This page is maintained by Forkin Cooking to answer common security and privacy questions about the site. It’s editable project content, not an independent certification or audit.
Sign-in is handled by our managed authentication provider. Passwords are hashed by that provider — we never see or store them. Email/password and Google sign-in are supported; you can delete your account at any time by emailing us.
Your email, the recipes/lessons/notes you save, ratings and likes you leave, and any optional profile fields you fill in. Anonymous page-view and CTA analytics are stored against a randomly generated browser ID, not your account.
Published recipes, lessons, food notes and public comments are visible to everyone. Your saved items, collections, ratings and profile answers are visible only to you. Admin tools and Search Console analytics are restricted to the site owner.
Every database table has row-level security enabled. Personal data is scoped to the signed-in user; admin-only tables require an explicit admin role. Anonymous writes (analytics, likes) are length- and shape-validated server-side.
The site is served over HTTPS by our hosting platform. The database and file storage are managed by our backend provider. Server-only secrets stay on the server and are never shipped to your browser.
A session cookie keeps you signed in. We use first-party analytics to see which pages are useful. No third-party ad tracking, no data sold to brokers.
We rely on a managed hosting platform, a managed backend platform (database, auth, storage), and an AI model gateway for assistant features. These providers process data on our behalf under their own security programmes.
Email hello@forkincooking.com to access, correct, export or delete your data. See also our Terms & Privacy page.
Please report suspected vulnerabilities privately to hello@forkincooking.com with steps to reproduce. We’ll acknowledge and investigate promptly. Don’t test against other people’s accounts or attempt destructive actions.
Forkin Cooking is responsible for the application code and how data is scoped inside it. Our hosting and backend providers are responsible for the underlying infrastructure. You’re responsible for keeping your password and email account secure.