Privacy Policy
Effective 29 August 2026
PLATE. is a place to share what you're eating. This policy explains what we collect, why, and what you can do about it. It is written to be read.
Who is responsible
The service is operated by PLATE. from Spain. For anything about your data, write to hello@plating.app.
What we collect
- Account. When you sign in with Apple we receive a stable identifier for your Apple ID and, only if you choose to share them, your name and email address. There are no passwords.
- Profile. Your handle, display name, bio, city and avatar. These are visible to other people.
- What you post. Photos, dish names, captions, the places you attach, cook-off entries, comments, likes, saves and who you follow. Public accounts are visible to anyone; a private account shows plates only to approved followers.
- Finding friends (optional). If you allow access to your contacts, phone numbers and email addresses are scrambled on your phone with a one-way hash before anything is sent. We store those scrambled codes to find matches; your contacts themselves never leave your phone. You can remove the codes at any time from Settings.
- Phone number (optional). If you add your number so friends can find you, we verify it with a text message and store it with your account. You can remove it from Settings.
- Device. A push notification token (if you turn notifications on), your app language, and whether the app is a test or App Store build, so notifications reach the right place.
- Technical logs. Our servers log requests (IP address, endpoint, time) for security and debugging. Logs are kept for up to 90 days.
- Crash reports. When something breaks, an error report (device model, OS version, the failing request) is sent to Sentry so we can fix it. It never includes your photos.
Why we use it
- To run the service you asked for: your account, your feed, your notifications (performance of a contract).
- To keep PLATE. safe: rate limits, abuse prevention, moderation of reported content (legitimate interest).
- Finding friends, phone verification and push notifications only happen when you turn them on (consent), and you can turn them off.
We do not sell your data, show ads or profile you for advertising.
Where it lives
Accounts and content are stored on servers in the AWS region in Spain (eu-south-2); photos are stored in Amazon S3 in the same region and served through short-lived signed links. Notifications go through Apple's push service. Error reports go to Sentry (Functional Software, Inc.). Text message codes, when enabled, go through Twilio. These providers process data on our behalf under their own data processing terms.
How long we keep it
For as long as your account exists. When you delete your account, your profile, plates, comments, likes, follows, scrambled contact codes, phone number and device tokens are removed within 30 days; encrypted backups roll over within a further 30 days. Content you posted that other people reported may be kept in anonymised form to enforce our rules.
Your rights
Under the GDPR you can ask for a copy of your data, correct it, delete it, restrict or object to how we use it, and receive it in a portable format. Most of this you can do yourself in the app: edit your profile, delete plates, remove your phone number and contact codes, or delete your account from Settings. For anything else, email hello@plating.app. You can also complain to the Spanish data protection authority (AEPD) or the authority where you live.
Children
PLATE. is for people aged 13 and over, and under the age of digital consent where you live (14 in Spain) only with a parent's permission. If you believe a child has an account, tell us and we will remove it.
Security
Everything travels over TLS. Photos are served through signed links that expire. Access to production systems is limited to the people who run the service.
Changes
If this policy changes in a way that matters, we will say so in the app before it takes effect. The date at the top always tells you the current version.