Privacy at Plato
This page explains what data Plato processes, why we need it, and which choices remain yours.
Last updated July 28, 2026
1. Controller and scope
This Privacy Policy explains how we process personal data when you use the Plato app, joinplato.app, and related services. The controller under Art. 4(7) GDPR is:
Quiet Day Ventures UG (haftungsbeschränkt)
Sophienstraße 40
38118 Braunschweig
Germany
Represented by its managing director: Felix Jähn
Commercial register: Amtsgericht Braunschweig
Registration number: HRB 213182
Email: hello@joinplato.app
You can send privacy requests to hello@joinplato.app.
2. General principles
We process personal data only where this is necessary to provide Plato, perform a contract, comply with legal obligations, protect legitimate interests, or where you have consented. We do not sell personal data, serve behavioural advertising, or create advertising profiles.
Where processing is based on legitimate interests, the relevant interest is explained below. You may object to that processing where the requirements of Art. 21 GDPR are met.
3. Account, sign-in, and profile
An account is required to use the app. When you sign in with Apple or Google, we process the data supplied by that service which is needed for sign-in. This may include email address, first name, and the provider's unique identifier. We also process an internal account ID, language, region, time zone, account and subscription status, and separate decisions for optional consent.
We use this data to create and administer the account, authenticate you, localise the app, and provide the contracted features under Art. 6(1)(b) GDPR. Without data marked as required for sign-in and account administration, we cannot provide a synchronised Plato account. Profile name, health information, analytics, and marketing are optional; refusal does not limit other features unless the information is needed for the particular feature you request.
Limited security logs are processed under Art. 6(1)(f) GDPR to prevent misuse and protect the service.
4. Content, households, and communications
We process content you create or upload in Plato, including recipes, ingredients, steps, photos, meal plans, shopping lists, notes, cooking history, reactions, favourites, and feedback. This enables storage, synchronisation, display, and the features you choose to use. The legal basis is Art. 6(1)(b) GDPR.
If you create or join a household, your profile name and content you share there are visible to household members. Household owners can manage membership. Merely leaving a household does not remove content belonging to other members or independent copies that another member previously saved to their own area. Original content created by you is removed from Plato's active data when you delete that content or your account; technically independent copies made by another user are that user's content.
If you contact us by email or send feedback or an error report, we process the information to handle your request. Error reports can include the affected URL, technical error description, app version, platform, timestamp, and stack trace. The legal basis is Art. 6(1)(b) GDPR where the request concerns the contract, otherwise Art. 6(1)(f) GDPR for reliable communication and troubleshooting.
4a. Electronic content notices and withdrawals
If you submit an Article 16 DSA content notice or a contract withdrawal through joinplato.app, we process the information requested by the relevant form. Content-notice data includes the electronic location, content type, country or legal system, legal ground, explanation, necessary evidence, good-faith declaration, and, unless a statutory exception applies, name and email address. Withdrawal data includes name, email address, contract identification, optional contract date, and the withdrawal declaration. We additionally store language, receipt time, a case reference, and a random secret receipt token.
We use the data to receive, assess, document, and respond to the declaration and to provide a durable receipt. The legal bases are Art. 6(1)(c) GDPR together with the applicable DSA and consumer-law duties and Art. 6(1)(f) GDPR for traceable processing and legal claims. The data is stored in Cloudflare KV and sent through Brevo for receipts and internal notifications; the internal notification reaches our mailbox.org inbox. Form and receipt records are normally deleted automatically no later than four years after receipt. Mandatory retention duties and longer case-specific storage for concrete legal claims remain unaffected. Do not share the secret receipt address with third parties.
5. Technical data and security
Using the website or API necessarily produces technical connection data. This can include IP address, date and time, HTTP method, a parameter-free route template, HTTP status, data volume, device or app version, and a technical error category. We use it for delivery, stability, security, misuse prevention, and troubleshooting under Art. 6(1)(f) GDPR. Our legitimate interests are secure delivery, attack prevention, and correction of technical faults.
The website uses the language supplied by your browser and a country indicator coarsely derived by the infrastructure provider to select a language. We do not create a location profile from it. We normally retain server and security logs containing personal data for no more than 30 days. Technical logs sent to our observability provider must be limited to 14 days. Longer, access-restricted retention is limited to a specific security incident or legal claims.
6. Device permissions
The app requests system permissions when you select the corresponding feature. Camera and photo access are used to capture or choose recipe images. Only after you permit notifications do we send a device token issued by Apple Push Notification Service or Firebase Cloud Messaging, together with platform and necessary delivery details, to our backend. You can revoke permission in device settings and remove the token by signing out. Plato does not request location, microphone, or App Tracking Transparency permission.
Push notifications. Functional messages concern reminders, cooking actions, or household activity you requested. We process the device token, platform, category, and delivery data needed for those functions under Art. 6(1)(b) GDPR. Optional push messages about features, releases, offers, or product news are separate, off by default, and sent only after specific consent under Art. 6(1)(a) GDPR and subject to Section 7 UWG. OS permission and analytics or email consent do not replace this marketing consent. You can withdraw it in Notification Settings without losing functional notifications or any other app feature. The device token remains until OS permission is withdrawn, sign-out, account deletion, or technical invalidation; a marketing receipt is kept only for the required evidence and limitation period. APNs or FCM receive delivery data as independent platform services.
The app stores information on your device where needed for its functions. This includes encrypted sign-in tokens, local settings, consent status, an offline recipe copy, unsent error reports, and local state for widgets, drafts, or active cooking. Local counters controlling the frequency of Apple's or Google's system rating prompt are kept only after analytics consent and are not transmitted to us or third parties. Where local access is not strictly necessary for a feature you request, it takes place only after consent.
On the website, the only first-party cookie is __plato_household_invite_access when a protected household-invitation link is opened. It is used only for a short access check, is HttpOnly, Secure, SameSite=Lax, and expires after 15 minutes. Strictly necessary device access relies on Section 25(2) no. 2 TDDDG; optional analytics access relies on consent under Section 25(1) TDDDG.
6a. Siri, Shortcuts, and Spotlight on Apple devices
Siri and Shortcuts. On supported Apple devices, you can trigger Plato actions through Siri or the Shortcuts app. Apple processes your spoken request and system interaction under its own Siri, Dictation & Privacy notice. Plato requests neither microphone nor speech-recognition permission for this integration and receives no raw Siri audio recording. The Plato App Intent receives structured information that you spoke, typed, or selected. This can include a search term, recipe identifier or selection, servings, ingredient selection, date, meal and conflict choice, import URL or text, and Smart Plan settings. Where the chosen action searches, creates, or changes server data, we send the necessary information with account authentication to our backend. The purpose and legal basis are to perform the Plato feature you requested under Art. 6(1)(b) GDPR. Transmitted health information additionally remains subject to the consent rules in section 7.
Local functional state. To let App Intents operate securely without launching the Flutter interface, Plato uses its own App Group and a shared iOS Keychain. The sign-in tokens needed by Plato are stored there; they are not sent through the Flutter method channel or included in Spotlight content. Plato may also store locally the internal account ID, verified Premium status and verification time, and the context of the recipe currently open. Recipe context contains the route, recipe identifier, title, selected servings, and update time. It is no longer used after 30 minutes and is removed when you leave the view or sign out. Account, context, and index state are cleared on sign-out or account change.
Optional Spotlight index. The seven Siri and Shortcuts actions work without a recipe index. Only after you expressly enable the switch under “Siri & Spotlight” does Plato add entries to Apple's private search index on this device containing the recipe identifier and deep link, title, cuisine, preparation time, ingredient count, tags and custom tags, and up to 25 ingredient names. Instructions, notes, household details, nutrition and health information, and authentication data are not indexed. Under Apple's Core Spotlight specification, this index remains on the device, is sent to neither Plato nor Apple, and does not sync to other devices. Enabling the switch is your express request for this optional device feature; the legal bases are Art. 6(1)(b) GDPR and Section 25(2) no. 2 TDDDG. You can disable it at any time in the same place. Disabling, signing out, or changing accounts deletes the entire Plato index; deleted or inaccessible recipes are removed immediately or during the next reconciliation.
6b. Cooking timers, alarms, and device label
When you create a cooking timer or reminder, the app stores the required recipe or step identifier, duration, end time, and local timer state on your device and passes the necessary information to the operating system's alarm or notification function. Android may use permission to schedule exact alarms; supported Apple devices may use AlarmKit. This processing occurs only for the timer you requested under Art. 6(1)(b) GDPR and Section 25(2) no. 2 TDDDG. The operating system may display or trigger the alarm while the app is closed.
When registering for push, Plato may store a general device label supplied by the operating system, such as the model or device name, in addition to the token and platform. It is used only to distinguish and manage multiple push registrations for an account, is not used for profiling or advertising, and is removed with the registration on sign-out, account deletion, or technical invalidation.
6c. Optional re-engagement push
An at-most-weekly message encouraging you to cook again or continue a streak is treated as marketing or re-engagement, not as a functional cooking reminder. It is sent only together with the expressly named optional push messages about features, releases, and offers after a separate consent that is off by default. Earlier consents using narrower wording were reset and do not cover this purpose. Withdrawal stops these messages without affecting cooking timers, reminders you create, or household notifications.
7. Allergies, intolerances, and dietary preferences
Information about allergies, intolerances, dietary preferences, and nutrition goals is optional and may constitute health data under Art. 9 GDPR. The selected preferences are normally stored locally on your device. Before their first Smart Planner transmission, we request separate explicit consent.
The Smart Planner is a purely rules-based algorithm. It uses neither artificial intelligence nor a language model. When you request it, the selected information is sent to our backend with your authenticated planning request. The immediate preferences are not retained as permanent fields in the user table and are not sent to AI or language-model providers. The generated plan is, however, stored with your account and contains rules-based calculations such as calorie and protein targets, deviations, macronutrients, and health, quality, and gut-health scores. These values remain with the plan until you delete the plan, the health data, or your account.
The legal basis is your separate explicit consent under Art. 9(2)(a) together with Art. 6(1)(a) GDPR. You can withdraw it in nutrition settings. Withdrawal stops future transmission and lets you delete local preferences and stored health inferences. Without consent, the Smart Planner itself remains available with neutral defaults and all non-health planning options; only health-related personalisation is omitted.
8. Recipe imports, photos, and AI features
When you request an import from a URL, photo, or text, or use an AI feature such as recipe optimisation or nutrition estimation, we process the content needed for that request. For URL imports, data comes from the public website or social-media source you select; Apify may retrieve public posts, descriptions, comments, or transcripts. For a YouTube link, our backend sends the video ID to Google's YouTube Data API and receives public metadata such as title, description, channel, thumbnail, and duration; Google also receives technically necessary request and connection data. The API response is used for the requested import, while the resulting recipe and any shared cache follow the retention periods below. Do not submit private URLs, credentials, or third-party data that is unnecessary for the purpose.
Depending on the feature and availability, we use OpenAI and Google Gemini or Vertex AI. The selected provider receives the recipe text, URL content, images, audio, or instructions needed for the request. Account ID and email are not supplied as separate AI fields, but content can itself contain personal information. A surface involving direct AI interaction identifies the use of AI or the machine-generated output. A general recipe import may combine several technical extraction steps and is not represented as wholly AI-generated merely because an AI-assisted step was used. Do not use the features for content you may not or do not wish to send to the relevant provider.
General AI recipe adaptations work without transmitting your locally stored dietary preference or allergies. Only if you select the highlighted health-related personalisation do we request separate express consent immediately beforehand. Only after server confirmation are the selected dietary preference and allergies or intolerances sent with the required recipe to Google Gemini/Vertex AI and, depending on technical availability, OpenAI; processing may take place in the United States. The legal bases are Art. 6(1)(a) and Art. 9(2)(a) GDPR. This voluntary consent is strictly separate from the health consent for the purely rules-based Smart Planner, is off by default, and can be withdrawn at any time in Nutrition settings. Without it, the Smart Planner and all general AI recipe adaptations remain available.
For your own data in other AI and import functions you request, the legal basis is Art. 6(1)(b) GDPR. Where the content you selected unavoidably includes third-party personal data, the processing limited to that single import relies on Art. 6(1)(f) GDPR. Our legitimate interests are providing the specific import function requested and avoiding a technically impracticable manual separation; we do not use that third-party data for our own profiles or advertising. Data subjects may object on grounds relating to their particular situation at hello@joinplato.app. Do not submit special categories of third-party data under Art. 9 GDPR; we do not intend to process them and will do so only where a statutory exception under Art. 9(2) demonstrably applies. Photo-import image data is discarded after processing; job status is normally retained for up to seven days. A created recipe remains until you delete it or your account. Where direct notice to a third party would be impossible or disproportionate, we document the conditions of any Art. 14(5) GDPR exception and make this policy publicly available.
8a. Shared extraction cache
To accelerate repeated imports, a recipe extracted from a publicly accessible source may be stored in a shared cache. The cache contains structured recipe information such as title, ingredients, quantities, cooking steps, times, source type, any publicly named author, and image address. The source URL is held there only as a SHA-256 lookup key, and cache content is deleted no later than 365 days after its first entry. For AI-assisted extraction, cooking steps are produced in independent, concise cookbook wording; promotional or personal accompanying text is not intended to be retained.
Where the source contains personal data, the legal basis is Art. 6(1)(f) GDPR. Our legitimate interests are fast and resource-efficient delivery of repeatedly requested public recipe information and avoidance of repeated retrieval. The information comes from the public source selected by a user and may be supplied to the infrastructure and AI processors listed in section 14. Data subjects may object or request rectification or erasure by sending the precise public location to hello@joinplato.app; such a request does not restrict individual users' import function or other Plato features.
8b. Transient photo and AI processing
The Plato backend writes original images uploaded for photo import neither to the recipe database nor to a persistent file system; it holds them in memory only for the active processing operation. The selected AI provider processes the request and result to perform the feature requested. We do not authorise use of this API content to train the provider's general models. Where a provider may keep technically limited security or abuse logs, their duration is governed by the production-verified processing and transfer agreement and they must then be deleted. The result stored in Plato and a job status retained for up to seven days are separate from that transient provider processing.
9. Recipe photos
When you add a photo to a recipe, we store it in Cloudflare R2. The app removes EXIF metadata, including GPS data, where possible before upload. The photo is linked to your account and is visible to household members when you share the recipe.
Image files are currently delivered through a random, non-indexed object address. Possession of that address permits retrieval, so it must be treated as a secret link rather than complete access control. Do not share it publicly or upload particularly sensitive photos. The address contains no readable account or recipe identifier. The legal basis is Art. 6(1)(b) GDPR. We initiate deletion when the recipe or account is deleted; technical backups may persist until the documented backup cycle ends.
10. External websites and media
The app can open external websites or media in an in-app browser or your device browser, for example Google search results or pages from recipe sources and social networks. When you open such a page, its operator processes data such as IP address, browser or device information, cookies, and the address you request under its own responsibility. That operator's privacy information applies. Importing a URL into Plato additionally triggers the processing described in section 8.
To display, immediately import, or locally cache a recipe image at your request, the app can retrieve the image address of an external source directly from your device. The operator of that source thereby receives your IP address and the technically necessary request. Automatic background preloading after a mere recipe synchronisation is restricted to image origins controlled by Plato. If you choose to share a story to Instagram or Facebook, the app passes the image you selected to that app. From that point, its operator processes the data under its own responsibility.
11. Subscriptions and payments
Premium subscriptions are purchased and billed through Apple App Store or Google Play. We do not receive card or bank details. We use RevenueCat to verify, restore, and manage entitlements. It processes an internal account ID and purchase, product, trial, renewal, cancellation, store, price, currency, and where supplied coarse country data.
Necessary entitlement and purchase management relies on Art. 6(1)(b) GDPR.
A/B testing of paywall and offers. To improve our product, we periodically test different paywall designs and offer variants. RevenueCat assigns you to a test variant server-side at random based on the internal account ID; the assignment stays stable for the duration of a test and is not based on profiling or personal characteristics. Prices may vary between test groups during such tests; the price shown to you before purchase always applies. Evaluation uses aggregated purchase and subscription metrics at RevenueCat. No additional access to your device takes place for this purpose. The legal basis is our legitimate interest in optimising our offering under Art. 6(1)(f) GDPR. You may object to this processing at any time on grounds relating to your particular situation under Art. 21 GDPR. Behavioural analysis of individual usage events via PostHog still takes place only after the analytics consent described in section 12.
Deleting a Plato account does not cancel a store subscription.
12. Analytics and consent
We separate two analytics tracks. Without analytics consent, export is currently limited to a daily import-volume aggregate created on the server before export. Pro and free cohorts are emitted only where at least ten different accounts contributed that day; smaller cells are suppressed entirely. User, device, session, content, and network identifiers and individual call times are not exported. In particular, no individual registration, import, AI, nutrition, or adaptation event is exported without consent. PostHog receives only the approved aggregate and creates no person profile for this track. Controller-side daily aggregates are deleted after 25 months. The legal basis is Art. 6(1)(f) GDPR for data-minimised capacity and cost planning. You may object on grounds relating to your particular situation. You can do so directly under Settings > Legal > “Exclude from daily aggregate”; future imports are then excluded before counting. You may alternatively contact us.
Individual events about onboarding, screens, features, paywalls, purchases, retention, attribution, or experiments are processed only after express analytics consent. It is off by default and is not a condition of using Plato. Data may include a pseudonymised hash of the internal account ID, app/build version, OS major version, broad device class, language/region, and allowlisted events and categories. Recipe content, URLs, health data, email, name, and raw error text are excluded. The legal bases are Art. 6(1)(a) GDPR and, for optional device access, Section 25(1) TDDDG.
You may withdraw at any time under Settings and Legal. Withdrawal stops SDK processing locally and triggers deletion of PostHog data stored under your analytics pseudonym. Consent-based events are retained for no more than 13 months. We record each consent decision separately by purpose with timestamp, text/policy version, language, source, and withdrawal to meet Art. 7(1) GDPR.
13. Email
We use Brevo for necessary account and purchase messages. It processes email address, optional name, language, subject, content, and delivery status. These messages contain no product advertising and rely on Art. 6(1)(b) GDPR. Terminal delivery records and failed attempts are normally deleted after 30 days.
We use mailbox.org for direct enquiries to hello@joinplato.app and internal business correspondence. The provider and processor is Heinlein Hosting GmbH, Schwedter Straße 8/9B, 10119 Berlin, Germany. It processes in particular sender and recipient addresses, subject, message content, attachments, timestamps, and technically necessary connection and delivery data. Depending on the enquiry, the legal basis is Art. 6(1)(b), (c), or (f) GDPR; our legitimate interest is secure and reliable communication. Correspondence is deleted when the matter is closed unless statutory retention duties or legal claims require longer storage.
We send newsletters or other marketing only after separate, account-bound consent confirmed by double opt-in under Art. 6(1)(a) GDPR and Section 7 UWG. Selecting the option in the app alone does not trigger marketing. You can withdraw in the app or through the unsubscribe link in each marketing message. Open and link tracking remains disabled without valid consent for that purpose.
14. Recipients and processors
We use providers only for the purposes described and, where required, under Art. 28 GDPR. They include:
- Scalingo SAS, France: application, PostgreSQL, and where used Redis.
- Cloudflare, Inc.: website/security infrastructure, form and receipt records in KV, and R2 recipe photos.
- PostHog, Inc.: the EU analytics environment described in section 12.
- Grafana Labs, where enabled in production: technical logs, traces, and metrics with a 14-day log limit.
- Brevo / Sendinblue SAS, France: account, purchase, form, and confirmed marketing email.
- Heinlein Hosting GmbH, Germany (mailbox.org): direct email enquiries and internal business correspondence.
- RevenueCat, Inc.: subscription entitlements, purchase events, and randomised assignment of offer variants for A/B tests.
- OpenAI, L.L.C. and the relevant Google entity: AI features under section 8.
- Apify Technologies s.r.o., Czechia: retrieval of public social-media and YouTube content.
- Apple and Google: sign-in, store processing, APNs/FCM push, Siri or Dictation, Shortcuts and operating-system search and, where activated solely for protection, App Attest or Play Integrity.
Apple processes Siri, Dictation, and operating-system interactions under its own privacy notices and may act as an independent controller for that processing. Apple, Google, store entities, and operators of selected external sources may also be independent controllers for their own purposes. We disclose data where legally required or needed for legal claims.
14a. Contact form and YouTube metadata
For the contact form, we process name, email address, optional subject, message, receipt time, a reference, and technically necessary connection data. Cloudflare KV retains the form data for no more than 90 days; Brevo forwards the message to our mailbox.org inbox. The legal basis is Art. 6(1)(b) GDPR for contract-related enquiries and otherwise Art. 6(1)(f) GDPR. Our legitimate interests are a reliable direct contact channel and abuse prevention.
For a YouTube import you request, our backend sends the video ID directly to the YouTube Data API of the relevant Google entity. Google processes the video ID and technically necessary request and connection data and returns public video metadata. Google may act as an independent controller for its own security and operational purposes; sections 8 and 15 apply to the subsequent import processing.
15. International transfers
Some recipients are located in the United States or may access data from there. Where data is processed outside the EU or EEA, we ensure the safeguards required by Art. 44 et seq. GDPR. Depending on the recipient, this is an adequacy decision, including the EU-U.S. Data Privacy Framework where the recipient is certified, or the European Commission's Standard Contractual Clauses with supplementary measures. You can request information about the specific safeguard in use at hello@joinplato.app.
16. Retention and deletion
We retain account data and active recipes, plans, notes, and household content until the account or content is deleted. Plan-related health inferences remain until the plan is deleted or health consent is withdrawn. Completed and viewed imports are deleted after seven days; failed or unrecognised imports after 30 days; completed cooking sessions after 150 days; checked shopping items after 48 hours or 14 days; photo-import jobs after seven days; error reports after 90 days; and expired or revoked sign-in tokens seven days after expiry or revocation. Terminal email-outbox entries are deleted after 30 days.
Account deletion blocks further use, removes linked data from active systems, and creates deletion tasks for analytics and image files. Legal duties and data restricted for legal claims remain unaffected. Consent evidence is kept only for the necessary evidence and ordinary limitation period, generally three years from year-end after withdrawal or contract end. Backups are overwritten on a documented cycle, are not restored into ordinary operation, and are reconciled against deletion lists after a recovery.
17. Your rights
Subject to the statutory requirements, you have rights of access, rectification, erasure, restriction, data portability, and objection. You may withdraw consent with effect for the future. You can create a machine-readable copy of Plato account data and your own contributions directly under Settings > Legal > “Export my data”. This self-service copy does not limit a broader access request. To exercise your rights, contact hello@joinplato.app.
You also have the right to lodge a complaint with a data-protection authority. The authority responsible for us is: Die Landesbeauftragte für den Datenschutz Niedersachsen, Prinzenstraße 5, 30159 Hannover, Germany, lfd.niedersachsen.de.
18. Automated decisions
We do not make automated decisions, including profiling, that produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR. Recipe suggestions and meal plans are convenience features and do not replace your own decision.
19. Children
Plato is not directed at people under 16. We do not knowingly process data of people below that age. If you believe that such data was provided to us, please contact hello@joinplato.app.
20. Changes to this Privacy Policy
We update this policy when processing activities, features, or the law change. The current version is available at joinplato.app/privacy. We will communicate material changes where required by law.
The July 28, 2026 version uses clearer language and updates the information about our email provider. This does not change the purposes or wording of consents requested in the app, so their evidence version remains unchanged.