Privacy policy
Last updated: 30 July 2026
MemeChef is run by Code Cowboy Limited, a company registered in Hong Kong at Room 1505, 15/F, Yu Sung Boon Building, 107–111 Des Voeux Road Central, Hong Kong. We're the data controller for everything described here. This policy covers the MemeChef iOS app and the memechef.app website. We collect the data needed to turn your photos into memes and send photos to AI providers only to generate the images you request. We don't sell your data. MemeChef itself does not use your photos to train AI models. You can delete your photos, creations, or account in the app. Questions: contact@codecowboy.dev.
What we collect
- Account: your name, email address, and avatar from your sign-in provider.
- Your photos, face data, and content: the photos you upload or take, resized and cropped versions of those photos, images generated from them, private object references and short-lived links used to process them, and the prompts and recipes used to make your images.
- Purchases: your subscription status, purchase history, and credit balance. The App Store processes payments, so we never see your card details.
- Support: messages and attachments you send through the in-app support chat.
- Device and usage: basic app analytics (device model, OS version, app version, and how the app is used, tied to your account), crash reports, push notification tokens, and the server logs (IP address, request metadata) that any online service generates. We may derive an approximate country or region from your IP address for analytics, diagnostics, and service security.
Your photos and face data
In this policy, face data means a photo containing a face and information derived from that photo for capture, cropping, and image generation.
- Source photos: photos you select or take when creating an identity, using AI Camera, editing an image, or completing onboarding.
- Derived images: resized and cropped photo variants and the generated images that may depict the person in a source photo.
- Capture guidance: the app detects a face and its bounding area on your device to guide capture and cropping. Those results are held only in memory, aren't transmitted, and are discarded when the capture session ends.
- Technical references: private storage object keys and short-lived signed links used to give our processors temporary access to a source photo.
We use this data only to create, crop, moderate, store, and deliver the images you ask for. We don't create or store face embeddings or biometric templates, perform face recognition, identify or authenticate anyone from a face, or use face data for advertising, marketing, profile building, or data mining. We never sell, lease, or trade it. When we create square image variants, Cloudflare's image service may perform face-aware cropping on our servers.
Before a photo is sent to an AI provider, the app asks for explicit consent and explains that third-party AI processing is required. You can revoke (withdraw) that consent at any time and stop any further collection or use of your face data; the “Face-data retention and deletion” section below explains exactly how. MemeChef is an 18+ service: photos of anyone under 18 aren't allowed, and we delete them when we find them.
How we use your data
We use your data to run your account, generate your memes, and answer support messages as part of our contract with you. We also use it to process purchases and maintain accurate credit records under our contract and legal obligations. Our legitimate interests are the legal basis for securing the service, preventing abuse and fraud, fixing crashes, and seeing how people use features so we can improve them. We process your face photos with your explicit consent. We don't make automated decisions about you that have legal or similarly significant effects. Our content moderation may block a prompt or image that breaks the rules.
Who receives face data
- Cloudflare: stores private source and generated image files in R2 and provides image resizing and face-aware cropping.
- Neon: stores account records, photo metadata, private object keys, and generation records. Raw photo bytes are not stored in Neon.
- AI generation providers: we send the photos and prompt needed for a requested generation to fal.ai or WaveSpeed. They process that data only to provide the requested generation service.
We also use service providers for hosting, private storage, image processing, account sign-in, subscriptions, payments, notifications, analytics, crash reports, and customer support. Support messages and attachments are relayed through a third-party messaging service so our team can reply. These providers process data for the services we ask them to perform. Any third party with whom we share face data will provide the same or equal protection of your face data as stated in this policy: we require each of them to protect it to at least the standard described here and to process it only on our instructions. The same requirement applies to every provider that handles any of your personal data. We don't intentionally send photo files or on-device face-detection results to advertising or analytics providers. We don't sell or rent your personal data or share it with advertisers or data brokers. We may also disclose data if the law requires it or to defend our legal rights.
Where face data is stored and processed
We're based in Hong Kong. Your photo files are stored in a private Cloudflare R2 bucket configured for WNAM (Western North America); WNAM is a regional location hint, not a guarantee that data stays in one country. Account records and photo metadata are stored with Neon on AWS us-east-1 in Northern Virginia, United States. On-device capture guidance is not stored. fal.ai and WaveSpeed process generation data on infrastructure that they and their subprocessors operate; they do not give MemeChef a fixed data-centre location for each request. Where the law requires it, we use recognised safeguards for international transfers, such as standard contractual clauses.
Face-data retention and deletion
- On-device face detection: face bounds used for capture guidance exist only for the current capture session and are discarded when that session ends.
- Saved identity photos: kept while the corresponding identity remains in your account. Source photos and their stored variants are removed from active storage when you delete the photo, identity, or account. Snapshot copies of identity photos inside your past cooks remain with those cooks and are removed when you delete your account. A photo already fetched by the app may remain in its private device cache for up to 24 hours.
- Temporary generation photos: AI Camera, AI Edit, and onboarding scratch inputs and outputs have a configured retention window of 65 minutes: they become eligible for deletion at one hour old and cleanup runs every five minutes. A failed deletion is retried by later cleanup runs.
- Generated creations: kept while they remain in your library. Deleting a creation removes it from your library immediately; its remaining files and records are removed when you delete your account.
- fal.ai processing: MemeChef instructs fal.ai not to persist JSON generation inputs or outputs. Source photos are supplied through short-lived private links rather than uploaded to fal.ai's file storage, and generated media is configured to expire after one hour.
- WaveSpeed processing: source photos are supplied through signed links that expire after no more than six hours. After a generation finishes or fails, MemeChef requests deletion of the corresponding WaveSpeed prediction task. If the normal terminal path does not complete, the task is scheduled for deletion no later than three hours after submission. WaveSpeed's published maximum retention for generated media is seven days.
- Database records and backups: active photo metadata and private object references are removed with the related photo, identity, creation, or account. Encrypted Neon backups may retain deleted database metadata for up to 30 days. Raw photo bytes are not stored in Neon.
- Support messages: kept while your account exists. Copies relayed to our support provider may remain for a limited period under that provider's retention rules.
- Analytics and crash data: kept only as long as needed to understand app use, investigate problems, and protect the service. Providers may retain limited records under their own retention schedules.
- Revoking consent and deleting your face data: you can revoke your consent to our collection and use of face data at any time, directly in the app: delete an individual photo or a whole identity (open the identity and tap Delete) to remove its source photos and stored variants from active storage immediately, delete a creation to remove it from your library, or delete your account in Profile → Settings to erase everything, as described below. Once you delete a photo, identity, or your account, we no longer use its face data, and we collect new face data only if you choose to upload or capture new photos. You can also email contact@codecowboy.dev and we'll handle any of this for you.
- Account deletion: starts immediately and removes your active account, photos, identities, creations, support records, settings, and billing profile from MemeChef. It also schedules deletion of associated provider tasks and clears MemeChef's sensitive local image caches. We revoke our access to your sign-in account where supported. Service providers may retain security, billing, or legal records under their disclosed schedules, and we may keep records required by law. The App Store keeps its own purchase records. Deleting the app from your phone does not delete your account. Use Profile → Settings in the app.
Your rights
Wherever you live, you can ask us for a copy of your data, correct it, delete it, export it, restrict or object to certain processing, and withdraw consent at any time. The fastest route for most of this is the app itself (delete identities, creations, or your whole account); for anything else email contact@codecowboy.dev and we'll respond within 30 days (Hong Kong law allows up to 40 for access requests). You can also complain to your data protection regulator, such as the PCPD in Hong Kong, the ICO in the UK, or your local authority. For California residents: we don't sell or share personal information as CCPA defines those terms, we don't discriminate against you for exercising privacy rights, and because we don't track you across other companies' apps or sites, our services don't respond to Do Not Track signals.
If someone uploaded a photo of you
Our terms require users to have the permission of everyone in the photos they upload. If someone put your face into MemeChef without your consent, email contact@codecowboy.dev and we'll remove it. Non-consensual imagery is removed within 48 hours of a credible report.
Analytics, crash reports, and notifications
We collect basic product analytics, such as which features are used, the device model, and the app version. We also collect crash reports so we can fix bugs. There's no advertising SDK, session recording, or tracking across other apps or websites. Push notifications cover things you've asked for, such as cook results and support replies. We'll only send marketing notifications with your consent. You can turn notifications off in iOS Settings.
Age
MemeChef is for adults: you must be 18 or older. We don't knowingly collect data from anyone under 18, and photos of minors aren't allowed anywhere in the service. If we learn we hold either, we delete it. If you believe a minor is using MemeChef, tell us at contact@codecowboy.dev.
Security
Your content is kept in private storage and shared with the app through short-lived, secure links. Traffic is encrypted in transit, and access to production systems is restricted. No online service can promise perfect security, but if a breach puts your data at real risk, we'll tell you and the relevant regulator as the law requires.
Changes to this policy
We may update this policy as MemeChef changes. The latest version and its date will always be posted here. We'll flag material changes in the app before they take effect.
Contact
Code Cowboy Limited, Room 1505, 15/F, Yu Sung Boon Building, 107–111 Des Voeux Road Central, Hong Kong. codecowboy.dev
