Privacy Policy
Last Updated: 29 June 2026
Dishly is a registered trademark in England and Wales and is operated by Novodian Group Ltd. (the "Data Controller").
Dishly is a free application provided "as is". This Privacy Policy explains how we collect, use, share, and protect personal data when you use the Service.
1. Information We Collect
We collect the following categories of personal data:
Account Info: Email address, username, password (securely hashed), and date of birth (for age verification).
Optional Profile Info: Biography, profile photo, language preferences.
Food Preferences: Allergies and dietary requirements. This may include special category (health) data under GDPR, which we process only with your explicit consent. This data is retained only for as long as your account remains active and is deleted upon account deletion or consent withdrawal.
User Content: Comments, recipes, posts, and saved/liked content.
Technical Data: Device, diagnostic, and usage data (analytics, crash reporting).
2. How We Use Your Information
We use personal data to:
Create accounts, verify age eligibility, and enable account recovery.
Provide, operate, and improve the Service.
Personalise content and recommendations (including profiling based on dietary preferences; you may disable this in settings).
Ensure security, prevent abuse, and send essential service communications.
Send push notifications (where enabled in device settings).
3. Legal Basis (UK GDPR / GDPR)
We process personal data based on: Contract (to provide the Service), Consent (for dietary preferences), Legal obligation (fraud prevention), and Legitimate interests (analytics and app stability).
4. Public Content
Your username, profile photo, biography, comments, and publications are visible to other users. Do not share information you wish to keep private.
5. Content Moderation and AI Processing
We use automated systems and trusted AI providers (such as OpenAI and Anthropic) in real time to detect harmful, abusive, or unsafe user-generated content.
This may involve automated decisions to flag or block content, but users may request a human review.
No sensitive personal data (emails, passwords, DOB) is shared with these providers.
These providers act as data processors and do not use your data to train general-purpose AI models.
6. Third-Party Service Providers & Analytics
We use trusted infrastructure processors: AWS (hosting), Google Cloud / Firebase (analytics, backend, crash reporting), and Brevo (email).
We use Firebase Analytics for performance and feature usage. We do not:
Use advertising tracking, behavioural advertising, or Apple’s ATT framework.
Track users across third-party apps or websites.
Sell or share data for advertising or data brokerage purposes (under CPRA).
7. Log Data & Identifiers
For stability, we may collect IP addresses, device/OS info, and crash logs. We do not use browser cookies; some SDKs use device identifiers strictly for core app functionality.
8. International Transfers
Where data is transferred outside the UK/EEA, we utilize EU Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA).
9. Data Retention
Account data: Retained until account deletion.
Logs: Typically retained up to 12 months.
Special category data (dietary preferences and allergies): Retained only while your account is active. Deleted immediately upon account deletion or withdrawal of consent.
Data is only held longer if strictly required for legal or fraud prevention obligations.
10. Account Deletion
You may delete your account at any time in-app via account settings, or by submitting a request via our webpage at https://dishly.net/delete-account-request. Upon deletion, personal data is permanently erased or anonymised.
11. Security
We use appropriate technical measures to safeguard data. In the event of a legally reportable data breach, we will notify affected users and relevant authorities.
12. Your Rights
Depending on your location (including the UK, EU, and California under CPRA), you have the right to access, correct, delete, or restrict your data, object to profiling, and withdraw consent at any time. To exercise any of these rights, contact us at legal@dishly.net. We will respond within 30 days (or within any shorter period required by applicable law). EU/UK users can complain to their data protection authority (e.g., the ICO).
13. Children’s Privacy
The Service is not intended for users below 13 (or the minimum digital consent age in your jurisdiction). We use DOB verification at registration; if a user is found to be underage, account creation is refused and no personal data is retained. Any data incidentally collected during a failed age verification is deleted immediately and not used for any purpose.
14. Third-Party Links & Changes
We are not responsible for third-party privacy practices. We will notify users of material changes to this policy via in-app notice at least 14 days before changes take effect.
15. Contact
Data Controller: Novodian Group Ltd.
Registered Address: 38 Cottage Field Close, Sidcup DA14 4PD (United Kingdom)
Email: legal@dishly.net
We may require identity verification before responding.