Privacy Policy
This Privacy Policy describes how BakeCost: Cake Pricing & Profit
(“BakeCost”, “the app”, com.kymbria.bakecost) handles information when
you use our mobile application and website. BakeCost is built
offline-first: the app works entirely on your device and is
designed to collect as little information as possible.
- 1. Information stored on your device
- 2. No account, no registration
- 3. Advertising (AdMob)
- 4. Purchases (Google Play / RevenueCat)
- 5. Push notifications (OneSignal)
- 6. Remote configuration & support messages
- 7. What we do NOT collect
- 8. Children
- 9. Your rights
- 10. Retention & deletion
- 11. Security
- 12. Changes to this policy
- 13. Contact us
1. Information stored on your device
Your recipes, pantry items, pricing settings and app preferences are stored locally on your device (using on-device storage — Hive on Android/iOS, IndexedDB if you use the web version). This data never leaves your device unless you explicitly export or share it yourself. We do not operate a recipe or account server.
2. No account, no registration
BakeCost does not require — and does not offer — a user account. You can use every free feature without providing a name, email address or phone number.
3. Advertising (AdMob)
The free tier of the Android and iOS apps displays ads served by Google AdMob. Google and its partners may use the advertising ID of your device to serve ads and measure their performance, subject to Google’s advertising policies. You can reset or delete your advertising ID in your device settings, and ads are removed entirely when you upgrade to BakeCost Pro.
The app retrieves its ad configuration (on/off toggle and ad unit identifiers) from our server; these requests are anonymous and contain no personal data.
4. Purchases (Google Play / RevenueCat)
BakeCost Pro subscriptions are processed by Google Play Billing (on Android) and validated through RevenueCat, our subscription management provider. Purchase validation uses anonymized, app-scoped identifiers managed by the store — we never receive your payment details, and payment data is processed solely by Google under the Google Play Terms of Service. See RevenueCat’s privacy policy for details.
5. Push notifications (OneSignal)
If you allow notifications, we use OneSignal to deliver optional service messages (for example, new features or maintenance notices). OneSignal processes a push token and a random subscription identifier for your device; it does not receive your recipes or pricing data. You can withdraw permission at any time in your device settings. See OneSignal’s privacy policy.
6. Remote configuration & support messages
On launch the app fetches a small anonymous configuration file (minimum app version, ad settings and any service notice) from our server. The request contains no personal information or unique identifiers. If you contact us through the website contact form, we store the name, email address and message you provide solely to answer your inquiry.
7. What we do NOT collect
- We do not collect or upload your recipes, pantry or pricing data.
- We do not require or store credentials for app usage.
- We do not access your contacts, photos, location, microphone or camera.
- We do not sell personal data to anyone.
8. Children
BakeCost is a business tool intended for general audiences and is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.
9. Your rights
Depending on your jurisdiction (for example the GDPR in the EU/EEA or CCPA in California), you may have rights to access, correct, export or delete personal data we hold about you. Because nearly all app data lives only on your device, deleting data is usually as simple as uninstalling the app. For anything we do hold (a support message), contact us and we will honor your request.
10. Retention & deletion
On-device data persists until you uninstall the app or delete the data in the app. Support emails are kept only as long as needed to resolve your inquiry, then deleted. Push tokens are removed when you uninstall the app or disable notifications.
11. Security
All network communication uses HTTPS. Backend administrative access is protected by hashed passwords and session-based authentication. No system can guarantee absolute security, but we limit what we hold precisely so there is very little to compromise.
12. Changes to this policy
We may update this policy to reflect changes in the app or the law. Material changes will be announced in the app or on this page, and the “last updated” date above will be revised.
13. Contact us
Questions about this policy? Reach us through the contact form or by email at [email protected].