Privacy
Privacy policy
Last updated 1 August 2026
DishCopy asks for as little as it can get away with: an e-mail address to sign in, and the photos you choose to copy. This page says exactly what happens to both, and who else touches them.
Who is responsible
DishCopy is run from Madame Curiestraat 17, 2171 TW Sassenheim, the Netherlands, and is owned by TranspaClean B.V. (Chamber of Commerce number 69870691) and TecWeb B.V. (Chamber of Commerce number 69862109). Both are joint controllers for everything described here. Questions, or a request about your own data: [email protected].
What we collect, and why
Four things, and nothing else:
- Your e-mail address — so you can sign in and so your remaining copies survive a reinstall. There is no password; we send a four-digit code instead.
- The photos you copy — the ingredient list and, if you take one, the dish. They are needed to produce the recipe.
- The recipes we generate for you, together with the settings you chose (language, voice, how healthy) and any answers you gave to the app's questions. This is what lets us show you what went wrong when a copy is poor.
- The recipes you save and the photos attached to them, backed up so a lost phone doesn't mean a lost cookbook — and so a second device can show them. This is every account, not only Plus.
What happens to your photos
This is the part people ask about most, so plainly: a photo you copy is sent once to our server, which passes it to OpenAI to read and then discards it. We do not keep it, and it is not used to train any model.
The exception is the photos attached to your saved recipes. Those are stored on our storage provider so your recipes survive a lost phone and a second device can show them. You delete them by deleting the recipe, or all of them by deleting your account.
Who else touches your data
We use four outside companies. The first three act on our instructions and may not use your data for anything else. Google is the exception: for advertising it decides for itself what it does with what it collects, under its own policy rather than ours.
- OpenAI — reads your photos and writes the recipe. Photos and the resulting recipe are processed in the United States. OpenAI does not use API data to train its models.
- Bunny.net — stores the photos attached to your recipes, in the European Union.
- Mailgun — delivers your sign-in code. European Union.
- Google — serves the advertising on the free plan, through AdMob. It receives your device's advertising identifier, your approximate location, and how you interact with the ads. DishCopy Plus removes advertising, and Google then receives nothing.
What we do not do
We run no analytics inside the app, we use no tracking pixels, and we never sell anything to anyone. The app does not know which recipes you cook, only which ones you made. This website counts visits with Google Analytics, but only if you accept it in the banner — decline and nothing is loaded at all.
Advertising is the honest exception. On the free plan Google's AdMob reads your device's advertising identifier, along with your approximate location and how you interact with the ads, in order to choose them and to measure whether they worked. That counts as tracking, and we would rather write it down here than let you find it on the App Store listing.
You get a say in it. In the EU, the UK and Switzerland we ask before any of it happens, and refusing takes one tap — you still see ads, they are simply not targeted. On iOS the system asks you a second time, separately, and you can say no there too. DishCopy Plus removes advertising altogether, and this exception with it.
How long we keep it
- Sign-in codes: fifteen minutes, then they are useless.
- Sign-in sessions: six months, or until you sign out.
- Your account, recipes and copy history: until you delete your account.
Deleting everything
In the app: Settings → Delete account. It removes your account, your copy history, your synced recipes and every synced photo — ours and our storage provider's. It is immediate and it cannot be undone.
Export your recipes first if you want to keep them; Settings → Export takes a second and produces a file you own.
Your rights
Under the GDPR you can ask us for a copy of your data, correct it, delete it, or object to how we use it. Deletion and export are built into the app so you do not have to ask. For anything else, write to [email protected] and we will answer within a month.
You can also complain to your national data protection authority if you think we have got something wrong.
Legal basis
We process your e-mail address and your copies to provide the service you asked for (performance of a contract). We keep short-lived technical records to stop abuse of the sign-in and copying endpoints (legitimate interest).
Children
DishCopy is not aimed at children under 16 and we do not knowingly collect their data.
Changes
If we change anything that matters we will say so in the app before it takes effect, not quietly on this page.
When someone invites you
If a DishCopy user invites you by e-mail, we store that address so we can send the invitation and recognise you if you sign up later. It is used for nothing else: not advertising, not a mailing list, and it is never sold or shared.
An invitation can be sent at most three times, and stops counting after thirty days. You can ask us to delete your address at any time by writing to [email protected], even if you have never used DishCopy — you do not need an account to ask.