DINNR ("we", "us", "our") is committed to protecting your privacy. This policy explains what data we collect, why we collect it, how it is processed, and your rights under the General Data Protection Regulation (GDPR) and applicable EU/EEA data protection law.
The data controller responsible for your personal data is:
DINNR
Email: dinnr@derekfidler.com
When you create an account we collect your email address and a securely hashed password (or, if you sign in with Google, a token from Google). Your recipes, meal plans, and grocery lists are stored on our behalf by Supabase (see section 5).
Legal basis: Article 6(1)(b) GDPR — processing is necessary to perform the contract (providing the DINNR service to you).
We use PostHog to understand how people use DINNR — for example, which pages are visited, when recipes are created, and which client (web or desktop) is being used. This helps us prioritise improvements.
ip: false).Legal basis: Article 6(1)(f) GDPR — our legitimate interest in improving product quality and reliability. This processing uses no directly identifying data and is limited to aggregated behavioural signals.
We use Sentry to automatically capture errors and crashes so we can fix them quickly.
Legal basis: Article 6(1)(f) GDPR — our legitimate interest in maintaining the security and stability of the service.
DINNR uses browser localStorage (not traditional cookies) for:
None of this data is shared with third parties beyond the processors listed in section 5.
| Data | Retention period |
|---|---|
| Account & recipe data | Until you delete your account |
| PostHog analytics events | 12 months (PostHog default) |
| Sentry error events | 90 days (Sentry default) |
When you delete your account via Settings → Delete Account, all your recipes, meal plans, and grocery items are permanently deleted from our database. Your PostHog and Sentry records are identified only by UUID; you may request deletion of those records by contacting us (see section 7).
We use the following sub-processors to deliver the service. Each has been assessed for GDPR compliance and processes data only as instructed by us.
| Processor | Purpose | Data location |
|---|---|---|
| Supabase | Database & authentication hosting | EU (Ireland) |
| PostHog | Product analytics | EU (PostHog Cloud EU) |
| Sentry | Error & crash monitoring | EU (Germany) |
We do not sell your data to any third party, and we do not use it for advertising.
All of our data processors are hosted within the EEA. No personal data is transferred to countries outside the EEA.
You have the following rights regarding your personal data:
To exercise any of the above rights, contact us at dinnr@derekfidler.com. We will respond within 30 days.
Passwords are hashed by Supabase and never stored in plain text. All data in transit is encrypted using TLS. We follow industry-standard security practices and monitor for errors via Sentry.
DINNR is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
We may update this policy from time to time. Material changes will be communicated via the app. The date at the top of this page reflects when the policy was last updated.
For any privacy-related questions or GDPR requests:
Email: dinnr@derekfidler.com