PlateDiary
Back to PlateDiary

Privacy

Your memories stay yours.

Your food-memory library lives on your device. PlateDiary sends limited information to named providers for app health, purchases, notifications, and optional online features you choose to use.

Effective August 12, 2026

At a glance

The short version

the table is yours →

Information that stays on your device

PlateDiary is built around a local library. Your food photos, generated saves, save names and kinds, ratings, thoughts, tags, companions, locations and place details, moments, collections, themes, Share Studio designs, widget settings, and the PlateDiary database are stored on your device. GIFs you add in Share Studio are downloaded into local storage so the finished design can work offline. PlateDiary does not upload this library to a PlateDiary account or cloud service.

When you choose to share a moment, save an image or video to your photo library, place a Table Window on your Home Screen, or export a backup, you decide where that copy appears. Those copies are then handled by the app, service, or storage location you selected.

Limited technical information we receive

PlateDiary uses a small set of Google Firebase services to understand whether the app works well. This technical information is separate from your food-memory library.

Firebase Analytics

PlateDiary records product-interaction events such as opening the app, viewing a screen, starting a capture or import, changing a view or filter, exporting a share image, and responding to a notification or feedback prompt. Events may include limited details such as a screen name, feature choice, format, or count, along with technical properties supplied by Firebase.

PlateDiary's custom analytics events do not include your photos, save names, thoughts, companion names, place names, coordinates, or search text. For search, PlateDiary records only the query length and number of results.

So that those events count devices and sessions rather than people, Firebase Analytics attaches identifiers of its own: an app-instance identifier it generates for this install, and, on Android, the device advertising identifier your system settings control. PlateDiary reads these only as counts in its own usage reports. It shows no advertising, builds no advertising or personalization audiences, and never joins them to your food-memory library or to information from other apps and websites.

Firebase Crashlytics

When PlateDiary crashes or encounters an error, Crashlytics may receive crash logs, stack traces, non-fatal error details, timestamps, app version, device and operating-system information, and short technical breadcrumbs that identify the area of the app where the problem occurred. Crashlytics also generates an installation identifier for this install, so a run of crashes counts as one affected device rather than many. We use this information to find and fix reliability problems.

Firebase Cloud Messaging

If you allow notifications and opt in to announcements, Firebase Cloud Messaging creates an app-instance registration token and records the announcements topic subscription needed to deliver those messages. PlateDiary does not use that token as a user account or attach your food-memory library to it.

App updates

When PlateDiary starts, it asks Expo's update service whether a newer version of the app's own code has been published for the version you installed. That request carries a randomly generated install identifier, your platform, and the app's runtime version — enough to answer the question and to count how many devices took an update. It carries no part of your food-memory library.

RevenueCat and app-store purchases

PlateDiary uses RevenueCat to load Premium products, confirm or restore a purchase, and keep Premium access current. Because PlateDiary has no account sign-in, RevenueCat creates a random app user ID for this install. RevenueCat and the applicable app store may process that ID, app and device information, product identifiers, purchase dates and status, and an Apple receipt or Google purchase token. PlateDiary does not send your food-memory library to RevenueCat.

Invites

Invites are optional. Nothing below happens unless you open the Invite friends screen, enter a friend's code, or have already entered one.

When you use invites, PlateDiary contacts its invite service, which runs on Cloudflare Workers, and sends only: a device key, the random RevenueCat app user ID for this install, the app version, a one-time random value, a device-verification token described below, and — if you are entering one — the eight-character code itself. The invite service stores the device key only as a one-way salted hash, so the original value cannot be recovered from it. It records which codes exist, how many friends a code has credited, and whether a free month has been granted.

PlateDiary never sends the invite service any part of your food-memory library. No photos, saves, save names, kinds, ratings, thoughts, tags, companions, locations, place details, moments, or collections leave your device for this feature, and the invite service holds no email address, name, or other contact detail.

To confirm that a request comes from a genuine, unmodified copy of PlateDiary on a real device — which is what keeps the promotion from being drained automatically — PlateDiary asks the platform for a device-verification token: Apple's DeviceCheck on iPhone, or Google Play Integrity on Android. On iPhone that mechanism also lets our invite service read and set two yes/no flags that Apple stores for this device and this developer account, recording whether the device has already used an invite and whether it has already received a free month. Those flags hold no other information and cannot be read by other developers. On Android, PlateDiary derives the device key from an Android-provided identifier that is specific to PlateDiary, and hashes it on your device before sending it.

If you are offline, the invite screen shows what it last knew and says so; a pending credit is sent later. A free month itself is applied through RevenueCat, described above.

Klipy GIF discovery

Share Studio's GIF picker is optional and online. Opening it requests trending GIFs from Klipy; using GIF search sends your search words to Klipy. Klipy may also receive ordinary request information, such as your IP address and device or app details. Selecting a result downloads that GIF to PlateDiary's local storage. PlateDiary does not send Klipy your photos, saves, notes, places, companions, or Share Studio design.

Downloadable type themes

PlateDiary's default typeface is built into the app and always available offline. If you choose a type theme that is not built in, PlateDiary downloads that font file from the jsDelivr CDN and keeps it on your device, so later launches use it with no connection at all. jsDelivr may receive ordinary request information, such as your IP address and the file requested. It never receives your photos, saves, notes, places, or companions, and no download happens unless you pick such a theme.

Messages you send us

If you email PlateDiary or send a note through the website's feedback form, we receive your message and whatever contact details you choose to include so we can respond.

The website's contact form asks for a topic, your email address, and your message, and optionally your name and a description of your phone and app version. The email address is required there only so we can write back. We use what you send to answer you and to fix or improve what you raised. Your board is never attached to a submission: no photos, saves, names, notes, ratings, places, companions, or moments are included.

This website

Netlify, the company hosting the site, delivers messages submitted through the feedback form and the contact form, stores those submissions so we can read and reply to them, and may process ordinary request information such as an IP address, browser type, requested page, and request time to deliver and secure the site.

The website also uses Google Analytics to understand how the pages are used. It sets Google Analytics cookies in your browser and records page views along with a small number of events the site sends itself: opening a download button, following a link away from the site, opening an FAQ answer, starting or sending a form, switching the theme, how far down a page you scrolled, and which sections you reached. Google Analytics also receives ordinary technical details such as an IP address, page address and referring page, device and browser type, and approximate region.

These website events never include anything you type. The message and email address in a form are sent only to Netlify when you submit them — Google Analytics is told that a form was started or sent, and nothing about its contents. Invite links are treated the same way: an invite address is recorded as /i/ with the code removed, so the code in your link is never sent to Google Analytics or passed on when you follow a link away from that page.

The PlateDiary app does not use Google Analytics, and the website analytics are separate from your food-memory library, which never leaves your device.

Permissions and device services

PlateDiary asks for access when a feature needs it. You can change permissions later in your device settings.

  • Camera: snaps the table so PlateDiary can create saves on your device.
  • Photos: imports existing food photos or saves an original or shared image when you ask.
  • Location: remembers where you ate and groups nearby saves into moments. PlateDiary stores the saved location locally. Apple or Google platform services may receive the coordinates needed to find a place name or display map content.
  • Microphone and speech recognition: lets you speak thoughts instead of typing. PlateDiary does not intentionally keep an audio recording, but your device's Apple or Google speech service may process audio or transcription data under its settings and privacy terms.
  • Motion: lets saves tumble and slide when you use gravity mode. PlateDiary does not store or send your motion readings.
  • Notifications: delivers announcements only after you grant permission and turn the option on.

How we use information

We use limited technical and support information to operate features you request, understand how app features are used, diagnose crashes and errors, improve reliability, deliver announcements you opted into, verify and restore Premium purchases, return GIF results you request, and answer your messages.

PlateDiary does not sell personal data, show third-party ads, or use its technical information to build advertising profiles or follow you across unrelated apps and websites.

Service providers

PlateDiary relies on providers that process limited information for the purposes described above:

These providers process information under their own terms and privacy practices.

Retention and deletion

Your local memories remain on your device until you delete individual saves or moments, use PlateDiary's erase controls, or remove the app and its data. Locally cached GIFs and Share Studio designs are included in PlateDiary's backup, restore, and erase flows. Exported backups, widgets, images, and videos remain wherever you put them until you remove them there.

Invite records — a hashed device key, a code, credit counts, and whether a month was granted — are kept for as long as the promotion needs them to prevent the same device being rewarded twice, and are deleted when they are no longer needed for that purpose. On iPhone, the two yes/no flags described above are stored by Apple for this device and developer account and persist until Apple removes them; they are what makes "once ever" mean once ever, and they hold nothing else.

Firebase, RevenueCat, Cloudflare, Klipy, jsDelivr, the app stores, and other providers retain technical, request, and purchase information according to our service configuration, their operational or legal needs, and their policies. We keep support messages only as long as reasonably needed to answer the request, maintain an appropriate record, or meet legal obligations.

Your choices

  • Use device settings to allow or deny camera, photo, location, microphone, motion, and notification access.
  • Turn announcements off in PlateDiary or in device notification settings.
  • Block cookies or use a tracker-blocking extension or browser setting to stop the website's Google Analytics measurement, or install Google's Analytics opt-out browser add-on. Every page, form, and link on the site keeps working without it.
  • Skip Share Studio's GIF picker to avoid sending trending or search requests to Klipy; bundled decorations and already-saved designs continue to work offline.
  • Skip invites entirely — never open Invite friends and never enter a code — and PlateDiary contacts the invite service no times at all.
  • Keep the built-in typeface, or a theme you have already downloaded, and PlateDiary never contacts the font CDN.
  • Reset or delete your advertising identifier in your device's privacy settings. PlateDiary's usage and crash reports keep working without it, because nothing in the app depends on that identifier.
  • Manage or cancel subscriptions through your App Store or Google Play account, and use Restore purchases in PlateDiary when needed.
  • Delete saves, moments, backups, or the local library with PlateDiary's controls.
  • Delete exported files from the place where you saved them.
  • Remove PlateDiary and its local data through your device.
  • Email us to ask a privacy question or request deletion of a support conversation.

Children's privacy

PlateDiary is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has sent us personal information, contact us so we can review and delete it where appropriate.

International processing

Service providers may process limited technical or support information in countries other than the one where you live. Their processing is subject to their safeguards, contractual commitments, and applicable law.

Changes to this policy

We may update this policy as PlateDiary changes. The latest version will appear on this page with a revised effective date. When practical, we will provide an appropriate notice of a material change.

Contact

PlateDiary is the operator of the app and website. For privacy questions, use the contact form and choose “My data or privacy”, or email platediary.app@gmail.com.