Privacy
Effective: September 13, 2026
This page describes how the currently published One Card Recipes application handles data. It is a plain-language operational description, not legal advice.
What the application receives
One Card Recipes does not have user accounts. The application itself does not set cookies, use browser local storage, or include advertising or analytics scripts.
When you use the site, Cloudflare receives ordinary request information needed to deliver and protect the service, such as IP address, time, requested path, user agent, and network diagnostics. A recipe search, ingredient list, or pasted URL is sent to the Worker as a URL query parameter. URLs containing embedded credentials or common secret-bearing query keys are rejected rather than fetched or cached.
Do not enter confidential, medical, or otherwise sensitive information into the search box.
Where input goes
- Dish and ingredient searches are sent to Tavily to obtain candidate public web pages.
-
The Worker fetches candidate recipe pages, or a URL you paste, using the service's own
network request and identifies itself as
OneCardRecipes/1.0. - A source website receives the requested URL and ordinary request metadata. The request is made by Cloudflare's Worker infrastructure, which may add its own network or proxy headers under Cloudflare's platform behavior.
- If a search fails, the interface may offer a Google search link. Nothing is sent to Google unless you choose that link; following it takes you away from One Card Recipes.
Tavily, Cloudflare, Google, and source websites operate under their own privacy terms.
Storage and retention
Cloudflare KV caches extracted recipe data for up to seven days and search results for up to 24 hours. Short negative-result markers expire after about 90 seconds. Cache keys are hashed, but cached search values can contain the submitted query and public recipe data.
A Durable Object stores a global monthly Tavily usage count. It does not store searches, URLs, IP addresses, or per-user records. Monthly count rows may remain until the operator removes them.
Rate limiting uses connection IP metadata as a transient request key and short counters to control abuse. These counters are not stored in application KV and are not used as an accounting database.
Workers Logs and Traces are sampled. Platform-generated request query strings are redacted in configuration. Retained diagnostics are intended to contain event names, status information, and safe host-level context rather than search text or full URLs. Cloudflare controls the underlying plan-dependent retention, currently up to seven days.
Expiration and deletion from application storage do not necessarily remove copies already held in a third party's systems or short-lived infrastructure backups.
Use and disclosure
Data is used to return recipes, operate caches and limits, diagnose failures, and protect the service. One Card Recipes does not sell personal information or use searches for targeted advertising.
Information may be disclosed when required to operate the providers above, comply with applicable obligations, or protect the service and its users.
Requests and questions
For a privacy question or deletion request, contact the site operator. Include only the minimum information needed to identify the request. Do not send an IP address, private search history, credentials, or other sensitive data unless a private channel has been arranged.
Because the service has no accounts and deliberately limits identifying storage, the operator may not be able to connect an anonymous request or cache entry to a particular person. Source opt-out and takedown requests are handled under the Content Policy.
Changes
Material changes to this policy will be published on this page with a revised effective date.