It's Dinnertime! privacy policy
Effective September 30, 2026 · It's Dinnertime! is made by Smart Home Life LLC.
The short version
Unless you connect an oven for alerts, we keep no record of who you are or what you do. The app has no accounts and no tracking, and it sends us no analytics. Your recipes, plans, lists, photos, ratings, notes and past grocery orders live on your device and, if you use iCloud, in your own private iCloud storage that only you can read. The one exception is a week you share with your household: it is kept in the iCloud of whoever set the household up, and only the people in it can read it. We cannot. Our own service remembers which stores are near a zip code, for a day, so the store finder stays fast: a fact about a place, never about you. If you connect a Samsung oven so the app can alert you while it is closed, our service keeps that connection until you disconnect it. "Oven Alerts" below lists every piece of it.
What stays on your device or in your iCloud
Recipes you save, weeks you plan, your grocery list, dish photos you take, the pictures drawn for recipes without a photo, your ratings and notes, your settings, and your past grocery orders. If you connect a store, what the app reads from your order history (items, prices, totals) is stored on your device and in your own iCloud, and never reaches us. If iCloud is on, Apple syncs these between your devices through your private iCloud database. We cannot read it: it belongs to your Apple Account, not to us.
Your grocery list is kept in Apple's Reminders, in a list you choose, so you can share it with your family the way you already share Reminders. That data is governed by your device and your Apple Account, not by us.
Sharing your week with your household (optional)
Add someone, in Settings, Household, makes a one-time invitation link through Apple's iCloud. Each link lets exactly one person join. The household lives in the iCloud of the person who set it up, as a shared space Apple keeps for them. Nothing about it passes through our service, and we cannot read it.
Everyone in the household can see:
- The week that was planned. Each night's dish, its note, ingredients and steps, and how many servings; for a dinner from a recipe on the web, a link to that page and its photo; nutrition figures when there are any. A dinner planned from one of your saved recipes brings that recipe's ingredients and steps, never your photos of it.
- The name each person typed when they joined, if they typed one. The app never reads anyone's Apple Account name, email or phone number, and someone who typed nothing shows as "Someone". To tell people apart, the app uses an identifier Apple's iCloud gives it for each person's account, which cannot be turned into a name or an email.
- The nights someone said no to. Which night, who crossed it off and when, and which of those were settled with Keep it.
- Invitation links nobody has used yet, and when each was made, so each can close after three days.
- Each person's colour, and their photo if they add one. A photo is small (under 64 KB), chosen with the system photo picker, which gives the app only the one photo you pick, so the app never asks for access to your photo library. It is saved on your phone and in your household's iCloud, and only the people in your household can see it. It is never sent to us. Remove your photo in Settings, Household and it leaves the household's copy too. Someone who has left, or was removed, may keep a photo their phone had already downloaded.
Not shared: your saved recipes and their photos (except one you send to someone, below), what you have cooked, your ratings and notes, your settings, a week you have planned ahead, and your allergens and diet. Your grocery list is shared only if you share it in Reminders. The Recent Activity list in Settings, Household is kept only on your phone: it is never sent to iCloud or to us, and your other devices keep their own.
Everything the household shares counts against the iCloud storage of the person who set it up, including what other people add to it. If you join someone else's household, the name you type, your photo and colour, and the nights you cross off are stored in their iCloud, not yours.
If you are in a household, Dinnertime can tell you when its week changes, or when someone crosses off a night, takes one back or keeps one. These notes are sent by Apple's iCloud, from a request saved in your own iCloud account, through Apple's push notification service. Nothing about them passes through our service. They say only that something changed, never who or which dinner. If you made an invitation link, Dinnertime can also remind you, on your own phone, about 48 hours after you made it, that the link has not been used and closes tomorrow. That reminder is scheduled on your phone and never leaves it. Each kind of note has its own switch in Settings, Notifications, and the switches apply to every device signed in to your Apple Account.
You can send one of your saved recipes to someone in your household, from its menu in Recipes. It goes into the household's shared space with its picture, addressed to them, and waits there until their phone copies it into their own recipes, which takes it out of the shared space again. While it waits, it counts against the storage of whoever set the household up, and like everything the household shares it can be read by the phones of the people in it. Your rating and notes on it are not sent. Once it is copied it is theirs: your later changes do not reach it, and they can change or delete their copy. Their copy is marked with the name you typed for the household.
Anyone can leave a household in Settings, Household. The person who set it up can also remove someone, close a link nobody has used, or stop sharing, which ends the household for everyone. Removing someone deletes their name and the nights they crossed off from the household, and so does leaving, the next time the phone of whoever set it up syncs the household. Stopping sharing deletes everything the household shared from their iCloud, and their own week stays on their phone. What a phone had already received may stay on that phone: one person's tap cannot reach into someone else's device.
Apple Health
Two optional connections, each off until you turn it on.
Sending your dinners. If you turn on "Send cooked dinners to Apple Health" in Settings, the app writes the nutrition figures for each dinner you finish to Apple Health on your device. Figures the app estimated are marked as estimates in Health. Nothing it writes is read back.
Seeing the rest of your day. If you tap "Connect Apple Health" on the week's totals, the app reads today's calories, protein, carbohydrates and fat that other apps have logged in Apple Health, and shows them beside your dinner. What it reads is displayed on your device and then forgotten: never stored, never synced to iCloud, never sent anywhere. It leaves out what this app itself wrote, so a dinner is never counted twice. You can turn sending off in the app's Settings, turn either connection off in iOS Settings (Privacy & Security, Health) or in the Health app, and manage or delete what was written in the Health app itself.
What leaves your device, and what it carries
- Fetching a recipe you asked for. When you paste or share a recipe link, the app fetches that page directly from that website, the same way a browser would. The website sees an ordinary page request from your device. Browsing the starter-recipe catalog goes through our own service instead, which passes the request along and keeps nothing; the starter recipes' photographs load from TheMealDB directly, like any picture on a web page.
- Store prices (Pro). When you look up prices, the app asks our price service for a product search at your chosen store. The request carries the search words and the store, and for the store picker your zip code. It never carries your name, an account, or anything that identifies you. Our service keeps no record of who asked or what anybody searched; the one thing it does keep is a shared day-long note of which stores are near a zip code, so the store finder does not have to ask the catalog twice. Supabase, the company that runs our service, keeps short request logs of its own; because the search words and the zip code travel in the request's address, those logs can hold them, with the internet address the request came from, until they expire about a day later. Price data comes from the store's own public catalog service. A price lookup also carries your Pro purchase's signed receipt, which our service checks and does not keep. The store finder instead carries a proof that the request comes from a real copy of this app (Apple's App Attest), which says nothing about you and is not kept either.
- Signing into a store's website (optional). If you connect a store (Kroger, Walmart, Whole Foods, Publix, Costco, or an Albertsons-family store), you sign into that store's own website in a secure web view on your device. Your sign-in belongs to that store; we never see or store your credentials, and their privacy policy governs what they do. With a store connected, the app can read prices and your own order history from the store's pages, on your device; what it reads stays on your devices and never reaches us. To keep you signed in, the app keeps the store's sign-in cookies in your device's Keychain for up to 30 days, on that device only, never in a backup, and removed when you disconnect the store.
- Scanning a barcode. When you scan a product, the app asks Open Food Facts, a nonprofit open food database, what that barcode is. The barcode digits are all that go; no account, no device, nothing about you, and nothing about anything else you have scanned. It comes back with a product name, which is what lets the app search your stores for the right thing. If the database does not know the barcode, the app says it could not confirm it rather than guessing.
- Sending items to your Kroger cart (Pro, optional). If you connect your Kroger account for the cart, Kroger's sign-in hands the app a connection code, and our service exchanges it with Kroger for the app. That is the one moment it passes through us; it is not logged or kept, and the resulting connection lives only in your device's Keychain.
- Connecting a Samsung oven (Pro, optional). You sign in on Samsung's own page; we never see your Samsung password. Samsung asks you to let Dinnertime read the devices and locations (homes) you have in SmartThings. That access is read-only: the app can never turn anything on, change a temperature or start a cycle. Samsung's page hands the app a sign-in code, and our service swaps it with SmartThings for the connection's keys, because that swap needs a secret the app must not carry. The swap itself keeps nothing, and the app stores the keys in your device's Keychain. Your phone then looks through your SmartThings devices for ovens, on the phone. While you are looking at your oven in the app, your phone reads it straight from SmartThings about every 20 seconds, not through us.
- Oven Alerts (Pro, optional). To reach you when the app is closed, our service keeps a small record of your oven connection and your phone, SmartThings sends it your oven's changes, and each alert travels to your phone through Apple's push notification service. This is the one feature where our service keeps something tied to you. "Oven Alerts" below lists all of it.
- Sharing a recipe with other cooks (optional). If you share a recipe with other cooks, the recipe itself (its name, ingredient lines, steps, yield, time, category, and your own photo of the dish if you added one) is posted to the app's public iCloud database, where anyone using the app can read it and save it. Nothing about you goes with it: no name, no email, no location, no notes, no ratings, and no link. Apple's iCloud notes which iCloud account posted it as an opaque identifier that we cannot turn into a person; we see that identifier only in Apple's developer console, and use it for nothing but removing a post. Reading shared recipes sends nothing. You can remove your own post at any time from its page, and we remove anything reported that is not a recipe. If you report a recipe, the report (which post, your reason, and any note you type) is written to the same public iCloud database so we can read it in Apple's developer console; write nothing personal in the note. Hiding a cook's recipes sends a report the same way.
- AI planning. Meal planning and substitutions run on Apple Intelligence, on your device or in Apple's private cloud (Private Cloud Compute), which is designed so that nobody, including Apple and including us, can read your requests. If you paste your own Claude, ChatGPT or Gemini key, the request goes to that provider instead, under its terms and your own account, and that is your choice each time. What is sent is the week the app is planning or the recipe it is writing: your saved recipes' names, which dinners you marked liked or disliked, what your household does not eat, and a recipe's own lines when you ask for one to be completed; never a link, and never your key to us. On Google's unpaid Gemini tier, Google's terms allow it to use what you send to improve its products and to have people read it; a key billed to a paid Google account is covered by different terms. The app says this beside the key field.
- Purchases. Pro is bought through Apple. We receive no payment details. The app verifies your purchase with a signed receipt; our service checks the signature and keeps nothing.
- If an ad brought you here. The app tells Apple, on the phone, how far it has got: opened, a free trial started, or Pro bought. If you installed it after an ad on a network such as Meta, Reddit or TikTok, Apple later tells that network the furthest step, in an anonymous report, through Apple's SKAdNetwork and AdAttributionKit, so an ad can be judged by who stays rather than who downloads. The report carries no identifier and nothing about you or your recipes. Apple sends it, not us, and it never reaches us. Apple does not count it as tracking. Without an ad, there is no report.
Oven Alerts (Pro, Optional)
If you own a Samsung oven, range or cooktop, you can connect it through SmartThings in Settings, Connections, so the app shows what it is doing and alerts you when it turns on, reaches temperature, finishes its own timer, has a burner turned on, is left on, or has its door left open. This is the one part of the app where our service keeps something tied to you, and it exists only so an alert can reach your phone while the app is closed. If you never connect an oven, none of this exists for you.
While your oven is connected, our service keeps exactly this:
- Which connection is yours. The SmartThings ids for this connection, for your SmartThings location, and for the one oven you chose. SmartThings sends us that oven's changes by these ids, and we ignore changes from anything else.
- The connection's keys. Your SmartThings access and refresh tokens, encrypted, so the connection keeps working.
- Where to send alerts. Your phone's push token, and whether it belongs to Apple's test push service or its normal one, so each alert reaches your phone.
- Which alerts you want. The switches you set for the six alerts.
- The oven's last reading, and only the last one. Whether it is on, its temperature and set temperature, mode, door, timer and burners, the probe's temperature and target, whether the cooktop surface is still hot, and when that reading arrived. An alert like "Your oven is at 400° F." comes from noticing a change, which takes one earlier reading to compare against. Each new reading replaces the one before.
- A few times, only while the oven is on. When it turned on, when its door opened, and when its own timer finished, plus two notes that the "left on" and "door open" alerts were already sent, so each is sent once. All of them are cleared the moment the oven turns off.
- Two dates for the connection itself. When the app last renewed it, which the 30-day rule below counts from, and when anything in it last changed.
We never keep a history of your oven's readings, a log of what it did, your name, your email, your Samsung password, what you cooked, or anything else from the app. Each alert's words are put together at the moment it is sent and are not stored.
When it is deleted. All of it goes:
- the moment you tap Disconnect in Settings, Connections, with or without Pro;
- when SmartThings tells us the connection has been removed on its side;
- in every case, 30 days after the app last renewed the connection. The app renews it each time it starts while you have Pro, so if you delete the app, or Pro ends, the connection goes on its own.
Your phone's push token alone is cleared sooner if Apple tells us it no longer works. You can also switch off any alert and keep the oven connected.
Samsung's own privacy terms cover what SmartThings does with your account.
What we collect
Almost nothing, and unless you connect an oven for alerts, nothing about you. The App Store label declares a coarse location (the zip code you give the store finder, remembered by place for a day), search history (the product words that pass through our price service, which keeps none of them; its host's request logs can hold them for about a day), and user content (a recipe you choose to share with other cooks, and only that), none of it linked to you. Connecting an oven adds the identifiers listed under "Oven Alerts", which are linked to you because an alert cannot reach your phone without knowing which phone, and which are used for that and nothing else. Sharing your week with your household adds nothing to this list: it lives in your household's iCloud and never reaches us. Nothing is used for tracking, and none of it is sold or used for advertising. We run no analytics and no crash-reporting SDKs. The one measurement is the anonymous ad report under "If an ad brought you here" above, which Apple sends to the ad network and never to us. If you choose to share diagnostics with Apple, Apple may show us standard crash reports under Apple's own privacy terms; these contain no recipes, plans, or identities.
Data retention and deletion
Unless you connect an oven for alerts, we hold no data about you, so there is nothing for us to retain or delete. If you do, "Oven Alerts" above says exactly what is held and when each part goes, and Disconnect in Settings, Connections deletes all of it, with or without Pro. (The store finder's zip-to-stores note expires on its own within a day.) A recipe you share with other cooks stays visible until you remove it or we do. A week you share with your household stays in the iCloud of whoever set the household up until they stop sharing; "Sharing your week with your household" above says what each way out deletes. If you turn on the shared recipes digest in Settings, the app checks for new shared recipes in the background the way it does when you open it, and posts a note on this phone; nothing about you leaves it. Everything the app stores is yours to delete: remove recipes and photos in the app, remove the app to delete its local data, and manage or delete its iCloud data in Settings > iCloud > Manage Storage on your device.
Consent
The app asks permission before using the camera (cookbook pages, dish photos and barcodes), Reminders (your grocery list), location (finding stores near you, only if you use "Use current location"), the microphone and speech recognition (cooking hands-free; speech is recognized on the phone), Apple Health (only if you turn it on), and notifications (when you first start a cook timer, start a free trial, turn on the shared recipes digest, connect an oven, or join or set up a household, for notes from your household). Every feature has a path that works if you say no, and you can change any of these later in Settings.
Children
It's Dinnertime! is made for adults who plan and cook meals. It is not directed at children. What we declare above is the same for every user, and we knowingly collect nothing further from anyone, children included.
Changes
If this policy changes, the new version will be posted at this address with a new effective date.
Contact
Smart Home Life LLC · anthonyharmond@smarthomelifellc.com
