Privacy Policy
Last updated 28 July 2026
Paid-release review notice: the legal operator details, production AI providers, transcription path, processor settings, and retention schedule are being verified. The AI Baking Coach will not be enabled until those details are named in this policy and the matching in-app disclosure.
Who we are
Lievanto is a baking logbook, planning, calculator, and optional AI Baking Coach app operated by an individual developer based in the Netherlands. This policy covers the Lievanto mobile app and the website at lievanto.com. The full paid-release legal operator and service-address details will be inserted here after owner and legal verification.
For privacy questions, data requests, or account deletion help, email privacy@lievanto.com.
What we collect
We collect the minimum data needed to run the service. If you create an account, we store your email address, display name, password hash, account settings, recipes, cook sessions, notes, ratings, photos, flour profiles, price book entries, planned bakes, starter logs, and other content you choose to save.
The app also stores authentication metadata, such as refresh tokens and timestamps, so you can stay signed in securely. We may keep short-lived server logs for security, debugging, abuse prevention, and reliability.
If you explicitly rate an equipment-aware suggestion, we store the agree or disagree choice and any optional comment you submit so we can evaluate and improve those suggestions.
If you start a trial or subscribe to Lievanto Pro, we process the product, storefront, trial and entitlement status, renewal state, expiry, and limited provider transaction or customer references needed to activate and support Pro. Apple handles your payment credentials; Lievanto does not receive your full card details.
If you use the optional AI Baking Coach, we process your versioned permission, the content needed for the action, completed Coach advice and conversations, helpful/not-helpful feedback, and allowance and cost metadata. Raw provider prompts and unvalidated provider responses are not stored as your Coach history.
If you use the website launch notify form, we store the email address you enter and, if you add one, your optional feature wish. We use this to send launch updates, understand what bakers want, and administer the early-supporter benefit described in the Terms.
Password-reset and launch-list requests pass through a bounded, encrypted delivery queue. Recipients, optional launch notes, rendered messages, and link tokens are not stored there in plaintext. Pending commands expire automatically; terminal records discard the encrypted payload and token seed and retain only short-lived, content-free operational metadata.
Why we use it
We use account data to provide the service you signed up for: sign-in, password reset, recipe storage, session history, exports, equipment-aware suggestions, and account deletion.
We use launch notify data with your consent. You can ask us to remove your email at any time by emailing privacy@lievanto.com.
We use logs and rate-limit counters under our legitimate interest in keeping the service reliable, secure, and protected from abuse.
Optional AI Baking Coach
Nothing is sent to an AI provider merely because you save a bake, recipe, plan, note, or photo. After you accept the current disclosure and explicitly start a Coach action, Lievanto may send the selected bake's recipe and plan context, session notes, observations, timings, ratings, equipment, bounded summaries of up to five recent bakes of the same recipe, confirmed Build a bake constraints, your typed question or reviewed voice transcript, and photos you explicitly select or capture when relevant to the named action.
Coach context excludes your email, password and authentication data, billing data, raw server logs, unrelated recipes or sessions, and other users' content. Coach image reads use bounded, orientation-corrected, metadata-stripped temporary derivatives. They are separate from Pro cloud-photo backup and do not change originals.
If voice input ships, microphone access starts only after you choose to record. Raw audio is used transiently to create a transcript for you to review and edit; it is not Coach history and must be deleted after transcription or cancellation. The final disclosure will name the transcription implementation/provider and its verified retention, training, region, subprocessor, transfer, and deletion terms.
The first-use disclosure and this page will name the selected primary provider and the fallback used only if the first attempt fails. Their verified retention, training-use, processing-region, subprocessor, and transfer terms are a blocking owner verification gate. No broader provider claim is made before that review is complete.
Coach is optional and its permission can be revoked in Settings. Revocation prevents new requests but does not automatically delete completed advice already in history. Deleting an individual Coach item hides it from your normal history and records when you deleted it. Lievanto retains that marked item until you erase your full account. Lievanto does not use your content to train a Lievanto-owned AI model.
Photos and cloud backup
Account text sync and the GDPR JSON export are available on the Free tier. Persistent cloud backup of session photos is a Lievanto Pro feature. Free photos remain local unless you explicitly select one for a transient Coach crumb read within your allowance.
Persistent Pro photos are stored in a private Cloudflare R2 bucket. The app retrieves them through Lievanto's authenticated media API; it does not receive a public bucket or presigned provider URL.
How long we keep it
Account data is kept while your account is open. If you delete your account, account content is permanently deleted from active systems. Private media deletion is durably queued and retried after transient storage failures without retaining an account identifier in the deletion job. When an individually deleted recipe, session, plan, starter, synced document, Coach item, calculator preset, flour profile, price-book row, or production run uses a retained soft-delete or tombstone state, normal app lists hide it while the legal account export includes it with its deletion time until full account erasure. Completed Coach history remains visible until you delete the item or your account. Temporary crumb derivatives are not retained by Lievanto as a second cloud-backup photo.
A prepared password-reset delivery job is deleted with its account. An unmatched public reset command deliberately has no account link so request behavior cannot reveal membership; it expires or becomes a no-op within a bounded window. Launch-list data remains separate from an app account and follows its own consent and withdrawal rules.
Logs, backups, billing or tax records, email-delivery records, and external-provider data can follow separate schedules. The exact production periods and deletion behavior are a blocking owner/legal verification gate and will be published here before subscriptions and Coach are enabled.
Your rights
If you are in the European Union, you can ask to access, correct, delete, export, restrict, or object to the use of your personal data. You can also withdraw consent where processing is based on consent.
The in-app JSON export includes your recipes, sessions, plans, normalized and synced starter history, calculator presets and history, flour profiles, ingredient price-book entries, production runs, recipe-fork lineage, equipment-adaptation feedback, bulk-fermentation check-ins, user-facing session-photo metadata, completed Coach advice, conversations, Coach feedback, consent history, and relevant logical AI usage/cost metadata. Retained recipes, sessions, plans, starters, synced document tombstones, and other items you deleted individually are included with their deletion time where the record has a soft-delete state, because Lievanto retains them until full account erasure. Provider secrets, authentication hashes, raw provider/webhook content, security and rate-limit records, media quota/accounting rows, parser/optimizer/weather usage logs, private storage-key fields, and internal email or deletion queues are excluded from the self-service portability file. User-facing protected media URLs remain and may contain an opaque object identifier. You can still request broader access by contacting us; that request is handled under applicable law. If you choose the ZIP photo bundle, it contains eligible remotely stored photo files owned by your account, including retained-session and account-level starter/check-in images where available, rather than link placeholders.
You can delete your account in the app from Settings, or use the public account deletion instructions. You can also email privacy@lievanto.com.
Deleting a Lievanto account does not cancel an Apple subscription or stop Apple billing. Manage or cancel the subscription in your Apple Account settings before deleting the Lievanto account.
If you think we handled your data incorrectly, you can complain to your local data-protection authority. In the Netherlands, this is the Autoriteit Persoonsgegevens.
Children
Lievanto is not directed at children under 16. The app asks new users to confirm they are 16 or older when creating an account. If you believe a child under 16 created an account, email privacy@lievanto.com and we will investigate.
Learn articles and sources
Lievanto Learn articles are original educational summaries written for Lievanto. Source links are provided for further reading. Third-party source text, images, brand names, book titles, and trademarks remain with their owners.
If you own a cited work and want a credit changed or removed, email privacy@lievanto.com.
Changes
We may update this policy as the product changes. If a change materially affects your rights or how your data is used, we will give reasonable notice before it takes effect.
Contact
Email privacy@lievanto.com with privacy questions or requests.