This Privacy Policy describes how Pregustà (“we,” “us,” “our”) collects, uses, and discloses information when you use the Pregustà mobile app (the “Service”).
Device identifier — the app generates a random identifier on your device the first time you open it, and uses it to count your free scans and recognize your subscription. On its own it is not tied to your name or email. It is held in your device’s keychain, so it normally survives deleting and reinstalling the app — that is deliberate, and it is what stops your free scans starting over. Erasing the device clears it. It does not move to a new phone by itself. If you sign in with Apple, this identifier is linked to your account — see below — and that link is what lets your history and your pass follow you to another phone.
Your account (Sign in with Apple) — signing in is optional and the app reads menus without it. When you do, Apple sends us a token identifying you, and we store two things from it: Apple’s own stable identifier for you with this app, and the email address Apple releases. If you chose Hide My Email, that is a relay address Apple made for us, not your real one — we cannot see behind it, and we do not try to. We never receive your Apple password, and we ask Apple for nothing else: no contacts, no other apps, no profile. Your name is not stored.
Signing in links this phone to that account, and any other phone you sign in on joins it. Two consequences worth stating plainly rather than leaving you to discover: your scan history becomes the account’s rather than this phone’s, so it appears on every phone you sign in to; and your free scans are counted for the account across those phones, so reinstalling or switching phones no longer starts the free count again.
Signing out makes that phone stop showing the account’s history, pass and member number until you sign in again. It does not erase the record that the phone was linked, and the scans made on that phone still count toward its free scans.
IP address — we record a salted, one-way hash of your IP address, never the address itself, to detect abuse of the free-tier scan limit and to rate-limit requests. It is stored with each scan for 24 hours — the length of that limit's window — and then erased.
Menu photos — when you scan a menu, the photo is sent to our server, resized, and forwarded to OpenAI to read the menu and generate dish photos. The original menu photo is not stored after that request completes. If you've used your free scans, we may still read that menu to show you part of it — at most one preview shown a day, from no more than three tries a day at reading one. What we read — the menu's dishes and, if you allowed location, where you scanned it; never the photo — is kept for up to 24 hours so that unlocking can finish the scan without reading it again, and is then erased. A scan you unlock this way is saved with the place you scanned the menu, not where you were when you paid.
Where you scanned — when you scan a menu, the app asks your phone for your location at about 100-metre accuracy and, if you allow it, keeps the coordinates it gets back. We do not ask for a more precise fix than that, and we do not sharpen it afterwards. To be exact about what is stored: for the first 72 hours we keep the coordinate at the full precision your phone returned, which can place you more closely than 100 metres even though that is not what we asked for. After 72 hours it is rounded to about 1 kilometre — the neighbourhood rather than the restaurant — for as long as the scan is in your history. The 72 hours exist so a dish photo you add at the table is matched to the right restaurant. Used for exactly one thing: telling apart two branches of the same restaurant chain, which have identical menus, so a diner's photo from one branch doesn't appear at another across town. Location is read only at the moment you scan — the app never tracks you in the background. Declining is fine: scanning and contributing photos both work normally without it.
Photos you contribute — if you add a photo of a dish, it is uploaded and stored indefinitely and used as a reference to correct the picture we generate for that dish. It is not shown to other people. We may decide to show contributed photos in future; if we do, we will say so here before any photo of yours is shown to anyone. It is stored with the dish name, the restaurant's name and its approximate location (rounded to about 110 metres, three decimal places), the dish names of the menu it came from, the measured size and sharpness of the image, the written verdict of the automated check described next, and your device identifier — not your name. Before it is kept it is sent to OpenAI, which checks that it is a photograph of food and not of a person or anything else unwanted; that check is why the verdict is stored. Please don't photograph people. You can ask us to delete a photo you added at any time.
Scan results — dish names, descriptions, prices, dietary tags, and AI-generated photos from a scan are stored, tied to your device identifier and, if you are signed in, to your account, so your scan history is available later in the app and on any phone you sign in to. Kept indefinitely unless you request deletion. The generated picture of a dish is the one exception to “tied to you”: it is kept once per dish in a shared cache, so the next person to scan that dish is shown the same picture instead of it being drawn again. That cache holds the dish and the picture and nothing about who scanned it — which also means deleting your data does not remove it, because there is nothing in it to connect to you.
Dietary preferences and allergies — if you set up a dietary profile (diet type and any allergies you select), it's stored tied to your device identifier — and, if you are signed in, it follows you to any phone you sign in on, the same way your scan history does — and used to flag matching or conflicting dishes on menus you scan and, if you ask a question about a menu, to aim that answer at you. Never used for advertising. Two things about this are worth naming rather than leaving you to work out: an allergy is health information, and choosing Halal, Kosher or Hindu says something about your religious practice. Both are sensitive, we treat them that way, and the profile is optional — the app reads menus perfectly well without one. It is stored only so that the same allergy doesn't have to be re-entered on every menu, it is never used to target anything at you, and deleting your data removes it. When you ask a question about a menu it travels with that one question to OpenAI — see the next item, and the “Health and religious information” section below, which is exact about it.
Questions you ask about a menu — when you use Ask, your question is sent to OpenAI, which writes the answer, together with the menu it is about, the dish you had open, up to six earlier turns of the same conversation, and your dietary profile if you have set one. We do not store the question or the answer — they live for the length of that one request and are never written to our database — so Ask adds nothing to what your history holds.
A question for the kitchen — when you ask the app to write a question to show your server, the dish, the menu it is on, and the one thing you asked about are sent to OpenAI, which writes the question in the menu’s language. That one thing is chosen from a fixed list: halal, kosher, Hindu, Jain, vegetarian, vegan, pork, alcohol, or one of the allergies the app offers. Nothing about it is stored — the question exists for that one request — so it adds nothing to what your history holds.
Your currencies — the currencies you choose to see prices in, and whether yours is shown first, are kept on your phone only and never sent to us. To convert a price, the app downloads that day’s exchange rates for the menu’s currency directly from jsDelivr, a public content network; like any web request it sees your IP address and which currency’s rates were asked for, and nothing else.
Dish interactions — tapping “I want this” or reporting a photo as inaccurate is recorded (dish name + device identifier) to improve the product.
App usage steps — we record which steps of the app you reach (for example finishing the intro, a scan working or failing, opening a dish, seeing the subscription screen, coming back from checkout), tied to your device identifier, so we can see where people get stuck. Some steps carry one small detail: which of your free scans it was, which plan, or where a screen was opened from. They never include what's on a menu, your dietary profile or allergies, your location, or anything you type. These records are not anonymous: they are linked to your device identifier, and deleting your data removes them. First-party only — no third-party analytics or advertising SDK.
Email address — only if you voluntarily join our waitlist, contact us directly, or ask to restore a purchase on a new phone. To restore, you enter the email you paid with: we look it up with Stripe and, if it bought a plan, email a 6-digit code to it through Resend. We don't store the address — only a one-way, keyed hash of it (to limit how many codes one address can receive) and a one-way hash of the code, both erased after 24 hours. A correct code moves your plan to the phone you entered it on; the old phone loses it. If that phone had its own trip pass running, a restored monthly plan takes its place, and a restored trip pass adds its remaining days to it. We keep a record of the move (the plan's reference, the two device identifiers, and any trip pass it replaced) so later billing updates reach the right phone.
Payment information — if you subscribe, payment is handled entirely by Stripe. We never see or store your card number. Each paid plan is given a member number, in the order plans were first paid for, stored with your device identifier and shown on your pass; it moves with the plan if you restore it on another phone.
The name on your pass — if you choose to put your name on your pass card, the text you type is stored with your device identifier so the card still reads the same after you restore the plan on another phone. It is whatever you type — a first name, a nickname, anything — we never check it against a real identity, it is shown only on your own pass, and it is not sent to Stripe, OpenAI or anyone else. Deleting your data erases it. Leaving it blank is fine: the card is a pass either way.
Crash and performance reports — when the app crashes or misbehaves, a report is sent to Sentry so we can find the bug. It carries the error, where in the app it happened, and your phone's model and OS version. It is deliberately configured to carry no personal information and none of your identifiers: crash reports are not tied to your device identifier, your scans, or your dietary profile, and they cannot be traced back to you. Reports are only sent from the released app, never while we are developing it.
Notifications — with your permission, the app may schedule a local reminder notification. This is generated and scheduled entirely on your device — not a push notification from our servers, and no notification content is sent to or logged by us.
We do not use third-party advertising networks or analytics trackers. We do not read your photo library — the app only ever receives the specific photos you choose, whether that's a menu to scan or a dish photo you contribute. We do not track your location in the background; it is read only at the moment you scan a menu. We do not sell personal information.
OpenAI (reading a menu, generating dish pictures, checking a dish photo you contribute, answering a question you ask about a menu — which carries your dietary profile if you have set one — and writing a question for the kitchen, which carries the one concern you picked), Stripe (subscription payments), Resend (sends the restore-purchase code email, only if you ask for one), Cloudflare (stores and serves dish photos), Sentry (crash and performance reports, carrying no identifier of yours), jsDelivr (serves the day’s exchange rates to the app; it sees the request, not who you are), and Supabase / Render (database and server hosting). Each processes data on our behalf under their own privacy and security terms; we don't sell or share your information with anyone else, including for advertising.
Scan history, dietary preferences, and dish-interaction data tied to your device identifier are kept indefinitely to support in-app history and personalization, unless you delete it yourself or ask us to. The IP hash stored with a scan is erased once the scan is 24 hours old. A scan's exact location is reduced to an approximate one (about 1 kilometre) once the scan is 72 hours old. A menu read only to show you a preview after your free scans are used is erased within 24 hours unless you unlock the scan, when it becomes part of your scan history. Restore-purchase requests (the email hash and code hash) are erased after 24 hours; the record of a plan moved to another phone is kept as long as that plan's billing record.
If you signed in with Apple, your account — Apple's identifier for you and the email it released — is kept until you delete the account, and is erased then. Deleting your data is not the same as deleting your account; both are in the app, and "Your choices" below says what each one does.
You can delete your scan history, dietary profile, and dish-interaction data at any time yourself, in the app, from the delete option at the bottom of Account. This takes effect immediately and does not require contacting us. If you'd rather we do it for you, email us at the address below.
If you signed in with Apple, you can also delete the account itself, in the app, under Account. That is a separate and larger thing than deleting your data: it signs out every phone on the account and erases Apple's identifier for you and the email it released, so that Apple identity can no longer be used to sign back into it. What remains is a record that an account existed and the date it was deleted, holding nothing that identifies you. Deleting your account does not cancel a subscription — the app says so before you tap it, and cancelling is done by opening Account and tapping your pass.
What stays after you delete: to keep the free-scan limit fair, each deleted scan leaves a minimal record — your device identifier, the date and time of the scan, and whether it worked. The menu, dishes, dish count, restaurant, and location are erased. A scan less than 24 hours old also keeps its IP hash until it turns 24 hours old, and then that is erased too. We also keep your device identifier with its platform, app version, and first/last-seen dates, and, if you have ever subscribed, your subscription record (Stripe customer and subscription references, plan status, and end date) so a paid plan keeps working — deleting your data does not cancel a subscription. If you ever restored a plan onto another phone, the record of that move stays for the same reason, as does a member number you were given. If you were signed in, the link between the deleted scans and your account goes with their contents — what survives is the bare usage row described above, and it names no account. A dish photo you contributed is kept as a reference for that dish, with your device identifier removed from it, so nothing that stays is tied to you. It is still not shown to anyone. Email us if you want the photo itself removed.
Two more things stay, and they are the ones most easily missed. If you ever joined the waitlist, that row is kept under your email address, with the link to this phone removed — email us to have it taken out. And if you signed in with Apple, deleting your data does not touch the account itself: Apple’s identifier for you and the email it released stay on the account record until you delete the account, described above. Two different choices with two different effects — if what you want is for us to hold nothing at all, delete the account.
Backups: we take a nightly backup of our database, held in private storage, so that your scans and your pass survive a failure or a mistake on our side. A backup is a snapshot of one moment, so anything you delete stays inside the backups that were taken before you deleted it, and is gone once those expire — that takes up to 30 days. We do not use backups to bring back data you asked us to delete; they exist only to recover from failure.
The Service is not directed to anyone under the age of 18, and the Terms do not permit their use of it. We do not ask your age and we have no way to verify it, so this is a rule rather than a check. We do not knowingly collect information from anyone under 18; if you believe we have, email us at the address below and we will delete it.
A dietary profile is the one place this app holds something about you that some US states treat as a special category. An allergy is health information. A diet set to Halal, Kosher or Hindu says something about religious practice, even though the app only ever uses it to read a menu.
Nothing here is collected unless you set a dietary profile yourself. When you save one, the diet type and the allergies you selected are stored on our server tied to your device identifier — not your name — and used for one thing only: telling you how a dish on a menu you scanned stands in relation to it. That covers the badges on a scan and, if you ask a question about that menu, the answer. It is never used for advertising, never sold, and never used to infer anything else about you.
One part of that deserves to be exact rather than reassuring, because it is the sensitive category: when you ask a question about a menu, your diet type and your allergies are sent to OpenAI as part of that request, so the answer can be about your restrictions instead of a stranger’s. It goes nowhere else. It is not sent when you simply scan a menu — only when you ask — and neither the question nor the answer is stored afterwards. The kitchen card is the one other way any of it leaves: if you ask the app to write a question for your server about halal, kosher, Hindu or Jain food, or about one of your allergies, that one concern is sent to OpenAI with the dish so the question can be written, and it is not stored either. OpenAI appears under “Who we share data with” above and handles it on our behalf under their own terms. If you would rather it never left, clear your dietary profile: Ask still works, and answers for a stranger.
You can change or clear it at any time in the app under your dietary profile, and deleting your data from the bottom of Account removes it outright and immediately. Clearing it withdraws your consent for us to hold it; nothing about the rest of the app stops working. If you would rather we deleted it for you, or want to know what is held, email us at the address below.
Washington, Nevada and Connecticut residents: this section, together with "What we collect" and "Your choices" above, is our consumer health data disclosure. We do not sell consumer health data, and we do not share it for targeted advertising.
We use commercially reasonable measures to protect your information, but no method of transmission or storage is 100% secure.
We may update this Privacy Policy from time to time. We will post any changes on this page and update the “Last updated” date above.
If you have questions about this Privacy Policy, contact us at hello@pregusta.com.