YesPlate

Privacy policy

YesPlate app and website Effective 13 August 2026

You can use YesPlate without an account and without telling us anything. We do not ask for your name or what you can and cannot eat — you pick a filter and it stays on your device.

You may create a passwordless account with your email address so that a pass can work across devices. If you buy without creating one first, we create it from the email Paddle verifies during payment. That account stores only your email and pass record — §8 explains exactly what we receive, what we never receive, and why your card details are not on the list.

This policy describes the small amount of data that is processed either way, and what you can do about each part of it. It covers the mobile app and the website equally — they run the same code and process the same things.

Who is responsible

The controller for the processing described here is:

Ruslan Balzhyk, Bulgaria hello@yesplate.eu

We have not appointed a data protection officer; the size and nature of this processing does not require one under Art. 37 GDPR. As the controller is established in Bulgaria, no representative under Art. 27 GDPR is required.

What is processed, and why

1. Your preferences, on your device

Your chosen city, dietary filter, interface language, search mode, the "include places with no menu" setting, whether you asked for nearest-first, and your answer to the measurement question are stored on your device. A cache of recent search results is stored alongside them so the app opens without a spinner. On the website the same things live in your browser's local storage.

None of this is sent anywhere. It never leaves the device, and deleting the app deletes it. It is stored because you set it — this is storage strictly necessary for a service you asked for, and it is not covered by the measurement consent below.

Cookies. The app uses none. The website sets one, yp_variant_v1, and only if you allowed measurement — if you declined, it is never written. It holds a random identifier, no name and no email, which records which version of the unlock offer you were shown so we can tell whether one works better than another. It lasts 90 days, no one else reads it, and it is never used for advertising or to follow you to another website.

If you buy a pass, your browser also stores the session that keeps you signed in. That one is not a matter of consent and is not a cookie: it is storage strictly necessary for a service you explicitly asked for — it is what makes the thing you paid for work — and signing out removes it.

2. Your approximate location — only if you ask for it

The app never asks for location on its own. It is requested only when you press a control that needs it — "use my location" in the city picker, "nearest first" in the results list, or the locate button on the map — and only for as long as the app is in the foreground; background location is disabled in the app's build configuration.

If you grant it, your position is rounded to about 100 metres before it is stored or sent anywhere, and the rounded pair is sent to our database server for two purposes:

It travels inside the request, is used to answer that request, and is not written to any table, log or profile. We keep no history of where you have been. If you decline, or if a position cannot be obtained, results are sorted by match count instead and everything else in the app works as normal.

One thing is deliberately not rounded, and never leaves your device: the blue dot on the map. It is drawn by the map component from your device's own location, at whatever precision your device gives it, because a dot rounded to the nearest 100 metres sits on the wrong side of the street and makes the map look broken. Nothing reads that position except the map you are looking at, and nothing transmits it.

Legal basis: consent, Art. 6(1)(a) GDPR, given through your device's location permission. You can withdraw it at any time in your device settings.

3. Measurement — only if you allow it

When you first open the app you are asked whether we may count how it is used. If — and only if — you allow it, a small and fixed set of events is recorded. They cover:

That is the whole of it. The set is closed rather than open-ended: it is defined in one place in the app's source, and it is not extended without updating this notice.

None of it carries your name, your email address or your card details, and we never receive your card details at all (see §8). A random identifier is generated on your device so that repeat visits can be counted; it is not linked to your pass, to any name, or to a device identifier issued by Apple or Google, and it is not shared with anyone for advertising.

There is no advertising, no tracking across other apps or websites, no session recording or screen capture, no automatic collection of screens or taps, and no profile is created for you on our analytics provider. IP-based location lookup is switched off, so your IP address is used to deliver the request and is not turned into a location.

If you do not allow this, none of it happens: the analytics software is never started, no identifier is generated, and nothing is written to your device for this purpose.

Legal bases: consent, Art. 6(1)(a) GDPR, and — because the dietary filter you choose may reveal information about your health or your beliefs — explicit consent under Art. 9(2)(a) GDPR. Storing and reading the identifier on your device is done on the basis of your consent under national law implementing Art. 5(3) of the ePrivacy Directive.

Withdrawing: Settings → Help improve YesPlate. Turning it off stops collection immediately. Stop and erase usage data additionally resets the identifier on your device. Withdrawal does not affect the lawfulness of what was collected beforehand.

4. Menus, restaurants and searches

Everything you see in the app is served from our database. Requests carry the city, your dietary filter, what you typed in the search box and — if you have granted it — the rounded position described above. These requests are served and not stored against you; we do not build a history of your searches, and without measurement consent there is nothing that could link two requests together.

Legal basis: legitimate interests, Art. 6(1)(f) GDPR — answering the request you made by using the app.

5. Error reports and contact messages

The "report an error" and "get in touch" forms are hosted by Tally. What you write is sent to us, along with which restaurant and dish the report is about, the dietary filter and search mode that were active, the city, the platform and the app version. That context is what makes a report reproducible; without it, "the tofu one is wrong" cannot be checked.

Please do not put personal details into the message — nothing in the form needs them. If you give us your email address so we can reply, we use it for that and nothing else.

Legal basis: legitimate interests, Art. 6(1)(f) GDPR — correcting errors in data that people rely on for dietary decisions. Where you volunteer contact details, consent, Art. 6(1)(a).

6. The map

Map tiles are loaded from OpenFreeMap, a free public tile service built from OpenStreetMap data. Loading a map necessarily tells the tile server your IP address and which part of the map you are looking at. We do not send it anything else, and the tiles are the same public basemap used by the YesPlate website. Map data is © OpenStreetMap contributors, © OpenMapTiles, served by OpenFreeMap.

7. Restaurant photos

Photos are not copied onto our servers. Each one is loaded by your device straight from wherever it already lives — the photo attached to the restaurant's public business listing, or an image on the restaurant's own website, which in practice means whichever host that site uses. Loading an image necessarily tells that host your IP address and which image you asked for, exactly as loading a map tile does.

We choose which photo to point at and send nothing else with the request. We have no relationship with those hosts and they are not acting on our instructions, so what they do with a request for a picture is governed by their own policies rather than ours.

If you would rather not load them at all, the app works without photos: every row and every restaurant page has a placeholder for the many venues that have no photo in the first place, and nothing about finding a dish depends on the picture.

8. Accounts and buying a pass — only if you choose to

Searching is free and always shows results. A free search shows the first five matching dishes and tells you how many there are in total; a pass shows all of them. There are two, one lasting 14 days and one lasting a year, and both are a single payment — nothing renews, so there is no stored payment method and nothing to cancel.

We never see your card. Payment is handled by Paddle, which sells the pass to you as the merchant of record — legally, Paddle is the seller and we are its supplier. Your card details are entered in Paddle's own payment window, go to Paddle, and are never sent to us or stored by us. Paddle is an independent controller for the payment itself: it decides what it needs in order to take a payment, prevent fraud and account for VAT, and its own privacy notice governs that.

What we receive back. When a payment succeeds, we receive from Paddle: your email address, an identifier for you and for the transaction in Paddle's system, which pass you bought, whether it is active, and when it runs out. We do not receive your card number, your billing address or your name unless it is part of the email address you gave.

The account. You can create a free account before buying by entering your email address and opening the secure link we send. If you buy without one, we create it from the email address Paddle verifies at checkout. There is no password. After payment we sign you in on that device and email a fallback link; on another device, signing in with the same email restores the pass. The account holds your email address and pass record and nothing else: no name, no searches, no preferences and no saved places. Those stay on each device.

Which searches you ran are never attached to it. The account and the search history are deliberately not connected. What you searched for is measurement, it happens only if you allowed it, and it is anonymous — see §3.

Records we keep. We keep the record of what Paddle told us about your payments for as long as tax law requires us to. That is an obligation, not a choice, and it is the one part of your data that a deletion request cannot remove while the period runs — see "Your rights".

Legal bases: performance of a contract and steps you request before entering one, Art. 6(1)(b) GDPR — providing the optional account, granting the access you paid for and keeping it working across devices require your email address. For the payment and accounting records we are required to keep, compliance with a legal obligation, Art. 6(1)(c). For checking that a purchase is genuine and not a fraudulent or duplicated charge, our legitimate interests, Art. 6(1)(f).

Who else is involved

Recipient What they do Where the data is
Supabase Hosts the restaurant and menu database that serves your requests France (EU)
PostHog Processes the measurement events, if you allowed them EU (eu.i.posthog.com)
Paddle Sells the pass as merchant of record, takes the payment and tells us that it succeeded UK / EU; an independent controller for the payment itself, not our processor — see §8
Tally Hosts the report and contact forms EU
OpenFreeMap Serves map tiles Receives your IP address when the map is open; a free public tile service, not a processor, see §6
Photo hosts Serve the restaurant photos your device loads — business-listing image servers and the restaurants' own websites and CDNs Each receives your IP address when it serves an image; not processors, see §7
Expo Builds and, where used, delivers app updates
Apple / Google Distribute the app and provide crash reporting at the operating-system level under their own policies

Each of these acts on our instructions under a data processing agreement, except OpenFreeMap and the photo hosts, which are not processors — your device connects to them directly and we have no arrangement with either (§6, §7) — Paddle, which is an independent controller and the seller of record for the payment (§8), and Apple and Google, who act as independent controllers for what they collect through the store and the operating system.

Some of these companies are established in the United States or have US parents. Where personal data is transferred outside the EEA, that transfer is covered by the European Commission's Standard Contractual Clauses — except for Paddle's UK entity, where it rests on the Commission's adequacy decision for the United Kingdom, which needs no clauses.

Opening directions sends you to an external maps service, opening a venue's map page sends you to that service too, and opening a restaurant's website sends you to that website. From that point you are on their service and their privacy policy applies, not ours.

How long it is kept

Your rights

You have the right to access your data, to have it corrected or erased, to restrict or object to processing, to portability, to withdraw consent at any time, and to complain to a supervisory authority — for us, the Commission for Personal Data Protection (Комисия за защита на личните данни), 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria, https://www.cpdp.bg — though you may also complain to the authority in the country where you live.

If you have an account, these are straightforward. Write from its email address and we can find it, tell you everything held against it, correct it, or delete it. If it has an active pass, deleting it ends that access — we will say so before we do it — and it does not touch payment records that tax law requires us to keep for the stated period.

For everything else, there is an honest complication. We cannot tell which measurement events came from you: the identifier is random and we hold nothing that connects it to a person. That stays true even for account holders and people who have bought a pass, because the account and the measurement identifier are deliberately not linked (§8). Under Art. 11 GDPR we are not required to collect more data purely to make you identifiable, and we will not. In practice:

We answer within one month.

Children

YesPlate is not directed at children and collects nothing that identifies age.

Automated decision-making

The app decides whether a dish probably fits a dietary filter by reading the published menu. That is an assessment of a dish, not of you, and it has no legal or similarly significant effect on anyone within the meaning of Art. 22 GDPR. It is also not always right — see the terms of use.

Restaurants and their data

The app describes restaurants: name, address, contact details, published menu, and ratings. Where a restaurant is run by an individual, some of that may be personal data about them. It was not collected from them directly (Art. 14 GDPR): it comes from public business listings and from the menus each restaurant publishes on its own website. We process it in our legitimate interest in providing a directory of published menus.

If you run a listed business and want your entry corrected or removed, write to hello@yesplate.eu and we will do it.

Changes

If this policy changes materially we will update the app and the effective date above. Where a change requires consent, we will ask again rather than assume the old answer covers it.

Questions: hello@yesplate.eu