Buk.

Privacy

Last updated 26 August 2026

Buk is for the recipes your family wrote down. That is about as personal as a file gets, so this page says exactly what we hold, who else touches it, and how to make it go away. No defined terms, no capitalised paragraphs.

What we store

Your account — your name, your email address, and a one-way hash of your password. We never see the password itself.

What you put in— recipes you import, type or photograph, the books you assemble from them, cover images, and the settings that decide how a page looks. Photographs of recipe cards are stored as-is, so if a card has someone's handwriting or a note in the margin, we hold that too.

Ordinary technical records — server logs with IP addresses and request paths, kept short and used for fixing things.

Feedback you send us — the message, plus the page you were on, your plan, and your browser, so we can reproduce what you saw.

How you use Buk — a short line each time you finish something (a book made, a book organised, a PDF exported), each time a limit stopped you, and each time an import failed, plus one row per day you were signed in and doing something. Kept on our own server, against your account. The section below lists every one of them, and what is never in them.

Where it lives

On a server we run in Amazon Web Services' Oregon region, in a Postgres database on an encrypted disk. Your photographs are in that same database rather than a public file store, so there is no shareable URL to leak.

Who else processes it

Four companies, each for one job:

  • Amazon Web Services — the server and its storage.
  • Google — the Gemini API reads a recipe or a photo when you import one, and writes the tidied version. We use the paid tier specifically because content sent to it is notused to improve or train Google's models.
  • Cloudflare — carries traffic between your browser and our server.
  • Purely Mail — sends the handful of emails we send: your invitation, password resets.

Counting how Buk gets used

We measure how Buk gets used. We do it ourselves, on our own server. The numbers never leave it, and we will never sell or share them with anyone. Not with an analytics company, not with an advertiser, not at any price. There is no third-party tracker here to hand them to in the first place.

Buk is built by one person, and the plain reason this exists is that we cannot otherwise tell which parts of it work and which ones quietly waste your time. So here is all of it. What gets counted:

  • That you finished something — a book created, a book organised, a recipe or a book exported as a PDF, a recipe sent to one of your collection links by a family member, and one of those accepted into a book. Which of those it was, which book or recipe, and when.
  • That a limit stopped you — which limit it was, and which plan you were on. This is how we find out we have put a wall somewhere silly.
  • That an import failed — the site's domain (say bbc.co.uk, never the full address), whether you gave us a link, typed text or a photo, and a one-word reason. Recorded the moment it breaks, so it still tells us something after you dismiss the failure.
  • One row per day you were active — literally your account number and a date, nothing else. It is how we tell whether people come back, without watching what they do while they are here.
  • Plan changes — started, cancelled, given for free, a pack bought or expired.

What never goes in: anything you wrote. No recipe, note, title or book content. No photographs. No free text of any kind. Not your name, your email or your IP address. Not the full web address of anything — a domain at most. And nothing that watches you inside a page: no session recording, no screen replay, no heatmaps, no scroll, mouse or keystroke tracking, no fingerprinting, and nothing that follows you to another site. Nothing extra is stored in your browser for any of it.

It sits in the same Postgres database as your recipes, on the same server, read by the same one person. Deleting your account deletes it — see below.

What we don't do

We don't sell your data, and we don't share it with anyone — not for advertising, not for analytics, not for anything. We don't train anything on your recipes. We count how Buk gets used, in the narrow way described just above, and those numbers never leave our server. There is no Google Analytics, no third-party tracker, no advertising pixel and no session recording on this site: nothing follows you around the web, and nothing records your screen. The only things stored in your browser are your sign-in token and your display preferences.

Backups — read this one

There are no backups during the beta. If the server is lost, your recipes here are lost with it. Please keep your original cards, photos and printouts — let Buk sit alongside them rather than replace them. Proper backups are the first thing on the list before Buk opens to the public.

Getting your data out, or deleted

Out: every recipe and book exports as a PDF from inside the app, whenever you like.

Deleted: email [email protected] from your account address and we'll erase the account, every recipe, every photograph, every book, and every usage record described above — the counts, the failures and the day rows. Because there are no backups, deletion is immediate and complete — there is no copy to chase down later.

One exception, and we'd rather say it than bury it: any feedback you sent usis kept, with your account details stripped off it. Someone leaving shouldn't erase the reason they left, and once it isn't attached to you it isn't about you. Ask and we'll remove that too.

Who can use Buk right now

The beta is invite-only and, for the moment, offered to people in the United States. We aren't set up for the data-protection obligations that come with serving the EU or UK yet, so we're not inviting people there — not a judgement about those rules, just honesty about what a one-person beta is ready for.

Buk isn't intended for children, and we don't knowingly collect their data.

Changes

If this page changes in a way that matters, invitees get an email — not a quietly updated date. See also the beta terms.