Your table
Information that stays on your device
PlateDiary is built around a local library. Your food photos, generated saves, save names and kinds, ratings, thoughts, tags, companions, locations and place details, moments, collections, themes, Share Studio designs, widget settings, and the PlateDiary database are stored on your device. GIFs you add in Share Studio are downloaded into local storage so the finished design can work offline. PlateDiary does not upload this library to a PlateDiary account or cloud service.
When you choose to share a moment, save an image or video to your photo library, place a Table Window on your Home Screen, or export a backup, you decide where that copy appears. Those copies are then handled by the app, service, or storage location you selected.
App health
Limited technical information we receive
PlateDiary uses a small set of Google Firebase services to understand whether the app works well. This technical information is separate from your food-memory library.
Firebase Analytics
PlateDiary records product-interaction events such as opening the app, viewing a screen, starting a capture or import, changing a view or filter, exporting a share image, and responding to a notification or feedback prompt. Events may include limited details such as a screen name, feature choice, format, or count, along with technical properties supplied by Firebase.
PlateDiary's custom analytics events do not include your photos, save names, thoughts, companion names, place names, coordinates, or search text. For search, PlateDiary records only the query length and number of results.
So that those events count devices and sessions rather than people, Firebase Analytics attaches identifiers of its own: an app-instance identifier it generates for this install, and, on Android, the device advertising identifier your system settings control. PlateDiary reads these only as counts in its own usage reports. It shows no advertising, builds no advertising or personalization audiences, and never joins them to your food-memory library or to information from other apps and websites.
Firebase Crashlytics
When PlateDiary crashes or encounters an error, Crashlytics may receive crash logs, stack traces, non-fatal error details, timestamps, app version, device and operating-system information, and short technical breadcrumbs that identify the area of the app where the problem occurred. Crashlytics also generates an installation identifier for this install, so a run of crashes counts as one affected device rather than many. We use this information to find and fix reliability problems.
Firebase Cloud Messaging
If you allow notifications and opt in to announcements, Firebase Cloud Messaging creates an app-instance registration token and records the announcements topic subscription needed to deliver those messages. PlateDiary does not use that token as a user account or attach your food-memory library to it.
App updates
When PlateDiary starts, it asks Expo's update service whether a newer version of the app's own code has been published for the version you installed. That request carries a randomly generated install identifier, your platform, and the app's runtime version — enough to answer the question and to count how many devices took an update. It carries no part of your food-memory library.
RevenueCat and app-store purchases
PlateDiary uses RevenueCat to load Premium products, confirm or restore a purchase, and keep Premium access current. Because PlateDiary has no account sign-in, RevenueCat creates a random app user ID for this install. RevenueCat and the applicable app store may process that ID, app and device information, product identifiers, purchase dates and status, and an Apple receipt or Google purchase token. PlateDiary does not send your food-memory library to RevenueCat.
Invites
Invites are optional. Nothing below happens unless you open the Invite friends screen, enter a friend's code, or have already entered one.
When you use invites, PlateDiary contacts its invite service, which runs on Cloudflare Workers, and sends only: a device key, the random RevenueCat app user ID for this install, the app version, a one-time random value, a device-verification token described below, and — if you are entering one — the eight-character code itself. The invite service stores the device key only as a one-way salted hash, so the original value cannot be recovered from it. It records which codes exist, how many friends a code has credited, and whether a free month has been granted.
PlateDiary never sends the invite service any part of your food-memory library. No photos, saves, save names, kinds, ratings, thoughts, tags, companions, locations, place details, moments, or collections leave your device for this feature, and the invite service holds no email address, name, or other contact detail.
To confirm that a request comes from a genuine, unmodified copy of PlateDiary on a real device — which is what keeps the promotion from being drained automatically — PlateDiary asks the platform for a device-verification token: Apple's DeviceCheck on iPhone, or Google Play Integrity on Android. On iPhone that mechanism also lets our invite service read and set two yes/no flags that Apple stores for this device and this developer account, recording whether the device has already used an invite and whether it has already received a free month. Those flags hold no other information and cannot be read by other developers. On Android, PlateDiary derives the device key from an Android-provided identifier that is specific to PlateDiary, and hashes it on your device before sending it.
If you are offline, the invite screen shows what it last knew and says so; a pending credit is sent later. A free month itself is applied through RevenueCat, described above.
Klipy GIF discovery
Share Studio's GIF picker is optional and online. Opening it requests trending GIFs from Klipy; using GIF search sends your search words to Klipy. Klipy may also receive ordinary request information, such as your IP address and device or app details. Selecting a result downloads that GIF to PlateDiary's local storage. PlateDiary does not send Klipy your photos, saves, notes, places, companions, or Share Studio design.
Downloadable type themes
PlateDiary's default typeface is built into the app and always available offline. If you choose a type theme that is not built in, PlateDiary downloads that font file from the jsDelivr CDN and keeps it on your device, so later launches use it with no connection at all. jsDelivr may receive ordinary request information, such as your IP address and the file requested. It never receives your photos, saves, notes, places, or companions, and no download happens unless you pick such a theme.
Messages you send us
If you email PlateDiary or send a note through the website's feedback form, we receive your message and whatever contact details you choose to include so we can respond.
The website's contact form asks for a topic, your email address, and your message, and optionally your name and a description of your phone and app version. The email address is required there only so we can write back. We use what you send to answer you and to fix or improve what you raised. Your board is never attached to a submission: no photos, saves, names, notes, ratings, places, companions, or moments are included.
This website
Netlify, the company hosting the site, delivers messages submitted through the feedback form and the contact form, stores those submissions so we can read and reply to them, and may process ordinary request information such as an IP address, browser type, requested page, and request time to deliver and secure the site.
The website also uses Google Analytics to understand how the pages are used. It sets Google Analytics cookies in your browser and records page views along with a small number of events the site sends itself: opening a download button, following a link away from the site, opening an FAQ answer, starting or sending a form, switching the theme, how far down a page you scrolled, and which sections you reached. Google Analytics also receives ordinary technical details such as an IP address, page address and referring page, device and browser type, and approximate region.
These website events never include anything you type. The message and email address in a form are sent
only to Netlify when you submit them — Google Analytics is told that a form was started or sent, and
nothing about its contents. Invite links are treated the same way: an invite address is recorded as
/i/ with the code removed, so the code in your link is never sent to Google Analytics or
passed on when you follow a link away from that page.
The PlateDiary app does not use Google Analytics, and the website analytics are separate from your food-memory library, which never leaves your device.
When you choose
Permissions and device services
PlateDiary asks for access when a feature needs it. You can change permissions later in your device settings.
- Camera: snaps the table so PlateDiary can create saves on your device.
- Photos: imports existing food photos or saves an original or shared image when you ask.
- Location: remembers where you ate and groups nearby saves into moments. PlateDiary stores the saved location locally. Apple or Google platform services may receive the coordinates needed to find a place name or display map content.
- Microphone and speech recognition: lets you speak thoughts instead of typing. PlateDiary does not intentionally keep an audio recording, but your device's Apple or Google speech service may process audio or transcription data under its settings and privacy terms.
- Motion: lets saves tumble and slide when you use gravity mode. PlateDiary does not store or send your motion readings.
- Notifications: delivers announcements only after you grant permission and turn the option on.
Only what helps
How we use information
We use limited technical and support information to operate features you request, understand how app features are used, diagnose crashes and errors, improve reliability, deliver announcements you opted into, verify and restore Premium purchases, return GIF results you request, and answer your messages.
PlateDiary does not sell personal data, show third-party ads, or use its technical information to build advertising profiles or follow you across unrelated apps and websites.
Who helps
Service providers
PlateDiary relies on providers that process limited information for the purposes described above:
- Google Firebase for analytics, crash diagnostics, and opted-in messaging. Read Firebase's privacy and security information and the Google Privacy Policy.
- Google Analytics for website usage measurement on platediary.app only. Read how Google Analytics safeguards data and the Google Privacy Policy.
- Apple and Google platform services for app distribution and billing, permissions, speech recognition, maps, and notification delivery, depending on your device. Read Apple's Privacy Policy and the Google Privacy Policy.
- RevenueCat for Premium product information, purchase validation, restoration, and entitlement status. Read the RevenueCat Privacy Policy.
- Cloudflare runs and stores PlateDiary's invite service, and may process ordinary request information such as an IP address to deliver and protect it. Read the Cloudflare Privacy Policy.
- Klipy for optional trending and GIF search in Share Studio. Read the Klipy Privacy Policy.
- jsDelivr delivers the font file for a type theme that is not built into the app, and only when you pick one. Read the jsDelivr Privacy Policy.
- Expo provides app-update infrastructure. Read the Expo Privacy Policy.
- Netlify hosts platediary.app, maintains standard security and access records, and receives and stores messages submitted through the website's feedback form and contact form. Read the Netlify Privacy Policy.
These providers process information under their own terms and privacy practices.
How long
Retention and deletion
Your local memories remain on your device until you delete individual saves or moments, use PlateDiary's erase controls, or remove the app and its data. Locally cached GIFs and Share Studio designs are included in PlateDiary's backup, restore, and erase flows. Exported backups, widgets, images, and videos remain wherever you put them until you remove them there.
Invite records — a hashed device key, a code, credit counts, and whether a month was granted — are kept for as long as the promotion needs them to prevent the same device being rewarded twice, and are deleted when they are no longer needed for that purpose. On iPhone, the two yes/no flags described above are stored by Apple for this device and developer account and persist until Apple removes them; they are what makes "once ever" mean once ever, and they hold nothing else.
Firebase, RevenueCat, Cloudflare, Klipy, jsDelivr, the app stores, and other providers retain technical, request, and purchase information according to our service configuration, their operational or legal needs, and their policies. We keep support messages only as long as reasonably needed to answer the request, maintain an appropriate record, or meet legal obligations.
In your hands
Your choices
- Use device settings to allow or deny camera, photo, location, microphone, motion, and notification access.
- Turn announcements off in PlateDiary or in device notification settings.
- Block cookies or use a tracker-blocking extension or browser setting to stop the website's Google Analytics measurement, or install Google's Analytics opt-out browser add-on. Every page, form, and link on the site keeps working without it.
- Skip Share Studio's GIF picker to avoid sending trending or search requests to Klipy; bundled decorations and already-saved designs continue to work offline.
- Skip invites entirely — never open Invite friends and never enter a code — and PlateDiary contacts the invite service no times at all.
- Keep the built-in typeface, or a theme you have already downloaded, and PlateDiary never contacts the font CDN.
- Reset or delete your advertising identifier in your device's privacy settings. PlateDiary's usage and crash reports keep working without it, because nothing in the app depends on that identifier.
- Manage or cancel subscriptions through your App Store or Google Play account, and use Restore purchases in PlateDiary when needed.
- Delete saves, moments, backups, or the local library with PlateDiary's controls.
- Delete exported files from the place where you saved them.
- Remove PlateDiary and its local data through your device.
- Email us to ask a privacy question or request deletion of a support conversation.
Young people
Children's privacy
PlateDiary is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has sent us personal information, contact us so we can review and delete it where appropriate.
Across borders
International processing
Service providers may process limited technical or support information in countries other than the one where you live. Their processing is subject to their safeguards, contractual commitments, and applicable law.
If this changes
Changes to this policy
We may update this policy as PlateDiary changes. The latest version will appear on this page with a revised effective date. When practical, we will provide an appropriate notice of a material change.
Questions
Contact
PlateDiary is the operator of the app and website. For privacy questions, use the contact form and choose “My data or privacy”, or email platediary.app@gmail.com.