SayDish Privacy Policy
Effective date: 17 September 2026.
Who is responsible
SayDish is operated by Andriy Kovnatskyy, an individual based in Poland, who is responsible for the personal data processed for the service. Contact saydishsupport@gmail.com for privacy questions or requests.
Contact address: 45 Kolejowa Street, 01-210 Warsaw, Poland.
SayDish is for people aged 18 or over. This age requirement does not mean that the app verifies your age. If you believe someone under 18 has provided personal data through SayDish, contact us.
Information we collect and why
SayDish creates recipes from text or short voice recordings and lets you keep them in History and Favorites. It has no preference onboarding, allergy questionnaire, medical profile or therapeutic-personalization feature. Ingredient exclusions such as “without peanuts” are supported as cooking preferences, not as a medical assessment or an assurance of allergy safety. We process information to provide these features, manage accounts, respond to support requests, protect the service, prevent duplicate requests and reconcile service costs.
| Information | How we use it |
|---|---|
| Account information | Firebase Authentication processes your email/password or Sign in with Apple credentials, account identifier and sign-in information. Apple may provide a private relay email address. We do not store passwords in the recipe database. |
| Profile and settings | We store your account identifier, display name when supplied, sign-in provider, account status, timestamps, language, time zone, measurement preferences and service-access information in Firebase. |
| Requests and recipes | We process typed or transcribed requests and the settings used to create a recipe. Firebase stores saved recipes and Favorites, together with operational request records used for recovery and diagnosis. |
| Technical and accounting information | Request identifiers, encoded request fingerprints, outcomes, provider references, service usage and cost records help us avoid duplicate processing, investigate failures and reconcile unresolved requests. |
| Subscription information | Adapty processes your account identifier, subscription profile, app/device information and product or purchase status. Its integration is already active even though SayDish purchases are not currently enabled. We do not deliberately send Adapty your recipe requests, recordings, dietary settings or additional name/email attributes. |
| Support correspondence | Gmail receives your sender details and whatever you choose to include in a message to support. Contact Support does not automatically attach recipes, recordings or account details. |
The app also keeps session information, cached recipes and information needed to recover an unfinished request on your device. Recovery information may include request text; the server retention periods below do not automatically erase every local copy.
We do not ask you to provide medical information. We do, however, process the text and voice you voluntarily submit: audio is transcribed, and requests are used for recipe generation and handled as described below. If you include health information, it may therefore be transmitted to our providers and retained with your request or reflected in a recipe. We do not claim that it is automatically detected, removed or made nonsensitive by submission.
Please avoid diagnoses, medical histories and unnecessary personal information about yourself or others. You can express ordinary ingredient preferences without explaining a medical reason. If you have included information you want removed, contact saydishsupport@gmail.com to request erasure. Microphone permission and acceptance of the Terms are not explicit consent to processing health data. You can use text input without granting microphone access.
Legal bases for ordinary service data
Under the GDPR, we rely on:
- Performance of the service contract (Article 6(1)(b)) for the information needed to create your account, process the recipe requests you make, keep your saved recipes and Favorites, recover unfinished requests and provide account-related support. These features require the relevant account and request data.
- Legitimate interests (Article 6(1)(f)) in securing accounts, preventing abuse and duplicate processing, diagnosing failures and reconciling service costs, using proportionate operational records. These interests must be balanced against your rights; they do not justify unrelated tracking or indefinite retention of all request content. You may object by contacting us.
- Legal obligations (Article 6(1)(c)) when processing is necessary to handle requests to exercise your GDPR rights.
These bases concern ordinary service data. They do not, by themselves, authorize processing special-category health information or turn voluntarily submitted health details into ordinary cooking data.
Voice recordings and text
SayDish records audio using Apple's recording facilities after you grant microphone permission. It does not use Apple Speech Recognition. Each recording is limited to 60 seconds. Finishing a recording, or reaching the limit, sends it through our Firebase backend to OpenAI for transcription. A successful nonempty transcript automatically starts recipe generation. You can speak in different languages; the current release produces recipes in English.
You can cancel recording or use text instead. Recording does not continue in the background. Cancelling after submission cannot guarantee that a provider has not already received or processed the recording.
Audio is held in a temporary file on your device. The app removes that file when it normally finishes reading the recording for upload or when recording is cancelled. An abrupt shutdown can leave a temporary file until the voice feature next initializes or starts and cleans up its leftovers.
Our backend handles audio during the request and does not keep it in permanent audio storage. Audio and full transcripts are not deliberately written to diagnostic logs. The transcript is separate from the audio: it can remain in generation records and local request-recovery information, and its content may be reflected in a saved recipe.
These statements describe SayDish's handling of recordings. They are not a promise of immediate deletion from every provider system.
Service providers and processing locations
- Google Firebase and Google Cloud provide authentication, database storage, server processing, app-integrity checks and operational/security logging.
- OpenAI processes audio for transcription and request text with relevant recipe settings for recipe generation. We do not deliberately attach your email address or account identifier to these AI requests, but the content you submit may itself identify you.
- Adapty provides subscription-profile and product information and processes related device and service telemetry. Optional advertising-identifier collection, optional IP-address collection and advertising attribution are disabled in our integration. Providers may still process connection information necessary for their services.
- Apple provides Sign in with Apple, device attestation and App Store services. If subscriptions become available, Apple will handle purchase and billing transactions.
- Gmail handles correspondence sent to our support address.
The app does not integrate Firebase Analytics or Firebase Crashlytics and does not include advertising integrations. This does not mean that infrastructure logs or Adapty service telemetry are absent.
International processing
Providing SayDish involves sending account and recipe information to Google Firebase, audio and recipe requests to OpenAI, and subscription-profile information to Adapty, as described above. Support messages are handled through Gmail. Our Firebase infrastructure includes locations in the United States, so processing is not limited to Poland or the European Economic Area. Using these services can involve international transfers; data-protection rules may differ between countries.
The providers publish standard contractual safeguards for international processing. The Google Cloud terms for the Firebase services we use incorporate a Cloud Data Processing Addendum, which provides for transfer safeguards under applicable privacy law. OpenAI’s Data Processing Addendum is incorporated into its Services Agreement; for EEA data it provides for onward transfers using standard contractual clauses or an applicable adequacy decision. Adapty’s Data Processing Agreement forms part of its service terms and provides for standard contractual clauses where required. These standard arrangements do not imply a separately negotiated agreement, EEA-only processing or special retention privileges for SayDish.
Support uses a regular Gmail address, not a Google Workspace account. Google describes its international safeguards, including adequacy decisions and standard contractual clauses, in its transfer-framework information. We do not claim that a Workspace data-processing agreement covers this mailbox. Contact saydishsupport@gmail.com to request information about safeguards applicable to your data or an available copy, subject to necessary protection of confidential information.
Provider retention is separate from SayDish's retention schedule. OpenAI sharing for model feedback, evaluation/fine-tuning data and API inputs/outputs is disabled for the organization used by SayDish. Recipe generation requests disable response storage. These settings do not mean Zero Data Retention or rule out provider security/abuse-monitoring records. We have not confirmed special retention periods for all provider logs, backups or transaction records and do not promise that providers retain nothing. OpenAI describes its API data controls in its data-use documentation; Adapty describes its processing in its end-user privacy information. These general policies do not establish a special retention arrangement for SayDish. OpenAI’s standard documentation lists up to 30 days of abuse-monitoring retention for recipe-generation API content, with legal and safety exceptions; it lists no application-state or abuse-monitoring retention for the audio-transcription endpoint. These endpoint policies are distinct from other provider account, security or billing records.
Retention
| Information | Current retention and deletion behavior |
|---|---|
| Account profile, saved recipes and Favorites | Kept to provide your account and saved lists. Account deletion removes this content. Removing a Favorite does not delete the recipe. Deleting an individual recipe removes it from your lists immediately. Its stored content becomes eligible for physical erasure 30 days after the recorded deletion, subject to reliable ownership/completion records and no unresolved dependencies. A minimal deleted-result record may remain to prevent replay. |
| Completed generation request content | Request text, applied settings and diagnostic content become eligible for removal 30 days after confirmed completion, subject to checks that no active or deletion operation depends on them. This does not delete the saved recipe. Necessary accounting information is retained separately. |
| Detailed generation and transcription records | Details become eligible for removal 90 days after confirmed completion, only when the request and its costs are reconciled. Reconciliation is a condition for removal; it does not start a separate 90-day period. A smaller record remains to prevent duplicate processing and retain necessary outcome and cost information. |
| Minimal request records and deleted-account markers | These have no automatic expiry while needed to prevent replay or account restoration. The service does not yet have the verified safeguards necessary to remove them safely. They contain no recipe/request content and are not anonymous records. |
| Historical usage counters and cost summaries | Historical daily rate counters become eligible 30 days after the UTC day ends, only when dependency checks pass. Separately reconciled historical cost summaries are eligible 90 days after documented reconciliation. The current shared accounting record is not erased under these rules. Missing proof or unresolved accounting can prevent cleanup. |
| Unfinished operations and unresolved costs | These are not erased solely because a retention period has passed. Information needed to resolve them remains. Eligible request text may be removed separately without discarding the unresolved accounting record. |
| Support email | Ordinary correspondence is deleted manually 12 months after the case closes. Unnecessary attachments are removed sooner. Relevant material may be retained for a specific unresolved dispute, security investigation or legal requirement, with the need reviewed every 90 days. Individual privacy requests are assessed separately. |
Cleanup runs daily in batches. Thirty and ninety days are eligibility thresholds, not promises of deletion at an exact moment. Unresolved dependencies, missing reliable completion dates, processing backlogs or service interruptions can delay removal.
Infrastructure logs and provider copies have separate retention. The confirmed Google Cloud settings are 30 days for standard logs and 400 days for required audit logs. Our database has no scheduled managed backups, and extended point-in-time recovery is disabled; its configured version-history window is one hour. These settings do not establish a deletion deadline for every export, local cache or copy held by a provider.
Deleting your account
Use Settings → Delete Account. You may need to authenticate again. The process blocks new work for the account, handles any active requests, removes your Firebase profile, recipes, Favorites and operational generation records, and deletes your Firebase Authentication account. The app clears its account state. Where required, the Apple sign-in flow also revokes authorization.
The process requests deletion of the associated Adapty profile. If external cleanup fails, it is retried and unresolved work remains pending for follow-up. Account removal in one system does not mean every provider has completed its own processing at the same moment.
A minimal marker linked to the former account identifier remains to prevent the deleted account from being recreated by delayed activity. Existing request records retain necessary duplicate-prevention and accounting information with the owner reference replaced by a pseudonym. Pseudonymized information is not anonymous. These residual records follow the retention explanation above.
Deletion of an Adapty profile does not establish that every Apple transaction, provider backup or later subscription event has been erased.
Deleting your SayDish account does not cancel an Apple subscription. Manage subscriptions separately in Apple's subscription settings. You can delete your SayDish account without cancelling a subscription first. See Apple's cancellation instructions.
Your rights and choices
Subject to applicable conditions, you may request access, correction, erasure, restriction or portability of your personal data, and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing.
Contact saydishsupport@gmail.com. We may need proportionate information to verify your identity; do not send passwords or authentication codes. We will respond within the applicable legal period, normally one month under the GDPR, and explain any permitted extension within that period.
You may complain to a competent data-protection authority, including Poland's President of the Personal Data Protection Office (UODO). See UODO contact information and the European Data Protection Board's rights guidance.
Automated recipe and security checks can reject or delay a request. You can contact support about a restriction. SayDish does not provide medical assessments.
Changes to this policy
We will update this policy when our processing changes and provide notice where required. A policy update does not itself authorize unrelated processing or start a paid subscription.