Privacy Policy
Version of July 21, 2026.
This policy explains what Receita Lucrativa, the app published in the stores as "Recipe Cost & Pricing", does with personal data: yours and your customers'. The party responsible is F98K Solutions. Contact: profitrecipe-support@receitalucrativa.com
## What changed in this version
Publishing a menu now requires you to identify yourself: a Google or Apple login linked to your account, and a phone number verified by SMS. Three consequences of that are new in this policy, and all of them are detailed further down. The number you verify becomes the public contact number of your menu. It is also what keeps someone who has been suspended from coming back with another account. And, for that second part to work, a record derived from it survives the deletion of your account, with no date to come off.
The previous version of this policy corrected a mistake in the ones before it, and the correction still holds: those versions said most of the app's data was stored locally on your device, and that was already wrong when it was written — the backup to our servers was already running. Part of your data is on our servers. That is what makes your menu exist on the internet, lets orders reach you, and lets your backup be restored on another device. This policy says exactly what is stored where.
This version also documents an internal record that already existed: one record per owner, tied to your account, bringing together the phone number, the login provider, the menu and the device, for moderation and support. No new data is collected — it is the same data, now also consolidated in one place, and it is deleted when you delete your account.
## Your account
You do not sign up to use the app. We do not ask for an email, we do not ask for a password and we do not ask for your name.
The first time the app opens, it creates an anonymous account for you on its own, identified only by a code the system generates. This happens without you doing anything, and you have probably not noticed that this account exists.
Your data is tied to that account: your backup, your subscription and your menu. Whenever this policy says "your account", it means that account.
It stops being anonymous when you publish a menu. Publishing requires linking a Google or Apple login and verifying a phone number, and from then on the account also carries the email address of the login you linked — with Apple, that may be a relay address that hides your real one — your name, when the provider sends us one, and the number you verified. It is the same account as before: it is not replaced, it gains those links.
Anyone who only uses the app and does not publish a menu needs none of this and stays with the anonymous account.
## We have two different roles
This matters because it tells you who to ask for what.
For the orders on your menu, you are in charge. You are the controller of your customers' data, and we are only the processor: we handle that data on your behalf and on your instruction.
For your own account data, your backup, menu statistics, the usage and device profile, the feedback you send us, and abuse and fraud prevention, we are the controllers. In those cases the decision about the processing is ours, and we are the ones you talk to.
## What stays on your device
Your recipes, your costs, your ingredients, your inventory and your finances are created and used on your device.
An item leaves your device when you publish it on the menu, and also when the backup sends a copy of it to our server. Backup is on by default, without you having to do anything. The next section explains how it works and how to turn it off, if you prefer.
## What is stored on our server
Backup and sync. Backup of your data is on by default. As soon as you start using the app, a copy of your data uploads automatically to our server, tied to your account, without you needing to do anything. We always keep the most recent version of that copy, and it is accessible only to you and to our systems. This is what guarantees you do not lose your work if you switch devices, reinstall the app, or lose your phone.
Because backup is on by default, the legal basis for this processing is not your consent: under Brazil's General Data Protection Law (LGPD), consent requires a free, informed and explicit choice, and an option that already comes turned on does not meet that bar. The legal basis here is performance of the contract — backup is a feature of the service you sign up for when you use the app. You can turn backup off at any time in Settings, under Account & Backup, in the Automatic backup switch; if you turn it off, your data goes back to existing only on your device.
Published menu. When you publish a menu, the server stores your page address, the business details you chose to display, the published items with name, description and price, and the photos and cover image. This is public by nature: it is a web page, made to be seen by anyone.
The owner's verified phone number. When you publish, we store the number you verified. It is stored as a readable number in three places: in Firebase Authentication, tied to your account; in the published menu, as the public contact — it is where your customer's order goes over WhatsApp, so anyone who opens your page can reach it; and in the owner's consolidated record, described further down in this section, which is internal and closed to customers. This does not increase what is already public: the number was already exposed on the menu; the record just adds one more place where it is also stored.
That number serves three purposes, and it is worth separating them because the legal basis for each one is different. Identifying who publishes, and being the menu's public contact, are part of the service you sign up for when you publish: the legal basis for both is performance of the contract. The third is preventing abuse — keeping someone who was suspended over illegal content from republishing under another account; the legal basis for that one is legitimate interest (LGPD art. 7, IX; GDPR art. 6(1)(f)). The section "If your menu is suspended" explains how it works in practice, because it is the part of this policy that most needs explaining.
To send the SMS with the verification code, the number passes through Firebase Authentication, from Google. See "Who we share with".
The owner's consolidated record. When you publish, we also store an internal record, tied to your account, that brings together in one place data we already keep separately: the verified phone number and the code computed from it, the login provider you linked (Google or Apple), your menu's address, the snapshot of the device you use, and the version of the terms you accepted, plus the date of your first and your last publish. It serves moderation and abuse prevention — starting from a reported phone number or a uid, finding the owner, the menu and the device behind it, and cross-referencing the suspension record derived from your phone number (section "If your menu is suspended") to identify repeat offenders — and it serves support. It is not used for marketing or product metrics. The legal basis is the same one already described for phone-based abuse prevention: legitimate interest (LGPD art. 7, IX; GDPR art. 6(1)(f)). Unlike the suspension record derived from your phone number, this record does not survive: it exists for as long as your account exists, and it is deleted when you delete your account.
Terms acceptance. When you accept the Terms of Use and this policy on the app's screen, we store which version you accepted, the date and time, the IP address the acceptance came from, and the identification of the app or browser that sent it. This exists so we can show, if it is ever needed, which text you saw and when.
Orders. The orders your customers send through the menu. The next section has the details.
Subscription. The status of your Premium plan, so we know whether the subscription is active. The payment itself happens at the store, not with us.
Usage and security. Menu access statistics, such as visit counts, and technical access logs that we use to keep the service running and to prevent abuse and fraud.
Usage and device profile. Tied to your account, we keep a snapshot of the device you use: model, operating system and its version, app version, language and time zone. We also keep how many times the app talked to our server, the date of the first and the last access, and whether you chose the light or dark theme. This is for us to understand how the app is used and to improve it. For that data, we are the controllers.
Feedback inside the app. If you answer an opinion survey in the app, we keep the score you gave, the comment you wrote, the topics you tagged and the date, tied to your account. This is for us to improve the app. For that data, we are the controllers.
Support. If you write to us, we keep your message and your contact so we can reply.
## Your customers' data
When someone places an order on your menu, we collect the name, the contact (phone or email), the address only when the order is for delivery, any notes the person writes, the chosen items and the total.
That data is stored on behalf of your business and used for a single purpose: getting the order to you.
We keep each order for 90 days. After that it is deleted automatically.
For that data, you, the menu owner, are the controller. We are the processor. If one of your customers wants to access, correct or delete their data, they should talk to you. If they come to us, we direct them to you and, at your request, we carry out the deletion.
We do not sell, rent or use your customers' data for advertising.
## Who we share with
We do not sell your data. We share it only with those who are necessary for the app to work.
Firebase and Google Cloud, from Google, which provide the infrastructure: server, database and storage. That is where the menu, the orders and the backup are hosted. Firebase Authentication is also what holds the links to your Google or Apple account and what sends the SMS with the verification code to your phone.
Google AdMob, which serves the ads on the free plan.
Apple App Store and Google Play, which process in-app purchases and subscriptions.
These providers handle data according to their own privacy policies. We do not use any other third party to process your data.
We may also share data when the law requires it or to comply with an order from a competent authority.
## Your rights
The Brazilian General Data Protection Law (LGPD) gives you the right to confirm whether we process your data, access that data, correct incomplete or wrong data, request deletion, request portability, and know who we share it with.
When a processing activity depends on your consent, you also have the right to withdraw it. Backup does not depend on it: its legal basis is performance of the contract, as we explained above. There is no consent to withdraw there. What there is instead is the switch in Settings, which turns backup off whenever you want.
If you are in the European Union, the GDPR applies to the processing of your data and gives you rights equivalent to the ones above, plus two that matter here: the right to object to processing we carry out on the basis of legitimate interest (art. 21), and the right to lodge a complaint with the data protection authority in your country. The processing where this weighs most is abuse prevention, described in the section "If your menu is suspended".
To exercise any of these rights, write to profitrecipe-support@receitalucrativa.com. We reply within the legal deadline.
If the request concerns the data of a menu's customer, the owner of that menu is the one who answers, because she is the controller. We help route it.
## If your menu is suspended
We may suspend a menu when its content violates the Terms of Use or the law. The decision is made by a person on our team, with the reason on record; it is not an automated decision. When it happens, we keep two records, and the two have different fates.
The first is tied to your account. It holds the reason, the date, who on our team decided, and what your menu's address was. It is identifiable data, and it is what lets us tell you why you were suspended and review your appeal. That record is deleted when you delete your account.
The second is derived from the phone number you verified. It does not hold the number: it holds a code computed from the number using a secret key of ours (an HMAC-SHA256), from which it is not possible to get back to the number. Next to that code sit the date, the reason, the number of the report that started the case when there was one, and the internal identifier of the account that existed at the time — a code of ours, pointing at an account that has already been erased. Not your name, not your phone number, not what you had published.
That second record is not deleted when you delete your account, and it has no date to come off. Of the two, it is the only one that survives the deletion — and, as the next section explains, it is also the only data of ours we do not delete on request.
Why it exists: the first record lives entirely inside what account deletion erases. Without the second one, deleting your account, creating another and republishing the same content would be enough — and the suspension would mean nothing.
The legal basis for it, plainly. It is legitimate interest (LGPD art. 7, IX; GDPR art. 6(1)(f)) in stopping someone suspended from a publishing platform from coming back to do it again. It is not a legal obligation on us: it is a choice, which the law allows when it is proportionate. The proportionality here is in what we keep: a code from which nobody gets to your number, the date and the reason. Nothing that describes you, nothing that describes what you published, nothing that serves any other purpose. On deletion: the LGPD right to erasure (art. 18, VI) covers data processed on the basis of your consent, and this is not such data. Under the GDPR, the right to erasure has an exception when the data is necessary for the establishment, exercise or defence of legal claims (art. 17(3)(e)), and you can object to processing based on legitimate interest (art. 21) — if you object, a person genuinely reviews your case.
One thing we are not going to write here is that this code is anonymous, because it is not. It is pseudonymous: nobody gets to your number from it, but it still refers to a person. We treat it as personal data, and that is why it is described in this policy instead of left out of it.
How to contest. Write to profitrecipe-support@receitalucrativa.com. This holds even after you delete your account: tell us the number you had verified, because that is how we locate the record — we recompute the code from it, since the reverse path does not exist. A person reviews it. If the suspension is lifted, both records are deleted: the second one included, and even if your account no longer exists.
## Deleting your account
The app has a delete-account function. Read this section before you use it.
What it deletes: the backup of your data on our server and the records of that backup; your account, with the Google or Apple links and the verified phone number; your published menu, which goes offline, along with the photos you uploaded; the orders your customers had already sent; the menu statistics; the record of your terms acceptance; the owner's consolidated record; and the suspension record tied to your account, if there is one. After that, you can no longer restore that data.
What it does not delete: the suspension record derived from your phone number, explained in the section above — of the two suspension records, it is the only one that survives, by design. Also still on our server: the record of your subscription, the usage and device profile, and the feedback you sent us.
If you want what is left to be deleted, write to profitrecipe-support@receitalucrativa.com and ask. The one exception is the phone-derived suspension record: it does not come off on request, it comes off only if the suspension is reviewed.
## Security
Access to data on the server requires authentication, and your backup and your orders are not accessible to other app users. We use encrypted connections and access control in our systems.
We take reasonable measures to protect your information. Even so, no method of transmission over the internet or of electronic storage is completely secure, and we cannot promise absolute security.
## Changes to this policy
We may update this policy. When a change is relevant, we notify you in the app and ask for a new acceptance. The version date is at the top of this page.
## Contact
For questions about this policy or to exercise your rights: profitrecipe-support@receitalucrativa.com