Privacy Policy
- There is no account. We never ask for your name, email or phone number.
- Your recipes, lists and plans are stored on our servers under an anonymous ID, so they are there when you open the app.
- We do not sell your data, show ads, or track you across other companies' apps and websites.
- To have everything deleted, email us from the app. Details are in Deleting your data.
Who we are
DishVault is made by Qajim Labs ("we", "us"). We are responsible for the personal data described here. You can reach us at hello@qajimlabs.com.
What we store, and why
| Data | Why |
|---|---|
| An anonymous app ID, created on your phone the first time you open DishVault | It is how our servers know which recipes are yours. It is a random string, not your name or Apple Account. |
| What you save: recipes (titles, ingredients, steps, your notes, links to the original and to its photo), collections, your shopping list and your meal plan | To keep them for you and show them in the app and its widgets. |
| Your app settings: the language you chose and your region | To show the app, and translate recipes, in your language and units. |
| A record of each import: the link, whether it worked, and the error if it did not | To find and fix sites and platforms that stop importing. |
| Whether you are subscribed, as reported by Apple through RevenueCat | To unlock the app. We never see your payment details; Apple handles payment. |
| How the app is used: screens opened, features used, app version, device model, iOS version and language, tied to the anonymous ID | To understand what works and what to improve. Never used for advertising. |
What leaves your phone when you add a recipe
- A link you paste or share: our server fetches the page to read the recipe from it.
- A page shared from Safari: the recipe data on that page and its visible text are sent to our server, only when you share it.
- Photos and PDF pages: sent to our server and to an AI model to read the recipe from them. They are not stored after the recipe has been read.
- Recipe text can be sent to an AI model to pull the ingredients and steps out of it, or to translate it into your language. The model returns the result and is not given your app ID.
Who processes it for us
We use these service providers. Each one processes data only to provide its service to us.
- Cloudflare: runs our servers and stores your data.
- RevenueCat: manages subscriptions and creates the anonymous app ID.
- PostHog (United States): app usage analytics.
- OpenRouter, and the AI model providers it routes requests to: reading and translating recipes.
- Apple: the App Store, payments, and the sign-in to your Apple Account that subscriptions use.
Some of these providers are based in, or process data in, the United States and other countries outside your own. Where the law requires it, those transfers are covered by safeguards such as the European Commission's Standard Contractual Clauses.
What stays on your phone
- Reminders are scheduled on your phone. Nothing about them is sent to us, and we use no push notification service.
- Widgets read a copy of today's meals and your list that the app keeps on your phone.
Legal basis
If you are in the European Economic Area or the United Kingdom: we process the data you save, your settings and your subscription status to provide the app you asked for (performance of a contract). We keep import records and usage analytics because we have a legitimate interest in keeping DishVault working and improving it. You can object to analytics at any time by emailing us.
Deleting your data
- Deleting a recipe, collection, list item or planned meal in the app deletes it from our servers.
- To delete everything we hold about you, open DishVault, go to Settings, tap Send feedback and ask. The email already contains your anonymous app ID, which is the only way we can find your data. We delete it within 30 days and confirm by email.
- Deleting the app from your phone does not delete what is stored on our servers. Ask us, as above.
Your rights
Depending on where you live, you can ask to access, correct, export or delete your data, and to restrict or object to how we use it. Email hello@qajimlabs.com from the app as described above, so we can match the request to your data. If you are in the EEA or UK you can also complain to your local data protection authority. California residents: we do not sell or share personal information as those terms are defined by the CCPA.
How long we keep it
We keep your data while you use DishVault and delete it when you ask us to. Anything you delete in the app is deleted from our servers at that point.
Children
DishVault is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has used the app, contact us and we will delete the data.
Changes
If we change this policy we will update this page and its date. For a significant change we will also tell you in the app.
Contact
Qajim Labs, hello@qajimlabs.com