Privacy policy
Last updated 21 September 2026
Half Plate is made by Dobreon sp. z o.o., a company registered in Poland, which is the controller of the personal data described here. Write to support@dobreon.com about anything on this page.
The short version: the cooking half of the app needs nothing from you. The recipe library, the week's plan, the shopping list, cooking mode and the food diary all work with no account and no connection, and used that way the app sends us nothing at all. Two things are the exception, and each says so before it happens: signing in, which adds syncing, and asking the assistant, which sends that one request to an AI service.
Signing in is optional, and what it changes
The app opens on Kitchen with no account and no questions in front of it. Planning a week, cooking from it, shopping, saving a recipe, adapting one by hand and keeping a diary all work signed out.
Signing in adds syncing between your devices. You can sign in with Apple, with Google, or with an email address and a password, and this is handled by Firebase Authentication, which is Google. Apple and Google sign-ins involve no password at all. An email account has one and we never see it: the app hands it to Firebase, which stores only a salted hash, and a forgotten one is reset by a link Firebase emails you — there is nothing for us to look up. What Firebase holds is your email address, the identifier the provider gives us or the password hash, and the times you signed in. Signing in with Google tells Google that you use Half Plate; we receive your email address and name and nothing else, and we never ask for access to anything in your Google account. If you use Apple's Hide My Email, the relay address is the only one we ever see.
Before you sign in, the app makes an anonymous Firebase account for your phone the first time it needs one — that is what the assistant's free passes are counted against. Signing in links that guest rather than replacing it, so nothing you made is lost.
What syncing stores, and where
With an account, what you make is kept in Cloud Firestore, Google's database, so it can reach your other devices:
- Your plans, your own recipe versions, what you cooked and rated, and the recipes you saved.
- Your shopping list and My food — what is at home and what is still to buy.
- Your diary: meals, portions, water, activity, weights, daily targets and the profile behind them.
The database is in Frankfurt and the data stays in the European Economic Area. Your records are stored underneath your own account identifier, and the security rules refuse any read or write that crosses from one account into another, or that names a different owner from the one asking.
When you delete something it is marked deleted rather than removed outright, so the deletion reaches your other devices instead of the row quietly reappearing from one of them. Those markers are cleared from the server after 90 days.
The assistant, and what each request sends
Several features ask an AI service outside the app: adapting a recipe in Recipe Lab, reading a shelf or a meal from a photograph, reading a recipe you paste or photograph, the ideas in Food Explorer, and Chat.
Nothing is sent until you agree. The first time any of them would send something, a sheet says what that request carries, what it never carries, and who receives it. «Not now» sends nothing and leaves every manual path open. You can take the agreement back at any time in You → Assistant, and from then on nothing is sent until it is given again — including a photograph that was already waiting for a connection.
| What you asked for | What is sent |
|---|---|
| Adapt a recipe (Recipe Lab) | The recipe, the change you asked for, your food limits and cooking conditions. |
| Read a shelf | The photographs you just took of your shelves. |
| Read a meal | The photograph you just took, and a note if you add one. |
| Bring a recipe in | The text you pasted, or the photograph of the recipe. |
| Food Explorer | The dishes the app itself chose, and the foods you have cooked with. The choosing happens on your phone; the request is only for the words under each idea. |
| Chat | Your message, and what you chose to attach to it. |
What is never sent, whatever you ask: your name, your weight, anything from Apple Health, your diary, and any photograph you did not attach to that request. A photograph in Chat is a question and is never logged as a meal by itself.
Who receives it. Our own server, and from there the model provider: Google (Gemini) or OpenAI. We name both because the server can be pointed at either — Google answers ordinarily, and OpenAI is the fallback when it cannot. Both process the request under their API terms, which exclude data sent through the API from being used to train their models; both keep it for a limited time for abuse checks, under their own policies.
- Our server does not store what you send. It holds the request in memory for as long as it takes to answer and writes it nowhere. What we log is operational only: which model answered, how long it took, what it cost in tokens, and whether the answer passed the app's own checks. Never the photograph, never the message, never the food.
- We do count the requests. One record per account holding how many of each kind have been used, against the free passes and the daily and monthly ceilings, and the times of the last few. Nothing about the content. The app cannot read or change that record — anything that could would let a client erase its own usage — and it goes when you delete your account.
- Photographs stay with you. The copy on your phone is the only lasting one; it goes when you delete the meal.
- The legal basis is the performance of the contract: you asked the app to do something it cannot do on the phone.
The numbers are never the model's. Calories, macronutrients, plate scores and amounts are all counted by us from USDA FoodData Central, on confirmed ingredients — the request schemas have no numeric fields for the model to put a figure in. It proposes composition, steps and wording; the arithmetic is ours.
Proving the app is the app
Every assisted request costs us money, so the server checks two things before it spends any: who is asking, and what is asking. The second uses Apple's App Attest. Your phone's secure hardware signs a statement that this really is Half Plate, unmodified, on a real device; Apple and then Google's App Check confirm that signature, and our server sees only a yes or a no. What travels is a cryptographic assertion about the app and the device — nothing about you, nothing about your food. It carries no advertising identifier, the key is created inside your phone and never leaves it, and Apple's design gives every app its own key, so it cannot be used to recognise you across apps.
Who else handles your data
Two companies process data on our behalf, and no others.
- Vercel hosts our server. As every host does, it records the technical shape of each request — the IP address it came from, the time, the size, the status code — for security and abuse prevention, and keeps that under its own retention schedule. What you sent is never written to disk there.
- Google, through Firebase, handles signing in and holds your email address and sign-in history; stores what you make, in Frankfurt; and answers assisted requests through Gemini. OpenAI answers them when Google cannot.
Apple appears as a sign-in provider rather than as a processor: it acts on its own account when it tells us who you are, and its own policy covers that. Google wears both hats — processor for everything above, and its own account when it identifies you.
What you make is stored inside the European Economic Area, in Frankfurt. Vercel, Google and OpenAI are United States companies, so an assisted request and signing in transfer data outside the EEA. Those transfers rest on the standard contractual clauses in our agreements with each of them.
Barcodes and the food database
Scanning a barcode sends the number — and nothing else — to Open Food Facts, a free public food database, to look the product up. Searching it by name sends the words you type, in the same way and to the same place. No photograph is sent, no account is needed and nothing identifies you or your device beyond what any web request carries. Open Food Facts is run by a French non-profit association and its servers are in the European Union. If the product is not there, the app opens the manual form instead.
Apple Health
Health is off until you switch it on, and switching it on asks your permission separately. With it on the app reads your body mass, step count, active energy, workouts and sleep, so that a connected scale and your day's walking do not have to be typed in twice. The app writes nothing to Health, and nothing from Health is ever sent anywhere — not to our server, not to a model. It is read on the phone and shown on the phone.
Notifications
Notifications are off until you allow them, and every one of them is something you switched on: a reminder to plan the week, a nudge before a meal you planned, a cooking timer that finished. They are scheduled on your phone; we do not send push messages and have nothing to send them from.
Purchases
Subscriptions and message packs are bought through Apple. We never see your payment details. What our server receives is the signed proof of purchase from Apple, which tells it whether the account is on Pro and, for a pack, that a particular transaction was paid for — the identifier of that transaction is remembered so that the same receipt is not credited twice.
What we never collect
There is no analytics SDK, no crash reporter, no advertising identifier and no third-party tracker of any kind in the app. Nothing you log or cook is sold, shared with advertisers, or used to build a profile of you. We do not use what you make to train anything.
Children
Half Plate is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has an account with us, write to us and we will remove it.
Your rights
Under the GDPR you can ask for a copy of your data, ask for it to be corrected or erased, object to processing or ask that it be restricted, and complain to a supervisory authority — in Poland, the President of the Personal Data Protection Office (UODO).
Two of these you do not have to ask us for. Export is in the app, under Progress → Reports, and produces your own data as a file. Deletion is in the app too, behind your avatar: it erases what you made from our database and then your identity from our sign-in provider. It happens when you tap it and cannot be undone. If you never signed in, there is nothing of yours on our side at all — deleting the app deletes everything.
Changes
If this page changes materially we will say so in the app before the change takes effect. The date at the top is the last change of any kind.