Privacy Policy
dishi learns what you like to eat from what you actually eat. That only works if you trust us with honest ratings and real photos, so this policy is written to be read. It explains what we collect, what we do with it, what we will never do with it, and how you stay in control.
1. Who we are and what this covers
dishi (“dishi”, “we”, “us”) operates the dishi service at dishi.me and any related apps, pages and APIs (together, the “Service”). This policy covers personal data we collect through the Service. It is written with the Hong Kong Personal Data (Privacy) Ordinance (Cap. 486) in mind and applies wherever you use dishi.
2. What we collect
Account and sign-in. Your email address; if you sign in with Google, the email address and basic profile (name) Google shares with us. We do not use your Google profile picture. A one-time code sent to your email is how we verify it is you.
What you log. Dish photos you upload, the names and prices of dishes, the restaurant or home-cooking context, your ratings, comparisons (duels), notes, diet flags, bookmarks, and any menu photos you scan. Your own username and display name.
What we derive. A taste profile built from your ratings, including per-dimension scores, confidence, version history, the “taste creature” that visualises it, and predictions we seal before you rate a dish so we can show you how well we know you.
Location. If a photo you upload carries location metadata, we read it to suggest where the dish was eaten. When you look up a restaurant, we use the location you supply or your device’s location (with your permission) to search nearby. We do not track your location in the background.
Shared tables. If you join a table with other people, the dishes picked, who picked them, and the table’s state are shared with everyone at that table.
Public posts and pages. Anything you choose to publish — a dish post, your public profile page — is public and may be viewed, indexed and shared by anyone with the link.
Restaurant owners. If you claim a restaurant page, we collect the details needed to verify the claim and the menu information you publish.
Device and usage data. Standard technical data such as IP address, browser type, device type, language, pages viewed, timing, crash and error reports, and cookies or similar identifiers needed to keep you signed in and keep the Service working.
Communications. Messages you send us and our replies.
3. How we use your data
- To run dishi. Sign you in, store what you log, show your journal, run tables, publish what you choose to publish.
- To learn your taste. Build and update your taste profile, compare dishes, seal and reveal predictions, and recommend what to order. This is the core of the Service and cannot be separated from it.
- To let you take your taste anywhere. Generate a taste export for you to paste into an AI assistant of your choice, when you ask for it.
- To recognise dishes and menus. Send photos and menu images to AI vision and language providers that identify dishes, read menu text and estimate ingredients. Images are processed to produce those results; see section 5.
- To improve dishi. Analyse how the Service is used, fix bugs, evaluate and improve the models that recognise dishes and learn taste. Where we use your data for this, we use it in de-identified or aggregated form wherever the purpose allows.
- To build dish-level insight. Combine ratings across many people into aggregated, de-identified statistics about dishes and restaurants — for example, how a dish compares between two shops. These statistics power recommendations and may be offered to restaurants and partners as part of our business (section 4).
- To keep dishi honest and safe. Detect fake ratings, manipulation, abuse, fraud and security incidents, and enforce our Terms of Service.
- To talk to you. Send sign-in codes, service notices, and replies to your messages. We will ask before sending anything promotional.
- To meet legal obligations and to establish, exercise or defend legal claims.
4. Our commitments
dishi is a business, and we intend to build one. We reserve the flexibility to develop new products and revenue models on top of what people log. These commitments bound that flexibility, and we will not cross them without changing this policy and telling you first:
- We do not sell your personal data. Not your email, not your photos, not your individual ratings, not your taste profile. Ever.
- Insight we offer to restaurants or partners is aggregated and de-identified. It describes dishes, not people. It will not identify you or let anyone work out that you personally ate or rated something, and we will not release it in slices small enough to do so.
- Recommendations are never for sale. No restaurant or advertiser can pay to appear in, or move up, what dishi recommends to you. If we ever show sponsored content, it will be labelled as such and kept apart from recommendations.
- If we introduce advertising, advertisers will not receive your personal data. Any targeting would happen on our side, in aggregate, and you would be able to opt out.
- No social graph. dishi does not ask for your contacts, does not build a friends list, and does not tell other people what you rated unless you publish it yourself.
- Your photos are yours. We use them to run the Service and, in de-identified form, to improve dish recognition. We do not licence them to third parties for their own purposes.
- Your taste export goes where you send it. We do not send it to any AI provider on your behalf; you copy it, you choose the destination, and that provider’s policies then apply.
5. Who else sees your data
We share personal data only with parties that help us run the Service, under contracts that limit what they can do with it:
- Hosting and database providers that store your account and content and serve the Service.
- AI vision and language providers that process dish photos and menu images to recognise dishes, read text and estimate ingredients. We send the image and the minimum context needed, not your identity. We choose providers whose terms do not allow them to train on the data we send, where such an option exists.
- Sign-in and mapping providers — Google for “Continue with Google” and for restaurant search — which receive only what those functions require.
- Email delivery providers for sign-in codes and service notices.
- Analytics and error-reporting tools that help us understand usage and fix problems.
We may also disclose data where the law requires it, to protect the rights, safety or property of dishi, our users or the public, or as part of a merger, acquisition or sale of assets — in which case the receiving party will be bound by this policy for data collected under it.
Content you publish is, by definition, shared with the public. Content at a shared table is shared with the people at that table.
6. How long we keep it
We keep your account and what you log for as long as your account exists, because your taste profile is built from the whole history. If you delete your account we delete or de-identify your personal data within 30 days, except where we must keep it longer for legal, security or dispute reasons, or where it lives in backups that expire on their own schedule. Aggregated, de-identified statistics that no longer identify you may be kept indefinitely.
7. Your rights and choices
- Access and correction. You can see and edit most of what you have logged directly in the Service. You may also ask us for a copy of the personal data we hold about you, and ask us to correct it, as provided by the Personal Data (Privacy) Ordinance.
- Export. Your taste export is available in the Service at any time.
- Deletion. You can delete individual dishes, posts and bookmarks yourself, and you can ask us to delete your account.
- Publishing. Posting is per dish and opt-in; you can unpublish at any time.
- Location. You can strip location from photos before uploading, or decline the browser’s location permission.
- Marketing. We will not send promotional email without asking, and every such email would include a way to opt out.
To exercise a right, contact us at hello@dishi.me. We may need to verify that it is you. We aim to respond within 40 days, as the Ordinance requires, and usually sooner.
8. Security
We protect data with access controls, encryption in transit, row-level access rules in our database, and sign-in that never stores a password. No system is perfectly secure; if we learn of a breach that affects you, we will tell you and any regulator we are required to notify without undue delay.
9. Children
dishi is not directed at children under 13 and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will delete it.
10. Where data is processed
Our providers may store and process data outside Hong Kong, including in the United States and the European Union. Where we transfer data across borders we take steps intended to keep it protected to a standard consistent with this policy.
11. Changes to this policy
We will update this policy as dishi grows. Small clarifications take effect when posted. For material changes — especially anything touching section 4 — we will give notice in the Service or by email before they take effect. Continued use after that date means you accept the updated policy.
12. Contact
Questions, requests and complaints: hello@dishi.me. You also have the right to complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong.