Security

Your kitchen, kept private.

Recipes and grocery lists aren't state secrets, but they're yours. Here's exactly how Coena protects them — and the things we haven't built yet.

Found a vulnerability? Email security@coena.app.

Your kitchen is private

  • Every request is checked against your kitchen membership on the server; the app never decides on its own what you may see.
  • Recipes, plans, lists and the pantry are visible only to the people in your kitchen and to apps you connect yourself.
  • Removing someone from your kitchen ends their access at once, including their API tokens and Claude connection.

Accounts and passwords

  • Passwords are hashed with scrypt by Convex Auth; nobody at Coena can read them.
  • Changing your password signs out your other sessions.
  • Sign-in error messages don't reveal whether an email has an account.

The Claude connector

  • OAuth 2.1 with PKCE: you approve the connection on a Coena page, signed in as you, and Claude never sees your password.
  • Codes are only ever sent to Claude's own sign-in callbacks (and your own computer, for Claude Code), so a look-alike app can't collect them.
  • Access tokens last a day and refresh quietly; connections end after 90 idle days, or the moment you disconnect in Settings → Claude.
  • Sign-in endpoints are rate limited per IP address.

API tokens

  • Personal tokens are shown once and stored only as a SHA-256 hash.
  • Revoke any token anytime; kitchen owners can revoke anyone's.

On the web

  • HTTPS only. The .app domain is on browsers' HSTS preload list, so browsers never connect to coena.app over plain HTTP.
  • A strict Content Security Policy: scripts only from Coena itself, no inline scripts except one fixed, hash-pinned theme script, and no framing by other sites.
  • No ads, no analytics, no trackers. This site sets no cookies; the app keeps its sign-in token in your browser's storage.
  • The only third-party code the app may load is Cloudflare's Turnstile check on sign-up, to keep bots out.

AI features

  • The planner and photo imports use Claude, by Anthropic; recipe photos are made with Cloudflare Workers AI. Under their commercial terms, neither trains on what Coena sends.
  • Coena sends only what a request needs: your question with the relevant recipes and pantry items, or the page, text or photo you're importing. Photo prompts contain a recipe's title and ingredients, nothing about you.
  • Each kitchen has daily AI allowances, which also limits the damage a stolen session could do.
  • One switch in Settings turns every AI feature off for you. The server enforces it, so nothing you do reaches an AI provider.

Who handles your data

The companies Coena relies on

Service providers, what they do for Coena and what they receive
ProviderWhat forWhat it receives
ConvexDatabase, file storage, sign-in and the app's backendYour account and everything in your kitchen
CloudflareHosting for the app and this site; AI recipe photos; Claude connector sign-inRequests (including IP addresses), recipe titles and ingredients for photos, connector grants
AnthropicThe AI planner; reading recipes from photos, text and messy pagesYour question with relevant kitchen data; the page, text or photo being imported
KrogerLive grocery pricesProduct searches and the store you picked — not who you are
Open Food FactsCommunity grocery prices (Open Prices)Product searches and a store's location
ResendEmail: sign-in codes and reminders you turn onYour email address and the message
StripePayments for Coena PlusBilling details — Coena never sees your card number

Email and payments are only used once they're switched on. See the privacy policy for details.

Not yet

What Coena doesn't do (yet)

We'd rather tell you than have you assume.

  • Two-factor sign-in and passkeys.
  • End-to-end encryption: Coena's server reads your recipes to search, plan, price and import them.
  • An independent security audit or certification such as SOC 2.

Reporting a vulnerability

Email security@coena.app with what you found and how to reproduce it. We'll reply within three business days and keep you posted until it's fixed.

Please test only against your own account and kitchen, don't access other people's data, and give us a reasonable time to fix the issue before you publish it. We won't take legal action against good-faith research that follows these rules.

Machine-readable contact details: /.well-known/security.txt

Dinner, sorted.

Start with the recipes you already love. Coena is free to use — bring your household, your favorite sites and your Paprika library.