Privacy Policy — Dinner Bell
Last updated: 26 June 2026
This policy describes what data is processed by the Dinner Bell mobile app
(published in Poland as “Obiadnik”; the “App”) and the related service at
obiadnik.pl, for what purposes and on what legal basis,
and what rights you have.
1. Data controller
The controller of your personal data is Miłosz Kordecki SOFT — a sole
proprietorship registered in Poland, tax ID (NIP) 8982082468 (“we”, the “Controller”).
Privacy contact: [email protected].
2. The short version
- The App works without creating an account — by default you use a guest account, and your recipes live primarily on your phone.
- We show no ads and we do not sell your data.
- Signing in with Google or Apple is optional — it only serves to back up your data and sync it between devices.
- We collect the minimum data needed to run the App, diagnose crashes and improve the product.
3. What data we process
3.1. Account and identity
- Guest account (default): on first launch your device generates a random secret stored locally in the system's secure storage (Keychain / Keystore). Our server stores only its hash — it does not allow us to identify you as a person. A guest account requires no e-mail address or any personal data.
- Google / Apple sign-in (optional): if you choose to link an account, we receive your e-mail address and a stable account identifier from the provider. Apple may provide a relay address. This data is used for authentication and account recovery.
- Sessions: authentication tokens that keep you signed in.
3.2. Content you create
- Recipes (ingredients, steps, tags), shopping lists and meal plans.
- This content is stored on your device and — for synchronisation and backup — on our servers, linked to your account.
- If you deliberately share a recipe, you may (optionally) attach a signature with your name — only with your consent.
3.3. Diagnostic data (crashes)
- We use Sentry (EU region) to detect errors. When a crash occurs, a report is sent containing e.g. the device model, OS version, App version and a technical error trace (stack trace).
- Errors occurring offline are not sent.
3.4. Usage data (analytics)
- We collect usage events (e.g. saving a recipe, starting an import) in our own analytics infrastructure to understand how the App is used and to improve it. We do not use third-party advertising networks for this.
4. Purposes and legal bases (GDPR)
| Purpose | Legal basis (Art. 6 GDPR) |
| Providing the App (account, sync, content) | Art. 6(1)(b) — performance of a contract |
| Crash diagnostics and security | Art. 6(1)(f) — legitimate interest (a stable, secure App) |
| Analytics and product improvement | Art. 6(1)(f) — legitimate interest |
| Google / Apple sign-in | Art. 6(1)(b) and your consent expressed by choosing this method |
5. Recipients and processors
We use trusted providers who process data on our behalf:
- Hosting provider — servers and database.
- Sentry (EU region) — crash diagnostics.
- Cloudflare — content delivery network and service protection.
- Google / Apple — only if you choose federated sign-in.
We do not sell data and we do not share it with third parties for marketing purposes.
6. Transfers outside the EEA
We process Sentry data in the European Union region. Cloudflare,
and — if you use federated sign-in — Google and Apple, may process
data outside the European Economic Area, subject to the transfer mechanisms required by the GDPR
(e.g. standard contractual clauses or an adequacy decision).
7. Data security
We apply technical and organisational measures appropriate to the risk, in particular:
- encryption of data in transit with TLS;
- access control to production systems and secure storage of secrets;
- the guest-account secret is stored locally in the system Keychain / Keystore —
our server keeps only its hash.
8. Retention
- Account data and content — for as long as you use the App, until the account is deleted.
- Crash reports (Sentry) — up to 90 days, per the provider's retention policy.
- Analytics events — for as long as needed to analyse and improve the App, no longer than necessary; then deleted or anonymised.
- After account deletion, data is deleted or anonymised, subject to legal obligations.
9. Your rights
You have the right to: access your data, rectify it, erase it, restrict processing,
data portability and to object. You may also lodge a complaint with a supervisory authority —
in Poland this is the President of the Personal Data Protection Office (PUODO);
you may also contact the authority in your country of residence (e.g. the ICO in the UK).
To delete your account and related data, e-mail
[email protected]. We will delete them without undue delay.
10. Children
The App is not directed at children and we do not knowingly collect data of persons under 16.
11. Changes to this policy
We may update this policy. The date of the last change is shown at the top of this page.
We will communicate material changes in the App or on the website.