SendRecs / Privacy policy

Privacy policy

What SendRecs handles, why it’s needed, and what you can control.

Effective 2026-09-17

Who is responsible

Mala Studio Inc. operates SendRecs. Mala Studio Inc. is a Delaware corporation with operations in California. The initial app launch is intended for the United States. Privacy questions: support@sendrecs.app.

Recommendations in the app

The app stores the recommendations you enter, including your words, names you include, place information, and lists. The private library is stored on your device and uses Apple’s private iCloud storage for synchronization when available. Apple processes iCloud data under its own terms and privacy policy.

Saving a recommendation also sends its text, any city you provide, and language context to the SendRecs service hosted on Cloudflare. Anthropic processes the text to identify places and recommendation details. Google Places receives place searches and relevant city context to help find a match. This processing happens outside your device; a private library does not mean all processing stays on your phone.

The service can process submitted links and images where those input methods are supported. A submitted link may be fetched from its source website, and page text or a submitted image may be processed by Anthropic. Do not include sensitive information that is unnecessary for a recommendation.

When you send a list

Sending a list creates a separate snapshot hosted on Cloudflare. It can include the list title, recommendation text, attribution, dishes, and place details. Anyone with the link can read it and pass the link on.

Shared snapshots currently have no automatic expiry. Editing or deleting a recommendation or using “Delete everything” in the app does not change or revoke an existing shared snapshot. To request removal, contact support with the shared-list URL. A request may require verification; do not send the rest of your private library.

Service operation

The app sends a persistent installation identifier to help limit abuse. The service temporarily stores rate-limit counters and records operational information such as request identifiers, response status, timing, and a hashed installation identifier. Infrastructure providers also process technical connection information needed to deliver and secure the service. The identifier is not an account login.

SendRecs does not use the website for advertising tracking. The website serves its fonts directly and does not set marketing cookies. Operational data and service-provider processing are separate from the private library.

The beta waitlist

Joining the waitlist provides your email address for SendRecs beta invitations. The signup database stores your email, signup time, the invitation permission wording and version, and whether and when an invitation was sent. Signup does not subscribe you to a newsletter.

The waitlist is stored in Cloudflare D1. Signup requests use short-lived abuse-prevention counters derived from connection information; raw IP addresses are not stored in the subscriber table. We retain waitlist records only as needed to manage beta invitations and your signup preferences. We use a limited retention schedule and periodic cleanup, taking into account whether invitations are still being offered and whether you have requested removal. You may request removal at any time. Authorized exports and backup copies are handled separately as described by the applicable service and operator retention practices.

You can withdraw permission or ask for removal by contacting support from the address you used to join. Removing your address does not affect your ability to use the app.

Support messages

If you contact support, the operator receives your email address, message, and any information you choose to include. These are used to respond to your request. Please share only what is needed to explain the issue.

Providers and retention

Apple, Cloudflare, Anthropic, and Google process relevant data as described above. They may process it in countries other than your own. Their applicable service terms, privacy practices, and configured retention rules also apply. SendRecs does not promise that provider processing is retention-free.

Private library data remains until you delete it, subject to device and iCloud synchronization and backup behavior. Rate-limit records are short-lived; city lookup results may be cached. Shared snapshots follow the separate retention described above. Support and operational records are kept for service, security, and applicable legal needs.

Provider information: Apple, Cloudflare, Anthropic, and Google.

Your choices and requests

You can edit or delete recommendations and lists in the app and use “Delete everything” to remove the private library. Public snapshots must be handled separately. You can request access, correction, or deletion of information the operator holds about you and withdraw waitlist permission. Rights, verification requirements, and exceptions depend on where you live.

Send a privacy request: support@sendrecs.app. Include the email address or shared-list URL relevant to your request, without sending unrelated personal information.

Children and policy changes

The initial beta is intended for adults in the United States. Participants must be at least 18 and have reached the age of majority where they live. SendRecs is not directed at children. If you believe a child has provided personal information, contact support.

This page will identify the effective date of policy changes. Material changes to how information is used will be communicated where required.