Legal
Privacy Policy
Last updated: 29 July 2026
Dish (“Dish”, “we”, “us”) is a recipe library and smart shopping-list app. This policy explains what information we collect, how we use it, and the choices you have. By using Dish you agree to this policy.
Who we are
Dish is operated by Callum Deas, an individual trading as Dish in the United Kingdom. Callum Deas is the data controller for the personal information described in this policy.
Email: callumdeas@gmail.com
Information we collect
- Account information. When you create an account, our authentication provider (Clerk) collects your email address and name. If you sign in with Google or Apple, we receive basic profile information (name and email) from that provider. If you use Sign in with Apple and choose to hide your email, Apple gives us a private relay address instead of your real one.
- Content you create. Recipes (titles, ingredients, steps, notes, tags, dietary labels, and estimated nutrition), shopping lists and their items, your meal plans, which published recipes you have liked, and any shared “kitchens” you create or join, including their membership. A published recipe’s like total is public; we do not show anyone who liked it.
- Dietary preferences. If you choose to set dietary preferences in your profile (for example vegetarian, gluten-free or nut-free), we store them against your account and include them in requests to our AI provider so that recipe suggestions and ingredient substitutions can take them into account. Some of these preferences may reveal information about your health or your beliefs, so we treat them as special category data and rely on your explicit consent to process them. Setting them is entirely optional — the app works fully without them, and they only ever nudge a suggestion, never block one — and you can withdraw your consent at any time by deselecting them in your profile, which deletes them from your account. These requests are processed by Google Cloud on servers located in the European Union.
- Imported content. When you import a recipe from a web link, pasted text, a TikTok link, or a photo, we process that content to extract the recipe’s details. As a record of where the recipe came from, we also keep the photo you submitted for a photo import, and, for a TikTok import, the post’s thumbnail image, which we fetch ourselves.
- Photos you upload. You can add a cover photo to a recipe, and you can import a recipe by photographing it. Those images are uploaded to and stored in our own object storage, and are served back through a link on our servers that anyone holding the link can open — that is how a recipe’s photo appears in a share link, in Explore, and on our website. When a recipe is imported from a website, its image is instead displayed by linking to the image at its original source.
- Ingredient history. Ingredients you add are remembered to power autocomplete suggestions. The ingredient name on its own — with no link to you — also feeds a shared catalogue we use to improve grocery categories and icons for everyone. If you correct an item’s grocery category, that correction is additionally recorded as a vote stored against your account, so that several people correcting the same ingredient can update the shared catalogue.
- Usage and technical data. Product analytics events, if you have turned analytics on (see “Cookies and analytics” below), and standard server logs, which include your IP address and the requests your device makes. We use these to keep the service secure, apply rate limits and fair-use quotas, and diagnose problems.
How we use your information
- To provide the app and sync your recipes and lists across your devices.
- To import and structure recipes, and to power the app’s other AI features — conversational recipe editing, ingredient substitutions while cooking and on your shopping list, nutrition estimates, and grocery categorisation (see “AI and content checks” below).
- To operate your account and any shared kitchens you participate in.
- To check recipes published to the public Explore feed for unsafe or profane content.
- To understand how the app is used and improve it, using product analytics (PostHog) — in the app, only if you turn analytics on.
- To keep the service secure and reliable, including rate limits and monthly fair-use quotas on the AI features.
We do not sell your personal information, and we do not use it for advertising or to build advertising profiles.
Service providers we share data with
We share data only with providers that help us run Dish, and only so they can perform their part of the service:
- Clerk — authentication and account management.
- Google and Apple — sign-in, when you choose to use them.
- Railway and PowerSync — hosting, database and image storage, and real-time data synchronisation.
- Google Cloud (Vertex AI) — the AI features that involve your own words or photos: importing a recipe from a photo, conversational recipe editing, ingredient substitutions, grocery categorisation, and the display-name check. These run in Google’s European data centres.
- OpenRouter and the underlying model provider it routes each request to — reading a recipe out of a link, pasted text or a TikTok caption.
- OpenAI — content moderation for recipes published to the public Explore feed.
- PostHog — product analytics, to help us understand how the app is used and improve it.
- Sentry — crash and error reporting, so we find out when something breaks. See below for what a crash report contains.
Crash and error reporting
When the app or our server hits an unexpected error, we send a report to Sentry so we can fix it. A report contains the error message, the technical stack trace showing where in our code it happened, and which screen or API route was involved.
We deliberately do not attach your name, email address, account ID or IP address to these reports, and Sentry is configured not to store the IP address the report arrives from. Reports are processed in Sentry’s European region.
One honest caveat: an error message is free-form text written by us, and we filter it for things that look sensitive before sending. Our rule is never to put your content into an error message — but that is a rule we follow, not something the system can guarantee absolutely.
Where your data is processed (international transfers)
Dish is run from the United Kingdom, and your data is stored in the UK or the European Economic Area. Some of the providers above are based outside the UK, which means your personal data may be transferred to and processed in countries whose data-protection laws the UK has not judged equivalent to its own — principally the United States.
Where that happens, we rely on one of the safeguards recognised under UK data-protection law:
- Railway and PowerSync, PostHog, Sentry, and Google Cloud (Vertex AI) process our data in the EU or EEA. The UK recognises the EEA as providing equivalent protection, so no additional safeguard is needed. For the AI features listed above, our agreement is with Google’s Irish company and the processing is pinned to Google’s European region.
- Clerk (United States) is certified under the EU–US Data Privacy Framework and its UK Extension. Its agreement with us also includes the Standard Contractual Clauses together with the UK Addendum issued by the Information Commissioner, which apply if that certification ever stops being available.
- OpenAI (United States) receives data under the Standard Contractual Clauses as amended by the UK Addendum, which form part of our agreement with them. Content sent to OpenAI’s moderation service is not used to train their models and is not retained by them.
- OpenRouter (United States) is the one provider where we cannot point to one of those formal safeguards: the agreement that would carry it is only offered to their enterprise customers. We have kept what reaches them as narrow as we can. It is limited to reading a recipe out of a link, pasted text or a TikTok caption; no account identifier is sent with the request, so they cannot connect it to you; we instruct them on every request not to route it to any provider that stores or trains on it; and they do not retain the request or the response by default. We are reviewing whether to keep using them at all.
You can ask us for a copy of the safeguards we rely on, or for more detail about any transfer, by emailing callumdeas@gmail.com. You can check the Data Privacy Framework certifications yourself at dataprivacyframework.gov/list.
AI and content checks
Some features send your content to AI providers from our servers. We do not train any models of our own on your content.
- Features that involve your own words or photos (via Google Vertex AI, in Europe). Importing a recipe from a photo; conversational recipe editing; mid-cook ingredient substitutions; grocery categorisation; and the display-name check. Anything you type into those features is sent — the whole conversation in a recipe chat is sent again on every turn — along with imported photos and your dietary preferences. Chat messages are not stored on our servers: the app holds the conversation on your device and resends it.
- Reading a recipe from a link or text (via OpenRouter). Importing from a website link, pasted text, or a TikTok caption, plus nutrition estimates for those imports. The recipe text and any free-text note you add is sent and forwarded to whichever model provider OpenRouter routes it to. No identifier for your account goes with it.
- Moderation (direct to OpenAI). When you publish a recipe to the public Explore feed — and each time you edit a recipe that is already published — we send that recipe’s text and its cover photo to OpenAI’s moderation service to check for unsafe content. This call goes directly to OpenAI, not through OpenRouter.
- Profanity check. At the same points we also check the recipe’s text and your public display name for profanity. Your display name is checked via Google Vertex AI in Europe; the recipe text goes via OpenRouter. The result for your display name is stored against your account so we don’t re-check an unchanged name.
We keep a record of the outcome of these checks so we can review flagged content. For a profanity check, that record includes the specific words that were flagged. If an account publishes content that breaks our rules, we may turn off publishing and photo uploads for it — a decision a person makes after reviewing the content, never an automatic one.
Sharing recipes with other people
Your recipes are private to your account unless you choose to share them. There are three ways to share, and each exposes different information:
- Share links (“Pass the recipe”). Creates a public, hard-to-guess link to a single recipe. Anyone with the link can view it and save a copy without signing in. The link shows the recipe and its photo, but not your name or email address. You can revoke it at any time.
- Kitchens. Everyone in a kitchen can see the recipes, shopping lists and meal plans shared into it, and can see the name and email address of every other member. Only join a kitchen with people you are happy to share your email address with.
- Publishing to Explore. Publishing a recipe makes it public in the app’s Explore feed. It also gets a page on this website that search engines can index — unless you imported it from a website or a TikTok link, in which case it stays in the app only. Published recipes carry an author label: your name, or — if you have not set one — the part of your email address before the “@”. Unpublishing removes the recipe from the feed and the website, but search engines and other third parties may keep a cached copy for some time afterwards, which we cannot control.
If someone saves a copy of a recipe you published to Explore, that copy lives in their account and keeps a snapshot of your name as it was at the time — even if you later change it or unpublish the recipe. Deleting your account replaces that name with a generic label on every copy we can still trace back to you. A copy made from a recipe you had already deleted before closing your account may keep the name, because deleting the recipe severed the only link back to you. Only your name is copied this way, never the email-derived label, and a copy someone makes from a share link records no author at all.
Apple Health (iOS)
Dish can log a meal’s calories to Apple Health when you finish cooking it in Cook mode. This is off by default and only happens if you turn it on in Profile and grant Health permission. It is write-only: Dish never reads anything from Apple Health, and no Apple Health data is sent to our servers. You can turn it off at any time in Profile, or revoke access in the iOS Health app.
Storage and sync
Your data is stored in our database and synced to your devices through PowerSync, so the app works offline and stays up to date. Photos you upload are held separately in our object storage and served back through our servers. Data is transmitted over encrypted connections.
Cookies and analytics
On this website we set no analytics cookies and store nothing in your browser until you accept the cookie banner. Until you answer it, page views are still recorded, but anonymously — with nothing saved on your device that could link one visit to the next. Analytics requests are proxied through this site’s own domain.
In the app, analytics are off until you turn them on. We ask once, and you can change your answer at any time in Profile → Usage analytics. Until you say yes we record nothing; if you later turn it off we stop immediately and discard anything still waiting to be sent. While it is on, we use PostHog to record screen views and interactions, linked to an identifier for your account rather than to your name or email address. These events carry no recipe text or photos, though a few record a single ingredient name — for example when you ask for a substitute while cooking.
One exception worth stating plainly: version 1.0 of the app did send your name and email address to PostHog when you signed in. Where that happened, those details are still held against the analytics profile, and updating the app does not remove them — it stops anything further being sent, but it cannot delete what was stored before. To have them erased, email us at callumdeas@gmail.com and we will delete the analytics profile. Deleting your account from the app does not do this on its own — analytics live outside our database, so ask us and we will remove them.
Retention and deleting your account
We keep your information for as long as your account is active.
You can delete your account at any time from the app (Profile → Delete account). This deletes your sign-in identity and your account record, which removes your recipes, shopping lists, meal plans, ingredient history, your likes and category votes, and your kitchen memberships. It cannot be undone. You can also email us at callumdeas@gmail.com to request deletion.
Deletion also removes any kitchen you originally created — together with its membership, invite links, and shared meal plans — even if you have since left that kitchen and someone else runs it. Recipes and shopping lists other members had shared into it return to whoever created them.
Some things are not removed automatically:
- Photos you uploaded may remain in our image storage. Email us and we will remove them.
- Copies of your recipes that other people already saved stay in their accounts. Your name is replaced with a generic label on those copies, except where the recipe they copied had already been deleted — see above.
- Our moderation records are kept as an audit trail. The link to your account is removed, but the record itself stays — including, for a profanity check, the specific words that were flagged.
Children
Dish is not directed to children under 13 (or under 16 in the UK and EEA), and we do not knowingly collect their personal information.
Security
We use reasonable technical and organisational measures to protect your information. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Changes to this policy
We may update this policy from time to time. When we do, we’ll revise the “last updated” date above.
Contact
Questions about this policy or your data? Email callumdeas@gmail.com.