Privacy

Last updated: 6 August 2026. What Dishy (“we”, “the app”) collects, why, and what control you have.

The short version

  • No account is needed to browse, and there is never a password. Verifying that you’re a student creates one, and you can delete it in the app.
  • Your dietary filters, allergens, favorites and searches stay on your device.
  • Ratings, notes and photos live on our server against that account, because other students have to see them. Every photo is approved by a person before it appears.
  • Asking us to add a campus sends the school, and a push token if you want telling when it lands. It carries no account.
  • We do not sell data and there is no advertising SDK. Deleting the app removes what it kept on your phone; what you posted, and the account behind it, you delete from inside the app.

What stays on your device

Dishy keeps your preferences on the phone: dietary filters and allergens, favorite dishes and halls, recent searches, and appearance and layout choices. None of it is uploaded, so there is no server-side copy to request or delete. The school you picked is the exception: it goes out with every menu request, and is stored on your account if you verify. Dishy also caches recently viewed menus so the app works without a signal; that cache holds menu data, nothing about you. Settings › Advanced › Reset Dishy clears all of it, including the local copies of your reviews and photos, and signs you out; deleting the app removes everything it kept.

What leaves your device

Our backend is hosted by Supabase, where your account, ratings, notes, reports and photo records live, while the photo files themselves sit in Cloudflare R2.

Menu data

To show you a menu, Dishy asks our backend for the menus, locations and hours published by your school’s dining service, naming the campus and the dates being viewed. Those requests carry no account identifier.

Student verification

Verifying is optional; every menu works without it. You give us your school email address so we can send a six-digit code and confirm the domain. The account it creates holds that address, the campus it belongs to, a display name if you set one, and an account identifier: a random id that each rating, note and photo you post is filed under, and that your blocked list is stored against. A sign-in token in your device’s Keychain keeps you signed in, and is what proves a rating or a photo came from a real student.

To delete the account, open My Dishy from your avatar and use the menu on your student card. Your email address, campus, display name and student verification go with it. A photo still waiting to be checked, or one we turned down, is withdrawn immediately, and the file itself is erased after about thirty days. An approved photo, and any rating or note, stays on the dish with your name and account identifier detached.

Requesting a campus

If your school is not on Dishy and you ask for it, we store the school’s name as you typed it, its email domain and country when the app knows them, the version of Dishy you asked from, and a random identifier the app generated for itself when you installed it, so that asking twice counts once. That identifier is not an account and not Apple’s advertising id, and nothing in the stored request links it to your student email. Allow notifications and the request also stores your device’s Apple push token and which of Apple’s push services it belongs to, for the one message this exists for: your campus is live. Sending it deletes the token in the same step; if your campus never launches, the token stays with the request. Decline and the request is still filed; nothing promotional.

Because it carries no name, email or account, we cannot single your request out if you later ask us to delete it.

Reporting and blocking

Report a review or a photo and we store which item you reported, the reason you picked, any note you add, and that it was you who sent it. A moderator working inside the app never learns who reported: their queue carries the content, the reasons and the count, while your address sits in a separate queue only the key we hold on the server can read. One report per person per item, and enough separate reports hides the content automatically while a person reviews it. A report is erased with the content it is about, and when you delete your account.

Blocking someone stores a pair of account identifiers on our server, yours and theirs, so we can keep their ratings, notes and photos out of your app. It is one-directional and private: they are not told, and cannot see that you blocked them. Undo it in Settings › Reviews & photos, where the list of people you have blocked also lives.

Posting anonymously

Settings › Reviews & photos lets you post as “Anonymous” instead of under your name. The switch is retroactive: turning it on hides your name on everything you have already posted, and turning it off shows it again. An anonymous review also has its timestamp rounded to the hour. “Anonymous” means anonymous to other students, not to the few people who moderate: we still know which account wrote what, so that we can act on a report and you can delete it, and a moderator reviewing your post can see the name on the account behind it.

Location

Dishy asks for location only when you use the map or sort halls by distance, and only while you are using the app. Placing you on the map, and working out how far away a hall is, happens on the device: not stored, not sent to us. The one exception is a walking route or ETA drawn inside Dishy, Apple’s routing service needs your position to answer. Decline and everything except distance sorting keeps working.

Photos and camera

Picking a photo asks for nothing at all: the picker is Apple’s and runs outside Dishy, so the app is never granted access to your library and receives only the image you chose. Taking a new photo does need the camera, so iOS asks the first time and you can say no. Dishy never writes anything back to your library.

A photo you add is uploaded to our image store and is not shown to anyone but a moderator until a person has checked it. Approved photos appear under the dish, credited to your display name or to “Anonymous” if you have that switched on. One we turn down is withdrawn straight away, and the file is erased after about thirty days.

Children

Dishy is intended for students and is not directed at children under 13. We do not knowingly collect information from them.

Third parties

Menu content originates with each school’s dining service. Beyond our own server, your phone fetches the worldwide school list from GitHub, school logos from logo.dev, map tiles and routing from Apple, and a dining hall’s photo from wherever that campus hosts it. Each of those hosts sees your IP address and the request; none of them gets an account, an email address or a device identifier from us. The one with a real consequence is logo.dev: a logo loads for every school on screen, so it sees which schools you scroll past, and your own campus whenever its crest appears. Tapping Directions hands the destination, and nothing about you, to whichever maps app you pick, which then works under its own privacy policy.

Changes

If this policy changes in a way that matters, we will update the date at the top.

Contact

Questions about privacy: [email protected].