Privacy notice
Privacy information for the Korevu website, waitlist and app. Last updated: 24 September 2026.
Website and waitlist
Who is responsible?
MKVibe, the sole proprietorship of Robert Molenkamp (KVK 42164470, VAT ID NL005547449B96), is responsible for this processing. For questions and privacy requests, email info@mkvibe.app.
What data do we process?
When you sign up, we store your email address, your name if provided, the signup time, your IP address and the browser information sent by your browser (user-agent). Your name is optional. We also store your selected platform (iOS or Android), language, a personal unsubscribe token and, if you choose updates, the time and version of your consent. We need your email address to add you to the waitlist. The server also records technical information about requests and the processing of signups.
Why and on what legal basis?
For iOS, we use your signup to handle your request for a TestFlight alpha invitation, as a step towards providing the testing access you requested. Only with your separate consent do we send development updates for your selected platform until version 1.0. You give that consent through the unchecked opt-in checkbox. Android is not yet available; you can request development updates for it. Existing signups are not automatically added to this new update list. We use technical data to manage and secure the waitlist, based on our legitimate interest in keeping the service reliable. You can object to this processing.
Where does your data go?
Signups are stored in the waitlist database. MKVibe also receives an internal email notification containing the name, email address, signup time, IP address, platform and your update preference. MKVibe operates its own mail server for this purpose. When we email you, your email provider also processes the message to deliver it to you.
How long do we keep signups?
We keep your signup until the release of Korevu version 1.0. At that release, we delete the waitlist data and the associated internal signup notifications. We delete your signup sooner if you withdraw consent or if the waitlist is no longer needed, for example if the project ends. We do not automatically turn your signup into a newsletter subscription after version 1.0. For newsletters, we record the campaign submitted to the mail server, time and sending status against your signup. We also record newsletter opt-outs and block undeliverable addresses from further newsletters. When your entire signup is removed, its linked sending records and suppression are also removed. We do not use tracking pixels to measure whether you open a newsletter.
Your choices and rights
Every development update includes a personal unsubscribe link. The unsubscribe link in a newsletter lets you stop development updates only. Your iOS alpha request remains active; an Android signup is removed because it is only for updates. You can also request removal of your entire signup through the email address below. Associated internal notifications and any other copies are cleaned up under our deletion policy. You can also withdraw consent and leave the waitlist at any time by emailing info@mkvibe.app. Withdrawal does not affect the lawfulness of processing before it. You can also request access, correction or deletion of your data and, where applicable, restriction, portability or object to processing. Include the email address you used to sign up. You can lodge a complaint with the Dutch Data Protection Authority.
Scope of this notice
This section covers the website and waitlist. For the app, see the separate app privacy notice below.
Privacy notice — Korevu app
Last updated: 24 September 2026.
1. Who we are
Korevu is provided by MKVibe, the sole proprietorship of Robert Molenkamp, registered with the Dutch Chamber of Commerce under number 42164470. MKVibe is responsible for the personal-data processing described below.
For privacy questions or requests about your data, contact info@mkvibe.app.
This notice covers the Korevu app, including its TestFlight beta. The website and waitlist are covered by the separate information on this privacy page.
2. Data on your device
The app stores your pantry, shopping lists, recipes, meal plans, ratings, settings and explicitly attached product/recipe photos on your device. Your entries may include personal information, for example in names, notes or recipe preferences.
The basic features work without a Korevu account. Manual entry and built-in recipes do not require an AI server. The app includes no advertising or tracking SDK.
Photo-based grocery recognition is not available in this version. Photos you deliberately attach to products or recipes are stored by the app. Your original library photos remain subject to your device and iCloud settings.
3. Optional iCloud sync
If you review the explanation and enable iCloud sync, supported pantry, shopping, recipe, meal and preference data is stored in your private iCloud database. This can include notes, barcodes, recipe text and explicitly attached reduced-size photos.
Apple processes this data through iCloud under its terms and privacy policy. Your iCloud account and available storage affect whether syncing works. Korevu does not use its own central pantry database for this feature.
You can turn off sync in Settings. Turning it off does not automatically erase previously stored iCloud data. When sync is enabled, deletions may be propagated to your other devices. Sync may retain deletion markers to prevent deleted items from reappearing.
4. Encrypted backups
You can export a password-encrypted backup to a location you choose, such as Files or iCloud Drive. The backup can contain app data and attached photos. AI access credentials are excluded.
The app does not retain the backup password. You manage exported files and copies. Deleting data in the app does not delete existing backup files. Apple system backups follow your device settings.
5. AI recipes
On-device Apple Intelligence
When the app uses its Apple Intelligence option, recipes are generated on your device. This app feature does not send your recipe request to the Korevu server or enable Private Cloud Compute.
Optional Korevu Server
After your consent and activation of tester access, the app can generate recipes through Korevu Server. Automatic provider selection may use the server when Apple Intelligence is unavailable and external access is enabled.
Requests contain selected ingredient names, available amounts, units, a use-soon indicator, language, measurement system, meal occasion and your recipe preferences. Local pantry IDs, pantry notes, photos and exact expiry dates are excluded from these recipe requests. Text you enter in ingredient names or recipe preferences is included.
Requests go to our gateway at openai.mkvibe.nl. The gateway sends recipe requests to OpenAI to generate recipes. See the OpenAI API data controls information. MKVibe operates the gateway and its other servers itself in the Netherlands. The OpenAI project uses the Global setting, so processing is not restricted to the Netherlands or the EEA. Personal data processing through the API is governed by the OpenAI Data Processing Addendum. For transfers outside the EEA, it provides for European Commission standard contractual clauses or an applicable adequacy decision. You can request more information about these safeguards at info@mkvibe.app.
We retain session logs on our gateway for three days to investigate technical issues. These logs contain the generated prompts for recipe requests, without location data or IP addresses as log fields. User-entered text in a prompt may still contain personal information. We do not share these logs with third parties. This is separate from sending recipe requests to OpenAI for processing.
Only MKVibe’s owner has access to our logs. The reverse proxy retains session logs for three days.
OpenAI has its own retention policy. The project’s Data retention setting is None: no special Zero Data Retention or Modified Abuse Monitoring controls are enabled. Under the standard policy, OpenAI may retain abuse-monitoring logs containing request content for up to 30 days, with exceptions for legal obligations or protection against harm. Disabling audit logging does not change this.
Backups also contain prompt logs and are overwritten daily. A log deleted from active storage may therefore remain in a backup until the next daily overwrite.
Sharing API data with OpenAI for model improvement is disabled.
You can disable external AI or disconnect it in Settings. This stops future server requests from the app, but does not automatically erase previously processed data from the services. Use manual entry and built-in recipes if you do not want external AI. Do not include unnecessary personal or sensitive information in AI requests.
6. Tester activation and security
Tester access is activated per device through api.pantrychef.mkvibe.nl. An activation code and recovery secret are sent for this purpose. The activation service records information including access status, expiry and hashed code/recovery values. The services also receive ordinary connection information, such as an IP address, for request handling and security.
The app stores credentials in device-only Keychain. They are excluded from Korevu iCloud sync and app backups. Contact the tester administrator if access expires or is revoked.
The activation server retains logs for three days. Tester activation and deletion of activation records are managed manually. We delete activation records no later than 30 days after access expires or is revoked. Backups are overwritten daily; a deleted record may remain there until the next overwrite.
7. Barcodes and other Apple features
When you look up a barcode, it is sent over an encrypted connection to Open Food Facts. That service also receives ordinary connection information, such as your IP address, and an app-version/project header. The app does not send your full pantry, photos or recipe text with barcode requests. You can enter products manually instead. See the Open Food Facts privacy information.
Local expiry reminders are optional. Siri, dictation, the system photo picker, iCloud and device system backups also follow Apple's settings and terms. See Apple's privacy policy.
8. Feedback and contact
If you email us, we process your email address and message to respond and investigate the issue. Share only the information needed for that purpose.
During TestFlight testing, Apple may process testing, crash and feedback data and make it available to the developer. Do not include activation codes, passwords or unnecessary private information in feedback or screenshots.
For crash reports and feedback/support messages received by email, we use automatic inbox rules. Crash reports are moved to trash 30 days after receipt; feedback and support messages are moved to trash 90 days after receipt. Trash is emptied automatically each day, so permanent deletion from the mailbox follows no later than one day afterward. Any separate working copies are retained for no longer than the same period. Backups are overwritten daily; deleted data may remain there until the next overwrite.
These periods apply to our own copies; data managed by Apple is subject to Apple’s retention policy.
9. Why we process data
We use data to provide the features you choose, handle sync and recipe requests, manage access, respond to questions and secure the services.
We request consent for optional iCloud sync and external AI. You can disable these features again; this does not affect the lawfulness of processing previously based on consent. We process necessary data to provide requested services and support in performance of our agreement with you. For necessary security and abuse prevention, we rely on our legitimate interest in keeping the services reliable, taking your interests into account.
10. Retention and deletion
Local app data remains until you delete it or clear the app's local storage. Removing the app does not automatically delete all iCloud copies, Keychain credentials or exported backups. Manage these separately. Processing by Apple and Open Food Facts is also described in their own privacy information.
The specific retention periods and deletion procedures above apply to data held by MKVibe and the AI services. Email info@mkvibe.app for requests about data managed by MKVibe. We may ask for information needed to verify your request and identity. Do not send passwords or secret access codes.
11. Your rights
Depending on the processing, you may request access, correction, deletion, restriction or portability of your personal data. You may withdraw consent and object to processing based on legitimate interests. Contact info@mkvibe.app to exercise these rights. You may also complain to the Dutch Data Protection Authority.
12. Changes
We update this notice when the app or its data processing changes. The date above identifies the latest update. Where a change requires new consent, we ask for it before enabling that processing.