Effective date: [EFFECTIVE DATE] · Last updated: [DATE]
⚠️ DRAFT — NOT LEGAL ADVICE. This is a working template prepared to give a qualified attorney a strong starting point. It is not legal advice and must be reviewed and adapted by a licensed lawyer before you publish or rely on it — especially the biometric (Illinois BIPA / Texas / Washington), minors (COPPA), and California (CCPA/CPRA) sections, which carry statutory penalties. Replace every [BRACKET] placeholder. See
legal/README.mdfor the high-risk items.
CookCredit ("CookCredit," "we," "us") is operated by [COMPANY LEGAL NAME], [ENTITY TYPE], located at [ADDRESS]. This Privacy Policy explains what we collect when you use cookcredit.com, the CookCredit app, and the in-browser knife-skill capture tool (together, the "Services"), how we use it, and the choices and rights you have.
By using the Services you agree to this Policy and to our Terms of Service. If you do not agree, do not use the Services.
build training datasets for cooking-skill assessment and robotics/AI. This is the core of what we do — please read Sections 3–5 carefully and review the consent you give.
described here, including to train AI/robotics models (see Section 5) — your consent to that is a condition of using the skill-capture feature.
Section 9. California, and other state, residents have additional rights (Section 10).
18, and we do not knowingly collect data from anyone under 13.
This Policy applies to: visitors to cookcredit.com; people who create an account; cooks who take a skill assessment or list services; and eaters/customers who browse or book. It applies whether you use the web app, a mobile app, or the camera-capture tool.
a) Information you give us
cuisines, location area, and service details.
that you enter before a capture, plus the consent checkbox state.
b) Camera & motion data (the sensitive core)
positions over time) used to detect strokes and score technique.
cut type).
**face detection check to confirm a real person is present. We do not perform facial recognition, do not build a faceprint, and do not store face-geometry templates.** See Section 6.
c) Information collected automatically
location area you provide. We do not collect precise GPS unless you explicitly enable it.
We do not intentionally collect special-category data beyond what is described above. Do not submit information about others without their permission.
on-device score is provisional; a canonical score may be computed server-side. No score is a professional certification or a guarantee of employability — see the Terms.)*
models for kitchen manipulation — using your recordings and motion data, subject to the consent and license you grant** (Section 5 and the Terms). Where feasible we de-identify or aggregate before model training.
Legal bases (where required, e.g., GDPR-equivalent): your consent (camera/motion data and model training), contract (to provide the Services you request), legitimate interests (security, product improvement), and legal obligation.
Building cooking-skill and robotics/AI datasets is a primary purpose of CookCredit. When you check the consent box and complete a capture, you grant CookCredit the license described in the Terms of Service to store and use your recordings and motion data to develop, train, evaluate, and improve such models and the Services.
hand- and tool-trajectories, motion embeddings, skill features, scores, and any synthetic or derivative datasets built from your sessions. It does not include your payment information or account-identity credentials.
new model training in in-app settings or by emailing [PRIVACY EMAIL]. Our default depends on context: free / practice ("PLAY") sessions are opted in to model-training use as a condition of the free feature, while paid or B2B validation sessions are opted out of training by default unless you choose otherwise.
datasets already created, from previously-consented data, but we will stop using your data for new training and delete your raw recordings on request, subject to legal retention.
defeat the purpose.
Several states regulate biometric identifiers (e.g., Illinois BIPA, Texas CUBI, Washington). These laws can apply to face or hand geometry used to identify an individual and carry significant penalties.
capture, store, or use a face template / faceprint, and we do not use face data to identify you.
motion to score technique, not to identify you. Because hand-geometry data can qualify as a "biometric identifier" under these laws, we do not hedge — we treat it as biometric** and handle it accordingly.
we present a dedicated, default-OFF biometric notice and release, separate from the general consent box, that states (a) exactly what is collected, (b) the specific purpose, and (c) the exact retention term. We collect your affirmative consent to that release and store a logged, timestamped electronic-signature record tied to the text you saw. We do not begin biometric capture until you sign it.
collect hand-geometry data from residents of Illinois, Texas, or Washington.**
Schedule (Section 7) and we do not sell or lease** biometric data or profit from it.
The full point-of-collection notice, the BIPA §15(b) written release you sign before any hand-geometry data is collected, and the consent-logging terms are set out in our standalone Biometric Notice & Written Release, which governs that collection and is read together with this §6 and the §15(a) Retention & Destruction Schedule.
🔴 Attorney action required: confirm the exact BIPA §15(b) release wording, the §15(a) public retention/destruction schedule, and the per-state go-live gating before any collection from Illinois/Texas/Washington residents. BIPA carries a private right of action with per-violation statutory damages and minors are the #1 litigation target — this remains the single highest-risk area.
deletion, then deleted or de-identified, whichever is sooner.
Biometric Data Retention & Destruction Schedule. It is destroyed on the earlier of (a) the purpose for collection being satisfied or (b) 3 years from your last interaction with the Services. Destruction reaches backups, caches, and shadow copies, and is wired to account deletion. (Publishing this schedule as a standalone page — not just this sentence — is required under Illinois BIPA §15(a).)
required by tax, accounting, and legal obligations.
indefinitely.
The Services are 18+ only. "Minimum Age" is defined in the Terms of Service §1 as 18, or a greater age where local law requires it for us to lawfully collect biometric data.
personal information from children under 13 (COPPA, including the 2025 Rule update that treats biometric identifiers as personal information for under-13s). If you are under 18, do not use the Services.
separately governed with per-jurisdiction parental consent, a BIPA-compliant guardian release, exclusion of minor data from the training corpus, and no credit payout to minors.
delete the associated data, including any captured video and hand-motion data.** Parents/guardians may contact [PRIVACY EMAIL] to review or delete a minor's data.
You can:
To exercise any right, email [PRIVACY EMAIL] or use in-app settings. We will verify your identity and respond within the timeframe the law requires. We will not discriminate against you for exercising a right.
California residents have the right to: know the categories and specific pieces of personal information we collect, the sources, purposes, and recipients; delete personal information; correct inaccurate information; opt out of "sale" or "sharing" of personal information; and limit the use of sensitive personal information. You may also designate an authorized agent.
activity; audio/visual information (your recordings); sensory data; geolocation (approximate); inferences; and sensitive personal information (which may include the camera/motion data and precise data if enabled).
sharing qualifies as a "sale" or "share" under the CPRA, you may opt out via [Do Not Sell or Share My Personal Information link] or by sending a Global Privacy Control (GPC) signal, which we honor.
what is necessary to provide the Services. We do not use sensitive PI to infer characteristics.
parties for direct marketing (we do not make such disclosures).
Residents of states with comprehensive privacy laws have rights to access, correct, delete, obtain a portable copy, and opt out of targeted advertising, "sale," and certain profiling. Where required, we obtain opt-in consent before processing sensitive data (which may include biometric/health-adjacent data). To exercise these rights, contact [PRIVACY EMAIL]; you may appeal a decision by [APPEAL CONTACT].
See Section 6. We obtain consent, disclose retention, and do not sell biometric data.
We use strictly-necessary cookies to run the Services and, with consent where required, analytics/performance cookies. You can control cookies in your browser. We honor Global Privacy Control (GPC) signals as opt-out requests where applicable.
We use technical and organizational measures (encryption in transit, access controls, signed upload URLs, least-privilege cloud configuration). No system is perfectly secure; we cannot guarantee absolute security and you share data at your own risk.
We share data with vetted processors strictly to operate the Services — e.g., cloud hosting and processing (Google Cloud Platform), authentication, payment processing, email, and analytics — under contracts that limit their use of your data. We may disclose data to comply with law, respond to lawful requests, enforce our Terms, or protect rights and safety, and in a merger/acquisition (with notice).
The Services are operated from the United States and intended for U.S. users. If you access them from outside the U.S., you consent to processing in the U.S. We do not currently target the EU/UK/EEA; GDPR/UK-GDPR terms will be added if and when we do.
We may update this Policy. Material changes will be notified via the Services or email, and the "Last updated" date will change. Continued use after changes means you accept them.
Questions or requests: [PRIVACY EMAIL] · [COMPANY LEGAL NAME], [ADDRESS]. California "Notice at Collection" and rights requests: [PRIVACY EMAIL / portal link].
CookCredit — draft legal documents. This is a beta preview and not legal advice.