Data and privacy
Last updated: 2026-08-24
Your recipes, pantry, shopping list, and menu history stay inside your kitchen. This page covers the narrow exceptions: an aggregate signal about ingredient names that the operator uses to grow the shared ingredient catalog, and counts about how well ingredient matching did on the recipes you import.
What stays in your kitchen
The operator can’t read these through the admin console:
- Your recipes and their text, tags, or categories
- Your menu and meal plan
- Your pantry contents and overrides
- Your shopping list, custom items, and aisles
- Your menu history
- Who in your kitchen typed what, or when
What the operator sees
When you type an ingredient name that isn’t in the shared catalog yet, Mirepoix saves it as a pending discovery in your kitchen. The operator’s admin view collects those pending names across every kitchen. It shows two things drawn from kitchen data — yours and everyone else’s — per name:
- The ingredient name itself
- A count of how many kitchens have seen it
The view also shows a suggested USDA food match for each name — found by looking that same name up against the bundled USDA reference data, offered as a starting point for a new catalog entry. The lookup uses only the name shown above; the match itself — its description, nutrients, everything about it — is USDA’s own public data, nothing pulled from your kitchen or anyone else’s.
The view leaves out anything that could tie a name back to you:
- No kitchen identity, name, or slug
- No user identity
- No recipe, quick bite, or pantry entry it came from
- No name that appears in fewer than three kitchens
That last threshold is a floor, not a setting. A name has to show up in at least three separate kitchens before it’s visible to the operator at all.
Getting to the admin view takes a separate admin sign-in that times out every twelve hours. Every page load lands in the security log.
What it’s used for
One thing: deciding which entries to add to the shared ingredient catalog. New entries give future kitchens nutrition data and the right unit handling out of the box.
The aggregate isn’t fed into any machine-learning model or training pipeline — it’s a read-only signal a person reads and acts on. Adding entries to the shared catalog is a separate, reviewable change to the project’s source, not a click in this view. Names drop off the view once the catalog can resolve them.
Imported ingredient matches
When a recipe arrives by import — saved from one of Mirabel’s import steps, or restored from a file or a backup archive — Mirepoix records what its ingredient matcher decided about that recipe’s ingredient names shortly after the recipe is created, weighed against the shared catalog only. One record per distinct name in that recipe: the name as the recipe wrote it, which catalog ingredient the matcher picked or that it had no candidate at all, whether it was confident, and how far ahead of the runner-up its pick was. Recipes you type in the editor yourself aren’t recorded this way, and editing an imported recipe afterward doesn’t add more records.
If you later match one of those names to a catalog ingredient in the Review ingredients dialog, or clear a match, that correction is stamped onto the record — which ingredient you chose, or that you removed the match, and when. Only the first correction for a name is kept; a later change to the same name doesn’t overwrite it. A match is kitchen-wide, so the stamp lands on every uncorrected record of that name in your kitchen.
These records stay inside your kitchen. There’s no admin page for them — the operator’s admin console doesn’t show them at all. They’re deleted when the recipe is deleted, and nothing else expires them: they last as long as the recipe does.
What leaves your kitchen is counts. The operator can run a report on the server that groups these records by which import path a recipe came in on and shows, per path: how many kitchens, how many ingredient lines, how many the matcher was confident about, how many it was unsure about, how many had no candidate, and how many were later corrected. No ingredient name, no recipe, no kitchen identity — and a path shows up only when at least three separate kitchens have imported through it, the same floor the catalog-gaps view uses. That report can also print the records line by line, ingredient names included, for a single kitchen the operator names by hand when running it. That’s a command on the server, not a page in the admin console.
Each import also writes one line to the server’s own log carrying those same counts for that import — how many ingredient lines, how many confident, how many unsure, how many with no candidate — along with which import path it came in on and which kitchen it happened in. Counts only: no ingredient name reaches that log.
It’s used for one thing: measuring how well ingredient matching does on recipes it has never seen before, so the matcher and the shared catalog can be improved. A correction is the only honest signal that a match was wrong, which is why it’s recorded. None of it is fed into a machine-learning model or a training pipeline — the matcher is ordinary code working against the shared catalog, and a person reads these numbers and acts on them.
AI features and third-party processing
Two features send content outside your kitchen, and both run only when you choose to use them. In each case the content goes to Anthropic, the company that provides Mirepoix’s AI, and nowhere else.
AI import. When you start an AI import, the recipe text and any photos you submit are sent to Anthropic to generate the recipe. So the new recipe can be filed under one of your existing headings, your kitchen’s category and tag names are sent along with it. The request is made with settings that keep your content from being used to train any model. The text you submit is stored on Mirepoix’s servers only briefly — kept with your recent conversation for about three days, then deleted automatically; the photos go sooner, deleted as soon as the draft is made. Even while it’s stored, it’s never used to train a model, and the text you type isn’t written to logs. Photos are downscaled in your browser before anything leaves your device, and camera metadata such as location is stripped in the same step. Only the resized image is sent.
Mirabel. When you ask Mirabel, the in-app help assistant, a question, the text you type — along with the recent back-and-forth of your current conversation, so she can follow what you mean — is sent to Anthropic to generate her reply. If your conversation has been inactive for an hour, Mirepoix starts a fresh one instead of sending the earlier back-and-forth. When you ask about your own recipes, she can also search your recipe collection: the matching recipe titles and their page addresses, categories, and tags are included in that request so she can answer. When it comes to importing a recipe, what reaches Anthropic depends on how you hand her the recipe, so the two ways are described separately here. Through her import steps — the sources behind Add Recipe (I’ll paste the text, From a website, From a file), a web address you paste into the box on its own and then tap Import this recipe on, or the import bookmarklet and the phone Share sheet — what you give her goes to Mirepoix’s own server, which tries to read it there with no AI at all; nothing goes to Anthropic unless that read doesn’t come out cleanly, or you tap Use AI instead. When it does, the text is sent the way AI import sends it, along with your kitchen’s category and tag names so the draft can be filed correctly, and with the same no-training settings. In an ordinary message to her, there is no read-it-first step: everything you type or paste into the Message Mirabel box is sent to Anthropic to generate her reply, recipe text included, before any import decision is made — and if she goes on to build a draft from it, that text is sent again to do the extraction. If you ask her to import recipe text from the recent conversation, or ask her to revise or condense the draft she made, that text and the draft are sent to Anthropic the same way, with the same no-training settings. A backup archive, or several files at once, is a different thing again: Mirepoix’s server restores those itself and nothing about them goes to Anthropic. The same split applies to a link. Either way Mirepoix’s server fetches the page for you, and that fetch is a request to the site, not to Anthropic; but only on the import steps is the page read on Mirepoix’s server first, with what it found reaching Anthropic just when the page is too messy to read cleanly or you ask for AI. A link you raise in an ordinary message goes to Anthropic with that message, and the page text goes too when she builds the draft. Pages are fetched only when you ask, are not stored, and each fetch is recorded by site name only. When the page offers a recipe photo, Mirepoix’s server fetches that image too and holds it briefly — until you save the recipe, or the conversation is cleaned up after about three days — so it can be added to the recipe if you save; like any recipe photo, its location metadata is stripped before it’s stored. You can also attach a photo of a recipe — a cookbook page, an index card, a handwritten note — and she’ll read it to build the draft. Reading a photo always takes AI; there’s no version of it Mirepoix’s server can do on its own, so a photo has no read-it-first step. It doesn’t ride along with your message either: your message tells Anthropic only that you attached a photo, and the image itself is sent when she builds the draft. Photos are downscaled in your browser and camera metadata such as location is stripped before anything leaves your device; only the resized image is sent to Anthropic, and it’s held just long enough to build the draft — deleted as soon as the draft is ready. If you ask her to change one of your saved recipes, that recipe’s text is sent to Anthropic — along with your kitchen’s category and tag names, the same way AI import sends them — so she can draft the edit, and nothing in your kitchen changes until you review the proposed edit and apply it yourself. When you ask her what to cook — a weekly plan or tonight’s dinner — she draws on your menu history (how many weeks each recipe has spent on your menu, and how long since it was last there), how many of each recipe’s ingredients you’d still need from your pantry, and roughly how long each takes to make, and those figures are sent to Anthropic as part of generating her reply, so she suggests from recipes that have earned a spot on your menu before and what you have on hand. When you chat with her on a recipe page, your recipe list, your Menu, your Groceries, or your Pantry, a short note about that page rides along with your message — the kind of page and its name, plus a recipe’s own page address — so references like “this recipe” point at the right thing. It’s the page’s type and name only, never anything on the page, and only while you’re chatting with her. If your kitchen has saved cooking preferences in Settings — how many people you usually cook for, any diets your kitchen follows, and ingredients to avoid — a short summary of them rides along with your message too, every time you chat with her, so her suggestions and drafts respect them. It’s what’s saved in Settings and nothing more, visible and editable there rather than a hidden profile, and it uses the same no-training settings as the rest of what she sends. She can offer to save one of these preferences for you, but nothing is saved unless you tap to confirm, and only a kitchen owner can change settings. When you ask her about the rest of your kitchen, she can look at four more things, each only when your question calls for it: whether particular ingredients are on hand and what’s running low in your Pantry, what’s on your Menu right now, what’s already on your shopping list, and what one of your saved recipes still needs from the store, worked out against your Pantry and your shopping list together. What she finds in the first three — the ingredient names, the on-menu recipe titles with their page addresses and the category each is filed under, the on-menu QuickBite titles and their categories, the item names — is sent to Anthropic as part of generating her reply, with the same no-training settings as everything else she sends. The last of the four sends a combination those three don’t: that recipe’s title and its page address, the names of the ingredients it still needs to buy — the ones your Pantry lacks that aren’t already on your list, up to twenty of them, plus up to twenty more the recipe marks optional and filtered the same way, with a note telling her the list was trimmed if it ran longer — and three counts: how many are left to buy, how many more your Pantry lacks that your list already holds, and how many the recipe needs from the store in all. Looking changes nothing, and nothing is stored beyond her conversation. She can also offer to add, on two surfaces that confirm differently. Ask her to put items on your shopping list, or saved recipes on your Menu, and she shows a confirm chip listing exactly what she’d add — up to twenty item names, or up to five recipes, and nothing is added unless you tap to confirm. The other is the workshop pane that holds what a saved recipe still needs: under the list it just showed you sits one button naming that count — Add 3 items to your list — and tapping it puts that whole list on your shopping list. That one is not a chip and has no second confirm step; the tap under the list is the confirm. It is also not capped — it adds the whole of that list, however long it runs, the same way the Groceries page’s own add is uncapped — and it adds only what the recipe requires and your list doesn’t already hold, never what it marks optional. What lands is worked out again at the moment you tap, so it’s what’s missing and not already on your list then, rather than the number the button named. Either way the tap is what writes, and she has no way to make the change herself: the chip posts to the same shopping-list and Menu actions those pages’ own buttons use, and the pane has an address of its own but makes the same underlying shopping-list write, with no more reach than the Groceries page’s own button has. Nothing new is sent to Anthropic for either: the chip’s item names are her own words from your conversation, the recipe titles are the same ones already sent when she searches your recipes, and the pane’s list was composed on Mirepoix’s own server — tapping to add sends none of it back. After you tap, a short note of what actually landed joins the conversation — a count of items for the list, the recipe titles for the Menu — so she can’t claim a change that didn’t happen, and it rides along with your next message the way the rest of the conversation does. She still can’t change your Pantry, check an item off your list, or take anything off your Menu. Apart from what you ask her to look up, plan, add, or edit — that note about which page you’re on, and your kitchen’s saved cooking preferences — she reads nothing else in your kitchen, and nothing tied to your account. The request uses the same no-training settings as AI import. Your recent conversation is now kept on Mirepoix’s servers for a short time — about three days — so Mirabel can pick up where you left off after a reload or on another device, then it’s deleted automatically.
How long this is kept. Mirabel conversations — and the drafts and import text in them — are kept on Mirepoix’s servers for about three days, then deleted automatically. Each of her answers also carries two small bookkeeping notes, kept and deleted on that same schedule. The first is a pointer to whichever pane the answer opened, so a reload or another device reopens the same one: it records which kind of pane it was — her recipe draft, a comparison of a proposed edit, your saved cooking preferences, or what a saved recipe still needs from the store — and, for two of those four, one address apiece: the recipe’s page address for the store-list pane, and an identifier for the answer that made the draft for the draft pane. The other two record nothing but the kind. The second note applies only when an answer failed, and records whether trying again could help, so Mirepoix can leave out a Try again button that couldn’t work. Neither holds anything you typed or anything else from your kitchen, and neither is sent to Anthropic — both are written on Mirepoix’s own server after the answer is made. That’s long enough to recover a request you started on another device or after closing the tab, not a lasting record. An encrypted backup may keep an older copy until it rotates out.
Both features draw on your kitchen’s monthly AI allowance, which they share.
Recipe photos
When you add a photo to a recipe, Mirepoix removes its location metadata before storing it. That covers the GPS a camera records and the location a photo editor can add. Stored recipe photos carry no location.
This matters most when you share. A recipe holds one photo, and a shared link shows it as the preview — the full-size photo, not a thumbnail. Because the location is already gone, the link can’t reveal where the photo was taken.
Menu history
Adding a recipe to your menu records when it joined, and taking it off records when it left. Those stretches — which weeks a recipe has spent on your menu — power Mirabel’s meal-planning suggestions, like forgotten favorites, and a few touches on your Recipes page: the small note on a recipe card saying how many days ago it was last on the menu, or how many times it’s been on the menu in the last year; one of the signals that can lift a recipe to the top of a large category instead of behind the fold; and the order recipes take within a folded list. Those page touches are for your kitchen’s own members: someone who opens a published kitchen’s link without being a member of it sees the recipes themselves, in full — no card notes, no working set, and no fold. The record itself stays inside your kitchen too: the operator can’t read it through the admin console. It’s kept for 13 months after a recipe leaves the menu and then deleted automatically, so suggestions can reach back across the seasons without keeping the record indefinitely. (When you ask Mirabel what to cook, figures derived from it are sent to Anthropic to generate her reply, as described under “AI features and third-party processing.”)
Pending imports
When you capture a page with your own recipe-import bookmarklet, Mirepoix holds what it harvested on the server — the page’s structured recipe markup, a short text excerpt, and its title and address — tied to the kitchen member who captured it, in that member’s pending-imports tray. It’s kept so you can import it at your leisure instead of finishing the import the moment you capture, until you import or dismiss it — dismissing deletes it right away, and importing deletes it once the import has gone through. One you never touch is deleted automatically after 30 days. Nothing about a pending capture is sent to Anthropic until you choose to import it — reaching Mirabel’s import steps then follows the same path already described above under “AI features and third-party processing.”
Sign-in and security logs
Mirepoix writes short lines to a security log so the operator can spot abuse like a password-guessing run. Most lines record a refusal at a security checkpoint — a sign-in, an invitation or join code, an email change, or an incoming payment-provider message that didn’t pass. Others record a security event that succeeded, such as a sign-in completing, a new device appearing, a passkey being registered, sessions being ended or revoked, an invitation or join code being used, or a kitchen transfer completing. These lines never contain your recipes or anything else in your kitchen. Which details a line carries depends on which checkpoint wrote it. Some note only what happened; others also record the network address (IP) the request came from, an email address, an identifier for the account, kitchen, or sign-in the request belonged to, or some combination of these:
- The request’s IP address is recorded when a sign-in, passkey, invitation, or join-code attempt is refused or throttled by network address, and when an incoming payment-provider message is rejected.
- The email address that was typed to sign in is recorded when someone tries to sign in with an address that isn’t a member here, and when a sign-in or email-change attempt is throttled by account.
- The new address someone tried to change their email to is recorded when that email change is refused because the address is already in use — a different address than the one above, since it’s the destination of the change rather than the one someone signed in with.
- For entries tied to a signed-in person or to a specific kitchen — a payment-provider message can write one with nobody signed in — an identifier for the account, kitchen, or sign-in the entry belonged to. Never a name or email address by itself, and never anything from inside your kitchen.
- The web address (host only — never the full page address) of a page sent to the operator’s recipe-capture intake is recorded on every capture attempt, accepted or refused. The endpoint serves the operator’s own browser bookmarklet, but a refused attempt from anyone on the internet is logged the same way.
- The web address (host only — never the full page address) of a page sent through your own recipe-import bookmarklet — the one tied to your account, separate from the operator’s own bookmarklet described above — is recorded when a capture is accepted, and when one is refused for being too large or for going over your account’s daily limit. It is never recorded for a rejection caused by a missing, wrong, or expired token, or a kitchen you don’t belong to, so an attempt to guess a working token leaves no host trail at all.
You already see your own request’s IP address and browser in the sign-in, new-device, and passkey-change emails Mirepoix sends you. What this section adds is that the IP address is also kept in the server’s security log — the browser is not — alongside the admin catalog-gaps page views described above.
Enforcing those limits also means counting recent attempts, and unlike the log lines above — written only when one of the events described there occurs — a counter is written on every attempt. The sign-in and sign-in-code counters are filed under the email address that was typed together with the request’s IP address. The rest are filed under the request’s IP address alone, or under your account or your kitchen — no other counter pairs an address with an IP. Pairing the two is deliberate: it keeps someone else’s attempts from using up the allowance for your own sign-in.
To enforce these limits, Mirepoix temporarily stores counts of recent attempts using the identifiers described above. Each counter stops affecting access when its rate-limit window ends; the sign-in and sign-in-code windows last 15 minutes. The counters are removed later through routine cache cleanup.
These logs don’t expire on a set schedule — what clears them is a new release. Each time Mirepoix is updated the server starts fresh with an empty log, and updates ship every few days, so a line usually survives days rather than months. A storage budget of about 300 MB caps the log as well, but at the rate these lines are written it has never been reached, so it isn’t what removes them. The few previous server copies keep their own logs until they’re cleaned up several releases later, so a line’s real life is longer than a single release — usually a couple of weeks, and longer than that whenever releases are further apart. There’s no fixed ceiling here: how long one of these lines survives tracks how often Mirepoix is updated.
What never happens
Your kitchen’s content — your recipes, tags, pantry, shopping list, menu history, and the link between any of those and your account — never:
- Gets sold
- Gets shared with third parties
- Gets used for advertising, recommendations, or behavioral profiling
- Gets exported to third-party analytics
- Gets used to train any machine-learning model, by the operator or by any third party
- Gets mapped to your kitchen identity in the admin view, in logs, or in exports
The one exception is the k-anonymized ingredient-name aggregate described above under “What the operator sees.” That aggregate is used solely by a human operator to decide which entries to add to the shared catalog. It isn’t sold, isn’t shared with third parties, isn’t used for machine-learning training, and contains no link back to your kitchen.
The import-matching counts described above under “Imported ingredient matches” are the second carve-out, and a narrower one: they carry no ingredient name at all, and the cross-kitchen report shows a figure only once at least three kitchens stand behind it. The one place a kitchen identity does appear is the server’s own log line for an import, which records which kitchen the import happened in beside those counts — never an ingredient name, and nothing else from the recipe. Like the aggregate above, none of it is sold, shared with third parties, or used for machine-learning training.
The other carve-out is the content you choose to send through the AI features, described above under “AI features and third-party processing.” That happens only when you start an AI import or ask Mirabel a question, applies only to what you submit in those moments, and is made with settings that keep your content from being used to train any model. The content you send through the AI features is now kept briefly on Mirepoix’s servers — about three days — to deliver and recover your request, associated with your kitchen and account for that window, then deleted automatically. It’s still not sold, not shared, not used to train any model, and still kept out of logs.
Changes
- 2026-08-24 — Widened the description of what menu history powers, under “Menu history.” It already fed Mirabel’s meal-planning suggestions; it now also feeds a few things visible directly on your Recipes page: the small note on a recipe card saying how many days ago a recipe was last on the menu, or how many times it’s been on the menu in the last year; one of the signals that can lift a recipe to the top of a large category instead of behind the fold; and the order recipes take within a folded list. All of those are shown to your kitchen’s own members only. Someone who opens a published kitchen’s link without being a member of it sees every recipe in each category, with no card notes, no working set, and no fold — publishing a kitchen shares its recipes, not what your household has been cooking lately. The underlying record still stays inside your kitchen, unreadable by the operator, and the 13-month retention is unchanged.
- 2026-08-09b — Disclosed a new record Mirepoix keeps about imported recipes, described above under “Imported ingredient matches.” When a recipe arrives by import, Mirepoix now stores what its ingredient matcher decided about each of that recipe’s ingredient names at the moment the recipe is created — the name as written, the catalog ingredient picked or the absence of a candidate, whether the match was confident, and how far ahead of the runner-up it was — and stamps your later correction onto that record when you match or clear a name in the Review ingredients dialog. The record stays in your kitchen, has no admin page, and is deleted with the recipe. What crosses the kitchen boundary is counts: an operator-run report groups them by import path, shows a path only once at least three kitchens have imported through it, and carries no ingredient name, recipe, or kitchen identity; the same report can print the line-by-line records for one kitchen the operator names by hand when running it. Each import also writes one counts-only line to the server’s log, which records which kitchen the import happened in but no ingredient name. Ingredient names and their resolution state were already stored in your kitchen and already fed a cross-kitchen count under the same three-kitchen floor; what’s new is that a prediction and the correction that falsifies it are recorded together, so how well matching does on recipes it has never seen can be measured.
- 2026-08-09a — Disclosed that a bookmarklet capture is held server-side, not only logged. A new “Pending imports” section states what’s stored — the harvested page’s structured recipe markup, a text excerpt, and its title and address — tied to the capturing kitchen member, kept so you can import at your leisure. Dismissing a capture deletes it right away; importing one deletes it once the import has gone through. An untouched one is deleted automatically after 30 days. Nothing about a pending capture reaches Anthropic until you import it. No behavior changed before this feature existed; this documents it as it ships.
- 2026-08-09 — Disclosed the security log line written by your own recipe-import bookmarklet, added under “Sign-in and security logs.” It’s a second capture-intake endpoint, separate from the operator’s own bookmarklet described just above it: yours is tied to your account by a personal token, writes into your kitchen’s capture tray rather than the operator’s review queue, and only logs the captured page’s host on an accepted capture or a refusal for size or your daily limit — never on a bad or missing token, so a guessed token leaves nothing behind. No behavior changed before this feature existed; this documents it as it ships.
-
2026-08-05a — Corrected the throttle-counter retention description under “Sign-in and security logs.” The page previously called two weeks an outer bound, but Solid Cache only considers old entries for removal when later cache activity triggers cleanup. The page now says that each counter stops affecting access when its rate-limit window ends, that the sign-in and sign-in-code windows last 15 minutes, and that the counters are removed later through routine cache cleanup. No behavior changed; this corrects the disclosure.
-
2026-08-05 — Disclosed two small bookkeeping fields now stored with each of Mirabel’s answers, described above under “How long this is kept.” The first is a pointer to whichever workshop pane that answer opened, so a reload — or picking the conversation up on another device — reopens the same pane. It records which kind of pane it was: her recipe draft, a comparison of a proposed edit to a saved recipe, your saved cooking preferences, or what a saved recipe still needs from the store. Two of those four carry one address apiece alongside the kind — the recipe’s page address for the store-list pane, and an identifier for the answer that produced the draft for the draft pane — and the other two carry nothing but the kind. Only those four kinds are accepted; anything else is discarded rather than stored. The second field applies only when an answer failed, and records whether trying again could help, so a Try again button that couldn’t work is left out. Neither field holds anything you typed or anything else from your kitchen, and neither is sent to Anthropic — both are written on Mirepoix’s own server after the answer is made, and neither joins the conversation history sent with your next message. Both live with the conversation and are deleted with it on the same roughly-three-day schedule. Nothing about what Mirabel can read, send, add, or change altered with this entry. What changed is that these two fields are stored at all: this page’s retention description named the question, the answer, and the draft, and these are new alongside them.
-
2026-08-03 — Completed the description of what Mirabel can look at and how she can add, for the workshop pane that works out what a saved recipe still needs. Ask what one of your saved recipes takes to cook and she now works it out against your Pantry and your shopping list together — a fourth lookup, listed above beside the Pantry, Menu, and shopping-list ones. What goes to Anthropic for it is that recipe’s title and page address, the names of the ingredients it still needs to buy — up to twenty, plus up to twenty more the recipe marks optional — and three counts: how many are left to buy, how many more your Pantry lacks that your list already holds, and how many the recipe needs from the store in all. Each of those was already disclosed here on its own: titles and page addresses when she searches your recipes, ingredient names when she checks your Pantry, the shortfall count when you ask her what to cook, and what your shopping list holds when she reads it. What this adds is that they go together, in one answer about one recipe — a shape the “three more things” enumeration didn’t describe. That pane also carries an add that isn’t shaped like the confirm chip described in the 2026-07-31b entry below: one button under the list it just showed you, where the tap is the confirm rather than a second step, and — unlike the chip’s twenty-name ceiling — it is not capped. It puts the whole of the list it just showed you on your shopping list however long that runs, the same way the Groceries page’s own add is uncapped, and it adds only what the recipe requires and your list doesn’t already hold, never what it marks optional. Nothing new is stored, the write has an address of its own but makes the same underlying shopping-list write the Groceries page’s own button makes — no extra reach, and it can only add to your list — and the same short note of what actually landed joins the conversation after the tap. Nothing about how any of this behaves changed with this entry — what changed is the description, which named three lookups and one add surface where there are four and two.
-
2026-08-02 — Corrected the description of when an import sends your recipe to Anthropic. Since 2026-07-07a this page has said that when you give Mirabel recipe text or a link to import, she reads it herself first without sending anything to Anthropic. That is true of her import steps, and it is not true of an ordinary message: everything you type or paste into the Message Mirabel box goes to Anthropic to generate her reply, recipe text included, before any import decision is made, and an import she runs from that message has no read-it-first step at all. The page now describes the two paths separately instead of stating one rule for both, and says plainly that a photo always takes AI. No behavior changed — this only corrects the description, and the flow it describes was already disclosed by this page’s opening statement that the text you type is sent to Anthropic to generate her reply.
-
2026-07-31b — Mirabel can now offer to add to your shopping list and your Menu. Ask her to put items on the list, or saved recipes on the Menu, and she shows a confirm chip listing exactly what she’d add — up to twenty item names, or up to five recipes. Nothing is added unless you tap to confirm, and the tap is what writes: it goes through the same shopping-list and Menu actions those pages’ own buttons use, and she has no way to make the change herself. Nothing new is sent to Anthropic — the item names are her own words from your conversation, and the recipe titles are the same ones already sent when she searches your recipes — and nothing new is stored. What changed is that she can now act on your tap; after one, a short note of what actually landed joins the conversation and rides along with your next message, so she can’t claim a change that didn’t happen. She still can’t change your Pantry, check an item off your list, or take anything off your Menu. This supersedes the 2026-07-31a statement that she can’t add to your menu or your shopping list.
-
2026-07-31a — Mirabel can now look at the rest of your kitchen when you ask. She can check whether ingredients are on hand and what’s running low in your Pantry, read what’s on your Menu, and read what’s on your shopping list; what she finds is sent to Anthropic as part of generating her reply, with the same no-training settings as everything else she sends. Nothing new is stored, looking changes nothing, and she still can’t add to your menu or your shopping list — you do that yourself. This corrects the earlier statement that she couldn’t read your shopping list.
- 2026-07-31 — Mirabel can now use your kitchen’s cooking preferences. A new Settings section stores how many people you usually cook for, any diets your kitchen follows, and ingredients to avoid. When you chat with Mirabel, that short summary is sent to Anthropic with your message so her suggestions and drafts respect it, with the same no-training settings as everything else she sends; it is part of your kitchen’s settings, visible and editable there, not a hidden profile. Mirabel can offer to save one of these preferences for you, but nothing is saved unless you tap to confirm, and only a kitchen owner can change settings.
- 2026-07-28 — Completed the security-log enumeration from 2026-07-18a below. First, entries tied to a signed-in person also carry an identifier for the account, kitchen, or sign-in the request belonged to — never a name or email address by itself, and never anything from inside your kitchen; this was previously omitted entirely. Second, the email-address bullet is now two: the address someone typed to sign in is one field, and the new address someone tried to change their email to — recorded when that change collides with an existing account — is a different one; the two were previously described together as “the email address that was typed,” which didn’t clearly cover the change-attempt case. Third, this section previously framed every log line as recording a refusal; in fact some lines record security events that succeeded — a sign-in completing, a new device appearing, a passkey being registered, sessions being ended or revoked, an invitation or join code being used, a kitchen transfer completing — and the section now says so. Fourth, the identifier bullet now also covers entries tied to a kitchen rather than a signed-in person — a payment-provider message can write one with nobody signed in. Fifth, disclosed that the operator’s recipe-capture intake records the captured page’s host (never the full address) on every attempt, accepted or refused. Nothing about what is logged changed; this only extends and clarifies the description to match current code.
- 2026-07-27 — Corrected how long the security logs described above are actually kept. This page previously said they are kept by volume rather than by calendar — a rolling storage budget of about 300 MB, with older lines falling off as newer ones arrive rather than expiring on a set schedule. Measuring it showed that budget has never been reached, and isn’t what removes these lines: what clears them is a new release, which starts the server with an empty log. Because Mirepoix ships every few days, a line usually survives days rather than months — a couple of weeks once the previous server copies are counted, and longer whenever releases are further apart. There is no fixed ceiling; how long a line survives tracks the release cadence. Nothing about what is logged changed — this only replaces a claim that overstated how long these lines are kept.
- 2026-07-25 — Disclosed the throttle counters that enforce Mirepoix’s rate limits. The “Sign-in and security logs” section now states that a counter is written on every attempt — not only refused ones, as the log lines are — and that the sign-in and sign-in-code counters are filed under the typed email address together with the request’s IP address, while the rest are filed under an IP address alone, an account, or a kitchen. The pairing itself is what changed: those two counters previously used the email address alone, so anyone could burn a named person’s sign-in allowance from anywhere; pairing it with the IP keeps someone else’s attempts off your allowance. A counter holds only a number; it stops counting after 15 minutes, and at the time this page described the stored entry as cleared within about two weeks. That retention description was corrected by the 2026-08-05a entry above. Both fields were already disclosed above individually; what this adds is that they are held together, that the pair persists beyond the counting window until that cleanup, and that one is written for every attempt rather than only refused ones.
- 2026-07-18a — Disclosed how Mirepoix’s security log records sign-in and other security-checkpoint failures. Added a “Sign-in and security logs” section stating that, depending on which check failed, a log line records the request’s IP address (refused or network-throttled sign-in, passkey, invitation, and join-code attempts, and rejected payment-provider messages), the typed email address (a sign-in attempt from a non-member address, an account-throttled attempt, and an email-change collision), or both, and noting these logs are kept by a rolling storage cap rather than a fixed time window. This documents existing behavior — the same request IP you already see in the sign-in and new-device emails — that the page previously described only for the admin catalog-gaps view; nothing about what is logged changed.
- 2026-07-18 — Disclosed that the operator’s catalog-gaps admin view also shows a suggested USDA food match for each unresolved name — found by looking that name up against the bundled USDA reference data, offered as a starting point for a new catalog entry. This has shown since the USDA-resolution work landed; the page previously only described the ingredient name and cross-kitchen count. The lookup uses only the name already described above; the match’s content is USDA’s own public data, and the rest of this section’s guarantees are unchanged.
- 2026-07-17b — Mirepoix no longer records cooks. The Menu’s “Made it” cross-off has been removed, and the cooking-history record it fed has been deleted. In its place, Mirepoix keeps a lighter record of when each recipe joins and leaves your menu, which now powers Mirabel’s suggestions. The same guarantees apply: it stays inside your kitchen, isn’t readable by the operator, and is deleted automatically 13 months after a recipe leaves the menu.
- 2026-07-17a — The dinner-picker’s wheel-spin feature has been removed from the app, so this page no longer describes cooking history as powering “the dinner picker’s variety.” The rest is description-only correction: the “Cooking history” section previously said this record powers all of Mirabel’s suggestions including quick wins, but quick wins draw on your pantry, not on cooking history. What Mirepoix collects, and for how long, is unchanged — cooking history still powers forgotten favorites the same way it always did.
- 2026-07-17 — Stopped recording which existing catalog ingredient a confirmed match binds to. When you match an unrecognized ingredient name to one already in the shared catalog, Mirepoix no longer keeps a note of that pairing in your kitchen. Nothing read this note anymore — the tool that once did was removed on 2026-07-15 — so what you and the operator see is unchanged; this simply stops collecting data that was no longer used. The ingredient name and its cross-kitchen count, described above, are unaffected.
- 2026-07-16 — Importing a recipe from a link now also brings over the source page’s photo. When the page offers one, Mirepoix’s server fetches that image along with the recipe and holds it briefly — until you save the recipe, or the conversation is cleaned up after about three days — so it can be added to the recipe when you save. Like any recipe photo, its location metadata is stripped before it’s stored; it’s never used to train a model and stays out of logs. This narrows the earlier statement that a fetched page is “never stored”: the page itself still isn’t, but a photo it offers now is, briefly.
- 2026-07-15a — Mirabel’s recent conversations, and the recipe text, links, and photos in an import, are now kept briefly on Mirepoix’s servers instead of only in your browser — long enough to deliver a slow import and to pick up where you left off after a reload or on another device. They’re associated with your kitchen and account for that window, kept for about three days and then deleted automatically (photos are deleted as soon as the draft is made), still never used to train a model and still kept out of logs. This corrects the earlier statements that the conversation lived only in your browser and that import text and photos weren’t stored.
- 2026-07-15 — Narrowed what the operator can see. The offline tool that read which existing ingredient a name had been matched to has been removed, so the catalog-growth signal is back to what it showed before 2026-06-30a: the ingredient name and a count of how many kitchens have seen it. The three-kitchen floor and the rest of this section are unchanged.
- 2026-07-12 — Mirabel now knows which page you’re on. When you chat with her on a recipe page, your recipe list, your Menu, your Groceries, or your Pantry, a short note about that page — its type and name, plus a recipe’s page address — is sent to Anthropic with your message, so references like “this recipe” resolve. It’s the page’s type and name only, never its contents, and it uses the same no-training settings as AI import; nothing new is stored.
- 2026-07-11 — A recipe now holds one photo instead of a gallery of up to ten, so this page no longer describes a “cover” photo chosen from several. What Mirepoix does with a photo is unchanged: location metadata is still removed before storing, and a shared link still previews the full-size photo. This only corrects the description.
- 2026-07-07a — Corrected the description of how Mirabel imports pasted recipe text and linked recipe pages. The earlier wording said that pasted text and linked-page content were always sent to Anthropic; since deterministic-first import landed (pasted text, and structured recipes on linked pages), Mirabel now tries to read both herself first, without AI, and content reaches Anthropic only when she can’t confidently parse it on her own or you ask her to redo the import with AI. No behavior changed — this only corrects the description.
- 2026-07-07 — Mirabel can now suggest what to cook — forgotten favorites, newest recipes, and quick wins. When you ask her what to make, figures from your cooking history (how many times and how recently you’ve made each recipe) and how many of each recipe’s ingredients you’d still need are sent to Anthropic to generate her reply, using the same no-training settings as AI import; nothing new is stored. This corrects the earlier statement that Mirabel had no access to your pantry. Separately, this page now discloses that cooking history is kept for 13 months and then deleted automatically — previously undocumented; the retention window grew from about three months to support the new “forgotten favorites” suggestions.
- 2026-07-02 — Ingredient matching for AI import now happens entirely on Mirepoix’s own server, without sending anything to Anthropic. Unresolved ingredient names no longer leave your kitchen for this purpose — the suggested matches you confirm are computed locally instead.
- 2026-07-01 — Mirabel can now propose edits to your saved recipes. When you ask her to change a recipe, that recipe’s text is sent to Anthropic with your request to draft the edit, using the same no-training settings as AI import; nothing is stored, and no change is made until you preview and apply it yourself. Each applied edit is recorded in the recipe’s history, labeled as made via Mirabel.
- 2026-06-30a — The operator’s catalog-growth signal now also shows, for a name at least three kitchens independently matched to the same existing catalog ingredient, which ingredient they matched it to — the cue to add that name as an alternate spelling. The same three-kitchen floor applies, the matched-to name is the catalog’s own, and nothing ties it back to your kitchen.
- 2026-06-30 — AI import now sends unresolved ingredient names to Anthropic to suggest catalog matches. When an imported recipe has ingredients the shared catalog doesn’t recognize, just those names — no quantities, recipe text, or photos — are sent to Anthropic, and you confirm which suggestions to apply. This uses the same no-training settings as AI import; the names aren’t stored or logged.
- 2026-06-28a — Mirabel can now import recipe text from the recent conversation when you ask her to, instead of requiring you to paste the same text again. This uses the same recent browser-stored conversation already sent when you ask Mirabel a question; nothing new is stored.
- 2026-06-28 — Mirabel now starts a fresh conversation after 24 hours of inactivity, instead of sending older browser-stored back-and-forth with a new question. This narrows what is sent to Anthropic after a quiet period; nothing new is stored.
- 2026-06-15 — Recipe photos now have their location metadata removed before they’re stored. A stored photo carries no location, whether a camera or a photo editor recorded it. Camera location (EXIF) was already removed; this adds the location some editors store separately. A recipe’s cover is the full-size image a shared link previews. Removing the location keeps that link from revealing where a photo was taken.
- 2026-06-15 — Corrected the AI-import disclosure. When you run an AI import — through the import dialog or by asking Mirabel to import, revise, or condense a draft — your kitchen’s category and tag names are sent to Anthropic along with the recipe, so the draft can be filed under one of your existing headings. This has always happened; the page now says so. No behavior changed, and the same no-training settings still apply.
- 2026-06-11 — Two new ways to start an import. A bookmarklet you keep in your browser reads a recipe from a page Mirepoix can’t open itself — anything behind a login or paywall — and hands the page’s text to Mirabel to build a draft after you confirm. That captured text travels in the page address and doesn’t reach Mirepoix’s servers until you confirm the import, after which it is sent to Anthropic the same way the existing import is. On a phone, you can also share a recipe link to the installed app; Mirabel opens on that link and turns the page into a draft, exactly as pasting a link already does. Both feed the import that already existed — nothing new is stored.
- 2026-06-11 — Mirabel can now import a recipe from a photo you attach in the chat. The photo is downscaled in your browser, has its camera metadata stripped, and is sent to Anthropic to build the draft — not stored. (This is the same photo handling the AI import dialog used; that dialog has been folded into Mirabel.)
- 2026-06-11 — Mirabel can now open a recipe link you paste and turn the page into a draft. When she does, Mirepoix’s server fetches that page and sends what it finds to Anthropic to build the draft. Pages are fetched only when you ask, are not stored, and the fetch is logged by site name only.
- 2026-06-11 — Mirabel can now turn recipe text you give her into a recipe draft and revise it on request. The text you provide and the working draft are sent to Anthropic to do that, exactly as AI import does; nothing new is stored, and drafts only become recipes when you open and save them in the editor yourself.
- 2026-06-11 — Mirabel can now search your recipes when you ask her about them: the matching recipe titles and their page addresses, categories, and tags are sent to Anthropic as part of generating her reply. Nothing is sent unless you ask, nothing new is stored, and she still can’t change anything in your kitchen.
- 2026-06-10 — Corrected the third-party-processing section. AI import is no longer described as the only feature that sends content outside your kitchen: Mirabel, the help assistant, also sends your question and recent conversation to Anthropic when you use her. Neither feature’s behavior changed — the page was simply out of date.
- 2026-06-07 — Disclosed that AI import sends the text and photos you submit to Anthropic to generate a recipe (user-initiated, made with no-training settings, not stored or logged), and that photos are downscaled with camera metadata stripped in your browser before upload.
- 2026-05-25 — Tightened the scope of “your data” claims to specifically name kitchen-private content, and added an explicit carve-out paragraph for the k-anonymized ingredient-name aggregate. No change to what the operator collects or sees; the prior wording was accurate but read as broader than the underlying behavior.
See also
Last updated August 24, 2026