Cookie Lab
DashboardRecipesCompareLogs
New Recipe
Cookie Lab Notebook — made with love and butter.
GuideSupportPrivacyTerms
DashboardRecipesCompareLogs
Back to Cookie Lab

Privacy Notice

What we collect, why, and the choices you have.

Last updated: 30 July 2026

This notice explains how Cookie Lab Notebook(“we”, “us”, “the app”) handles your information when you use the app at cookielabnotebook.com. We’ve tried to keep it in plain language. If anything is unclear, email us at cookielabnotebook@gmail.com.

The short version: Cookie Lab Notebook is a personal baking journal. We only collect what we need to run your account, take payment if you choose a paid plan, and store the recipes and bakes you save. We do not sell your data and we don’t show advertising. We do use a small amount of analytics to understand how the site is used — described under Cookies and Analytics below.

Who we are

Cookie Lab Notebook is the “data controller” for your information — the party responsible for it. You can reach us about anything in this notice, including privacy requests, at cookielabnotebook@gmail.com.

What we collect

Information you give us

  • Account details — your name, email address, and (if you sign up with a password) a securely hashed version of that password. We never store your password in plain text. If you sign in with Google instead, we receive your basic Google profile (name, email, and profile picture) so we can create your account.
  • The content you create — recipes, bake logs (ingredients, oven settings, ratings, notes), photos you upload, tags, and favorites. This is yours; we store it so you can come back to it.
  • Payment details, if you subscribe — our payment provider Stripe collects and handles your card information directly. We never see or store your full card number. We keep only what we need to manage your membership: a Stripe customer reference, whether your subscription is active, and when the current period ends.

Information we collect automatically

  • Login/session data — when you sign in, we store a session along with your IP address and browser type (user-agent). This keeps you logged in and helps protect your account.
  • Preference cookies — small settings such as your light/dark theme and whether you view temperatures in °F or °C.
  • Usage information — pages visited, clicks, scrolling, rough location (country/region, from your IP address), and device and browser type, collected by our analytics provider. See Analytics below.
  • Error reports— when something goes wrong, we record the technical details of the failure (the page involved and a diagnostic trace) and email them to our administrator so it can be fixed. These reports are about the fault, not about you, and we don’t use them to build a profile.

Cookies

We use essential cookies — one to keep you signed in (set by our login system) and a couple to remember your display preferences.

We also use analytics cookies set by Microsoft Clarity and Google Analytics, which help us see how the site is used so we can improve it. We do notuse advertising cookies, and we don’t sell what we learn.

Analytics

We use Microsoft Clarity to understand how people use Cookie Lab Notebook. Clarity records how visitors interact with the site — pages viewed, clicks, scrolling, and general behaviour — and can replay those interactions as anonymised session recordings, plus aggregate heatmaps. We use this only to find confusing pages and broken flows.

Clarity masks text content by default, so the recipes and notes you type are not intended to be captured. Microsoft may use the data it collects in line with its own privacy statement. You can opt out of this kind of tracking by turning on Do Not Track or a tracking blocker in your browser, and the app will still work normally.

We also use Google Analytics 4for aggregate numbers — how many people visit, which pages they land on, and how many complete key steps. Both tools receive a small set of named events for the actions that matter to us: signing up, signing in, saving a recipe or bake log, running a comparison, starting or completing a subscription, and failures such as a photo that wouldn’t upload. These record that an action happened, never the content of your notebook — no recipe text, ingredients, notes, or photos are sent to either provider. Google may use the data it collects in line with its own privacy policy.

How we use your information

  • To create and secure your account and keep you signed in.
  • To store and show you the recipes, bakes, and photos you save.
  • To send account emails you request, such as password resets.
  • To keep the app working, fix problems, and prevent abuse.

We do not use your baking data to train advertising profiles, and we do not sell or rent your personal information to anyone.

The services that help us run the app

We use a few trusted providers (“processors”) to operate the app. They only handle your data on our instructions:

  • Vercel — hosts the website and stores the photos you upload (Vercel Blob).
  • Neon — provides the database where your account and content are stored.
  • Brevo — sends transactional emails such as password resets.
  • Stripe — processes subscription payments and handles your card details. Stripe is the party that sees your card number, not us.
  • Microsoft — provides Clarity analytics (see above) and Bing Webmaster Tools, which reports how our public pages appear in Bing search.
  • GitHub — stores our encrypted-in-transit nightly database backups, so your recipes can be recovered if something goes wrong. Backups are private to us and are deleted automatically after 30 days.
  • Google— provides Google Analytics (see above); also used if you choose “Continue with Google” to sign in, and Google Search Console, which reports how our public pages appear in Google search.

These providers may store data on servers outside your country. Where that happens, we rely on their standard safeguards for international transfers.

How long we keep your data

We keep your account and content for as long as your account is active. You can delete your account yourself at any time from your account page— that immediately removes your personal data, recipes, bake logs and photos from the live database, and cancels any Pro membership so you aren’t billed again. Login sessions and password-reset links expire automatically.

We take a nightly backup of the database so your work can be recovered after a mistake or a failure. Backups are kept for 30 daysand then deleted automatically. This means that after you delete your account, a copy may remain in backups for up to 30 days before it ages out. Analytics data held by Microsoft Clarity and Google Analytics is retained under those providers’ own schedules.

Your rights and choices

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to certain uses. You can:

  • Edit your recipes and bakes directly in the app at any time.
  • Delete your account yourself, whenever you like, from your account page. It takes effect straight away.
  • Download everything we hold about you from your account page — profile, recipes, bake logs and ratings, as a file you can keep or take elsewhere.
  • Ask us for anything else above by emailing cookielabnotebook@gmail.com. We’ll respond within a reasonable time.

Security

Connections to the app are encrypted (HTTPS). Passwords are stored only as a secure hash, never in plain text. No online service can promise perfect security, but we take reasonable steps to protect your information and use reputable providers.

Children

Cookie Lab Notebook isn’t directed at children, and you should be old enough to agree to our Termsin your country (generally at least 13, or 16 in some regions). We don’t knowingly collect data from children below that age.

Changes to this notice

If we make meaningful changes, we’ll update the date at the top of this page and, where appropriate, let you know in the app.

Contact us

Questions or requests? Email cookielabnotebook@gmail.com.