Privacy Policy
Last updated August 1, 2026.
This policy covers selfmadecook.com (the "Site"), run by Curtis Shaw under the name SelfMadeCook ("we," "us"). It says what we collect, who else sees it, how long we keep it, and how to make us delete it. We've tried to write it the way we write recipes — plainly, and without claiming anything that isn't true.
You can read every recipe on this Site without telling us anything about yourself. But this is not a no-data site, and you should know all the places where it does collect personal information:
- Email sign-up forms — on the homepage, the Kitchen Notes index, and the cookbook page. They ask for your email address so we can send you a recipe each week.
- The contact form — it asks for your name, your email address, and your message.
- Member accounts — you can create an account to save recipes and unlock cookbook content online. That stores your email address, a sign-in session in your browser, the recipes you save, and, if you claim a cookbook licence key, the fact that you own the book.
- Technical data that arrives automatically whenever any page loads — your IP address, browser and device type, the page that referred you, and the pages you look at.
We do not take payment on this Site. If you buy a book, Gumroad handles the transaction and we never see your card details — see "If you buy a book" below.
Who is responsible for your data
Curtis Shaw, trading as SelfMadeCook, is the data controller — the person accountable for everything described here. SelfMadeCook is one person and a kitchen, not a company with departments, so there is no separate data protection officer.
The way to reach us about anything on this page — questions, corrections, deletion, complaints — is the contact page, or email hello@selfmadecook.com directly. Both reach the same inbox, which Curtis reads himself. We deliberately don't publish a postal address; if you need one for a formal legal request, ask through the contact page and we'll give it to you.
What we collect, and why we're allowed to
- Your email address, for the weekly recipe. Because you asked for it — you typed it into a form. In the UK and EU that legal basis is your consent, and you can withdraw it at any time using the unsubscribe link at the bottom of every email we send.
- Your name, email, and message, from the contact form. So we can answer you. We don't add contact-form senders to the newsletter.
- Your account details and saved recipes. To provide the account you asked for and keep your recipe box working across devices.
- Technical and traffic data. To keep the Site up, defend it against abuse, and understand which recipes people actually cook. Where that involves storing or reading anything on your device beyond what's strictly needed, it happens only after you agree in the consent prompt.
We do not sell your personal information, we do not buy email lists, and we do not use your data to build a profile of you for anyone else.
Who else receives your data
We use outside services to run this Site, and a normal page view involves several of them. Here is the full list, what each one gets, and why.
On every page you load:
- Netlify — our web host. Every page and image is served by Netlify, so it receives your IP address, browser type, and the URL you asked for, and keeps standard server logs. Netlify Forms also receives anything you submit through a form on this Site.
- Google Fonts — the two typefaces on this Site are loaded from Google's font servers, which means Google receives your IP address and browser details on every page, before you've clicked anything.
- Google Analytics — measurement, so we know which recipes are worth making more of. Aggregate reporting only; we never use it to identify you personally. No analytics storage is used on your device until you allow it in the consent prompt, and if you decline, measurement falls back to cookieless, aggregate signals.
- Google AdSense — the advertising that pays for the free recipes. It runs on the recipe and article pages, not on this policy, the Terms, About, Contact, Accessibility or the cookbook page. Google and its ad partners receive technical data and, if you allow advertising cookies, use them to choose which ads you see.
- Supabase — the database and sign-in system behind member accounts. Its client script runs on every page to check whether you're signed in, so Supabase receives a request (and therefore your IP address) even if you never make an account. If you do have one, it holds your email address, your saved recipes, and your cookbook entitlement.
- jsDelivr — the open-source CDN that serves the Supabase sign-in library. It receives your IP address and browser details when that script loads.
Only when you do something specific:
- YouTube — recipe pages show a still image with a play button, not a live player. Nothing is requested from YouTube until you click play; at that point a privacy-enhanced player (youtube-nocookie.com) loads and Google receives your IP address and viewing data under its own policy.
- MailerLite — sends the weekly recipe email. When you sign up, your email address travels from the Netlify form into our own Supabase database and then to MailerLite, which stores it, records whether you opened or clicked, and handles your unsubscribe.
- Gumroad — sells our recipe books. If you click through to buy, Gumroad collects your email and payment details as the seller of record, under its own privacy policy; we only ever see that a sale happened and the buyer's email address. If you paste a licence key into your account page, that key is sent to Gumroad to verify it.
Every one of these is a service provider acting on our instructions or an independent controller for its own part of the job. Their own policies are worth a read: Netlify, Google (Fonts, Analytics, AdSense, YouTube), Supabase, jsDelivr, MailerLite, and Gumroad.
Cookies, ads, and your choices
Every visitor is shown a consent prompt on their first visit, with three choices: accept all cookies, allow analytics only, or essential only. Analytics and advertising storage stay denied until you choose. Your choice is saved in your own browser (not on our servers) and you can change it at any time using the "Privacy choices" button in the footer of every page.
- You can opt out of personalized advertising in Google Ads Settings, and opt out of many third-party vendors at aboutads.info/choices or, in the EU, youronlinechoices.eu.
- You can opt out of Google Analytics site-wide with the Google Analytics Opt-out Browser Add-on.
- More on how Google uses data from sites that use its services: policies.google.com/technologies/partner-sites.
Note that the consent prompt controls cookies and similar device storage. It cannot undo the fact that our host, the font servers, and the CDN see your IP address in order to send you the page at all — that's how the web works, and it's why they're named above.
How long we keep it
- Newsletter subscribers — until you unsubscribe, which stops the email immediately. Unsubscribing leaves a suppression record so we don't mail you again by mistake; if you'd rather be erased entirely, ask through the contact page and we'll delete it.
- Contact-form messages — while the conversation is useful, and no more than 24 months after your last message, unless you ask us to delete it sooner.
- Member accounts and saved recipes — for as long as the account exists. Ask us to close it and the account and its saved recipes go with it.
- Purchase records — Gumroad keeps the transaction records it needs for tax and accounting; we keep only the buyer email that unlocks your access.
- Server logs and analytics — these live inside Netlify and Google on their retention schedules, which we don't set. We don't keep our own copy.
Where your data goes
Our service providers are based mainly in the United States, with MailerLite in the European Union. So if you're reading this in the UK, the EU, India, or anywhere outside the US, your data will be handled outside your country. Those transfers rest on the providers' own safeguards — the EU–US Data Privacy Framework and/or standard contractual clauses in their terms, linked above. We don't move your data anywhere else on our own initiative.
Your rights, and how to actually use them
Wherever you live, you can ask us to show you what we hold about you, correct it, delete it, or stop using it. You don't need a lawyer or a special form of words.
To ask for deletion: go to the contact page (or email hello@selfmadecook.com), write "delete my data", and give us the email address you used on the Site — that's the key everything is filed under. We'll confirm we received it, delete the newsletter record, the account and saved recipes, and the contact history tied to that address, and write back when it's done. We aim to finish within 30 days. It's free; we won't charge you or make you explain why. If we ever have to keep something — a purchase record Gumroad needs for tax, for instance — we'll tell you exactly what and why.
If you only want the emails to stop, the unsubscribe link at the bottom of any newsletter is instant and doesn't need us at all.
If you're in the UK or the EEA (UK GDPR / GDPR), you also have the right to object to processing, to restrict it, to receive your data in a portable form, and to withdraw consent at any time without affecting what came before. You have the right to complain to your data protection authority — in the UK the ICO, elsewhere your national supervisory authority — though we'd appreciate the chance to fix it first.
If you're in India (Digital Personal Data Protection Act, 2023), you have the right to access a summary of your data and how it's processed, to correct or complete it, to have it erased, to nominate someone to exercise your rights if you can't, and to a grievance redressal route. Our grievance route is the same one as everything else: the contact page, answered by Curtis Shaw. If we haven't sorted it out to your satisfaction, you can escalate to the Data Protection Board of India.
If you're in California (CCPA/CPRA), you have the right to know, delete, correct, and to opt out of the "sale" or "sharing" of personal information. We don't sell personal information for money — but showing personalized ads counts as "sharing" under California law, and choosing "Analytics only" or "Essential only" in the consent prompt (or the footer's "Privacy choices" button) turns it off. We won't treat you differently for exercising any of this.
If you buy a book
Our recipe books are sold through Gumroad, which is the seller and merchant of record. Gumroad collects your email and payment details and processes the payment; we never receive or store your card number. What reaches us is the buyer's email address, so we can unlock your access and honour updates. See the Terms of Use for what you're buying and how refunds work.
Security
The Site is served over HTTPS, sign-in is handled by Supabase rather than by passwords we store ourselves, and the keys that could read the database are kept out of the website's code entirely. No site can promise perfect security, and we won't. If we ever discover a breach that puts you at real risk, we'll tell you and the relevant regulator as quickly as we can.
Children
This is a home-cooking site, not a service for children. We don't direct it at children, don't knowingly collect personal information from anyone under 13 (or under 18 in India, where the law sets the higher bar and requires a parent's consent), and don't want accounts or newsletter sign-ups from them. If you believe a child has given us their details, tell us through the contact page and we'll delete it.
Changes to this policy
We may update this policy; the "last updated" date at the top reflects the current version. If we ever start doing something materially different with your data, we'll say so here rather than quietly changing a sentence.
Contact
Questions, requests, or complaints about any of this? Use the contact page or email hello@selfmadecook.com. A real person reads it.