Privacy Policy

How mati handles your data.

Last updated: 28 July 2026

mati is a personal recipe manager. This policy explains what we collect, why, and the rights you have over your data under the GDPR.

Your recipes are end-to-end encrypted. They are encrypted in your browser with a key derived from your password before they ever leave your device. We store only the ciphertext and cannot read your recipes, even if we wanted to.

Who we are

The data controller for mati is the operator of this service. For any privacy question or to exercise your rights, contact us at <replaceme>@email.com.

What we collect

We do not use analytics, advertising, tracking pixels, or any third-party trackers. There are no cookies used for tracking.

How your encryption works

For the technically curious, here is exactly how it works:

Important: because only you hold the keys, if you forget your password and lose your recovery code, your recipes cannot be recovered by anyone, not even us. Keep your recovery code somewhere safe.

Legal basis

We process your data to provide the service you signed up for, on the Terms of Use; this is performance of a contract (GDPR Art. 6(1)(b)).

Who processes your data (sub-processors)

If you never use recipe generation, none of your content is ever sent to Mistral.

International transfers

Your data is hosted within the European Union (France and Germany). All of the sub-processors above operate in the EU, so your data is not transferred outside it in the normal course of using mati.

How long we keep it

We keep your data for as long as your account exists. When you delete your account, your recipes and account are permanently erased and cannot be recovered.

Your rights

Under the GDPR you can, at any time:

You also have the right to lodge a complaint with your local data protection authority.

Changes to this policy

If we make material changes to how we handle your data, we will update this page and its "last updated" date.