Privacy policy
Your meals stay yours.
This policy explains what Dishiary collects, why we collect it, how long we keep it, and how you can export or delete it.
Last updated: July 15, 2026
Who we are
Dishiary is a private food diary and restaurant map operated by Xavier Engineering. It helps you remember meals, restaurants, notes, grades, photos, and what you would order again.
Contact: support@xavierengineering.com
Information we collect and why
- Account information: Sign in identifiers, name, and email from Apple are used to create and secure your account.
- Meal entries: Dish names, notes, grades, tags, dates, and would-order-again choices are stored so your diary works across sessions.
- Food preferences and health-related choices: If you ask Dishiary to remember likes, dislikes, foods to avoid, dietary needs, allergies, or situational preferences, we link that information to your account so the agent can filter and personalize results. Do not rely on Dishiary as medical advice; always confirm ingredients and cross-contact with the restaurant.
- Restaurant and place data: Restaurant names, addresses, coordinates, and visit history help build your private map.
- Photos: Food photos you capture or upload are stored so you can revisit the meal visually.
- Voice and transcription input: If you use voice logging, audio and transcription input are processed to create editable meal entries.
- Location data: With permission, location can help associate a meal with nearby restaurants. You can revoke this permission in iOS settings.
- Subscription state: App Store purchase and entitlement information is used to unlock paid features and handle support.
- Product interaction, agent conversations, and search history: Feature usage events, prompts, tool results, and in-app restaurant or diary searches help logging, recommendations, maps, export, restore, and account controls work as intended.
- Support emails: Messages you send to support are used to respond and resolve account, privacy, billing, or technical issues.
- Diagnostics and analytics: Basic app diagnostics, crash, and performance data may be used to keep the service reliable. We do not use website tracking to collect raw food data.
Automated processing
Dishiary may use automated services to reduce logging friction, such as identifying a dish from a photo, interpreting a note, extracting details you provided, or associating a meal with a place. Suggested details can be wrong, and you can edit your entries.
When you ask the agent to search your diary, analyze your eating history, remember a preference, or recommend food, Dishiary may process the relevant prompt, current menu text, diary text, and active preferences. We create numerical semantic indexes and a derived taste profile so meaning-based searches and personalized ranking can be fast. Private diary and private-menu indexing begins only after you use an agent intelligence feature.
Menu results are limited to stored current-menu evidence. Allergy and medical dietary filtering fails closed unless a menu claim has source-verified or user-confirmed evidence, and you should still confirm ingredients and cross-contact with the restaurant.
We avoid sending raw support message content or unrelated personal data to automated processors unless it is needed to provide the feature you requested.
Third-party processors
We use third-party service providers at a category level: Apple for sign-in, subscriptions, device distribution, and App Store billing; AWS for hosting, databases, storage, and infrastructure; automated processing providers where logging, semantic search, or agent features require processing; diagnostics or crash-reporting providers when enabled; and email or support providers for support responses.
For semantic indexing requests, Dishiary configures the provider route to deny provider data collection. We send bounded feature inputs rather than unrelated account data.
We do not sell your personal data
We do not sell your personal data. We do not operate Dishiary as a public review network, and your private meal diary is not sold to advertisers.
Dishiary does not use your data for cross-app advertising tracking.
Retention, export, and deletion
We keep account, meal, restaurant, photo, active and revoked food-preference history, agent conversation, subscription, and support data while your account is active or while needed for the service, security, legal compliance, or support. Semantic indexes and taste profiles are derived projections: they are rebuilt when their source changes and removed when the underlying data or account is deleted.
You can ask the agent to forget a remembered food preference. That revokes it from active filtering and personalization; its revoked history remains available in your export until account deletion. Request-scoped allergy or dietary constraints are not automatically saved as preferences.
You can request an export or deletion from in-app settings where available, from the privacy choices page, or by emailing support. Deletion requests are processed within 30 days unless we must retain limited records for legal, security, or financial reasons.
Permission revocation
You can revoke Photos, Location, and Microphone permissions from iOS Settings. Some features may be less convenient after permissions are revoked, but Dishiary should continue to support manual entry where available.
Contact
For privacy questions, export requests, deletion requests, or permission questions, email support@xavierengineering.com.
