Privacy notice
Your recipes are yours.
This notice explains how Munchblocks on iPhone handles recipe imports and cooking data.
Last updated 5 September 2026
Who operates Munchblocks
Munchblocks is operated by Matt Robinson. Privacy questions can be sent to mattmrobinson@gmail.com.
What stays on your iPhone
The app stores cooking sessions, timer dates and changes, chosen equipment, and optional “for next time” notes, dish photos, and voice memories in the app’s local container. There is no Munchblocks account or cloud sync in the app.
Live recipe compilation
When you choose Photo, URL, Paste, or Describe, the selected source is sent securely to the Munchblocks compiler so it can create a cooking guide. The source may include recipe text, a recipe webpage address and extracted page content, or up to four selected images. Do not include personal or sensitive information that is not needed for the recipe.
The compiler uses a provider selected by import type:
- URL imports: Google Gemini.
- Paste imports: Anthropic Claude.
- Photo and Describe imports: OpenAI.
Provider keys remain on the Munchblocks service. The app does not let a recipe choose a provider, and compiled guides are checked for valid structure and recipe references before the app displays them. Compare the guide with your original recipe before cooking.
Identity, storage, and retention
Apple App Attest verifies that compile requests come from a legitimate Munchblocks app installation. The service issues an opaque installation credential; it does not receive your Apple ID, email address, or name. The credential is kept in this-device-only Keychain storage, and only a cryptographic digest is stored by the service.
The compiler runs on Railway in Singapore with a private PostgreSQL database. Recipe source data is retained while a guide is queued or building, so an interrupted job can resume. It is cleared when the job succeeds or stops with an error. Jobs and their results expire within 24 hours. A completed guide may be retained for up to 24 hours to return the same result if a request is repeated. One-use security challenges expire within five minutes, rate-limit windows within one hour, and installation credentials expire after 180 days. An hourly cleanup removes expired rows. Short operational logs exclude recipe sources, images, full URLs, compiled output, credentials, and free-form validator messages.
Permissions
Munchblocks asks only when the related feature is used:
- Camera and photo library for recipe pages and optional dish photos.
- Microphone for an optional voice memory.
- Notifications for local timer alerts.
You can review these permissions in iOS Settings.
Analytics, Apple, and deletion
Munchblocks does not include advertising SDKs or product analytics in the app. Apple may process TestFlight installation, diagnostics, and feedback under Apple’s own terms.
Delete the app to remove its local container. The anonymous credential may remain in iOS Keychain until it is cleared by iOS or replaced, and its server record expires after 180 days. The app does not yet provide an in-app server deletion control. Email the address above with privacy questions, but do not send the recipe source itself.
Cooking and sensitive information
Munchblocks organizes cooking instructions. It is not a medical, nutrition, allergy, or food-safety service and does not guarantee doneness or appliance compatibility. Check food, ingredient labels, and authoritative local guidance.