Cooked.
HomeProductsAboutGet in touch
HomeProductsAboutGet in touch
Legal

Privacy Policy

Last updated: 3 October 2026

On this page
  1. Who we are
  2. Information we collect
  3. How we use your information
  4. How we share information
  5. Data retention
  6. Security
  7. Your rights and choices
  8. Cookies
  9. Children
  10. International transfers
  11. Changes to this policy
  12. App-specific details

01Who we are

Cooked Technologies Ltd (“we”, “us”) makes mobile apps, including Journey. This policy covers all of them, and any website where we publish it. We are the controller of the personal data described here. Our address is 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

Contact us about privacy at contact@cookedtech.com. We aim to reply within 14 days.

Our apps don’t all work the same way. This policy describes what applies across our apps. App-specific details, at the end, covers anything particular to one app, such as extra data it collects or where its settings are. Where the two differ, the app-specific details apply to that app.

02Information we collect

We collect only what you give us or what an app needs to work. Our apps have no advertising and don’t track you across other companies’ apps or websites. Depending on the app, we may collect:

DataWhat it includesWhen we collect it
AccountEmail address, password (stored hashed), display name, username, optional bio and profile photo. If you use Sign in with Apple: the name and email Apple shares, which may be a private relay address, and a token Apple issues so we can disconnect Sign in with Apple when you delete your account. If you reset your password, we email you a one-time codeWhen you create an account, in apps that have one
Content you createWhat you enter or save in an app, such as preferences, notes, saved items or photosAs you use the app
PurchasesWhether you have a subscription or in-app purchase, the App Store transaction ID, and a random ID that links the purchase to your account. We never see your payment details, which Apple handlesWhen you buy or restore a purchase
Device and notificationsA push notification token and your reminder settingsIf you allow notifications
Usage analyticsAnonymous events such as opening a screen or finishing a task, plus device model, OS version, app version and an anonymised ID for your app installation. Times are rounded to the hour and no IP address is stored. Never your name, email, account ID or the content you createWhile you use an app, unless you turn it off in that app’s settings
Support messagesYour email address and what you tell usWhen you contact us

When you enter your email to sign in, we also record your IP address for up to a day, to stop automated attempts to find out which emails have accounts. App-specific details lists exactly what each app collects. If you use an app without an account, your data stays on your device unless that app’s section says otherwise.

03How we use your information

We use your data to run our apps for you, and never to sell it or to advertise. Under UK GDPR, each use needs a lawful basis:

PurposeData usedLawful basis
Run your account and sync it across devicesAccount data, content you createContract: needed to provide the app
Provide an app’s featuresContent you createContract, or explicit consent where the data is sensitive (see App-specific details)
Provide purchases and enforce free usage limitsPurchases, usage recordsContract
Send reminders and alertsNotification token, reminder settingsConsent, through your device’s notification permission
Understand which features are used and improve our appsUsage analyticsLegitimate interests: improving our apps, using anonymous data only
Answer your questionsSupport messagesLegitimate interests: helping you
Prevent abuse and keep our services secureUsage records, IP address at sign-inLegitimate interests: protecting our services from misuse

04How we share information

We share data only with the service providers below, who process it on our behalf. We never sell your data.

Provider typeWhat they doData they receiveLocation
Cloud hosting providerHosts our databases, file storage and serversAccount and app dataEuropean Union (Ireland)
Apple Inc.Sign in with Apple, push notifications, App Store purchasesSign-in details, notification token, purchases, and a random ID that links a purchase to your accountUnited States and others
Analytics providerCounts how features are usedAnonymous usage events, with no name, email or account IDEuropean Union

We also use an email delivery provider to send account emails, such as password reset codes. It receives your email address and the email’s contents. Some apps use other providers too, such as an AI service. App-specific details lists them.

Each provider is bound by a contract that only lets it use your data to provide its service to us. If you’d like the names of our providers, email contact@cookedtech.com and we’ll tell you.

We may also disclose data if the law requires it, or to protect the rights and safety of our users or others. If we sell or transfer an app or our business, that app’s data may pass to the new owner, who must keep protecting it as this policy describes. We’ll tell you before that happens.

05Data retention

We keep your data until you delete it or delete your account.

  • Your account. Deleting your account in an app’s settings permanently removes it and all data linked to it straight away.
  • Backups. Deleted data may remain in our hosting provider’s encrypted backups for up to 7 days before it is overwritten.
  • Usage analytics. Anonymous analytics events are stored by our analytics provider in the EU. They’re available for analysis for a limited period, then moved to archive storage, which the provider expects to delete after 7 to 10 years. Because they can’t be linked to you, they aren’t removed when you delete your account.
  • Support messages. Kept for 30 days after your last message, then deleted.
  • On your device. Data stored on your phone is removed when you delete the app.

App-specific details lists any other retention periods.

06Security

We protect your data with encryption in transit (HTTPS) and at rest with our hosting provider, and with access controls so that only your account can reach your private data. Access to our systems is limited to us and protected by secure sign-in. No system is perfectly secure. If a breach puts your data at risk, we’ll tell you, and the Information Commissioner’s Office where the law requires it.

07Your rights and choices

You can ask us to access, correct, delete or export your data, or to restrict or object to how we use it. You can also withdraw consent at any time. Much of this you can do in the apps; for anything else, email contact@cookedtech.com.

You can object to usage analytics at any time by turning it off in the app’s settings (App-specific details says where). Nothing more is sent after that. You can turn off notifications in your device’s settings.

If you’re unhappy with how we handle your data, you can complain to the UK Information Commissioner’s Office at ico.org.uk. We’d appreciate the chance to fix it first.

08Cookies

Our apps don’t use cookies or similar tracking technologies.

09Children

Our apps are not intended for anyone under 16. An app may set a higher minimum age, shown in App-specific details. We don’t knowingly collect data from younger children. If you believe a child has given us data, contact us and we’ll delete it.

10International transfers

Some of our providers process data outside the UK, such as Apple and any AI service provider in the United States. Where they do, we rely on safeguards approved under UK law, such as the UK International Data Transfer Addendum or the UK-US data bridge.

11Changes to this policy

If we make significant changes, we’ll tell you in the affected apps before they take effect. The date at the top shows when this policy was last updated.

12App-specific details

Journey

Journey is a cosmetic skincare app. It gives cosmetic, informational guidance about how skin looks. It is not a medical service and does not diagnose or treat any condition.

What Journey collects. Besides account, purchase (Journey Premium), notification and analytics data, Journey collects:

DataWhat it includesWhen we collect it
Skin profileSkin type, dryness and oiliness, sensitivity, concerns, preferred and avoided ingredients, fragrance preference, budget. Optional: age range, climate, allergies or sensitivities, products you already useFrom the onboarding quiz and your profile. Optional fields can be left blank
Face photosThe photo you take for a skin scanEach time you run a scan. Saved to your account only if you switch on “Save this photo to my history”
Scan resultsA written summary and observations such as dryness or redness, each with a level, score and confidenceAfter each scan
Routine and progressProducts in your routine, when you tick steps off, daily check-ins (a 1 to 5 rating and an optional note), and how your scan results changed while you used a productAs you use the routine and progress features
Saved productsProducts you save in the ShopWhen you save one
Usage limitsA record of each scan request and when it was madeEach time you run a scan

Journey’s analytics events include finishing onboarding, completing a scan, viewing a product or opening a retailer link. They never include scan results, photos or your skin profile. Turn them off with “Share anonymous usage data” in You → Privacy & Data.

If you use Journey without an account, your profile and saved products stay on your device. If you then create an account or sign in, your saved products move to it. Scanning requires an account. When you create one, we ask for your date of birth to check you’re 16 or over. We use it only for that check and don’t store it.

Your face photos. Your scan photo is analysed by a third-party AI service provider, and we only keep it if you choose to. We ask for your permission on the screen before every scan.

  1. The app first checks on your phone that a face is visible. A photo with no face is never sent anywhere.
  2. The photo is shrunk and sent over an encrypted connection to our server, which passes it to our AI service provider. The provider’s AI model analyses the skin’s appearance and returns a written result.
  3. The provider processes the photo only on our behalf, under a contract that doesn’t allow it to use your photo to train AI models. The provider may keep the photo for up to 30 days for safety monitoring, then deletes it.
  4. We don’t store the photo on our servers unless you switched on “Save this photo to my history”. That setting is off by default.
  5. A saved photo is kept in private storage that only your account can access. It is never public or shown to other users. You can delete it at any time, and deleting a scan deletes its photo. When you view a saved photo, the app holds it in memory only and never stores it on your phone.

We don’t use your photos to identify you, and we don’t create face templates or other biometric identifiers from them.

How Journey uses this data.

PurposeData usedLawful basis
Analyse your photo and show resultsFace photos, scan resultsExplicit consent, given on the screen before each scan
Recommend products and build your routineSkin profile, scan results, routineExplicit consent, given when you fill in your profile or scan
Track your progress over timeScan results, routine, check-ins, saved photosExplicit consent
Enforce the free scan limitUsage limitsContract

We treat skin information as potentially sensitive, which is why we rely on your explicit consent for it. You can withdraw consent at any time by deleting the data or your account.

Scan results and product suggestions are produced automatically, by an AI model and by rules that match products to your profile. They are cosmetic suggestions only and don’t have legal or similarly significant effects on you.

Extra provider. An AI service provider analyses scan photos with an AI model. It receives your scan photo, for that scan only, and processes it in the United States.

Retailer links. When you tap Buy on a product, the retailer’s website opens. That retailer receives normal browsing information, as any website does, under its own privacy policy. Some links may include a tracking tag that earns us a commission; this doesn’t change your price. Product images are loaded from retailers’ image servers, which can see your IP address.

Retention. You can delete any scan, saved photo or your whole scan history from the You tab at any time. Deleting your account in You → Account removes your saved photos with everything else. Scan request records are kept for about 2 months to apply usage limits, then deleted automatically. IP address records from signing in are deleted after a day.

Questions about your privacy?

Get in touch →
Cooked. Technologies
HomeProductsAboutContactPrivacyTerms
© 2026 Cooked Technologies. All rights reserved.