Privacy Policy

Last updated 30 July 2026

This policy covers the Plate app for iPhone. If something here is unclear, ask us and we will fix the wording.

Who we are

Plate is built by Sector 42 Limited, a company registered in New Zealand. For the data described below, we are the data controller. You can reach us at [email protected].

What stays on your device

Recipes, photos, categories, collections, meal plans, shopping lists, timers and settings are stored in a database on your iPhone. If iCloud is on, a private copy is kept in your own Apple Account so your library survives a reinstall or a new device. That copy is held by Apple under Apple's privacy policy and controlled by your Apple Account. We have no access to it. You can turn syncing off under Settings ▸ iCloud in the app.

Four other things are held on your device:

  • Photos you take or choose. Plate asks for the camera only when you take a photo. When you pick an existing photo, iOS uses its own picker and hands Plate only the images you selected, so Plate never gets access to your photo library.
  • Website data from imports. Some recipe sites require you to clear a captcha or sign in before the page can be read. When that happens Plate opens a browser view so you can do it yourself. Cookies and cached files from that session are stored on your device, in an area separate from Safari, and reused for later imports of the same site so you are not asked again. Deleting the app deletes them. They are never sent to us.
  • Shopping list items sent to Reminders. With your permission, Plate writes shopping list items to Apple Reminders so your household can see them. Once an item is in Reminders it is Apple's to handle, under Apple's privacy policy and whatever sharing you have set up on that list.
  • Whether Plate Pro is unlocked. Plate asks Apple whether your Apple Account owns Plate Pro, and keeps the answer as a short marker in its own storage so the share extension can read it too. No receipt, card, or Apple Account details are kept, and none of it is sent to us.

When Plate uses the network

Plate makes a network request only when you ask for something that needs one:

  • importing a recipe from a link you supply, or refreshing one from its source;
  • fetching the photos a recipe page links to;
  • submitting a quality report you chose to send;
  • buying or restoring Plate Pro, and loading its price when you open the Plate Pro screen.

Separately, iOS registers your device with Apple so iCloud can tell Plate when your library has changed on another device, and Plate asks the App Store whether your Apple Account owns Plate Pro. Both are handled by Apple, and we receive nothing from either. Nothing phones home in the background, and there is no analytics beacon.

When Plate fetches a recipe page, that website sees the request much as it would see a browser, including your IP address. It handles that under its own privacy policy. We do not control those sites and never hear from them.

Quality reports

Quality reports are the only thing that ever reaches us. They exist so we can fix imports that don't work as expected. Sending one is optional every time: nothing is sent unless you tap the button, and there is no setting that makes it automatic.

What a report contains

  • the source material of the import: the web page as Plate fetched it, the photos you imported, the file you opened, or the text you pasted;
  • the recipe as it was saved in your library at that moment, including your own notes, rating and category names;
  • a technical trace of how the import ran, so we can see where it went wrong;
  • anything you type into the note field on the report screen;
  • the app version, the iOS version, the device type (for example "iPhone") and your locale (for example "en_NZ").

It contains nothing else from your library, and no Apple Account details, name, or email address. Photos are stripped of camera metadata, including any location, before they leave your iPhone. One thing to know before you send one: if the import came from a page you had signed into, the captured page holds whatever that site shows a signed-in subscriber, which on some sites includes your name or email address. If that matters for a particular import, skip the report. Nothing else in Plate changes.

What our servers receive

The report is encrypted on your iPhone before it leaves, against a public key shipped inside the app. Only Sector 42 Limited holds the private key that opens it. Our servers run on Cloudflare's global network and only ever store the encrypted bytes. Cloudflare cannot read them.

Alongside the encrypted report, we record:

  • a per-install identifier issued through Apple's App Attest. It proves the report came from a genuine copy of Plate rather than a script, and it lets us group reports sent by the same install. It is not linked to your Apple Account or any advertising identifier, and it tells us nothing about who you are.
  • the app version, the kind of report, its size, and when it arrived;
  • how many reports that install has sent, so we can apply a daily limit.

Cloudflare sees your IP address when your device connects, as any web server would, and we use it only to rate limit abusive traffic. We do not store it with your report or use it to identify you.

How long we keep it

  • The encrypted report is deleted from our storage within 15 days.

To have a report deleted before then, email [email protected] with roughly when you sent it, the source URL if it was a web import, and the app version, so we can find it.

What we use it for

Finding and fixing import bugs. Nothing else. We do not sell quality reports or anything derived from them. They are not shared for marketing or advertising, and not sent to a third-party AI provider.

What we never collect

  • Anything that identifies you as a person.
  • Accounts, sign-ups, passwords. Plate has none.
  • Payment details. Apple sells the app and Plate Pro and handles the payment. We never see your card or your Apple Account, only anonymous sales totals in App Store Connect.
  • Analytics or usage tracking of any kind, including our own.
  • Advertising or marketing identifiers, and any tracking across other apps or websites.
  • Your location. Plate never asks iOS for it and never uses it.
  • Crash reports, unless you have chosen to share diagnostics with developers in iOS Settings, in which case Apple gives us an anonymised copy with no way to identify you.

AI processing

Plate uses machine learning to read and import recipes. The models, Apple's and our own, run entirely on your iPhone. Nothing is sent to OpenAI, Anthropic, Google, or any other AI service, and nothing you write or import is used to train third-party models.

Children

Plate is a general audience app. It is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has sent us a quality report containing personal information, email us and we will delete it.

Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or export the personal information a company holds about you. Because Plate holds nothing that identifies you, there is usually nothing for us to produce or erase. Where we do hold something, which in practice means a quality report or an email you sent us, write to [email protected] and we will act on it.

For anyone in the UK or the European Economic Area, our legal basis for handling a quality report is your consent, given each time you send one. You can withdraw it by not sending further reports and by asking us to delete any outstanding one. You also have the right to complain to your local data protection authority.

For residents of California and other US states with similar laws: we do not sell or share personal information, and never have. We do not discriminate against anyone who exercises their privacy rights.

We operate from New Zealand and handle information under the Privacy Act 2020. A quality report you send is stored on Cloudflare's network and may be processed in the United States or elsewhere. It stays encrypted end to end throughout, and only we hold the key to it.

Deleting your data

Plate has no account, so there is no account to delete. To remove everything:

  1. Delete the Plate app from your iPhone. This removes the local database and any cookies.
  2. Open Settings ▸ [your name] ▸ iCloud ▸ Manage Account Storage, find Plate, and tap Delete. This removes the iCloud copy.

Shopping list items already written to Apple Reminders stay in Reminders. Delete them there.

Security

Quality reports are encrypted on your device before upload, and the key that opens them is held offline by us, never by our hosting provider. Every connection uses TLS. Data on your iPhone is protected by iOS.

Changes to this policy

If we change how Plate handles data, we will update this page and the date at the top.

Contact

Questions about privacy: [email protected].