Privacy Policy
#The short version
- We are The Cook's Cook LLC, a New Hampshire company. We publish recipes, essays and columns by hundreds of writers. Everything is free to read, and always will be — there is no paywall and there will not be one.
- If you make an account we keep your email address, your display name, and — if you use one — a scrambled password.
- We keep track of what you follow, save, collect and subscribe to. That list says a lot about you, so we never sell it and never use it to target advertising.
- If you post a community recipe, a comment or a photograph of something you cooked, that is published — other people can see it.
- We measure how the site is used, including before you have an account, using a random identifier stored on your device.
- Service email — verification, sign-in, security notices — cannot be turned off while you have an account. The digest and writer subscriptions can be stopped at any time.
- We use other companies to run the site: hosting, database, email, bot protection, analytics and content recommendations. They are named in section 5.
- We give brands who sponsor articles nothing about you. No email addresses, no audience lists, no reading history. If you follow a link to a sponsor's own site you are on their site, as you would be from anywhere else.
- If you had an account before we rebuilt the site, you still have one — and we will not delete it for going unused. See section 3.7.
- You can see and correct your data, close your account yourself, or ask us to erase you altogether. Two caveats: things you posted stay up with your name taken off, and closing a writer's account does not unpublish their articles.
- Questions: info@thecookscook.com, with "Privacy Request" in the subject line.
#Contents
- Who we are
- What this covers
- What we collect
- Why, and on what legal basis
- Who else handles it
- International transfers
- How long we keep it
- Your rights
- What closing and erasing actually do
- California
- Other US states
- Cookies, storage and similar technologies
- Children and minimum age
- Staff access to accounts
- Security and breach notification
- Changes
#1. Who we are
The Cook's Cook LLC, a limited liability company formed in New Hampshire, runs thecookscook.com. "We" and "us" mean The Cook's Cook LLC; "you" means whoever is reading — reader, member, writer, or someone who has not signed up for anything.
Under European and UK data protection law we are the controller of the personal information described here. That means we decide what is collected and why, so we are the ones you hold responsible for it.
Email: info@thecookscook.com — put "Privacy Request" in the subject line Post: The Cook's Cook LLC, 19 Gill Street, Exeter, New Hampshire 03833, United States
We have not appointed a data protection officer. We are a small publication and the processing we do is not the kind that requires one, and we have recorded our reasoning.
#2. What this covers
This policy covers thecookscook.com, the accounts you can create on it, and the emails we send. It does not cover other companies' sites. If you follow a link to a partner, a shop or a writer's own site, you are on their site under their policy.
What is switched on today. We are turning the member features on in stages. As of 26 August 2026 you can read everything on the site, and accounts work. Following writers, saving recipes, collections, comments, community recipes, photographs of what you have cooked, member profiles and writer newsletters are built but not yet switched on.
This policy describes all of them, so it is accurate from the moment each one arrives. Where a feature is not running, nothing is collected for it. This paragraph is updated as features go live.
#3. What we collect
#3.1 Your account
- Email address
- Display name
- If your account has a password: it is stored scrambled (hashed) — we cannot read it, and neither can our staff. Most accounts now sign in with a link sent to your email or with a passkey, and never have one.
- If you use two-factor sign-in: the secret your authenticator app needs, and your backup codes
- If you use a passkey: the public part of it. We never see the private part.
#3.2 Keeping the account safe
- Whether you have verified your email address
- When you have signed in
- Failed sign-in attempts, and whether an account has been locked
#3.3 What writers give us
If you write for us, your public profile holds your biography, portrait and the links you list. This is published — it is meant to be seen.
#3.4 What you follow, save and subscribe to
- Follows — which writers you follow
- Saves and collections — which recipes and articles you have kept, and how you have grouped them
- Subscriptions — which writers you receive by email
- Notification preferences, including the weekly digest
We list this separately rather than calling it "usage information" because of what it adds up to. A list of saved recipes can reveal what you cannot eat, what you will not eat, and why — an allergy, a health condition, a religion, how you were raised. We do not ask you for any of that and we do not want it, but it can be inferred, and you should know that.
We use it to run the features it belongs to: showing you your saves and collections, sending you the writers you subscribed to, recommending what to read next.
We never use it to decide which sponsored placements you see. We never sell it. We never turn it into audience segments for a brand. Sponsors pay to be associated with our writers, not to reach you.
We also do not try to work out anything about you from it. We do not derive or record whether you have an allergy, a health condition, a religion or any other sensitive characteristic, and nothing on the site treats you differently on that basis. Our recommendations work by comparing one article to another, not by profiling you.
#3.5 What you post
If you publish a community recipe, an article or a photograph, leave a comment, or upload a photograph of something you cooked, that content is published on the site with your display name. We review what members post, before it appears or afterwards.
Photographs carry hidden information, and we take off the part that matters. A phone records where a picture was taken. We take that location off before an image goes on the site, so your kitchen does not arrive with your address attached. Pictures posted before 26 August 2026 did not go through that step — if one of yours is on the site and you would rather it were cleaned, tell us and we will do it. We also keep a record of who uploaded an image, when, and what you told us about where it came from.
Section 9 explains what happens to all of this if you close your account or ask us to erase you.
#3.6 What we collect automatically, with or without an account
- A random device identifier. The first time a browser reaches the site — after you say yes, if you are somewhere we ask first (section 12) — we generate a random identifier and store it on the device. It is created before and independently of any account. If you later create an account, that identifier is recorded alongside it — so what you read after signing in is connected to you, and so is earlier reading from the same browser. It stops being anonymous at that point.
- What is read — which pages and pieces, used to recommend what to read next.
- Which version of a test you saw. We run more than one version of some pages to see which works better, and we record which one you were shown.
- Clicks on sponsored placements and on links out to partners.
- Analytics, passed to Google Analytics 4.
#3.7 If you joined before we rebuilt the site
The Cook's Cook has been running since 2015. When we rebuilt the site we brought the member accounts across from the old one, so that people who had an account then still have one now. Same publication, same address, rebuilt.
If that is you, your account holds your email address, your name and the date you originally joined. Nothing else came across — there were no saves, follows or collections on the old site to bring.
You have not been able to sign in since the rebuild, because the old passwords could not come with you. Use "forgot password" with the same email address and you are back in. You can close the account at any time — section 8 explains how.
Your account is yours and it stays. We will not delete it because you have not been back for a while, and there is nothing you need to do to keep it. If that ever had to change we would write to you first. If you would rather not have it, close it — that link is in the email and in section 8.
#3.8 What arrives on its own
- Your internet address. Every request a browser makes carries one. We use it for the security work in section 4 — rate limiting, blocking bots, noticing a sign-in that looks wrong — and for very little else.
- What your browser says about itself. The kind of browser and device you are using. Cloudflare looks at this to tell people apart from bots, and we record it when an administrator uses the site as someone else's account (section 14).
- What you write to us. If you email us, we keep the correspondence, so that we can answer you and show what we did.
None of this is a category we go out of our way to collect. All of it is personal information, so it belongs in this list.
#4. Why, and on what legal basis
If you are in Europe or the UK, we must have a specific legal reason — a "lawful basis" — for each thing we do with your information, and tell you what it is.
| What we do | Information used | Our legal basis |
|---|---|---|
| Create and run your account; sign you in | 3.1, 3.2 | Performing our agreement with you |
| Show your saves, collections and follows; send the writers you subscribed to | 3.4 | Performing our agreement with you |
| Publish what you post | 3.5 | Performing our agreement with you |
| Send service email — verification, sign-in links, security notices | Email address | Performing our agreement with you |
| Publish contributed work | Writer profile and submitted work | Performing our agreement with you |
| Keep accounts secure — lockouts, sign-in alerts, blocking bots, rate limiting — and moderate what people post | 3.2, 3.5, IP address | Our legitimate interest in keeping the site, your account and other readers safe |
| Send the weekly digest | Email address, preferences | Your consent, which you can withdraw at any time |
| Recommend what to read; measure how the site is used; run tests; count clicks on sponsored placements | 3.6 | In Europe, the UK and California: your consent, asked for before anything is set. Elsewhere: our legitimate interest in understanding and improving the site |
| Keep your account running if you joined before the rebuild | Email address, name, join date (3.7) | Our legitimate interest in keeping the account you already hold working across the rebuild, rather than closing it for you |
| Answer your requests about your data, and keep a record of what you agreed to | Whatever the request concerns | A legal obligation |
If you have an account but have not accepted our terms — because your account came across from the old site, or because we showed you the terms and you have not said yes — we keep it running on our legitimate interest in maintaining the account you hold, rather than on an agreement with you. Everything else in this table applies to you in the same way, and you can object, or close the account, at any time.
Where we rely on a legitimate interest, we have weighed it against your interests and recorded that assessment. You can object at any time — section 8.
We do not use your information to make automated decisions that have a legal or similarly significant effect on you.
#5. Who else handles it
| Company | What they do | Where |
|---|---|---|
| Amazon Web Services | Hosting and image storage | United States (Ohio) |
| MongoDB Atlas | The database holding accounts and the information in 3.4 and 3.5 | United States (Virginia) |
| Resend | All of our email — service email, the digest, writer subscriptions | United States |
| Cloudflare | Bot protection on the signup form only, which inspects signals from your browser; and DNS | Cloudflare's global network |
| Google Analytics 4 | Measurement | United States and elsewhere |
| OpenAI | Generates the embeddings behind our content recommendations | United States |
What we send to OpenAI, and what we do not. We send the text of articles and recipes we have already published, and for writers a short summary built from their published biography and the titles of their recent work — the same text anyone reading the site can see. That is all. We do not send your reading history, your saved recipes or your email address, and none of it is used to train anyone's AI model.
These companies act on our instructions and may not use your information for their own purposes, with two exceptions. Cloudflare also uses what it sees to protect its own network, under its own responsibility rather than ours. And Google's position depends on settings we control: we keep them set so that Google works for us and not for itself, and if that ever changes this policy changes first.
We keep a register of who they are, where they process data and on what terms, and we review it when anything changes.
We may also disclose information where the law requires it, or to protect our rights or someone's safety.
We do not sell your personal information. See section 10 for what California law means by "sell" and "share".
#6. International transfers
We are in the United States and so are the companies in section 5. If you are in Europe or the UK, your information is sent here, where the law protects it differently. It is sent under safeguards European and UK law recognises.
Amazon Web Services, MongoDB Atlas, Resend, Cloudflare and Google are all certified under the EU–US Data Privacy Framework and its UK extension, and several of them also hold standard contractual clauses as a fallback. OpenAI does not use the framework; its transfers run on standard contractual clauses, with the UK addendum for information coming from the UK.
Email us and we will tell you which applies to which company, and send you a copy of the terms.
#7. How long we keep it
| What | How long |
|---|---|
| Account data, while your account is open | Kept |
| Your account after you close it | Closing it hides it straight away and stops it being used — no email, nothing visible on the site. We keep the record so you can have it back if you change your mind, and we do not delete it automatically. If you want it erased rather than closed, ask us and we will do that instead |
| An account started on the site but never finished | Kept until you ask us to remove it. We do not sweep these up automatically |
| An account you have not used for a while | Kept. We do not delete accounts for being inactive. If that ever changed we would write to you first and give you a way to keep it |
| Follows, saves, collections, subscriptions | For as long as you have an account |
| Sign-in history | 12 months |
| Failed sign-in attempts and lockouts | 30 days |
| What you read, tied to the device identifier | 14 months |
| Sign-in codes and verification links | Deleted when used; purged 24 hours after they expire |
| Signups that were started and abandoned | 7 days |
| Rate-limiting records, which hold IP addresses | Minutes to hours — they expire as soon as the limit they enforce has passed |
| Sessions | Until they expire, plus 30 days |
| What you agreed to, and when — the record of the terms and consents you accepted | For as long as you have an account. It is the evidence that you agreed, so losing it would help nobody |
| What you told us about where a photograph came from | For as long as the image is on the site |
| Unsubscribe list | Kept — forgetting it would mean emailing you again |
| Accounts brought across from the old site | The same as any other account — kept until you close it |
| Published articles, recipes, community recipes and comments | Kept |
Some of these periods are enforced automatically; others are the periods we work to while we build that enforcement. Either way, you can ask us to erase your personal information at any time and we will, whatever the table says. Section 8 explains how, and that request does not wait for any of these periods.
#8. Your rights
Depending on where you live, you can ask us to:
- Show you what we hold about you
- Correct anything wrong
- Close your account — you can do this yourself, without asking us. It hides the account and stops it being used, and we can bring it back if you change your mind
- Have your information erased — a stronger thing than closing. Email us and we will remove or anonymise your personal information. Section 9 explains what stays and why
- Send you a copy you can take elsewhere
- Stop a particular use, where we rely on legitimate interests
- Pause a particular use while we sort out a disagreement about it — your information stays, but it stops being used
- Withdraw consent where we relied on it, at any time. Withdrawing it does not undo what we did beforehand.
Email info@thecookscook.com with "Privacy Request" in the subject line. We may ask you to confirm who you are first, so nobody else can make a request in your name. We respond within 30 days. If a request turns out to be complicated — an old account, a lot of material, or a question about whether something is really yours — it can take longer, and we will tell you that rather than let the date pass in silence.
Email you can turn off, and email you cannot. Service email — verification, sign-in links, security notices — comes with having an account and cannot be switched off while the account is open.
The weekly digest is different. We only send it if you asked for it — we never add you to it — and you can stop it whenever you like. Writer subscriptions work the same way: you chose each one. Every digest and subscription email carries a way to stop it, and when you use it we add you to a suppression list so it sticks.
If you are in Europe or the UK you can also complain to your national data protection authority. In the UK that is the Information Commissioner's Office.
#9. What closing and erasing actually do
Two different things, and it is worth being clear about which is which.
Closing your account hides it. You stop being able to sign in, we stop emailing you, and the things you posted as a member stop being visible. Change your mind and we can put it back.
If you have written for us, your published articles and recipes stay up. Closing your account does not unpublish them and does not remove your byline. Further down this section explains why.
Asking us to erase you goes further: we remove or anonymise your personal information, so what is left is no longer connected to you. Email info@thecookscook.com with "Privacy Request" in the subject line.
#What happens to things you posted
Community recipes, comments and photographs of what you cooked stay on the site, with your name taken off them. They show as posted by "a member".
We do this because other people have built on them — replied to a comment, cooked from a recipe, added their own photograph underneath. Pulling them out would break other people's contributions and leave conversations that no longer make sense. Taking your name off achieves what you asked for, which is not being identifiable, without deleting what other people did.
If a particular post is one you want gone rather than anonymised, ask us and we will remove it.
#What stays, and why
Work published under your byline stays published. If you have written for us, deleting or erasing your account does not unpublish your articles and recipes. An archive that quietly loses articles is a broken archive, and a byline that vanishes misattributes the work that remains. Your profile page stays too, so the byline still leads somewhere, but it stops being editable — and we will take down your photograph and biography on request, leaving a plain index of your work.
Work we commissioned and paid for stays published, and is not removed on closure or erasure. That is part of the arrangement when a piece is commissioned, and the Terms of Use set it out.
So "close my account", "erase my personal information" and "unpublish my writing" are three different requests. The first two we do. The third is a conversation — section 5.11 of the Terms of Use explains how to start it, and taking your byline off is easier for us to say yes to than taking the work down.
#10. California
If you live in California you have the right to know what we collect, to have it deleted, to have it corrected, and to opt out of the sale or sharing of your personal information. We will not treat you differently for asking.
Email info@thecookscook.com with "Privacy Request" in the subject line.
Notice at collection. The categories we collect are in section 3, the purposes in section 4, the recipients in section 5, and how long we keep things in section 7. We do not sell personal information.
Where it comes from. All of it comes from you, or from your browser as you use the site. We do not buy personal information, and nobody sends us lists.
Someone can ask for you. If you would rather an authorised agent made a request on your behalf, they can. We will check with you first that you asked them to.
We ask before we measure. If you are in California we ask your permission before we set the device identifier or load Google Analytics, the same way we do in Europe and the UK. Section 12 lists exactly what is covered.
Browser privacy signals. If your browser sends a Global Privacy Control signal we treat it as an opt-out of any sale or sharing, and we do that wherever you are, not only in California.
#11. Other US states
Wherever you are in the United States, you get the same rights from us: to know what we hold, to have it corrected, to have it deleted, to receive a copy, and to opt out of any sale or sharing of it.
We do not keep track of which state you live in. Working out where you are, so that we could give some people less than others, would mean collecting something we do not hold — and we would rather not.
Use the same email address as in section 8. We will not treat you differently for asking.
#12. Cookies, storage and similar technologies
Some of these are cookies. Some are stored by your browser in other ways but do the same job, so we list them together.
| Name | What it does | Party | Lifetime | In Europe, the UK and California |
|---|---|---|---|---|
__Secure-access-token |
Keeps you signed in | First | 10 minutes | Always — you cannot sign in without it |
__Secure-refresh-token |
Signs you in again without asking | First | 14 days, or 90 with "remember me" | Always |
__cf_bm |
Cloudflare — tells people apart from bots. Only on the signup form, and set there by Cloudflare's own widget rather than by us | Third (Cloudflare) | 30 minutes | Always, on that one page — you cannot create an account without it |
tcc_consent |
Remembers what you answered when we asked about the row below | First | Until you change it | Always — it is how we honour your answer |
| Sign-in security storage | Two-factor and passkey state, so you are not challenged twice for the same thing | First | Life of the session or the setting | Always — you cannot sign in securely without it |
tcc_last_email (localStorage) |
Your email address, remembered on this device so the sign-in box is already filled in next time. Stored on your device, not sent to us for this purpose. Clearing your browser data removes it | First | Until you clear it | Always — but see the note below |
tcc_aid (cookie and localStorage) |
The device identifier in 3.6 | First | 400 days | Only if you agree |
tcc_sid, tcc_sid_activity |
Groups a visit into one session; resets after 30 minutes idle | First | Until you close the tab | Only if you agree |
tcc_organic |
Records whether you arrived from a search engine | First | Until you close the tab | Only if you agree |
| Test assignment | Which version of a test you saw. Calculated from tcc_aid, not stored separately |
First | As tcc_aid |
Only if you agree |
_ga |
Google Analytics — tells one visitor from another | Third (Google) | 2 years as we set it; most browsers shorten it | Only if you agree |
_ga_GC85G0KYP1 |
Google Analytics — keeps the state of a visit | Third (Google) | 2 years as we set it; most browsers shorten it | Only if you agree |
If you are in Europe, the UK or California, we ask before we set anything marked "only if you agree" in that last column. Until you say yes, none of it is set — no device identifier, and Google Analytics is not loaded. Refusing is exactly as easy as agreeing, and you can change your mind at any time. The site works the same either way: you can still read, save, follow, subscribe and comment.
One exception, which we cannot put behind that question. The typefaces are served by Google Fonts, so your browser fetches them as the page loads and Google sees your internet address. It sets no cookie and connects to nothing else we hold. We are moving to serving the fonts ourselves.
About tcc_last_email. It is the one row above that holds something identifying, and
it exists to save you typing your address every time. It stays on your device. Clearing
your browser's site data for thecookscook.com removes it — worth doing on a shared
computer.
Everywhere else, the rows marked "always" are needed to run the site and the rest we set to understand how the site is used. You can opt out at any time, and if your browser sends a Global Privacy Control signal we take that as an opt-out without you having to ask.
#13. Children and minimum age
You need to be 16 or over to create an account. That is a rule in our Terms of Use. We do not keep your date of birth. If we ever need to check your age, we will keep the answer — old enough, or not — and not the date.
Writers must be 18 or over. We check that ourselves, because we invite writers rather than letting anyone sign up as one.
Children are welcome to read. You do not need an account to read anything on this site, and you never will. Every recipe, every article and every column is free to read and print without signing up for anything, and we intend to publish for younger cooks as well as older ones. What the account adds is following, saving, commenting and sharing photographs, and those are the things we keep to 16 and over.
If you believe a child has given us personal information, email info@thecookscook.com and we will delete it.
#14. Staff access to accounts
Our administrators can use the site as a writer's account. This is how an editor fixes a typo or checks an image without sending a piece back, and how we investigate a problem someone has reported.
We are telling you because you should know it is possible, not because it is routine. When it happens:
- Only administrators can do it.
- They record why.
- It lasts a maximum of 30 minutes and then ends.
- Anyone using the site as someone else's account sees a banner saying so throughout.
- We record who did it, whose account they entered, when and from where.
- Anything they change is recorded against them, not against you.
If an editor needs longer than half an hour they start a new session, and that is recorded separately with its own reason. There is no way to hold the door open.
#15. Security and breach notification
We protect your information with technical and organisational measures. Where an account has a password, it is stored hashed. Passkeys and two-factor sign-in are available and we recommend them. Accounts lock after repeated failed sign-in attempts. No website can promise perfect security, and we do not claim to.
If there is a breach that puts you at risk, we will tell you and the relevant regulator as the law requires, and we have a written plan for how we do that.
#16. Changes
If we change this policy we will update the version number and effective date at the top, and keep the previous versions published so you can see what changed. If a change materially affects you we will tell you — by email or a notice on the site — before it takes effect.