Privacy Policy
The short version
- SafeDish exists to check dishes against your profile. Everything we store is there for that, and nothing else.
- Your faith restriction is sensitive data. We use it only to compute your own results. It is never used for analytics, advertising, or shared with anyone for any other purpose.
- Photos you scan and the profile you set up are sent to OpenAI to produce the verdicts. OpenAI does not use that data to train its models.
- There is no advertising, no tracking, and no analytics SDK in the app. We do not sell data.
- You can delete any scan, all scans, or your whole account from inside the app. Deletion is immediate and complete.
Who we are
SafeDish is made by Tiny Studio LLC ("we", "us"). We are the data controller for the information described here. You can reach us at contact@tinystudio-llc.com.
This policy covers the SafeDish iOS app and the service behind it. It does not cover Apple's App Store, Apple Health, or the sign-in providers, each of which has its own policy.
What we collect
Your account
- Email address, used to sign you in and to reach you about your account. If you use Sign in with Apple you may choose to hide your email, in which case we receive Apple's private relay address instead.
- Name, only if the sign-in provider (Apple or Google) shares one with us, or if you type one as your profile name.
- The language you chose for the app.
We never see or store your password. Sign-in is handled by Supabase Auth; passwords are hashed there, and Apple and Google sign-ins give us an identity token, not your credentials.
Your profile
This is the part that makes SafeDish work, and the part we treat with the most care:
- Faith restriction — halal, kosher, vegetarian, vegan, or none — and for halal, your strictness level and whether hand-slaughter matters to you. This reveals religious belief, which is a special category of personal data. We process it because you have explicitly asked us to by setting it up, and only for the purpose described in Faith data.
- Allergies, from our list or typed by you.
- Diet goal (keto, high-protein, calorie target, cutting, bulking) and your daily targets for calories, protein, carbohydrates and fat.
- A profile name ("Me" by default). You can create profiles for other people, such as family members; the same rules apply to their data.
Your scans
- The photo you take or choose — of a menu, a food label, an ingredient list, or a plate of food. Menu photos rarely contain personal data, but we treat every photo as your content.
- For a barcode scan, the barcode number.
- The results: dish names and translations, the faith, allergy and nutrition verdicts with their reasons, the suggested question for the kitchen, the language the menu was in, and the language your results were written in.
- Reference dish images shown next to results come from Wikipedia or are generated; they are shared across all users and are not tied to you.
Your daily log
When you mark a dish as eaten we store the dish name, when you ate it, and its estimated calories and macros, so the app can show your running daily totals.
Purchases
Apple processes every payment. We never see your card or bank details. To know whether your subscription is active we receive, through RevenueCat, the product you bought, when it started, when it renews or expires, and Apple's transaction identifier. RevenueCat knows you only by a random account identifier — it never receives your profile, faith restriction, allergies, or goal.
Technical data
- For each analysis we record which AI job ran, the model used, how many tokens it consumed and what it cost. This is tied to your account so we can understand our costs; when you delete your account the link to you is removed and the row becomes anonymous.
- Our servers keep short-lived technical logs (request paths, timings, errors) for debugging. They do not contain your photos or results.
We do not collect your location, contacts, device identifiers for advertising, browsing history, or anything from other apps.
How we use it
- To produce your results. The photo and your profile — restriction, allergies, goal and targets, never your name or email — are sent to the AI model together with our own reference material on halal, kosher and allergens. The model returns the verdicts you see.
- To answer in your language and to write the kitchen question in the menu's language.
- To keep your history, so past scans, their photos and their kitchen cards stay available to you, including offline.
- To run your subscription: knowing whether scanning is unlocked, and restoring your purchase on a new phone.
- To keep the service working: understanding costs, fixing errors, preventing abuse.
We do not use your data for advertising, we do not build profiles of you for any purpose other than the one you set up, and we do not sell or rent it.
Faith data
Your faith restriction and its settings are used to compute your own verdicts and for nothing else. Concretely:
- It is stored in your profile and sent, with each scan, to the AI model as part of the instructions for that scan.
- It is not sent to RevenueCat, Apple, Google, or any analytics or advertising service — there are none in the app.
- We do not aggregate it, report on it, or segment users by it.
- It is deleted with your profile or your account.
Under the GDPR, this processing rests on your explicit consent, which you give by choosing a restriction in the app and can withdraw at any time by changing it to "None" or deleting your profile.
Who processes your data
We use a small number of providers to run SafeDish. Each receives only what its job requires.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database, sign-in, and photo storage (hosted in Paris, France) | Everything listed above, at rest |
| Railway | Hosts our application servers | Data in transit while a request is processed |
| OpenAI | The AI model that reads photos and produces verdicts | The photo, your restriction, allergies, goal and targets, your language. OpenAI's API terms prohibit using this data to train its models; it may be retained briefly for abuse monitoring |
| Apple | Sign in with Apple; App Store payments; Apple Health (on your device) | Per Apple's policies; we receive an identity token and purchase status |
| Sign in with Google (optional) | Per Google's policy; we receive an identity token, your email and name | |
| RevenueCat | Subscription status and receipts | A random account identifier and Apple's purchase details — nothing about your profile |
| Open Food Facts | Product data for barcode scans | The barcode number only, with no account information |
| Wikimedia | Reference photos of dishes | The dish name only, with no account information |
Apple Health
Connecting Apple Health is optional. If you allow it, SafeDish reads dietary energy, protein, carbohydrates and fat that you have logged in other apps so your daily total is complete, and writes the estimates of dishes you mark as eaten. Health data is read and written on your phone only. It is never uploaded to our servers, never sent to the AI model, and never shared with anyone. You can revoke access at any time in the Health app under Sharing → Apps.
What stays on your phone
- Your sign-in session, kept in the iOS Keychain.
- A cache of your profile and scan history, so the app works without a connection.
- Photos of scans taken while offline, held until they can be analysed.
- Your language choice.
Deleting the app removes all of these. Signing out removes the session and the cache.
Retention and deletion
- Scans are kept until you delete them. Delete one from its screen, or all of them from Settings; the stored photo is deleted with it.
- Your daily log is kept until you remove an entry or delete your account. A log entry survives the deletion of the scan it came from, by design.
- Your account: Settings → Account → Delete account removes your account record, every profile, every scan and photo, your daily log, and the link between you and our technical records. This happens immediately and cannot be undone. Anonymous cost records and short-lived server logs are the only things that remain.
- Purchase records at Apple and RevenueCat are kept for as long as their financial rules require, under their policies.
Your rights
Wherever you live, you can see what we hold (Settings → Account shows it; every scan and profile is visible in the app), correct it (edit your profile), delete it (above), or take it with you — email us and we will send a copy of your data in a machine-readable format within 30 days.
If you are in the European Economic Area, the United Kingdom or Switzerland you also have the rights to restrict or object to processing and to lodge a complaint with your supervisory authority. Our legal bases are: performing our contract with you (running the service you subscribed to), your explicit consent for faith and health-related data, and our legitimate interest in keeping the service secure and understanding its costs.
If you are in California, we do not sell or share personal information as defined by the CCPA, and we do not use it for cross-context behavioural advertising.
Security
All traffic between the app and our servers is encrypted in transit. Data is encrypted at rest by our hosting providers. Each person's data is isolated by database policies so that one account can never read another's — including the stored photos, which are only ever handed out through short-lived signed links. Access to production systems is limited to the people who run SafeDish.
Children
SafeDish is not directed at children under 13 (or the age of digital consent where you live, if higher), and we do not knowingly collect data from them. If you believe a child has created an account, email us and we will delete it.
Where your data goes
Our database and photo storage are in the European Union. Analysis requests are processed by OpenAI, and some of our other providers operate in the United States. Where data leaves the EEA we rely on the providers' standard contractual clauses or an adequacy decision.
Changes to this policy
When we change what we collect or who processes it, we will update this page, change the date at the top, and tell you in the app before the change takes effect. Older versions are available on request.
Contact
Questions, requests, or concerns: contact@tinystudio-llc.com. We answer within a few working days.