
We retain your account data for as long as your account is active. If you delete your account, we remove your data promptly.
When you delete your account, we remove:
- Your Supabase auth record
- Your usage and subscription data
- Any optional analytics data tied to your account
What we cannot delete on your behalf:
- Data stored in your browser's local storage — clear this via your browser settings
- Data stored in your Google Drive — delete it via Google Drive settings, or by revoking app access
18. Security
We use industry-standard security practices, including:
- Encrypted connections (HTTPS throughout)
- Secure authentication (Supabase Auth)
- Minimal server-side data storage by design
- Strict access controls on all infrastructure
No system is perfect. If you discover a security concern, please email hello@hook-cookbook.com immediately.
19. Changes to This Policy
We may update this policy from time to time.
- Material changes will be emailed to registered users and/or shown in the app
- Minor updates will be posted silently on this page
The "Effective date" at the top always reflects the latest version.
20. Contact Us
For questions, concerns, or data requests:
Questions? We're here.
hello@hook-cookbook.com