Last updated: September 19, 2026
Accounts
Your account and local library
You can browse the public catalog without an account. Sign in with Apple is used for account features, including social recipe imports. Nooktail receives an Apple account identifier and, when Apple provides it, an email address. Our account database stores hashed versions of these values, together with account and session records used to authenticate requests and protect your private imports.
Session credentials are stored in the shared iOS Keychain. Apple authorization tokens needed to revoke access are encrypted on our server. Favorites and notes you create locally use local app storage.
Social imports also have server records: source links, available author attribution, supplied recipe text, ingredients and steps, supporting evidence, drafts, saved recipes, cover images, and processing or save status. These records are associated with your account and are not added to the public catalog. Local copies may remain for viewing and recovery. Removing a note locally does not currently delete its server import record.
Social imports
What you allow us to process
Before sending a new import for processing, Nooktail asks you to allow the disclosed processing for your account. You can decline and continue browsing the catalog.
Nooktail sends the Instagram or TikTok post link you choose to Apify to retrieve available public post information, including caption, author attribution, cover images, and video. Our Cloudflare service parses recipe text and stores your import and saved recipe. When text lacks recipe details, an available source video is provided, including its audio, to Volcengine Ark (Seed Lite) in mainland China for AI analysis of ingredients and steps, together with the requested language.
The video-analysis request does not include your Apple credentials, Nooktail account identifier, or separately supplied caption text. A source video can itself contain people, voices, and other personal information. Only submit content you are permitted to use and send for this processing. Nooktail does not request your Instagram or TikTok password.
AI results can be incomplete or inaccurate. Review them before saving or using a recipe. Attribution and a source link identify the source; they do not grant permission to copy or process it.
Service providers
Who receives information
Cloudflare hosts our APIs, private database, cover-image storage, and work queue. Apify retrieves social post information. Volcengine Ark (Seed Lite) processes video and audio in mainland China for AI analysis. Apple supplies sign-in and, where enabled, App Store transactions. The existing RevenueCat integration processes account and purchase or entitlement information for subscription functionality and purchase reporting.
Public catalog data is delivered by Nooktail. Public catalog images are fetched directly from TheCocktailDB, which receives ordinary delivery metadata, and may use a bounded on-device image cache. Imported cover images are separate: Nooktail stores them privately for your account.
Providers receive information needed for their role and ordinary connection metadata. They may process information in countries other than yours. European storage for a database or image bucket does not mean all request handling, queues, logs, social retrieval, or AI processing stays in Europe.
Retention
How long information stays
Account-linked imports, drafts, saved recipes, and covers are kept to provide account features and recovery until account deletion. The current service does not automatically remove all of these records after a fixed number of days.
Cancelling an import stops further scheduled work where possible, but does not itself erase existing drafts, assets, or provider records. Signing out removes active local session access and hides account-scoped imports; it does not delete your account.
We request that video-model responses are not stored as retrievable results. This is not a guarantee of zero provider retention. The model request includes the video directly; Nooktail does not create a persistent provider file through the Files API. Provider security, safety, and operational records may follow separate retention policies. We do not promise a fixed provider retention period. Apify retention depends on its plan and storage configuration; some named storage does not automatically expire.
Local image caches can be removed by cache eviction or iOS. Local import journals and account-scoped covers have no fixed calendar expiry. Deleting the app removes its local app data subject to iOS shared-container and backup behavior; it does not request server account deletion or guarantee removal of Keychain credentials. We make no fixed retention promise for provider logs, backups, or support correspondence.
Your choices
Account deletion and privacy requests
You can initiate Delete Account in the app. Deletion disables account access and attempts to remove private imports and cover objects, delete the external billing identity, and revoke Sign in with Apple authorization. Local copies of account imports may be removed before all server deletion steps finish. If a step cannot finish, the app shows deletion as incomplete and allows retry. Some Apple failures require you to finish removal in Apple settings.
A completed Nooktail deletion receipt does not mean independent provider safety logs, backups, or the original social post have disappeared. Limited account and deletion records, including unresolved authorization-recovery records, can remain to complete and verify deletion. No fixed retention period is promised for those records.
Our current account-deletion process does not automatically submit deletion requests to Apify or Volcengine Ark. For help accessing, correcting, or deleting personal information, including provider-held information, contact hello@nooktail.app. Describe the request without sending passwords, sign-in codes, access tokens, or private video files.
Diagnostics and support
Information used to run the service
The catalog service records bounded route, status, latency, and error information for operation and troubleshooting. Private imports also maintain processing states, attempt counts, error codes, and deletion status. Infrastructure can process IP addresses and other ordinary request, security, and traffic metadata.
Nooktail does not implement advertising or cross-app tracking. If you contact support, your email and message are used to handle the request. For practical reporting guidance, visit Support. Updates to this policy will be published on this page.