ChocoForm ← Back to chocoform.pro
Legal

Privacy Policy

Last updated: June 2026

Overview

ChocoForm is built on a simple principle: your recipes and formulations are yours. The app is designed to work entirely on your device, and we collect as little data as technically possible to operate the service.

We do not sell your data. We do not share it with third parties for advertising. We do not use it to train machine learning models.

What we collect and why

Recipes and formulations

All recipes you create in ChocoForm are stored locally on your device using Apple SwiftData. They never leave your device.

iCloud sync is planned for a future update — when enabled, your recipes will be stored in your personal iCloud account using Apple CloudKit. We will have no access to that data; it will be governed entirely by Apple's iCloud Terms and Privacy Policy.

Subscriptions and payments

Subscription management is handled entirely by Apple via the App Store. We never see, store, or process your payment information. Apple provides us only with an anonymised receipt confirming your subscription tier (Pro or Pro+). For questions about billing, contact Apple Support directly.

AI features

ChocoForm offers three AI backends. Each is optional, opt-in per request, and disclosed explicitly:

Apple Intelligence (Pro and Pro+) runs entirely on-device using Apple's on-device foundation models. No prompts, responses, or related data leave your device.

Gemini Flash (Pro and Pro+) is an optional cloud backend that sends your prompts to Google's Gemini API through a Cloudflare AI Gateway operated by ChocoForm. We log only the count of API requests per anonymised device identifier to enforce a daily free-tier quota (per device and per network). Google's own data usage policy applies to the prompt content — see ai.google.dev/gemini-api/terms.

Claude Sonnet (5 lifetime trial requests on Pro, monthly quota on Pro+) sends your prompts to Anthropic's API through a Cloudflare proxy operated by ChocoForm. We log only the count of requests per anonymised subscription token (derived from your Apple subscription receipt) to enforce these quotas. We never log, store, or read the content of your prompts or the AI's responses.

Anthropic may retain prompts and responses for up to 30 days for abuse monitoring per their data usage policy — see anthropic.com/legal/aup. Pro+ subscribers may optionally configure a fallback to their own Anthropic API key in Settings; when that fallback engages, requests bypass our proxy entirely and Anthropic's terms apply directly to your key.

Infrastructure logs

Our Cloudflare Worker infrastructure logs standard request metadata (IP address, response code, request timing) for 24 hours for abuse prevention and debugging. These logs are not linked to your subscription identity and are deleted automatically after that window.

Ingredient database

When you search the USDA FoodData Central database from within the app, your query is sent directly to the USDA's public API as an anonymous HTTP request. We do not intercept, proxy, store, or see these queries. The USDA's own privacy policy applies to those requests.

Analytics and crash reporting

We do not embed any third-party analytics SDKs (no Firebase, Mixpanel, Amplitude, or similar). If you have opted into sharing analytics with developers in your iOS/macOS settings, Apple may share anonymised, aggregated usage data with us through App Store Connect. This data contains no personally identifiable information and we cannot link it to individual users.

Crash reports follow the same mechanism — opt-in through Apple's system, aggregated and anonymised before we see them.

Data we do not collect

Data retention and deletion

Because we store no personal data on our servers, there is nothing to delete on our side. Your recipes live on your device — you can delete them at any time from within the app. Uninstalling the app removes all local SwiftData storage.

The only server-side records we hold:

Children

ChocoForm is a professional tool intended for adults. We do not knowingly collect any information from children under the age of 13. If you believe a child has provided information to us, contact us at the address below and we will delete it promptly.

Changes to this policy

If we make material changes to this policy, we will update the "Last updated" date at the top of this page. We may also notify you through the App Store update notes. Continued use of the app after changes are posted constitutes acceptance of the updated policy.

Contact

Questions about this policy? Write to us at support@chocoform.pro. We aim to respond within 3 business days.