Privacy Policy
Last updated 2 September 2026
SpoonTip (“the app”, “we”) is built and operated by SpoonTip. This policy explains what data the app and this website handle, where it goes, and how you control it. We have tried to keep it short and specific. If anything here is unclear, email privacy@spoontip.com.
What leaves your device, and where it goes
| What | Where it goes | Why | Do we keep it on our servers? |
|---|---|---|---|
| Menu photos you scan | OpenAI | Reading and translating the menu | No |
| Text and photos you send in chat | OpenAI | Answering you and recommending dishes | No |
| Your voice, when you use voice translation or dictation | OpenAI | Turning speech into text | No |
| Your approximate location (city level), only if you allow it | Yelp and OpenAI | Finding restaurants near you; giving the assistant local context; suggesting a local language | No |
| Your email address and name, only if you sign in | Supabase, our sign-in provider | Signing you in and showing your name in the app | Yes, while your account exists |
| How many scans you ran each day | Supabase, our database | Enforcing the daily scan limit | Yes — we retain these counts |
| Currency codes | frankfurter.app | Converting menu prices | No — nothing personal is sent |
The details
Scanning a menu. Your photo is sent over an encrypted connection to OpenAI, which reads the text and translates it. We do not keep a copy of the photo. OpenAI processes it under OpenAI’s API terms, which state that API content is not used to train their models.
Chatting with the assistant. Whatever you type or send in chat — questions, photos, your answers to the assistant’s questions — goes to OpenAI to generate the reply. To answer questions about restaurants, the assistant may search the web through OpenAI; those searches go to OpenAI’s search service. We do not keep your conversations on our servers; they are stored on your device.
Voice. When you use voice translation or dictate a message, your audio is sent to OpenAI to be converted into text. We do not store the audio. This corrects an earlier version of this policy, which said speech recognition ran on your device — it does not.
Signing in is optional. By default the app creates an anonymous identifier through Supabase Auth on first launch. It is not tied to your name, email address, or phone number; it exists only to authorise access to our shared dish catalog and to count your daily scans. If you choose to sign in with Google, or with an email address and password, we store your email address and — from Google — your name. We use them only to sign you in and to show your name in the app. We do not send marketing email.
Location. Only if you grant permission, and only at city level. It is sent to Yelp to find restaurants near you, and to OpenAI as context when you ask the assistant about local food. We do not store your location. You can revoke permission at any time in iOS Settings → SpoonTip → Location.
What stays on your device. Your scan history, translated menus, cart, and preferences are stored on your device only. They are not sent to our servers and are not visible to anyone else. Menus you have already scanned open offline.
Scan counts. To enforce the daily scan limit we keep a count of how many scans your identifier ran each day. It contains no menu content, and we retain these counts.
Dish photos. Dish images shown in the app are loaded from our hosting provider, which sees your IP address in the ordinary way any web server does. We do not use this to identify you.
Maps. Tapping a restaurant’s address opens it in Apple Maps or Google Maps. From that point you are in their app, under their privacy policy.
What this website handles
Early access. “Ask for early access” opens your email app. If you write to us, we keep your message and address to reply and to let you know when the app launches. We do not add you to a marketing list or share your address. Ask us to delete it at any time and we will.
Analytics. This website uses Vercel Web Analytics to count page views. It is cookieless. Each view records the page, the referring page, your country and city, and your browser, operating system and device type. Visitors are told apart by a hash that is discarded after 24 hours and is not tied to your IP address, so there is no per-person history. The script and its beacons load from spoontip.com itself, not from a third-party domain. Nothing else on this site — no fonts, scripts or images — is loaded from third parties.
What we do not do
- We do not track you across apps or websites.
- We do not show ads.
- We do not sell your data, or share it for advertising.
- We do not use analytics that profile your identity. The app has no analytics or crash-reporting SDK at all; the website’s page-view counter is cookieless and keeps no per-person history.
Third-party processors
| Processor | Purpose | Their privacy policy |
|---|---|---|
| OpenAI | Reading menus, translation, chat, voice transcription, web search | https://openai.com/policies/privacy-policy |
| Supabase | Sign-in, shared dish catalog, scan counts | https://supabase.com/privacy |
| Yelp | Restaurant lookup, when you allow location | https://www.yelp.com/tos/privacy_policy |
| frankfurter.app | Exchange rates for price conversion | https://www.frankfurter.app/about |
| Vercel | Website hosting and cookieless page-view analytics | https://vercel.com/legal/privacy-policy |
Your rights and controls
- Clear everything on this device. In the app: Settings → System → Privacy → Clear All Data. This permanently removes every menu, cart entry, and preference from your device.
- Sign out. In the app: Settings → Account → Sign out.
- Delete your account. In the app: Settings → Account → Delete account. Or email privacy@spoontip.com and we will delete your account and its data.
- Revoke location. iOS Settings → SpoonTip → Location.
- Ask us anything. Email privacy@spoontip.com with any privacy question or request.
Children
SpoonTip is not directed at children under 13, and we do not knowingly collect personal information from them.
Changes to this policy
Material changes will be reflected in the “Last updated” date above and announced in the app on next launch.