Privacy Policy
For Top Plate, a mobile app for keeping track of the food you cook.
Effective 27 July 2026. Last updated 27 July 2026.
Top Plate is run by Noah Fisher ("we", "us"), an independent developer based in Florida, United States. This policy explains what the app collects, why, who can see it, and how to get rid of it.
The short version: we collect the account details you give us and the cooking content you create. As of the date above, there are no analytics tools, no advertising, and no third-party trackers in this app, and we do not sell your data. If that ever changes, we will update this policy and tell you before the change takes effect.
1. What we collect
| Category | What it is | Why |
|---|---|---|
| Account | Your email address, and a password if you sign up with one. If you use Google or Apple to sign in, we receive your email address and a unique ID from them — not your password. | To create your account and let you sign back in. |
| Profile | Username, display name, an optional short bio, and an optional profile picture. | So friends can recognise you. |
| Cooking content | Recipes you write (title, description, ingredients, steps, cuisine, times, servings), each time you log cooking one, plus any caption, notes, or photos you attach. | This is the core of the app — it's your cooking history. |
| Rankings | The head-to-head comparisons you make between your own dishes, and the ordering and scores we derive from them. | To build and maintain your ranked list. |
| Social | Friend requests and friendships, likes, comments, who you tag as having cooked with you, and the resulting notifications. | To make the social features work. |
| Technical logs | Our hosting provider records standard server logs, which include IP addresses, timestamps, and which requests were made. | Security, debugging, and abuse prevention. Not used to build a profile of you. |
2. What we do not collect
- No analytics or tracking SDKs. There is no Google Analytics, Firebase, Amplitude, Segment, Mixpanel, Sentry, or similar in this app.
- No advertising, and no ad identifiers. We do not track you across other apps or websites.
- No location tracking. The app never asks for your location.
- No access to your contacts, calendar, microphone, or health data.
- No data sales. We do not sell or rent personal information, and we do not share it for cross-context behavioural advertising.
This describes the app as it works today. If we later add something like analytics or advertising, we will say so here and notify you first, and we will not apply new uses to information collected before the change without asking you.
About photo location data. Photos taken on a phone often carry hidden metadata, including the GPS coordinates of where they were taken — frequently someone's home. Top Plate re-encodes and resizes every photo on your device before it is uploaded, which strips that embedded metadata. The coordinates never leave your phone.
3. Camera and photo access
The app asks for camera and photo library permission only when you choose to add a picture to a cook or set a profile picture. You can decline, and the rest of the app still works — photos are optional everywhere. We only ever receive the specific images you pick.
4. Who can see your content
Access is enforced at the database level, not just hidden in the app:
- Your cooking history and rankings are visible to you and, depending on each recipe's visibility setting, to your accepted friends. Recipes can be set to public, friends-only, or private.
- Photos of food are stored in a private location and are served through short-lived, expiring links. They are not publicly browsable.
- Comments and likes are visible to people who can already see the cook they're attached to.
- Tagging someone as having cooked with you puts that cook in their history too. Only tag people you actually cooked with.
One exception worth knowing. Profile pictures are stored in a public bucket. That means anyone who has the direct link to your profile picture file can open it, even without a Top Plate account. Your other content is not stored this way. If you'd rather not have a publicly reachable image, don't set a profile picture.
5. Who we share data with
We use a small number of service providers, and no one else:
- Supabase — hosts our database, file storage, and sign-in system.
Your data is stored on servers in the United States (AWS
us-east-1, Northern Virginia). - Google — only if you choose "Continue with Google". Google tells us your email address and a user ID.
- Apple — only if you choose "Sign in with Apple". If you use Apple's Hide My Email feature, we only ever receive the relay address, never your real one.
We may also disclose information if we are legally required to, or where it is necessary to investigate abuse or protect someone's safety.
6. Keeping and deleting your data
We keep your content for as long as your account exists. You can edit or delete individual recipes, cooks, comments, and photos from inside the app at any time.
To delete your entire account and everything in it, open Edit Profile and choose Delete account. Your account, your content, and your photos are removed immediately. Deletion is permanent — there is no recovery, so the app asks you to confirm twice. If you'd rather we did it for you, email [email protected] from the address on your account and we'll handle it within 30 days.
Some content may remain visible in a limited form after deletion: a cook you were tagged in belongs to the other person's history too, and their copy stays. Backups are purged on a rolling basis within 90 days. Anonymised logs that contain no personal identifiers may be retained.
7. Your rights
Wherever you live, you can ask us to show you what we hold about you, correct it, export it, or delete it. Email the address at the bottom of this page and we'll respond within 30 days. We will not treat you differently for exercising any of these rights.
If you're in California
Under the CCPA/CPRA you have the right to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information, so there is nothing to opt out of, but the other rights apply and are honoured through the same email address.
If you're in the UK, EU, or EEA
Under the UK GDPR and GDPR you have rights of access, rectification, erasure, restriction, portability, and objection. Our lawful basis is contract for the parts needed to run your account and the app's core features, and legitimate interests for security and abuse prevention. Your data is transferred to and stored in the United States. You have the right to complain to your local data protection authority.
8. Children
Top Plate is not intended for children under 13, and we do not knowingly collect information from them. If you believe a child under 13 has created an account, email us and we will delete it promptly.
9. Security
Traffic between the app and our servers is encrypted in transit (HTTPS). Access to your data is enforced by row-level security policies in the database, so one account cannot read another's private content even if the app itself is bypassed. Passwords are stored hashed by our sign-in provider and are never visible to us.
No system is perfectly secure, and we can't promise otherwise. If we ever discover a breach affecting your personal data, we will notify affected users and any regulators we're required to, without undue delay.
10. Changes to this policy
If we change this policy, we'll update the date at the top. For anything that materially affects how your data is used, we'll notify you in the app or by email before it takes effect.
11. Contact
Questions, requests, or deletions:
[email protected]
Noah Fisher, Florida, United States