Legal
Forko privacy policy
Version 1.9 — 29 September 2026
Forko keeps the minimum it needs to put together a plan that makes sense for you: your food preferences, your weekly plan and the photos of the dishes you choose to share. Here, with no small print, is what we keep, who else sees it and what you can do about it. This is Forko's privacy policy, version 1.9, of 29 September 2026.
Who processes your data
The controller of the data Forko collects is Lucas Céspedes, a private individual, with an address at Barcelona (España). Forko is a personal project and the app is free. Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 (LOPDGDD) and Spanish law apply. For anything to do with your data, write to us.
What we keep and why
Your email, your name and your @username, so that the account exists and so we can send you verification codes; if you sign in with Apple or Google, the email and the identifier that provider gives us. Your profile photo and your bio, so that other people recognise you. Your tastes, your diet style, your cooking level, your kitchen appliances, your servings and what Forko learns about you in the chat, to choose which recipes to suggest to you. Your weekly plan, your ratings, your shopping list, your own recipes and your messages with Forko, so that they exist and Forko can reply to you. The photos of your dishes, your posts, your comments, your likes, who you follow and who follows you, and the recipes you save, to publish what you choose to share and to show you what the people you follow share. Your points, your level and your badges, which come from what you cook and from how many people cook your recipes, to show you your progress. We process all this because it is needed to provide you with the service (GDPR art. 6.1.b). We also keep daily usage counters, reports and blocks, to prevent abuse, control the cost of the service and moderate content (legitimate interest and legal obligation). And the leaderboards, which are on by default: when you cook, you appear in that week's leaderboards with your name, your @username, your photo and your points, and if you publish recipes, in the monthly ones, with how many different people have cooked them. You can only be seen by those who can see your profile — with a private account, the people who follow you — and never by anyone with whom there is a block; a leaderboard with fewer than five people is not shown, and nobody is ever ranked by their allergies, their diet or any other data about them. This is a legitimate interest (GDPR art. 6.1.f) that you can object to with one tap: you can leave them whenever you like in Profile → Settings → “Show me on leaderboards”, you stop appearing in all of them at once and you no longer see them either. Your points, your level and your badges stay. And the leagues: once enough people are cooking, leagues are formed every week: groups of 15 to 29 people who cooked the previous week, split into five divisions and at random within each one. Your group can see your name, your @username, your photo, your points for the week and your position; when the week closes, those at the top move up a division and those at the bottom move down, and we let you know in your notifications (the bell). Only public accounts that haven't left the leaderboards take part: with a private account you don't join any league, and to anyone with whom there is a block you appear as “Someone”, with no name or photo. Here too, nobody is grouped by their allergies, their diet, where they live or any other data about them. We keep your division and your league weeks for as long as you have the account, and they are included in “Download my data”. The same switch, “Show me on leaderboards”, also takes you out of the leagues.
Allergies and health data
Your allergies, your intolerances and your dietary restrictions are health data, and the law treats them as a special category. So do we: they are used only to filter out the recipes you can't or don't want to eat, and we only process them because you give them to us deliberately (explicit consent, GDPR art. 9.2.a). That's why, before asking about your allergies, we ask you for that permission separately — during sign-up and the first time you add one from your Profile — and you can say “I'd rather not say”: the plan is made without that filter. You can change or delete them from your Profile whenever you like, and withdraw the permission in Profile → Settings → “Allergies and intolerances”: they are deleted at once.
Artificial intelligence
Some features use Claude, a model by Anthropic PBC (United States). Each feature sends it what that feature needs. Chat and recipe drafts: what you write, your plan for the week, your preferences, allergies and restrictions, your kitchen appliances and what Forko has learnt about you. “Let Forko estimate them”: the name and ingredients of your recipe, to work out calories and macros. Review of what you publish: the text of your recipes and the photo and text of your dishes in the feed, to check that they are food and not inappropriate content. Your name, your @username and your email are never sent. Anthropic acts as a processor (anthropic.com/legal/privacy) and processes the data solely to return the response. Nothing is sent without your permission: we ask you for it the first time you go to use one of these features, and you can withdraw it whenever you like in Profile → Settings → “AI features” (without it, the chat with Forko and the rest stop being available).
When you look for people in your contacts
Only if you turn it on. Forko reads only the email addresses in your contacts — not names, not phone numbers — and turns them ON YOUR PHONE into irreversible codes. Only those codes are sent, only to match them against people who have turned on “Let people find me by email” in their settings, and they are not stored anywhere: they are compared and discarded with the query. This is consent (GDPR art. 6.1.a), which you withdraw by revoking the contacts permission in your phone's settings.
Your photos have a public link
Your profile photo and the photos of your dishes are kept in storage that is public by link: anyone with the direct URL of an image can see it without a Forko account, even if your profile is private. The links aren't published anywhere, but don't upload anything you wouldn't want to be accessible through a link. Nobody but you can upload or delete files in your folder.
How we measure how Forko is used
To know at which step of sign-up people leave and which screens nobody opens, Forko sends PostHog (PostHog Inc.) the name of the screen you open, how many seconds you spend on it, the sign-up step you reach, which question of the sign-up questionnaire you reach (the question we show you, never what you answer) and actions without content: that a plan has been generated and how many dishes it has (and, if it came from the stack of dishes, how many you set aside first), that in that stack you have added or set aside a dish (by swiping, with a button or by undoing, and what position it was in; never which one), that you have changed a dish by hand, that you have opened a recipe card, that you have started, left or finished cooking (with how many steps you had done and how many minutes), how much of the shopping list you had ticked off when you left, how many items on the list you opened and how many you took off because you already had them at home, and, if you checked what you've got at home, how many things it showed you, how many you took off and how many you put back (never which ones), that you have shared the list, that you have looked up an item from the list in the supermarket's shop, that you have opened a dish Forko changed when balancing the shopping and what you decided (keep it, ask for another or go back to the previous one) and how many times you asked for another, that you have posted a dish (and whether you ticked saving it to favourites), that you have added or removed the heart on a recipe (what kind of recipe and from which screen, never which one), that you have saved or removed a post from your profile, and that you have noted something in your pantry (only whether it was because you marked “I've already got it” or because it came into your home when you marked it bought, never WHAT or HOW MUCH). Also when something fails: that a screen couldn't load, that sign-up hit an error at a step, or that a change of yours didn't manage to save on the server — and for each one, only a single word saying what type it was (offline, server, permissions, data or app). Never the error message, nor WHICH recipe, dish or ingredient: only that it happened, and counters. Each send includes your phone's model, the system and app versions, the language and time zone, and a random identifier that is generated on your phone and linked to your account when you create it. What you write, your email, your name, your allergies, your preferences, your plan, your location and your phone's advertising identifier are NEVER sent. We don't record the screen. This is a legitimate interest (GDPR art. 6.1.f) that you can object to with one tap: it is on by default and you turn it off with “Help improve Forko”, in the last step of sign-up or in Profile → Settings → Preferences. Turning it off stops the sending immediately on this phone, and signing out doesn't turn it back on.
What we DON'T do
We don't sell your data or hand it over for advertising purposes, and there are no ads in Forko. There is no cross-app tracking and no advertising identifier (IDFA): the only measurement is our own, the one in the previous section, without recording your screen. We don't access your location or ask for your phone number. There are no purchases and no payment details: if there ever were, we would update this policy first.
Who else sees your data
Supabase Inc. hosts the database, authentication and files, on servers in Ireland (European Union); it is a processor. Anthropic PBC (United States) processes what is described in “Artificial intelligence”: this is an international transfer covered by the European Commission's standard contractual clauses. PostHog Inc. receives the usage data and hosts it in the European Union; as it is a US company, the processing is also covered by the standard contractual clauses. Apple and Google, only if you choose to sign in with them, as identity providers and under their own policies. And other Forko users see what you publish: your profile (with your level and your badges), the dishes you share, your comments and the recipes you publish in the recipe book; and, if you haven't left the leaderboards, your position in them and, within your group, in your league.
How long we keep it
Your conversations with Forko delete themselves 7 days after the last message in each one. The rest of your data, for as long as you have the account: when you delete it, it is deleted. PostHog usage data is also deleted with the account: when you delete it, Forko asks PostHog to delete that data, and PostHog completes the deletion in the background.
Deleting your account
You can delete your account from the app, in Profile → Settings → Delete account, confirming with your password or, if you signed in with Apple or Google, with that same provider. Your account, your profile, your preferences and allergies, your plans, your posts, your recipes, who you follow and who follows you, your chat history and the photos you have uploaded are deleted there and then. The full steps, and what to do if you can't get into the app, are at forko.es/eliminar-cuenta (in Spanish).
Two things worth knowing
Deleting a post from the app doesn't delete its photo from storage: the direct link to that image keeps working until you delete your account. And if you signed in with Apple, you remove the link that Apple keeps in your Apple ID yourself, from its settings.
Automated decisions
Your weekly plan is generated by a program from your preferences, and you can change any dish. The review of the recipes you publish and of the dishes in the feed is automated and has no legal effects: if something is rejected or removed, you see the reason, and if you think it got it wrong, write to us and a person will look at it.
Minors
Forko is for people aged 14 and over (LOPDGDD art. 7), which is the age from which you can consent to the processing of your own data in Spain. When you sign up you expressly tick a box, which is not ticked by default, where you declare this: you can't create the account, whether with email or with Apple or Google, without ticking it. If we detect an account belonging to someone under 14, we will delete it.
Your rights
You can access your data, rectify it, erase it, restrict or object to its processing and take it somewhere else. From this menu you can download your data (“Download my data”) and delete your account (“Delete account”). For anything else, or if you can't get into the app, write to us from your account's email address: we reply within 1 or 2 working days and resolve it within the legal deadline of one month. If you think we haven't handled it properly, you can lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, aepd.es).
Security and changes
Everything that travels between your phone, our server and the processors above is encrypted, and your password is stored in a way that we can't read. If there were ever a breach affecting your data, we would tell you and notify the AEPD (GDPR art. 33). If we change anything significant in this policy, we will let you know in the app before it takes effect. The version and date above are the ones that count.