What Spike keeps, why we use it, who else may see it, and the choices you have. Written in plain English.
Last updated 5 September 2026
Spike is a personal project, built and run by one person — Ivan, in Australia — and used by a small group of friends. It is for adults: you must be 18 or older to use it, and we do not knowingly keep information about anyone younger. Questions and requests about your information go to the email address at the bottom of this page, and a person answers them.
Your account. Your email address and, if you set one, a password. Sign-in is handled by Supabase, which stores the password hashed — we never see it and could not read it. If you sign in with Google we receive your email address and name from Google instead, along with the picture on your Google account, which Spike does not currently use.
What you tell it about your eating. Your eating style, how you want to cook, and any allergies or ingredients you avoid. Some of this is about your health, so: allergies are optional, all of it is used only to rate ingredients and shape suggestions for you, nobody else — not even your household — can see it, and you can change or remove it from your profile at any time without deleting your account.
What you make. Recipes you write or edit, shopping lists, your weekly plan, collections and favourites. Optionally a display name and a profile photo. If you have used the “what do you already have?” step, what you said you had in the cupboard.
Photos you upload — for a recipe or your profile — are resized and re-saved in your browser before they are sent, which drops the hidden details a camera adds, such as where the photo was taken. They are then stored at a public web address that is not protected by sign-in: anyone who obtains that address can view or copy the photo. Addresses are long and hard to guess, but they are not private — please don’t upload a photo you would mind a stranger seeing. Deleting a photo, or your account, stops Spike serving it; it cannot recall a copy someone has already made.
A little of what you have opened. Which recipes you have viewed, which Discover ideas you have read, and when you last dismissed the “new recipes” banner — so the app can stop marking things as new. Not how long you looked at anything.
On your phone only. Your light or dark theme, any kitchen timers you have running, which ingredients you have gathered for a recipe you are cooking, a note of who was in your household last time (so Spike can tell you when someone joins), and which Discover page you came from, so Back works. These live in your browser, never reach our servers, and clearing your browser data removes them.
To run and protect Spike, the services that host it keep the basic technical records any website produces: your IP address (which gives a rough location), your browser and device, the time of each request, errors and security logs. Vercel keeps them for the app, Supabase for the database and sign-in. They are kept for a limited time under those providers’ own rules and are used only to keep the service working and safe — never to build a profile of you. Spike itself does not ask for or record your location.
There is no advertising, no tracking pixel and no behavioural analytics; no third-party script watches you use the app. We do not sell your information or share it for marketing. Spike does use what you tell it — your eating style and what you avoid — to personalise its own features for you. That is the point of the app, and it is the only kind of “profiling” that happens here.
Signing in sets a cookie that keeps you signed in (it is sometimes split into two parts). Signing in with Google, or resetting your password, briefly sets a second one to complete that step. There are no others. The items under “On your phone only” live in your browser’s storage, not in cookies.
There is no bot check on sign-in at the moment. If we turn one on, this page will say so first and name who runs it.
Spike is a small app built on other people’s infrastructure. Each of these handles some of your data, and all of them do so outside Australia:
Recipes you write, and your edited copies of ours, are private: nobody else can open them, even with the link. Spike’s own recipes, once we publish them, are public — anyone can read them without an account, and search engines can find them.
A shopping list you share gets its own link. Anyone holding it can read the list without an account (not change it), and can forward it on. Stop sharing from the list’s ⋯ menu and the link stops opening — but that cannot take back a screenshot or copy someone has already made.
If you join a household, the people in it can see, edit and delete your shopping lists, and there is one plan for the whole household that any member can change. Changes to a shared list are pushed to the other members’ phones as they happen. Other members see only your name and photo; your profile, eating information, favourites, collections and ingredient ratings stay yours alone. Leaving a household stops the sharing — your own lists stay with you, and you can take a copy of the plan.
For as long as your account exists. Spike keeps nothing on a timer except household invite codes, which expire after seven days and are removed. Delete your account and it all goes, as described below.
Most of your information you can change yourself, in your profile and settings. To ask for a copy of your data, a correction the app doesn’t let you make, or for something to be removed, write to us. We may ask you to confirm it’s you, and we aim to answer within 30 days.
If you think we have mishandled your information, tell us what happened; we will look into it and explain what we found. If you are not satisfied with our answer, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
You can delete your account from your profile. It removes your account and everything attached to it from Spike’s systems immediately, and it cannot be undone: your account and sign-in, your profile and preferences, recipes you wrote and your edited copies of ours, your favourites and collections, your shopping lists (including any you shared — their links stop working), what you told us you had in the cupboard, your reading history, invite codes you made, and every photo you uploaded. You leave your household; if you were the last person in it, the household and its plan go too. A plan that belongs to a household you leave behind stays with the people still in it.
Our database plan keeps no backups, so once your data is deleted there is no copy of it to restore from. Copies can linger for a short time in our providers’ caches and security logs before they expire on their own schedules; we do not use those for anything.
When the way Spike handles your information changes, this page changes with it and the date at the top moves. Anything that matters — a new service, a new use of your data — we will say so in the app as well.
Write to navicap89@gmail.com and you will reach the person who built Spike.