Privacy Policy

Last updated: 1 August 2026

The short version.

  • You do not need an account to use DinnerSwipe.
  • We use your location only to find restaurants near you. The person you are swiping with never sees it.
  • The person you are swiping with never sees your swipes — only a restaurant you both liked.
  • Ads never use your location, dinner choices, partner, or restaurant data.
  • Anonymous sessions are deleted within 24 hours.

This policy explains what DinnerSwipe ("we", "us") collects when you use the DinnerSwipe mobile app or website, why we collect it, who we share it with, and the choices you have. It applies to both the app and this site.

1. Using DinnerSwipe without an account

DinnerSwipe is anonymous by default. You can create a room, share it, swipe, and get a match without giving us a name, an email address, or a password. Creating an account is optional and only adds the features described in section 3.

2. What we collect when you use a session

Location

To show you restaurants that are actually nearby, we need a starting point. You give us one in one of two ways: by granting the app location permission (used only while you are using the app), or by typing an area or address yourself.

  • Your starting point is used to search for restaurants for that session.
  • We store rounded coordinates for caching, so repeat searches in the same area do not re-query our restaurant providers.
  • The other person in your session never receives your coordinates. This is enforced in our database, not just in the app: the view the app reads from does not contain the location field at all.
  • The precise starting point is generalised or deleted once the session ends.
  • We do not track your location in the background, and we do not build a location history.

Your swipes

We record which restaurants you liked or passed on, so we can tell when you and the other person have liked the same one.

  • You can only ever read your own swipes. This is enforced by database row-level security. The other participant cannot retrieve them, and neither can the app on their behalf.
  • The comparison happens on our server. The only result either of you sees is a mutual match.
  • Swipes are never used for advertising.

Session data

We store the room code, which mode you chose (eating out or ordering in), your filters, the deck of restaurants generated for the session, and its outcome.

3. What we collect if you create an account

An account is optional. If you create one, we additionally store:

  • Your email address and password. Passwords are hashed by our authentication provider; we never see or store them in readable form.
  • Your saved preferences — default mode, search radius, price range, dietary exclusions, cuisine preferences, and whether to show only places that are open.
  • Your dinner history — the general area label (for example, a neighbourhood name), the outcome, and the name of the restaurant you matched on. This does not include coordinates and does not include your swipes.
  • Push notification tokens, if you enable notifications, so we can tell you when your partner joins or you get a match. These tokens are stored encrypted.

Beta note. During the current beta, email confirmation is switched off so sign-up is as fast as possible. That means email addresses are not verified. Do not rely on your DinnerSwipe account as proof of an email address, and use a password you do not reuse elsewhere.

4. Advertising

The mobile app shows ads through Google AdMob. To do this, Google may access advertising identifiers and device information from your device, subject to your consent and your device settings.

We do not give advertisers your DinnerSwipe data. Ads never use your location, your dinner choices, who you are swiping with, or the restaurants you were shown. Nothing from sections 2 or 3 of this policy is shared with Google for advertising purposes.

You control ads in these ways:

  • In the app, open Account → Ad privacy choices to change your advertising consent at any time. Where the law requires a consent choice (for example in the UK, EU, and Switzerland), we ask before any personalised ads are shown.
  • On iOS, Settings → Privacy & Security → Tracking controls whether apps may request to track you.
  • On Android, Settings → Google → Ads lets you delete or reset your advertising ID and opt out of ad personalisation.

Under some privacy laws, showing personalised advertising counts as "sharing" personal information, even though no money changes hands. We do not sell your personal information. If you turn off personalised ads using the controls above, this sharing stops. You will still see ads; they will just be less relevant.

5. Crash and diagnostic data

We use Sentry to record crashes and errors so we can fix them. These reports include technical information such as the error, your app version, and your device type. They are configured to exclude coordinates, restaurant provider data, and your swipe history.

6. Restaurant information

Restaurant listings come from third-party providers — currently Yelp, Google Places, Foursquare, and OpenStreetMap, depending on the session.

  • These providers are called only from our servers, never from your device or browser. They do not receive your device details or your identity.
  • What they receive is a search area and filters for the session.
  • We cache the restaurant details they return for at most 24 hours.

7. Who we share data with

We do not sell your personal information. We share data only with the service providers we need to run DinnerSwipe:

ProviderWhat they handle
SupabaseDatabase, authentication, and server functions
CloudflareWebsite hosting and delivery
Google AdMobAdvertising in the mobile app (see section 4)
SentryCrash and error reporting
ExpoPush notification delivery and app updates
Yelp, Google Places, Foursquare, OpenStreetMapRestaurant listings (server-side only)

We may also disclose information where we are legally required to do so.

8. How long we keep things

DataKept for
A room waiting for someone to join15 minutes, then it expires
An active anonymous session1 hour, then it expires
A finished anonymous session24 hours, then deleted or anonymised
Cached restaurant detailsAt most 24 hours
Restaurant reference IDsKept, where provider terms allow
Account details, preferences, and dinner historyUntil you delete your account

9. Your rights and choices

Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to object to or restrict how we use it, and to opt out of personalised advertising. Exercising these rights will never cause us to treat you differently.

  • Location: revoke the permission in your device settings at any time. You can still use DinnerSwipe by typing an area instead.
  • Notifications: turn them off in your device settings, or from Account in the app.
  • Ads: use the controls in section 4.
  • Your account and all its data: email privacy@dinner-swipe.app from your account's email address and we will delete it.
  • Anything else: email privacy@dinner-swipe.app. We aim to respond within 30 days.

If you used DinnerSwipe anonymously, we usually have no way to identify which data was yours, so we may not be able to act on a request. Anonymous data is deleted automatically on the schedule in section 8.

If you are in the UK or EU, you also have the right to complain to your local data protection authority.

10. Children

DinnerSwipe is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contactprivacy@dinner-swipe.app and we will delete it.

11. Purchases

If we offer a paid ad-free upgrade, payment is handled entirely by the Apple App Store or Google Play. We never receive your card details. We receive only a record of whether your upgrade is active.

12. International transfers

Our service providers operate internationally, so your information may be processed in countries other than your own, including the United States. Where required, we rely on appropriate safeguards for those transfers.

13. Security

Access to your data is restricted at the database level rather than only in the app, so the privacy rules described above hold even if a client is modified. Push tokens are stored encrypted. No system is perfectly secure, but we design for the principle that data we do not keep cannot leak.

14. Changes to this policy

If we make a material change, we will update the date at the top of this page and, where appropriate, tell you in the app.

15. Contact

Privacy questions and data requests: privacy@dinner-swipe.app
Everything else: support@dinner-swipe.app