SafeDish

Privacy Policy

Effective 17 September 2026 · Tiny Studio LLC

The short version

Who we are

SafeDish is made by Tiny Studio LLC ("we", "us"). We are the data controller for the information described here. You can reach us at contact@tinystudio-llc.com.

This policy covers the SafeDish iOS app and the service behind it. It does not cover Apple's App Store, Apple Health, or the sign-in providers, each of which has its own policy.

What we collect

Your account

We never see or store your password. Sign-in is handled by Supabase Auth; passwords are hashed there, and Apple and Google sign-ins give us an identity token, not your credentials.

Your profile

This is the part that makes SafeDish work, and the part we treat with the most care:

Your scans

Your daily log

When you mark a dish as eaten we store the dish name, when you ate it, and its estimated calories and macros, so the app can show your running daily totals.

Purchases

Apple processes every payment. We never see your card or bank details. To know whether your subscription is active we receive, through RevenueCat, the product you bought, when it started, when it renews or expires, and Apple's transaction identifier. RevenueCat knows you only by a random account identifier — it never receives your profile, faith restriction, allergies, or goal.

Technical data

We do not collect your location, contacts, device identifiers for advertising, browsing history, or anything from other apps.

How we use it

We do not use your data for advertising, we do not build profiles of you for any purpose other than the one you set up, and we do not sell or rent it.

Faith data

Your faith restriction and its settings are used to compute your own verdicts and for nothing else. Concretely:

Under the GDPR, this processing rests on your explicit consent, which you give by choosing a restriction in the app and can withdraw at any time by changing it to "None" or deleting your profile.

Who processes your data

We use a small number of providers to run SafeDish. Each receives only what its job requires.

ProviderWhat it doesWhat it receives
SupabaseDatabase, sign-in, and photo storage (hosted in Paris, France)Everything listed above, at rest
RailwayHosts our application serversData in transit while a request is processed
OpenAIThe AI model that reads photos and produces verdictsThe photo, your restriction, allergies, goal and targets, your language. OpenAI's API terms prohibit using this data to train its models; it may be retained briefly for abuse monitoring
AppleSign in with Apple; App Store payments; Apple Health (on your device)Per Apple's policies; we receive an identity token and purchase status
GoogleSign in with Google (optional)Per Google's policy; we receive an identity token, your email and name
RevenueCatSubscription status and receiptsA random account identifier and Apple's purchase details — nothing about your profile
Open Food FactsProduct data for barcode scansThe barcode number only, with no account information
WikimediaReference photos of dishesThe dish name only, with no account information

Apple Health

Connecting Apple Health is optional. If you allow it, SafeDish reads dietary energy, protein, carbohydrates and fat that you have logged in other apps so your daily total is complete, and writes the estimates of dishes you mark as eaten. Health data is read and written on your phone only. It is never uploaded to our servers, never sent to the AI model, and never shared with anyone. You can revoke access at any time in the Health app under Sharing → Apps.

What stays on your phone

Deleting the app removes all of these. Signing out removes the session and the cache.

Retention and deletion

Your rights

Wherever you live, you can see what we hold (Settings → Account shows it; every scan and profile is visible in the app), correct it (edit your profile), delete it (above), or take it with you — email us and we will send a copy of your data in a machine-readable format within 30 days.

If you are in the European Economic Area, the United Kingdom or Switzerland you also have the rights to restrict or object to processing and to lodge a complaint with your supervisory authority. Our legal bases are: performing our contract with you (running the service you subscribed to), your explicit consent for faith and health-related data, and our legitimate interest in keeping the service secure and understanding its costs.

If you are in California, we do not sell or share personal information as defined by the CCPA, and we do not use it for cross-context behavioural advertising.

Security

All traffic between the app and our servers is encrypted in transit. Data is encrypted at rest by our hosting providers. Each person's data is isolated by database policies so that one account can never read another's — including the stored photos, which are only ever handed out through short-lived signed links. Access to production systems is limited to the people who run SafeDish.

Children

SafeDish is not directed at children under 13 (or the age of digital consent where you live, if higher), and we do not knowingly collect data from them. If you believe a child has created an account, email us and we will delete it.

Where your data goes

Our database and photo storage are in the European Union. Analysis requests are processed by OpenAI, and some of our other providers operate in the United States. Where data leaves the EEA we rely on the providers' standard contractual clauses or an adequacy decision.

Changes to this policy

When we change what we collect or who processes it, we will update this page, change the date at the top, and tell you in the app before the change takes effect. Older versions are available on request.

Contact

Questions, requests, or concerns: contact@tinystudio-llc.com. We answer within a few working days.