Privacy Policy
Last updated: August 5, 2026
The short version: SwipeDish stores the account and food preferences you give us so you and your partner can decide what to eat. We do not sell your data, we do not run ads, and we do not use third-party analytics or tracking. You can access or delete your data at any time.
1. Who we are
SwipeDish ("we", "us", "the app") is a mobile app that helps two people agree on what to eat. This policy explains what personal data we collect, why, and your rights over it. It applies to the SwipeDish mobile app and this website (getswipedish.com).
The service is operated by Mehmet Canhoroz, based in Türkiye. For any privacy question, or to exercise your rights, contact us at [email protected]. We act as the data controller for the personal data described below.
2. What we collect
We only collect what the app needs to work. That is:
Account information
- Your email address (used to sign in and to contact you about your account).
- Your display name.
- Your chosen avatar color and emoji.
Sign-in data
- One-time login codes we email to you. These are short-lived and stored only in hashed (scrambled) form, never in plain text.
- Session tokens that keep you signed in on your device. To protect your account, only one device is signed in at a time, so signing in on a new device signs you out on the old one. Access tokens are short-lived and refreshed automatically, and signing out revokes them.
Your shared space
- The invite code that links you and your partner into one shared space.
- Which accounts are members of that space.
- Inside a space, your partner can see your display name, avatar, the dishes you both vote on, your matches, the joint shopping list, and the meal history. Your email and login codes are never visible to your partner.
Food preferences and activity
- Your dietary tags and your "hard-no" ingredients.
- Your swipes (likes and passes) and the matches you and your partner agree on.
- Meal outcomes you record (for example, cooked or ate out), your shopping list, and your decision history.
- Your device time zone, used only to group your history by day and week.
Technical data
- Standard server logs, such as IP address, device or browser type, and timestamps. We use these to keep the service secure and reliable.
We do not collect your precise location, your contacts, payment card details, or any special-category data (such as health or religion). Dietary preferences are stored as plain food tags you choose, not as health records.
3. How we use it
- To create and run your account and your shared space.
- To sign you in securely with email login codes.
- To show you and your partner the right dishes, matches, plans, and history.
- To keep the service secure, prevent abuse, and fix problems.
- To respond to your messages and support requests.
We do not use your data for advertising, we do not build advertising profiles, and we do not sell or rent your personal data to anyone.
4. Legal bases (GDPR)
If you are in the EU, UK, or another region with similar laws, we rely on:
- Contract: to provide the app you signed up for (your account, space, matching, and plans).
- Legitimate interests: to keep the service secure, detect and prevent fraud and abuse, and improve reliability and performance. We weigh these interests against your rights and freedoms, and you can object to this processing at any time by emailing us.
- Consent: where we ask for it, for example before sending optional notifications. You can withdraw consent at any time.
- Legal obligation: where we must keep certain records to comply with the law.
5. Who we share it with
Your data stays with us except for the service providers we rely on to run the app. These providers process data only on our instructions:
- Hosting and database: the infrastructure that stores your account and the app's data.
- Email delivery: the provider that sends your login codes and account emails.
You can ask us for the current list of providers at any time by emailing [email protected]. Within your shared space, your partner can see the shared content of that space, such as the dishes you both matched on, the joint shopping list, and the meal history. Your email and login codes are never shown to your partner. We may also disclose data if required by law, or to protect the rights, safety, and security of our users and the service. We do not sell your personal data.
6. International transfers
SwipeDish is available worldwide, so your data may be processed in a country other than your own. Where data is transferred across borders, we use appropriate safeguards (such as the European Commission's Standard Contractual Clauses, or an equivalent recognized mechanism) to protect it.
7. How long we keep it
We keep your personal data while your account is active. Login codes expire within minutes. When you delete your account, we promptly delete your profile, sign-in credentials, preferences, and the personal data tied to your account. Some shared content in your space (such as past matches and meal history you created together) may be removed at the same time, so your partner may lose access to it. Server logs are kept for a limited period (up to 90 days) for security and troubleshooting. We keep data longer only where the law requires it, and only for as long as required.
8. Security
We protect your data with measures such as encrypted connections, hashing of login codes, and access controls that scope every request to the signed-in account. On your device, login tokens are kept in the platform's secure storage (the iOS Keychain or Android Keystore). No system is perfectly secure, but we work to keep your data safe and to respond quickly if something goes wrong. If a breach affects your personal data, we will notify you and any relevant authority where the law requires, without undue delay.
9. Your rights
Depending on where you live, you have some or all of these rights:
- Access: ask for a copy of the personal data we hold about you.
- Correction: ask us to fix data that is wrong or incomplete.
- Deletion: ask us to delete your account and personal data.
- Portability: ask for your data in a portable, machine-readable format.
- Restriction and objection: ask us to limit or stop certain processing.
- Withdraw consent: where we rely on consent, withdraw it at any time.
If you are in California, you also have the right to know what we collect, to request deletion, and not to be discriminated against for exercising your rights. Non-discrimination means we will not deny you the app, charge you a different price, or give you a lower quality of service because you used your privacy rights. We do not sell or share your personal data for cross-context behavioral advertising, so there is nothing to opt out of.
To exercise any right, email [email protected] and tell us which right you want to use. We may ask you to confirm your identity first. We will respond within 30 days, and we will let you know if a complex request needs more time (up to a further 60 days), as the law allows. If you are in the EU or UK and are unhappy with our response, you can complain to your local data protection authority.
10. Children
SwipeDish is not intended for children. You must be at least 16 years old (or the minimum age of digital consent in your country) to use it. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
11. Changes
We may update this policy as the app evolves. When we make a material change (for example, to what we collect, how we use it, who we share it with, or your rights), we will update the date at the top and let you know in the app or by email before it takes effect. Please check back from time to time.
12. Contact us
Questions, requests, or concerns about your privacy? Email us at [email protected] and we will help.
← Back to home