Privacy Policy

Last updated: 1 July 2026

Stokked is a family shopping list app with an AI meal planner. This page explains, in plain language, what data we hold on you and why.

Who we are

Stokked is operated by Stefan Crafoord-Wiklund (info@stokked.ai). The Stokked apps, the website, and the supporting servers are the “Service” this policy covers.

What we collect, and why

Account data

When you sign up, we store your email address and a hashed password. We use this to authenticate you and to let you recover access. Email is also used for transactional notifications (password resets, family invites). We never sell or share it for marketing.

Your shopping lists, items, families, and recipes

Everything you put into Stokked — list items, store names, categories, family memberships, saved recipes — is stored on our servers so it can sync across your devices and your family’s devices in real time. This is the data the app exists to manage; without it the app cannot function.

AI meal planner messages

If you use the AI Chef feature (part of Stokked Plus), the messages you send and the meal plans we generate are processed to produce your reply. We log a small usage record (timestamp, request type, token count) for each request so we can monitor cost and prevent abuse. We do not train any AI model on your messages.

Subscription and payment data

Stokked Plus is billed by Stripe. We never see or store your full card details — Stripe handles payment. Stripe sends us a customer identifier and a subscription status (active, past due, canceled, etc.) so we know whether to unlock AI features. That’s it.

Diagnostic data

We collect minimal server-side logs (IP address, timestamp, request path) for the usual reasons — debugging, blocking abuse, keeping the lights on. These logs are kept for 14 days and then rotated out.

Where your data lives

The Stokked database, authentication, and edge functions run on a server we operate in Frankfurt, Germany. Data is at rest in the EU.

The AI meal planner forwards your prompt to Anthropic (USA) for inference. This means the text you send to the AI Chef leaves the EU during processing. Anthropic returns the generated meal plan; we do not use your messages to train models. If you do not want any data transfer outside the EU, do not use the AI Chef feature — the rest of the app works without it.

Who else sees your data

We use a small number of third-party processors, chosen because their privacy practices match ours:

  • Stripe — subscription billing and payment processing.
  • Anthropic — AI inference for the meal planner (only when you use it).
  • Apple — App Store delivery, push notifications, and sign-in (iOS).

We do not share your data with advertisers, data brokers, or analytics companies. We do not run any third-party trackers in the app.

Family sharing

The whole point of Stokked is shared lists. When you join a family, every member can see and edit the lists, items, categories, and stores belonging to that family. Saved recipes and AI Chef chats are personal — only you see those, even within a family.

Your rights

You can access all your data (it’s the data you see in the app), correct it by editing, export it, and delete your account and everything tied to it. If you can’t sign in, email info@stokked.ai and we’ll help within 30 days. If you’re in the EU, EEA, UK, or Switzerland, you have these rights under GDPR / UK GDPR, and may lodge a complaint with your national data-protection authority.

Children

Stokked is not directed at children under 13 (or under 16 in the EU). We do not knowingly collect data from anyone in those age groups. If you believe a child has signed up, email us and we’ll delete the account.

Security

All traffic between your device and our servers is encrypted in transit (TLS). Passwords are hashed — we never store them in plaintext and cannot recover them, only reset. The database is access-controlled and only reachable from inside our server.

Contact

Questions, requests, or complaints — write to info@stokked.ai. A real human will reply.