This is a translation. If it differs from the French version, the French version prevails. Version française
Privacy policy
Last updated: 15 September 2026
DinnerFromHere collects as little data as possible: the app can be used without an account, without advertising and without any audience-measurement tool. This page explains what is processed, why, for how long, and how to exercise your rights.
Who is responsible for your data
Romain Couzon, sole trader (entrepreneur individuel), SIRET 881 477 343 00019, 245 avenue Marie de Montpellier, 34000 Montpellier, France. Contact: [email protected].
Data processed
Technical account: a random identifier and a session token (the server only keeps an unreadable fingerprint of it). No name, email or phone number is requested to use the app.
Sign in with Apple or Google (optional, required for Premium): the identifier this service sends us for your account and, if Google provides it, your email address. We never receive your password.
Photos of ingredients: sent to the server for analysis, processed in memory, stripped of their metadata (including location) and never kept after analysis.
Inventory, preferences and recipes: the ingredients you confirm, your choices (portions, time, Thermomix model), the recipes suggested, chosen or reported.
Purchases: transaction or purchase token identifier, product, validity dates, and a random billing account identifier sent to the store. Payment is processed by the App Store or Google Play: we never receive any banking data.
Service usage: number of analyses and recipes generated in the month, and, for each operation, its duration, success and estimated cost.
App verification: a token proving that the request comes from the genuine app on a real device (Firebase App Check, with Apple's App Attest or Google's Play Integrity).
Technical data: IP address, kept in memory for at most one hour to limit account creation, and server error logs.
Who processes this data for us
- Hetzner Online GmbH: server hosting, in Nuremberg (Germany).
- Apple and Google: sign-in with Apple or Google, app verification, and purchases on the App Store or Google Play, each under its own privacy policy.
- Google (Firebase App Check): verifying that requests come from the genuine app.
- Image analysis provider: today, analysis is simulated and no photo leaves our server. Once real analysis is enabled, photos will be sent to OpenAI for analysis, without being used to train its models; the app will indicate this before sending. OpenAI is based in the United States: this transfer is governed by the safeguards provided under the GDPR (standard contractual clauses or the EU–US Data Privacy Framework).
- Backblaze: once off-server copying is enabled, storage of encrypted backups that this provider cannot read.
- Cloudflare: hosting of this website, domain name resolution and delivery of emails sent to support.
We do not sell or rent your data, and do not use it for advertising purposes.
How long
- Account data (inventory, preferences, recipes, usage, Apple or Google identities): as long as you do not delete your data.
- Session: 90 days, extended with use, never more than one year after creation.
- Photos: the time it takes to analyse them, a few seconds.
- Encrypted backups: 14 days on the server, and about 32 days for the off-server copy once enabled. Deleted data therefore also disappears from backups within these timeframes.
- Proof of purchase: after account deletion, kept with no link to your other data, for proof of transactions and abuse prevention, for the period required by law.
- Account change log (when a device joins an existing account): 12 months.
Your rights
You can access your data, rectify it, erase it, retrieve it, object to certain processing or request that it be restricted:
- Export your data: Profile → "Export my data".
- Delete your data: Profile → "Delete my data", or see the dedicated page.
- For any other request: [email protected]. We reply within one month.
If you believe your rights are not being respected, you may contact the CNIL, the French data protection authority (cnil.fr).
Security
Exchanges are encrypted (HTTPS). The session token is stored in your device's protected storage area. Backups are encrypted with a key that is not stored on the server.
Changes
This page is updated whenever something changes; the date shown at the top is authoritative.