Last updated: 1 July 2026
Stokked is a family shopping list app with an AI meal planner. This page explains, in plain language, what data we hold on you and why.
Stokked is operated by Stefan Crafoord-Wiklund (info@stokked.ai). The Stokked apps, the website, and the supporting servers are the “Service” this policy covers.
When you sign up, we store your email address and a hashed password. We use this to authenticate you and to let you recover access. Email is also used for transactional notifications (password resets, family invites). We never sell or share it for marketing.
Everything you put into Stokked — list items, store names, categories, family memberships, saved recipes — is stored on our servers so it can sync across your devices and your family’s devices in real time. This is the data the app exists to manage; without it the app cannot function.
If you use the AI Chef feature (part of Stokked Plus), the messages you send and the meal plans we generate are processed to produce your reply. We log a small usage record (timestamp, request type, token count) for each request so we can monitor cost and prevent abuse. We do not train any AI model on your messages.
Stokked Plus is billed by Stripe. We never see or store your full card details — Stripe handles payment. Stripe sends us a customer identifier and a subscription status (active, past due, canceled, etc.) so we know whether to unlock AI features. That’s it.
We collect minimal server-side logs (IP address, timestamp, request path) for the usual reasons — debugging, blocking abuse, keeping the lights on. These logs are kept for 14 days and then rotated out.
The Stokked database, authentication, and edge functions run on a server we operate in Frankfurt, Germany. Data is at rest in the EU.
The AI meal planner forwards your prompt to Anthropic (USA) for inference. This means the text you send to the AI Chef leaves the EU during processing. Anthropic returns the generated meal plan; we do not use your messages to train models. If you do not want any data transfer outside the EU, do not use the AI Chef feature — the rest of the app works without it.
We use a small number of third-party processors, chosen because their privacy practices match ours:
We do not share your data with advertisers, data brokers, or analytics companies. We do not run any third-party trackers in the app.
The whole point of Stokked is shared lists. When you join a family, every member can see and edit the lists, items, categories, and stores belonging to that family. Saved recipes and AI Chef chats are personal — only you see those, even within a family.
You can access all your data (it’s the data you see in the app), correct it by editing, export it, and delete your account and everything tied to it. If you can’t sign in, email info@stokked.ai and we’ll help within 30 days. If you’re in the EU, EEA, UK, or Switzerland, you have these rights under GDPR / UK GDPR, and may lodge a complaint with your national data-protection authority.
Stokked is not directed at children under 13 (or under 16 in the EU). We do not knowingly collect data from anyone in those age groups. If you believe a child has signed up, email us and we’ll delete the account.
All traffic between your device and our servers is encrypted in transit (TLS). Passwords are hashed — we never store them in plaintext and cannot recover them, only reset. The database is access-controlled and only reachable from inside our server.
Questions, requests, or complaints — write to info@stokked.ai. A real human will reply.