This Privacy Policy explains how Clean Dish handles information when you use the Clean Dish mobile application, website, and related services.
The controller responsible for processing personal data through Clean Dish is Mustafa Ileri. The controller can be contacted at admin@cleandish.app.
Privacy at a glance
- We use your preferences to personalize recipes, plans, and shopping lists.
- Allergen information is optional and used with explicit consent.
- Pantry photos are processed only when you choose photo detection and are not stored in our database or object storage.
- We do not sell personal data or use it for third-party advertising.
- Where possible, usage analysis is aggregated, anonymized, or separated from direct identifiers.
Information we collect
We may process these categories of information:
| Category | Examples | Main use |
|---|---|---|
| Account and device identifiers | App and Firebase authentication identifiers, language, basic device or request data | Operate, secure, and remember your app profile |
| Analytics and diagnostics | App-instance or vendor identifier, approximate location, device and app information, screen views, feature interactions, and limited SDK diagnostics | Measure app usage, maintain reliability, and improve features; not advertising or cross-app tracking |
| Food and preference information | Allergens, diet, avoided or preferred ingredients, and cuisine preferences | Personalize recipes, meal plans, and safety-related filtering |
| App activity | Saved recipes, meal plans, shopping-list state, recipe interactions, cooking feedback, notes | Keep your app experience consistent and improve recommendations |
| Pantry photos | Images you choose to send for ingredient detection | Temporarily identify visible food ingredients; we do not store the photo |
| Support communications | Information you include when contacting us | Respond to support, privacy, and account requests |
How we use information
We use information to:
- provide personalized recipe discovery, meal planning, and shopping lists;
- apply saved food preferences and exclusions;
- analyze pantry photos when you request that feature;
- operate, maintain, debug, and secure the service;
- respond to support and privacy requests; and
- comply with applicable legal obligations.
De-identification and analytics
Clean Dish generally uses app or authentication identifiers that do not directly show your name or email address. If information can still be linked to your app profile or installation, we continue to treat it as personal data.
We may analyze service usage in aggregated, anonymized, or otherwise de-identified form where reasonably possible, for example to understand which features work well or where errors occur. We do not use aggregated or anonymized information to identify you.
Legal bases
Where the GDPR applies, we rely on the following legal bases:
- Performance of the service: Article 6(1)(b) GDPR for data needed to provide the features you request, such as saved non-health preferences, recipe activity, meal plans, and shopping-list state.
- Explicit consent: Articles 6(1)(a) and 9(2)(a) GDPR for optional allergen information that may constitute health data. This information is not required to use Clean Dish.
- Consent for optional photo analysis: Article 6(1)(a) GDPR when you choose to send a pantry photo for AI analysis.
- Legitimate interests: Article 6(1)(f) GDPR for limited diagnostics, security, abuse prevention, and maintaining a reliable service.
- Legal obligations: Article 6(1)(c) GDPR where processing is necessary to meet an applicable legal requirement.
You may withdraw consent at any time. Withdrawal does not affect processing that was lawful before withdrawal.
Service providers
We rely on service providers that process information on our behalf or provide platform services. These currently include Amazon Web Services for hosting, Firebase Authentication for app authentication, Firebase Analytics and Google Analytics for usage measurement, and OpenAI for optional pantry image analysis.
These providers handle information under their own terms and privacy policies and contractual data-protection obligations. We do not sell personal data or use it for third-party advertising.
Pantry image requests to OpenAI are configured with response storage disabled. Under OpenAI's default API controls, abuse-monitoring logs may still contain customer content and be retained for up to 30 days, unless a longer period is legally required.
Retention and security
Saved preferences and app activity are generally retained while the associated app profile remains active, until you reset or delete the relevant data, or until the data is no longer needed to provide the service. Pantry photos are processed temporarily and are not retained in our database or object storage. Support correspondence and limited security records may be retained as needed to resolve the request, protect the service, establish or defend legal claims, and meet legal obligations.
We use technical and organizational safeguards intended to protect information. No storage or transmission method is completely secure.
Your choices and data-protection rights
You can update or reset saved preferences from the Profile screen. The “Delete All My Data” action permanently deletes the profile associated with your installation, including preferences, favorites, plans, shopping lists, recipe notes, feedback, cooking history, reports, interactions, recommendation data, and the associated authentication identity.
You can also contact us to exercise rights that apply to you, including access, correction, deletion, restriction, objection, data portability, and withdrawal of consent. Requests may require reasonable verification using the anonymous identifier associated with your installation.
Camera access is optional and can be changed in your device settings. You can continue using manual pantry entry without camera access.
You also have the right to lodge a complaint with a competent data-protection supervisory authority, including the authority responsible for your place of residence or the controller’s establishment.
Children
Clean Dish is intended for adults aged 18 and over. We do not knowingly offer the service to or collect personal data from children.
International processing
Some service providers may process information outside Germany or the European Economic Area. Where required, transfers are protected by an adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful transfer mechanism together with appropriate safeguards.
Automated processing and policy changes
Clean Dish uses automated processing to personalize recipe suggestions and identify ingredients in optional pantry photos. These features do not make decisions that produce legal or similarly significant effects about you.
We may update this policy as the service changes. The effective date above identifies the current version.
Contact
For privacy questions or requests, email admin@cleandish.app.