Privacy notice
This notice explains what DinnerPlan does with your information, why, and what control you have. It is written for the UK GDPR and the Data Protection Act 2018. Last updated: February 2026.
Who we are
DinnerPlan is the meal-planning service at dinnerplan.co.uk. We are the data controller for the personal data described here. To contact us about privacy, use the support form and choose the “Privacy request” category.
What we collect
- Account details — your email address, first name, sign-in method and account status.
- Household content — the household you create or join, its members, servings, budget, dietary preferences, allergies, food inventory, recipes, meal plans and shopping lists.
- Uploaded images — receipt and food photos you choose to scan. They are held in private storage, used only to produce the resulting food list, and deleted within 24 hours of processing.
- Behavioural records — which recipes you save, cook, accept or reject, and when you use the planner. These power personalisation and are recorded against your user account only.
- Service records — AI generation and scan history (counts, timestamps and outcomes, not prompts or image contents), support tickets and messages, notifications, and security and audit events.
- Billing records — membership status, plan, renewal dates and payment outcomes. Card details are handled entirely by Stripe and never reach our servers.
Why we use it, and our lawful basis
- To provide the service (accounts, scanning, planning, shopping lists, support) — performance of our contract with you.
- To take payment and manage memberships — performance of our contract, and legal obligation for financial records.
- To keep the service safe and working (rate limits, abuse prevention, error diagnosis, audit logs) — our legitimate interest in a secure, reliable service.
- To personalise suggestions from your behaviour — your consent. You can turn behavioural personalisation off, and clear the history behind it, at any time in Settings. With it off, we use only the preferences you have explicitly entered.
- To send marketing email — your consent. Always separate from essential service messages, and withdrawable at any time.
Allergies and dietary data
Allergy and dietary information is special-category-adjacent health information, so we handle it with extra care: it is used solely to filter and label suggestions inside your household, it is never used for marketing or profiling, and it is never shared outside the processors listed below. Automated allergen filtering is an aid, not a guarantee — see the safety note below.
Who processes data on our behalf
- Supabase — database, authentication and private file storage (EU/UK region hosting).
- Lovable — application hosting, the AI gateway that routes scanning and recipe generation, and error reporting.
- Google (Gemini) and OpenAI — the AI models behind scanning, recipe ideas and meal planning, reached through the gateway above. Your content is sent for processing to return a result and is not used by us to train models.
- Stripe — payment processing and card data. Stripe is the controller for your payment card information.
- Google — sign-in with Google, if you choose it.
Some processors operate outside the UK. Where they do, transfers rely on UK adequacy regulations or the International Data Transfer Addendum to the EU Standard Contractual Clauses.
Automated decisions and AI limitations
DinnerPlan uses AI to read photos and to suggest recipes and weekly plans. These suggestions are assistive, not decisions with legal or similarly significant effects. AI output can be wrong: expiry dates are estimates, quantities may be misread, and allergen and diet filtering can miss things, particularly with own-brand or reformulated products. Always check packaging and use your own judgement, especially where an allergy is severe. You can review, edit or delete anything the AI produced before acting on it.
Sharing within a household
A household is shared by design. Other members of your household can see its inventory, recipes, meal plans and shopping lists. They cannot see your personal behavioural records, your support tickets or your billing details.
How long we keep things
- Uploaded images: deleted within 24 hours of processing.
- Household content: kept while your household exists, then deleted with it.
- Behavioural records: rolling 180 days, or until you clear them.
- Support tickets and messages: 24 months after the ticket is closed.
- Security, audit and AI usage records: 12 months.
- Billing and payment records: 7 years, to meet UK tax and accounting requirements.
When you delete your account we erase your personal records and remove you from your households. Where you are the only owner of a household, that household and its content are deleted too; households shared with other members are preserved for them. Anonymised billing records are retained where the law requires it, with your identity removed.
Your rights
You have the right to access, correct, delete, restrict or object to our use of your data, to data portability, and to withdraw consent at any time. Settings → Privacy provides a machine-readable export of your personal data and self-service account deletion; you can also ask us through support. We respond within one month.
If you are unhappy with how we have handled your data, you can complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the chance to put it right first.
Security
Data is encrypted in transit and at rest, access to household data is enforced at the database level by row-level security, uploads are stored privately and expire automatically, and administrative actions are logged. No system is perfectly secure, so we also keep the data we hold to what the service needs.
Children
DinnerPlan is for adults managing a household. It is not intended for children under 13, and we do not knowingly create accounts for them.
Changes
If we make a material change to this notice we will tell you in the app or by email before it takes effect.