Privacy Policy
Last updated: 19 August 2026 · Version 2026-08
This notice explains how myChef (“we”, “us”) collects, uses, shares and stores personal data when you use our website, mobile apps, web booking, WhatsApp, email, and the myChef app inside ChatGPT. The controller is the Brazilian company whose legal name is Mychef App Plataforma Digital LTDA.
It is written for Lei nº 13.709/2018 (LGPD) and also covers what OpenAI requires of ChatGPT apps: what we collect, why, who receives it, how long we keep it, and how you control it.
1. Who is the controller
Controller: myChef, operated by Mychef App Plataforma Digital LTDA (razão social as registered with Receita Federal)
CNPJ: 59.718.921/0001-37
Address: Rua Francisco Rocha, 198, Batel, Curitiba/PR, CEP 80420-130, Brazil
Privacy and LGPD requests: contato@mychef.com.br
myChef is a marketplace that intermediates bookings between customers and independent personal chefs. We decide why and how personal data is processed on the platform. Chefs who receive your booking details process that data to deliver the service you requested.
To exercise any right in this notice, email contato@mychef.com.br with the subject “LGPD”. We reply within 15 business days.
You may also petition the Autoridade Nacional de Proteção de Dados (ANPD): gov.br/anpd.
2. What this policy covers
| Surface | Where it lives |
|---|---|
| Marketing website | mychef.com.br |
| Web booking and payment | app.mychef.com.br/book |
| iOS and Android app | App Store and Google Play, “myChef” |
| ChatGPT app (MCP tools / OpenAI plugin) | tools in section 8 — POST /mcp |
| myChef Business number | |
| transactional and follow-up messages | |
| Chef forum | separate host for verified chefs |
This policy does not cover chefs’ own websites, WhatsApp chats they start outside myChef, or payment networks after they receive your card or Pix data.
3. Data we collect
We only collect what the product needs. Fields marked sensitive are treated under LGPD Art. 11.
3.1 Account (mobile app)
Created when you sign in with Google, Apple, or (in internal builds) email, via Firebase Authentication.
- Full name
- Firebase user id
- City you serve or live in
- Language and timezone
- Profile photo (optional)
- Cuisine preferences (customers)
- Notification topics you turn off
- Stripe and Pix customer ids we create for you
- Device platform and Firebase Cloud Messaging token (push)
We do not store your Google or Apple password.
3.2 Customer booking (website, app, ChatGPT, WhatsApp)
- Name, email, WhatsApp-capable phone
- Service date and time
- Guest / lunch-box / student quantity
- Chef, package, add-ons, cleanup, groceries, voucher code
- Service address: street, number, neighbourhood, complement, city, state, CEP
- Optional geocode (lat/lng) derived from that address
- Menu notes, event notes, guest notes
- Attribution: UTM tags,
gclid,fbclid, landing page, referrer, GA client/session ids, IP, user agent - Consent time, source and policy version (ChatGPT bookings)
3.3 Dietary information (sensitive)
Only if you type it:
- Dietary restrictions (vegan, vegetarian, pescatarian, dairy-free, nut-free, halal, kosher, paleo, keto)
- Food intolerances (lactose, fructose, histamine, FODMAP, salicylate, caffeine, MSG, sulfite, gluten-sensitive, casein)
- Free-text notes (allergies, preferences, occasion)
This is health-related data. We use it only so the chef can cook safely for your booking. We do not use it for ads.
3.4 Payment
- Card payments go through Stripe. We store the PaymentIntent id and client secret. Card number, CVC and expiry stay with Stripe.
- Pix goes through Asaas. To issue a charge we send your name, email and CPF. We store the Asaas customer and charge ids, QR / copy-paste payload, and payment status.
- The ChatGPT app never asks for card numbers, CPF or Pix keys. Payment always happens on myChef’s own pages.
- Apple Pay / Google Pay, when offered in the app, are processed by those platforms and Stripe.
3.5 In-booking chat (app and web manage page)
- Text (up to 2,000 characters on the web)
- Images, audio, video and files you attach
- Sender id, time, booking id
Web chat is stored in Google Cloud Firestore. App media is stored on Amazon S3. We block phone numbers and emails in web chat so contact stays on the platform.
Microphone, camera and photo library are used only when you choose to record or pick a file.
3.6 Reviews
Rating and optional written review of a chef. Approved reviews appear on the chef’s public profile (first name / display context). We may send review text to OpenAI for automated moderation and delete reviews that break our rules.
3.7 Chef-only data (app)
If you become a chef we also collect:
- Display name, bio, photo, gallery, menus, plates, prices, add-ons, weekly availability, cancellation policy
- Service city and commute fee
- Identity verification: CPF or CNPJ, phone, residential address, Pix key, photo of ID front and back, selfie
- Payout details (Pix / CPF)
ID photos and the selfie are used only to verify that you are a real person who can receive payouts. They are not published.
Chefs can send menu or bio text through our writing helpers. That text is sent to OpenAI to enhance, shorten, expand or translate. We do not send your ID photos to OpenAI.
3.8 Location (app)
With permission, GPS is used to suggest your city during sign-up. If you refuse, we can approximate city from IP. Location is not used to track you in the background. Booking addresses are stored because the chef has to go there.
3.9 Website and cookies
- Pages viewed, clicks on book / chef / experience buttons (Google Tag Manager
GTM-MTTL7HDCand Google Analytics) - First-touch cookie
mychef_attr(30 days, domain.mychef.com.br): UTM parameters,gclid,fbclid, landing URL, referrer. This is copied onto the booking lead so we know which campaign found you. - Essential cookies for the booking session (CSRF, locale, visitor token)
3.10 App analytics and diagnostics
In release builds the app sends:
- Screen views and named product events, including a hashed Firebase installation id — Amplitude
- App-open / conversion events — Meta (Facebook) SDK; Android may read the advertising id
- Crashes, performance traces and breadcrumbs — Sentry (US ingest) and Firebase Performance
- Remote config flags — Firebase Remote Config
3.11 WhatsApp and email
If you write our WhatsApp number we store the conversation, your phone, name, city, occasion, guest count and any dietary notes you send, as a lead (source = whatsapp).
We send transactional email (booking created, pay reminder, paid, chef confirmed, reminder, finished, cancelled, refused) through Amazon SES. Some marketing / ops emails include a 1×1 open pixel.
You can stop booking follow-up emails from the unsubscribe link on those messages.
3.12 ChatGPT app
See section 8. We receive whatever the model sends as tool arguments after you agree in that chat. We also store utm_source=chatgpt, utm_medium=mcp, a visitor token derived from the ChatGPT session, and user_agent = mcp/1.0.
3.13 Automatically collected
IP address, user agent, timestamps, language, and server logs needed to run and secure the service.
We do not sell personal data.
4. Why we use the data
| Purpose | Typical data | Legal basis (LGPD Art. 7 / 11) |
|---|---|---|
| Create and run your account | name, email, auth ids, city | Contract (Art. 7, V) |
| Match you with a chef and hold a slot | booking details, address, phone | Contract (Art. 7, V) |
| Tell the chef how to cook for you | dietary fields | Consent (Art. 11, I) |
| Charge you and pay the chef | Stripe / Asaas / CPF | Contract (Art. 7, V) and legal duty (Art. 7, II) |
| Email, WhatsApp and push about that booking | contact details | Contract (Art. 7, V) |
| Resume an unfinished web or ChatGPT booking | lead + consent record | Consent (Art. 7, I) |
| Verify chefs and pay them | CPF/CNPJ, ID images, Pix | Contract and fraud prevention (Art. 7, V and IX) |
| Moderate reviews and chat | review/chat text | Legitimate interest (Art. 7, IX) |
| Measure marketing and product | cookies, events, UTM | Legitimate interest (Art. 7, IX) |
| Security, abuse, logs | IP, device, account | Legitimate interest (Art. 7, IX) |
| Tax, consumer and bookkeeping duties | booking and payment records | Legal obligation (Art. 7, II) |
| Improve chef copy | text you submit to AI helpers | Contract / legitimate interest |
| ChatGPT discovery and booking | tool inputs in section 8 | Consent + contract |
If you refuse contact or address data we cannot complete a booking. If you refuse dietary data we still book, but the chef will not know your restrictions.
5. Who receives the data
5.1 People on the platform
- The chef you booked receives your name, phone, email, address, date, package, add-ons, dietary information and chat. They need this to cook at your home.
- You see the chef’s public profile, packages, ratings and approved reviews.
- myChef operators see leads and bookings to support you, stop fraud and pay chefs.
5.2 Processors (they act on our instructions)
| Recipient | What they receive | Where |
|---|---|---|
| Amazon Web Services (hosting, S3, SES, backups) | application data, files, email | United States (us-east-1) |
| Google (Firebase Auth, Firestore, Cloud Messaging, Performance, Remote Config, Sign-In, Analytics, Tag Manager, Maps/Places if used for address) | account, chat, push token, analytics | United States |
| Apple (Sign in with Apple, App Store, Apple Pay) | auth / payment tokens | United States |
| Stripe | name, email, amount, booking metadata — not full card data on our side | United States |
| Asaas | name, email, CPF, Pix charge | Brazil |
Meta (WhatsApp Cloud API, app SDK, fbclid) | phone and template contents; app events | United States / Brazil |
| Amplitude | product events, user/device ids | United States |
| Sentry | crash reports, device and app context | United States |
| OpenAI | (a) chef helper text; (b) review text for moderation; (c) ChatGPT tool calls when you use ChatGPT — see section 8 | United States |
| Contentful | public marketing content, not your booking | United States / EU |
5.3 Legal and corporate
We disclose data if required by law, to defend a claim, or to a buyer if the company is sold (they must honour this notice).
Chefs are independent contractors, not myChef employees. After we share booking data with a chef so they can perform the service, they are responsible for how they handle it offline.
6. How long we keep it
| Record | Retention |
|---|---|
| ChatGPT / web lead that never becomes a booking | Convertible for 7 days. The row may stay longer for fraud, metrics and your deletion request. Abandoned-booking emails stop when you unsubscribe or after the drip ends. |
| Reserved unpaid booking | Slot held 72 hours. If you do not pay, the booking is cancelled for timeout; the record remains. |
| Paid / completed / cancelled bookings | Kept for the service, disputes and Brazilian tax / consumer-defence duties (in practice up to 5 years after the last relevant event). |
| Chat messages | For the life of the related booking, then as long as the booking record is kept. |
| Chef verification files (ID, selfie, CPF) | While the chef account is active, then as long as payout or fraud rules require. |
| Reviews | Until you ask us to remove them, or we remove them for moderation. |
Analytics cookies / mychef_attr | Up to 30 days in the browser. Server-side UTM on a lead follows the lead. |
| App session / backend session | Up to 7 days. |
| Database backups | About 14 days. |
| Server logs | The short period needed to operate and secure the service. |
When you delete your app account we set your name to [DELETED], clear email, Firebase uid and Stripe customer id, and hide the chef profile. Booking rows are not erased, because we still need them for tax, chargebacks and the other party to the booking. Chat and reviews tied to those bookings may remain in anonymised form.
7. Your rights and controls
Under LGPD Art. 18 you can ask us to:
- Confirm that we process your data
- Access it
- Correct it
- Anonymise, block or delete data that is excessive or processed off this notice
- Port it
- Delete data processed on consent
- Tell you who we shared it with
- Tell you that you may refuse consent and what happens if you do
- Revoke consent
How to do that in the product
- App account: Profile → Account management → Delete account. Steps are also at mychef.com.br/en/deleting-accounts.
- App profile: edit name, photo, city, dietary preferences, notification topics.
- Web booking emails: unsubscribe link on the message, or the booking manage page.
- Cookies: browser settings. Blocking analytics cookies does not stop a booking. Blocking all cookies will break the booking form.
- Location, camera, microphone, photos, advertising id: device settings. The app still works; city suggestion, camera photo, voice notes or some ads measurement may stop.
- ChatGPT: do not agree when the assistant asks to share your name, email and phone. We will not call
start_bookingwithout that yes. You can also use the chef’s public profile link and book on the website instead. - Push: OS notification settings, or disable topics in the app.
Email contato@mychef.com.br if the in-product control is not enough. We may ask you to confirm the email or phone on the account.
8. ChatGPT app, MCP tools and the OpenAI plugin
This section is the full disclosure for the myChef app inside ChatGPT (an OpenAI plugin / ChatGPT app). It is what OpenAI’s review looks at: collected data, purposes, recipients, retention, and the current tool inputs and outputs.
8.1 How the connection works
You talk to ChatGPT. OpenAI decides when to call myChef. Each call is an anonymous JSON-RPC request to POST /mcp on our servers (Model Context Protocol). There is no myChef login in ChatGPT. The endpoint is public, rate-limited, and sits outside our crawler block so ChatGPT can reach it.
Typical order:
search_chefs → get_chef → get_chef_availability → quote_booking → start_booking (consent) → reserve_booking → you open payment_url in a browser.
list_service_cities is only for “where do you operate?” or an ambiguous city name.
We do not receive your ChatGPT thread. We receive the tool name and the arguments the model sends. If the model copies something you said into an argument (a city, a name, an address), that is when it lands with us.
OpenAI processes the chat itself under OpenAI’s privacy policy. That processing is OpenAI’s, not ours.
8.2 What we collect on every MCP call
- Tool name and the arguments listed in 8.5
- An MCP session id (
Mcp-Session-Id). It is not a password. It groups one conversation so we can reuse an unfinished ChatGPT lead instead of creating a duplicate, and so we can rate-limit that conversation. We derive a visitor token from it onstart_booking. - The request IP, used only to rate-limit abuse (ChatGPT shares OpenAI egress addresses, so IP alone is a weak identifier).
- Server logs: tool name, session id, error class/message. We do not log your full prompt.
langwhen the model sends it (pt,enores) — that language is also used for our emails and WhatsApp after a lead exists.
We do not collect ChatGPT account email, your ChatGPT password, or payment credentials in MCP. Asking for card, CPF or Pix in the conversation is forbidden in the tool instructions.
8.3 When data starts being stored
| Stage | Stored? | What happens |
|---|---|---|
Browse / quote (list_service_cities, search_chefs, get_chef, get_chef_availability, quote_booking) | No customer record | Public marketplace data and a price. Nothing is held. |
start_booking after you say yes | Yes — a lead | Name, email, phone, chef, package, quantity, consent time/source/policy version 2026-08, source = chatgpt, utm_source=chatgpt, utm_medium=mcp, visitor token, user_agent = mcp/1.0. We email and WhatsApp a 7-day resume link. A four-message drip can follow if you abandon the flow. |
reserve_booking after you confirm date, address and total | Yes — a real booking | Same booking as the website: address, slot, add-ons, optional dietary fields, totals. Status awaiting_payment (72 hours) or awaiting_chef if a voucher covers the total. Chef and customer are notified. |
start_booking requires contact_consent=true. Before that call the assistant must tell you, in that conversation, that your name, email and phone go to myChef, that we will contact you by email and WhatsApp about this booking, and must give you https://mychef.com.br/pt/privacy-policy/. Silence or earlier enthusiasm is not consent. If you decline, it must not call the tool; it should give you the chef’s public profile URL instead.
A ChatGPT lead is only reserved against a ChatGPT-created draft. The plugin cannot attach a web or WhatsApp lead.
8.4 Recipients, purpose, retention, controls
Purpose: find a chef, quote a price, take consent, create a lead, hold a slot, send you to pay on myChef, notify the chef.
Recipients of write-tool data: myChef operators; the chosen chef (once reserved); Amazon SES (email); Meta WhatsApp Cloud API; then Stripe or Asaas only after you pay on our site. OpenAI receives whatever it already has in the chat, plus our tool outputs (public chef data, quotes, draft_id, payment URL).
Retention: same as other leads and bookings (section 6). Unconverted ChatGPT leads are convertible for 7 days.
Your controls: refuse consent in the chat; book on the website instead; unsubscribe from resume emails; email contato@mychef.com.br to access, correct or delete the lead.
8.5 Current tool inputs and outputs
| Tool | Stores data? | Inputs we receive | Outputs we return |
|---|---|---|---|
list_service_cities | No | optional city query, lang | Public city list (city_id, name, state, currency, timezone) |
search_chefs | No | city or city_id, optional state, query, booking_type, cuisines, date, time, needs_cleanup, needs_groceries, limit, lang | Matching public chefs (id, name, city, rating, review/booking counts, cuisines, services, starting price) or city_candidates |
get_chef | No | chef_id, optional package_id, lang | Public profile: bio, photo URL, packages, menus/plates, add-ons, fees, cancellation policy, approved reviews, profile and booking URLs |
get_chef_availability | No | chef_id, optional package_id / booking_type, start_date, end_date, duration_hours, lang | Free start times in the chef’s timezone and as UTC instants. Nothing is held. Best-effort; not a hold. |
quote_booking | No | chef_id, package_id, guests, optional optional_ids, has_cleanup, has_groceries, voucher_code, lang | Price breakdown (subtotal, cleanup, groceries, commute, waiter, add-ons, voucher, service fee, total). Invalid vouchers are ignored (voucher_rejected). |
start_booking | Yes — creates a lead | Required: chef_id, package_id, guests, customer_name, customer_email, customer_phone, contact_consent=true. Optional: lang. | draft_id / lead_id, booking_created: false, chef reference, package, quantity, booking_url (valid 7 days), expires_at. Not a reservation. |
reserve_booking | Yes — creates a booking | Required: draft_id, package_id, service_datetime_utc (copied from slots_utc), guests, address_line_1, city, state, zip_code. Optional: address_line_2, address_complement, optional_ids, selected_plate_ids, has_cleanup, has_groceries, groceries_budget, dietary_restrictions, food_intolerances, dietary_notes, voucher_code, lang. | booking_id, reference, awaiting_payment or awaiting_chef, total, currency, payment_url, manage_url, 72-hour deadline (or zero if a voucher covers it). |
These seven tools are the current surface. If we add or change a tool that takes or returns personal data, we will update this section and bump the policy version.
9. Mobile app — permissions and SDK list
| Permission | When | Why |
|---|---|---|
| Location (when in use) | City picker | Suggest city. Not used for live tracking. |
| Camera | You take a profile, dish, ID or chat photo | Only that capture |
| Photo library | You pick an image | Profile, gallery, plates, chat |
| Microphone | You record a chat audio/video | Only that recording |
| Notifications | After you allow | Booking and chat alerts |
| Advertising id (Android) | App start | Meta SDK measurement |
| Network | Always | Talk to our API |
Sign-in: Google Sign-In, Sign in with Apple, Firebase Auth.
Payments in the app: Stripe (card), Asaas (Pix + CPF), Apple Pay / Google Pay where available.
Third-party SDKs in the app: Firebase (Auth, Firestore, Messaging, Storage, Performance, Remote Config, Installations), Stripe, Amplitude, Meta SDK, Sentry, Google Sign-In, Sign in with Apple, Google Fonts (typefaces only).
10. Children
myChef is for people 18 or older. We do not knowingly collect data from children. If a child created an account, email us and we will delete it.
11. International transfers
Our primary operation is in Brazil. Hosts and processors in section 5 sit mainly in the United States. Transfers rely on LGPD Art. 33: contractual clauses with those vendors and the fact that the transfer is required to provide the service you asked for (Art. 33, IX, when applicable).
12. Security
TLS in transit. Access to production is limited to operators who need it. Passwords for Google/Apple stay with those providers. Card data stays with Stripe. ID images live in private object storage. No method is perfect; if we have a breach that risks you, we will notify you and the ANPD as the law requires.
13. Changes
If we change this notice in a material way we will update the date and version at the top (the ChatGPT consent field consent_policy_version uses that version, currently 2026-08) and, when the law requires, tell you by email or in the app.
The Portuguese text at mychef.com.br/pt/privacy-policy is the version that governs for users in Brazil. This English page is a translation.
14. How to reach us
myChef · Mychef App Plataforma Digital LTDA
Rua Francisco Rocha, 198 — Batel
Curitiba/PR — 80420-130
CNPJ 59.718.921/0001-37
contato@mychef.com.br
Account deletion help: mychef.com.br/en/deleting-accounts.