Privacy Policy
Last updated September 13, 2026
This policy explains how DinnerDiary collects, uses, and shares data when you use our web and mobile apps.
Information we collect
- Account details: email, name, username, password hash, and profile settings.
- Profile and social data: optional bio, home city, avatar, Instagram handle, TikTok handle, friends, follows, comments, and community ratings.
- Lists and places: saved places, ratings, notes, visit history, tags, favorites, and uploaded photos.
- Usage and device data: page visits, feature usage, browser/app metadata, and diagnostics.
- Location data: if you allow location access, we use it for map context and nearby place search.
- Analytics: we use Umami analytics, including sampled session replays with masking.
How we use your information
- Provide, secure, and improve the service.
- Deliver your lists, map views, social features, and sharing.
- Run billing, usage limits, and subscription management.
- Send product, security, and transactional notifications.
- Prevent abuse, spam, fraud, and policy violations.
AI processing
AI features run through Vercel AI Gateway with models from OpenAI, Alibaba Cloud (Qwen), DeepSeek, and Anthropic. Providers process the data only to return a result and don’t use it for advertising. In the iOS and Android apps we ask for your permission before the first AI request, and you can turn AI features off in Settings. Data sent depends on the feature:
- Social import parsing: Instagram/TikTok captions and link metadata needed to identify places.
- Vibe search, AI picks, and recommendations: saved place names, cities, ratings, and list context relevant to your request.
- Screenshot import: text read from the screenshot on your device and, only when that text isn’t enough, the image itself. Screenshots are not stored.
Service providers
We use processors that help operate the product:
- Polar for web subscription billing and tax handling.
- Apple App Store and Google Play for in-app subscriptions, with RevenueCat to validate purchases and keep your Plus access in sync.
- Sign in with Apple and Google when you choose to sign in with them.
- Google Places for place data and lookups.
- Railway for API hosting.
- Vercel for web hosting and edge delivery.
- Vercel AI Gateway for managed access to OpenAI, Alibaba Cloud (Qwen), DeepSeek, and Anthropic models.
- Apple Push Notification service (APNs) and Firebase Cloud Messaging (FCM) for push delivery.
- Umami for product analytics.
Public content and discoverability
Public lists, comments on public lists, and community ratings are visible to anyone and may be indexed by search engines. List owners can remove comments on their own lists.
Payments
Web payments are processed by Polar as Merchant of Record. Purchases in the iOS and Android apps are processed by Apple or Google. We do not store full credit card details.
Cookies
We use first-party session cookies for authentication and app security. We do not run third-party ad tracking cookies.
Data retention
We keep account data while your account is active. We may keep limited records where legally required.
Your controls
You can manage profile privacy, data sharing preferences, and most account settings in the app. You can export your data from Settings. If you delete your account, active web subscriptions are canceled as part of deletion. App Store and Google Play subscriptions can only be canceled by you in your Apple Account or Google Play settings, so cancel them before deleting your account.
Changes to this policy
We may update this policy over time. Material updates are posted here with a new date.
Contact
Questions? Email privacy@dinnerdiary.app.