THE YUM PANDEMIC
Summer Launch Special: 20% off for your first 12 months. Or join for free!

Privacy Policy

This Privacy Policy describes how The Yum Pandemic collects, uses, and shares personal data for visitors and registered members across our recipe, community, AI content, and subscription features.

1. Scope and Operator

The operator of the Platform is Mr Andrew Tzionis trading as The Yum Pandemic, with registered address at Shop 3, 16 Christaki Kranou, Potamos Germasoyia, Limassol 4041, Cyprus (referred to as "The Yum Pandemic", "we", "us", or "our"). The Yum Pandemic is not operated through a registered company. This policy applies to all users globally, subject to regional overrides described in our Regional Legal Annexes and below.

2. Personal Data We Collect

  • Account Information: Name, email address, password, profile handle, profile picture, bio, date of birth, country of residence, and legal acceptance records.
  • Source Material and Community Content: Recipe information, ingredients, instructions, cooking methods, reference photos, original blogs, videos, comments, direct or community messages, and virtual cookbook collections that you submit or create.
  • Subscription and Billing Data: Stripe customer ID, payment status, subscription tier (Free, Home Cook, Chef, or Professional), Checkout session identifiers, transaction history, declared residence country, trusted request-country evidence where available, and the billing-country code returned by Stripe or Link. We do not store the full Stripe billing address or full credit card details.
  • AI-Assisted Activity: Recipe prompts, image generation inputs, safety classification results, and moderation history.
  • Technical and Usage Data: IP address, IP-derived or declared location, browser type, operating system, device/session security data, consent choices, and activity logs.
  • Profanity-Filter Preferences and Metadata: Your warning and viewing-mask choices, plus limited metadata for an ordinary matched submission (content type and identifier, rule-set version, internal rule identifiers, decision state, dates, and a keyed text-revision fingerprint). This metadata does not contain the matched word, surrounding text, or a copy of the submission.
  • Press subscription information: Where this feature is available, if you ask to receive press releases or media updates, we process your work email address, selected release language, the consent text, version and timestamp, email confirmation or withdrawal status, and limited delivery safety events. We automatically expire an unconfirmed request shortly before 30 days, then remove our local record no later than 30 days after it is made.

3. Purpose and Legal Bases for Processing

  • To create, secure, and maintain your account, verify age eligibility requirements, record legal acceptance, and apply child-safety defaults.
  • To retain and process your Source Material, operate moderation and provenance records, and host, publish, display, search, and distribute approved content and profile material.
  • To process subscription transactions through Stripe Managed Payments, apply supported-country controls, manage entitlements, stop or review inconsistent transactions, and operate cancellation, refund and renewal controls.
  • To provide generative AI tools that analyse Source Material and create rewritten recipe text, generated images, editorial enhancements, translations, and other Generated Platform Content.
  • To enforce our Community Guidelines and run automated and manual moderation tools.
  • To send transactional notices, failed payment alerts, annual renewal notices, and customer support responses.
  • To run a local, deterministic profanity filter on supported messages, comments, feedback, and profile posts. It can warn an author before an ordinary matched submission and mask matched text for viewers who use the mask preference. This filter does not send the submitted text to a third party, does not by itself create an enforcement queue, and does not by itself suspend an account or remove ordinary text that an author chooses to submit after the warning.
  • To operate voluntary Press Release and media update subscriptions: to confirm your request by email, send the requested updates after confirmation, honour unsubscribes and suppressions, and keep only proportionate consent records.

4. Data Sharing and Third Parties

  • Payment Processors: We share checkout and billing details with Stripe to handle payment security and subscription operations.
  • AI Providers: We share the Source Material and prompts needed to generate recipes, images, translations, and editorial enhancements with integrated third-party AI providers, such as OpenAI. We do not permit these providers to use your prompts, Source Material, or outputs to train their models.
  • Hosting & Analytics: We use secure cloud hosting, strictly necessary security/product telemetry, and optional third-party analytics only where consent and age eligibility allow it.
  • Email delivery providers: We use DreamHost authenticated email services for Press Kit subscription confirmations and other applicable platform mail. If Brevo is later activated for consented Press Release delivery, it will process only confirmed voluntary subscribers and related unsubscribe or delivery safety events. We do not use this subscriber route for uninvited newsroom contacts.
  • No Sale of Data: We do not sell your personal data or user-generated content to third parties.

5. Regional Restrictions and Data Protection

  • Minimum Age Gates: Account registration is restricted globally to users who are at least 16 years old. We collect date of birth and country of residence at registration to apply age, child-safety, legal-acceptance, analytics, and alcohol-content restrictions.
  • Alcohol-Related Restrictions: We restrict alcohol-themed recipes, cocktail posts, and related profiles in countries where the promotion or consumption of alcohol is legally restricted or prohibited. See Regional Legal Annexes for the list of restricted countries.
  • GDPR Compliance: We maintain GDPR-focused registration records, legal acceptance snapshots, consent preferences, data minimisation controls, and child-safety defaults. We review legal bases, international transfer safeguards, and retention periods as the service and applicable guidance change, and obtain external professional review where appropriate.
  • Local Compliance Overrides: Additional region-specific consumer protection and tax policies are detailed in the Regional Legal Annexes.

6. Data Retention and Deletion

We retain personal data only for as long as needed for account operation, content generation and publication, moderation, provenance, legal compliance, safety, billing, audit, and dispute purposes. Source Material associated with an active submission or published content may be retained while needed for those purposes. We keep compliance audit, legal acceptance, consent, age-verification attempt, and payment records only for the minimum legally required or operationally necessary periods. We do not store raw identity documents, biometric data, raw wallet credentials, or full IP addresses for age assurance.

When we erase applicable account data, we remove it from active systems and actively managed private storage. A limited residual copy may remain in DreamHost or other provider backups for a restricted restoration and security period. We do not claim immediate deletion from every backup. A recovered backup must apply deletion-suppression controls before normal use so erased data is not restored to active service.

7. Your Rights and Choices

  • Access & Export: You can request a self-service account-data archive from your Profile. Routine archives include approved account data and user-authored Source Material within the implemented package scope, but exclude Generated Platform Content, passwords, security secrets, internal moderation notes, provider payloads, and other users' content. The archive is collected from your Profile during the stated availability window and is not emailed or attached. Contact the Data Protection desk below for statutory or manual requests that are not fulfilled by the self-service archive.
  • Correction & Deletion: You can update your account details or request the deletion of your personal data.
  • Stripe Customer Portal: You can update payment methods, download invoices, and cancel your subscription online at any time.
  • Contact: To exercise your privacy rights, contact our Data Protection desk at Email us.
  • Account Closure: When self-service account closure is available, you can request it from your Profile after recent identity verification. It starts a seven-day cancellation period, revokes active account access and data archives, and then permanently erases applicable account data. It may retain only eligible public or reusable Generated Platform Content after verified provenance and removal of personal identity and protected expression. If ordinary account access is unavailable, use the dedicated closure-access route or contact the Data Protection desk.
  • Press subscriptions: You can use the unsubscribe link included in each message or contact Email us to withdraw from Press Releases and media updates.
The Yum Pandemic