← Plates
Privacy Policy
Last updated: July 16, 2026
Plates (“we”, “us”) is a food-only rating app where people share real photos of real dishes
and rate the food. This policy explains what we collect, how we use it, and the choices you
have. By using Plates you agree to this policy.
Information we collect
-
Account information. When you create an account we collect your email
address, a display name, and a username (handle). If you sign in with Apple or Google, we
receive your email and basic profile info from them. You may add a profile photo.
-
Content you create. Photos of dishes, ratings (1–10), captions, dish
names, lists, follows, likes, and saved places.
-
Location (optional). If you grant permission, we use your approximate
location to show nearby restaurants and to mark a post as a verified visit. You can turn
this off at any time in your device settings.
-
Contacts (optional, hashed on your device). If you choose “Find friends,”
your contacts’ emails/phone numbers are hashed on your device (SHA-256) and only the
hashes are sent to match against other users. We never receive your contacts in plain text.
-
Usage & device data (beta tracking). During the beta we record
product usage events (screens used, features tried — via PostHog) and crash/error
reports (via Sentry) so we can find and fix problems fast. These are tied to your
account so we can follow up on bugs you hit. Using the beta means you're OK with this;
if you're not, delete your account in Settings and the associated data goes with it.
How we use your information
- Provide the app — show your plates, profiles, follows, and ratings.
- Personalize what you see, like recommendations based on your taste and who you follow.
- Keep Plates safe — moderation, blocking, and abuse prevention.
- Communicate with you about your account.
AI and machine learning
We do not use your content or personal data to train AI or machine-learning models,
and we don’t permit our providers to do so on your data. We use AI only in limited,
disclosed ways: a per-photo nutrition estimate and an optional photo enhancement generated
for your post when you ask for them (the provider processes that single image to
return a result — it isn’t used to train models), reading a receipt you submit for
verification (below), and querying the aggregated food graph described below.
Receipt verification
You can verify a takeout or delivery plate by submitting a photo of your receipt or a
screenshot of your order confirmation (for example from DoorDash, Uber Eats, or
Instacart). Here is exactly what happens: the image is uploaded to private storage that
no other user can access; an AI provider processes that single image once to read the
restaurant name, order date, and address so we can confirm the purchase; and then
the image is deleted immediately — whether the check passes or fails.
Receipts are never shown on your post or anywhere else, and are never used to train
models. What we keep is only the outcome: the verification result, the merchant name and
date the AI read, and a one-way fingerprint of the image so the same receipt can't be
reused to verify a second plate. Payment details visible on a receipt are neither
extracted nor stored.
How information is shared
-
Public by design. Plates is a discovery feed: the plates you post, your
ratings, your handle, and your profile are visible to others. Your footprint map is limited
to mutual followers (or only you). Direct messages stay private to you and the recipient.
-
Aggregated, de-identified “food graph.” We build — and may license —
aggregated rating data (dish ratings, restaurant scores, cuisine trends) derived from
publicly posted reviews, and may make it queryable by partners and AI agents (so they can
answer questions like “best ramen near me”). This is aggregate and stripped of personal
identifiers — it describes dishes and places, not you. Any user can opt out
in-app: Settings → Anonymized dish data → “Opt out” excludes your
ratings from this aggregate.
-
We do not sell data that identifies you. If we ever wanted to share data
that identifies an individual, we would ask for your explicit opt-in first.
-
Service providers. Supabase (database, storage, auth), Apple/Google
(sign-in), Apple Maps and Google Maps (maps; Google on Android), and our photo-AI provider —
each under contract to use data only to provide their service.
- Legal & safety. We may disclose information if required by law or to protect people.
-
California residents. In addition to the in-app toggle above, you may
opt out of any sharing that could be considered a “sale” or “share” — email
hello@rateplates.ai with “Do Not Sell or Share.”
Restaurant data
Restaurant names and locations come from
OpenStreetMap (© OpenStreetMap
contributors, ODbL). That is public map data, not your personal information.
Your choices and rights
- Edit your profile and content in the app.
- Control location permission in your device settings.
-
Delete your account. In the app, open
Settings & privacy →
Delete account. This permanently removes your profile, plates, follows, and other
account content.
- Request access to or correction of your information by emailing us.
Data retention
We keep your information while your account is active. When you delete your account, your
profile and content are removed from our systems (backups age out on a rolling basis).
Children
Plates is not directed to children under 13, and you must be at least 13 years old to use
it. We do not knowingly collect information from children under 13.
Security
We use industry-standard measures to protect your information, but no method of transmission
or storage is completely secure.
Changes
We may update this policy. We will post the new version here and update the date above;
significant changes will be highlighted in the app.
Contact
Questions? Email hello@rateplates.ai.
© Plates.