Effective date: 28 June 2026 · Last updated: 28 July 2026
This Privacy Policy describes how DishDash ("we", "us", or "our") collects, uses, and protects information when you use the DishDash mobile application ("the App"). By using the App you agree to the practices described in this policy.
Account information
Content you create
Recipe generation data
When you generate a recipe, the request is sent through our servers to Google Gemini to produce a result. Depending on which generator you use, that request may include: what you typed (e.g., "pasta, under 30 minutes, vegetarian"), the filters you selected (diet, cuisine, calorie or nutrition targets), items from your pantry inventory, and your chosen recipe language. This data is processed by Google under Google's Privacy Policy. We do not store your prompts beyond what is necessary to display the result.
Nutrition lookups
To show calories and macros for a recipe, the ingredient lines of that recipe are sent from our servers to USDA FoodData Central, a public food-composition database operated by the U.S. Department of Agriculture, to be matched against known foods. Only the ingredient text is sent — no account identifier, and nothing that identifies you.
Health & fitness data (Tracker)
The Tracker can show your daily step count. With your permission it reads today's aggregated step total from Health Connect, the phone's central health store, so that steps already recorded by your phone, watch, or another fitness app are counted once. If Health Connect is unavailable or you decline, the app can instead count steps from your device's built-in step-counter sensor (the Physical activity permission), or you can enter progress manually — the Tracker works without either permission.
The Tracker also records the water and calorie totals and daily goals you enter yourself.
All of this health and fitness data is stored only on your device, in the app's private storage. It is never uploaded to our servers, never written to your cloud account, never shared with any third party, and never used for advertising or ad targeting. We cannot see it. Step data read from Health Connect is used solely to display your progress in the Tracker, is not retained beyond the day it belongs to, and is removed when you clear the app's data or uninstall the app. You can withdraw Health Connect access at any time in Health Connect's own settings, and revoke the Physical activity permission in Android Settings.
Microphone & voice input
Some screens offer voice input — adding pantry items by speaking, and dictating a recipe request. The microphone is active only while you are using that voice control, and only after you grant the microphone permission. The audio is passed to your device's speech-recognition service (on most devices this is provided by Google) which converts it to text; we receive only the resulting text, and we do not record, store, or transmit audio ourselves. Voice input is entirely optional — every screen that offers it also accepts typing.
Using the app as a guest
You can browse the app as a guest without creating an account. In guest mode no account is created and no personal data is stored in our cloud; features that require an account (such as saving to your recipe book) are unavailable, and anything the app keeps — such as Tracker progress and your language choice — stays on your device.
Usage quota
We track the number of recipe generations per user per day to enforce free-tier limits. This counter is stored in Firebase and is not shared with third parties.
Advertising
The App uses Google AdMob to show rewarded ads (which unlock additional recipe generations). The Google Mobile Ads SDK collects your device's Advertising ID (ad ID) and related ad-interaction data to serve ads, measure ad performance, and detect and prevent ad fraud. You can reset your Advertising ID or opt out of ad personalisation at any time in your device's Google Settings → Ads.
Device & usage information
Google's Firebase services (Authentication, Firestore, and Cloud Functions) process technical information such as your IP address as needed to operate the app securely and reliably. The App does not use Firebase Analytics or Crashlytics, and we do not maintain our own analytics on your in-app behaviour.
We do not use your health and fitness data for advertising, profiling, or any purpose other than showing you your own progress in the Tracker.
We do not sell, rent, or trade your personal information. We share data only with:
We never share your health and fitness data. Step, water, and calorie data does not leave your device, and is not disclosed to any of the parties above — including our advertising partner.
We may disclose information if required by law or to protect the rights and safety of our users.
Comments you post on community recipes are visible to all users (including guests). Comments include your display name and profile photo. You can delete your own comments at any time within the app. Other users may report comments that violate our guidelines; reports are reviewed and are not public.
Your data is retained as long as your account exists. When you delete your account (Settings → Delete Account), we permanently delete your saved recipes, meal plans, shopping lists, pantry inventory, cooking history, and your Firebase account. Community comments you posted are also removed. Advertising identifiers and related ad data are retained by Google AdMob in line with Google's data retention policies.
Health and fitness data (steps, water, calories, and your daily goals) is held only in the app's private storage on your device, for as long as the app is installed. Step totals read from Health Connect are kept only for the day they belong to. You can erase all of it by clearing the app's storage in Android Settings, or by uninstalling the app; because it is never uploaded, there is nothing for us to delete on our side.
DishDash is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
All data is transmitted over HTTPS. Firebase security rules ensure that each user can only access their own data. Account passwords are handled and stored securely by Firebase Authentication and are never visible to us in plain text. We regularly review our security practices, but no system is 100% secure.
We may update this policy from time to time. Material changes will be announced in the app or via email. Continued use of the app after a change constitutes acceptance of the updated policy. The "Last updated" date at the top of this page always reflects the most recent revision.
If you have questions about this Privacy Policy or want to exercise your data rights, contact us at:
support@dishdash.org