Privacy Policy
Disha is built so that as little data as possible is collected: no account, no email required, no ad trackers. What is still processed is listed here.
Last updated: August 04, 2026
1. Data Controller
The controller responsible for data processing within the meaning of the General Data Protection Regulation (GDPR) is:
Tim Heck
Neue Straße 19a
35096 Weimar
Germany
Email: hello@getdisha.app
Phone: +49 15120241787
A data protection officer is not legally required and has not been appointed.
2. Core principle: Disha is local-first
Using the Disha app does not require an account. There is no registration, no sign-in, and no requirement to provide an email address. We do not maintain user accounts and do not create user profiles.
All content data generated while using the app, your weekly plans, recipes, shopping lists, saved dishes, and settings (budget, supermarket, household size, diet, allergies, unwanted ingredients, preferences, kitchen equipment), is stored exclusively locally on your device in an SQLite database. There is no cloud synchronization. If you delete the app, this data is removed along with it.
Disha contains no advertising and no analytics or ad trackers. No cross-device tracking is performed and no data is shared with third parties for advertising purposes.
3. Creating weekly plans with AI
When you create a new weekly plan or swap a single dish, a request is sent to an AI model (Google Gemini). The request goes through a server proxy that we operate; your app does not talk directly to the AI provider.
What data is transmitted
Only your plan settings are transmitted:
- Weekly budget
- Country/region and selected supermarkets
- Household size
- Diet style (e.g. vegetarian, vegan, high protein)
- Allergies and intolerances
- Ingredients you have excluded
- Preferences and available kitchen equipment
- Desired meals and days of the week
Not transmitted: name, email address, phone number, advertising IDs, device identifiers for re-recognition, or your precise location. On their own, these details do not allow any conclusion about your identity.
Legal basis and purpose
The purpose of the processing is to provide the main service you requested: creating a meal plan. The legal basis is Art. 6(1)(b) GDPR (performance of a contract or steps prior to entering into a contract).
Information about allergies and intolerances may qualify as health data within the meaning of Art. 9 GDPR. However, since we fully anonymize this information and send it as part of the AI request without any user identifier whatsoever (no account, no email, no advertising ID), it cannot be traced back to you as a person. You provide it voluntarily to receive suitable recipes; as a precaution, the legal basis is your explicit consent under Art. 9(2)(a) GDPR, which you give by entering the information during onboarding and can withdraw at any time by deleting it in the settings.
Retention period, server logs, and third countries
When the proxy is called (via our provider Cloudflare), your IP address is technically processed. It is used to deliver the response and to prevent abuse (e.g. rate limiting) and is generally stored only briefly in server logs; the legal basis is Art. 6(1)(f) GDPR (legitimate interest in stable, abuse-free operation).
The request is transmitted to our AI provider Google (Google Gemini) in the United States. We base this transfer on the EU-US Data Privacy Framework. Please note: Google may potentially use the fully anonymized inputs (such as recipes and ingredients) to improve its models. However, since no personal identifiers are transmitted, no conclusion about your identity is possible.
You can find further information on data processing in the privacy policies of these providers:
4. Subscription handling (Disha Premium)
Disha Premium is an auto-renewing subscription. The purchase itself is handled entirely through the respective app store, via Apple (App Store) or Google (Google Play). We do not receive payment data such as credit card numbers or bank details.
For the technical management of subscription status, we use the service provider RevenueCat, Inc. RevenueCat receives an anonymous identifier generated by the app together with the store’s purchase receipts, in order to verify whether an active subscription exists. We do not link this to your name or email address. The legal basis is Art. 6(1)(b) GDPR.
You can find further information on data processing in the respective privacy policies:
5. Location request
Disha may ask you once for access to your location in order to suggest suitable supermarkets and prices for your region. The wording of the prompt in the app is: “Disha uses your location once to suggest suitable supermarkets and prices for your region.”
The request is optional, the app works fully without it. The legal basis is your consent under Art. 6(1)(a) GDPR, which you can withdraw at any time in your device’s system settings. Only the region is derived from the location; a precise location is not stored and not transmitted to the AI.
6. Notifications
If you enable the shopping reminder, Disha schedules local notifications on your device. These are generated entirely on the device. No push messages are sent via a server and no push tokens are transmitted to us. You can turn the reminder off at any time in the app or in your system settings.
7. This website
This website is a purely static informational page. It sets no cookies, embeds no analytics tools, and does not subsequently load external fonts, maps, or videos. There is no contact form and no login.
When the page is accessed, our hosting provider Vercel Inc. (USA) technically processes connection data required for operation (IP address, timestamp, page requested, data volume transferred, browser and operating system identifier) in server logs. The transfer of data to the USA is based on the EU-US Data Privacy Framework. The legal basis is Art. 6(1)(f) GDPR.
You can find further information on data processing by our hosting provider in the Vercel Privacy Policy.
The buttons linking to the App Store and Google Play are simple links. A connection to Apple or Google is only established once you click them. There is no advance embedding and no tracking pixel.
8. Disclosure to third parties
Data is only disclosed to the service providers named above and only to the extent described: to the AI provider for creating the plan, to RevenueCat and Apple/Google for subscription handling, and to the hosting provider for operating the proxy and the website. We do not sell data. Data is not disclosed for advertising purposes.
9. Your rights
Under the GDPR you have the right, at any time, to:
- access the data processed about you (Art. 15)
- rectify inaccurate data (Art. 16)
- erasure (Art. 17)
- restrict processing (Art. 18)
- data portability (Art. 20)
- object to processing based on legitimate interests (Art. 21)
- withdraw consent given, with effect for the future (Art. 7(3))
One important note on this: since we do not maintain accounts and your content stays exclusively on your device, we generally cannot identify you and therefore cannot match you to any data stored with us (Art. 11 GDPR). You can delete your data yourself at any time: in the app under “Me” → “Delete all plans”, or by uninstalling the app.
For inquiries, you can reach us at hello@getdisha.app.
10. Right to lodge a complaint
You have the right to lodge a complaint with a data protection supervisory authority about the processing of your data (Art. 77 GDPR). The competent authority is the one for your place of residence or for the controller: the Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit).
11. Children
Disha is rated for ages 4+ and is intended for adults managing a household. We deliberately do not collect any data that would allow age to be determined.
12. Changes
We adjust this policy whenever the app or the services we use change. The version published on this page always applies; the date of the last change is shown at the top of the page.