Skip to content

Plato

Privacy Policy — Effective September 26, 2026

📸 Your photos are kept for at most 48 hours and then deleted automatically

Plato (“the App”, “we”, “us”) is developed and operated by Torhen. Plato uses artificial intelligence to identify products in your pantry from a photo and suggest recipes. This Privacy Policy explains how we handle information when you use the App, and applies to Plato on both iOS (App Store) and Android (Google Play).

1. TL;DR

  • We don't ask for your email, name, phone, or address to use the App.
  • To keep your free-scan quota stable (so it doesn't reset when you reinstall), we ask you to sign in with your Google account (Android) or Apple ID (iOS) before your first scan; we store an identifier for that account, not your name, email, or password. You can delete your account from the App at any time.
  • We use in-app usage analytics (Firebase Analytics) to understand how the App is used and improve it. We don't run advertising or sell your data.
  • The photos you scan, what the AI detects in them and the generated recipes are kept on our server for at most 48 hours, to review service quality and fix errors. After that they are deleted automatically.
  • Your preferences (diets, appliances, shopping list) live only on your device.
  • Not for users under 13 years old.

2. Information We DO NOT Collect

Plato does not collect:

  • Your name, phone, or address.
  • Your Advertising ID (we show no ads), IMEI, or MAC.
  • Precise location (GPS or WiFi). We only record the approximate country and city that Cloudflare derives from your IP (see 3.4).
  • Contacts, calendar, calls, SMS, or other installed apps.
  • Biometric data.
  • Financial information (payments are handled by your platform's store).
  • Crash/error reports (we don't use Crashlytics or Sentry).

Note: when you sign in we store an identifier for your account (see 3.3), we keep a service usage log (see 3.4), and usage analytics use an installation identifier (see 5.6).

3. Information We Process and Store

3.1. Pantry Photos

When you tap “Camera” or “Gallery”, the image is sent encrypted (HTTPS) to our server (Cloudflare Worker) and from there to the Anthropic (Claude) AI service to identify visible products.

Retention:

  • On your device: held in memory while the screen is open. Cleared when you exit.
  • On our server: we keep the photo and the AI response (the detected products) for at most 48 hours. Only the Torhen team can see them, and only to review result quality and fix errors; they are not used for advertising, not sold, and not used to train AI models. An automatic process that runs every hour deletes them once they reach 48 hours. If you delete your account, they are deleted immediately.
  • On Anthropic: up to 30 days for abuse monitoring per their policy, then deleted. Anthropic does not use this data to train their models under their commercial API terms.

We don't recommend photographing products containing sensitive personal information (labels with your name, prescriptions, documents).

3.2. Ingredient List and Cooking Preferences

When generating recipes, we send the server the ingredient list (without the photo), your dietary restrictions, available appliances, selected mode, and number of people. The ingredient list and the generated recipes are kept for at most 48 hours, for the same purpose and with the same automatic deletion as photos (see 3.1).

3.3. Stable Identity for Your Scan Quota (Google or Apple sign-in)

The free version includes a limited number of scans. So that quota is fair and doesn't reset just by clearing the App's data or reinstalling, before your first scan we ask you to sign in with your Google account (Android) or with Sign in with Apple (iOS). Signing in is required to scan:

  • What we store: an identifier for your Google or Apple account (not your name, email, photo, or password; with Apple we do not request your name or email) and a count of scans used. If you have Plato Pro, the monthly quota is tracked per purchase, not per account: we keep an encrypted fingerprint (hash) of the store order number, so the same subscription restored on another account shares the same quota. On Android we obtain that identifier via Google Sign-In (Play Services); on iOS, via Sign in with Apple. So we can revoke Apple access when you delete your account, we also keep the refresh token Apple issues for Plato.
  • Where: on our server (Cloudflare, D1 database). Unlike photos, this counter is stored persistently while you use the App, because it's what lets us remember how many scans you have left across sessions and devices.
  • Why: solely to enforce the free-tier limit and the premium monthly allowance. Not used for advertising, not shared with third parties.
  • If you don't sign in: you can keep using the App (recipes, pantry, preferences), but not scan, because without an account we can't track your quota.

3.4. Service Usage Log

For each scan or recipe generation we record technical data: date and time, result (success or error), number of products or recipes, language, App version, device type, the approximate country and city and internet provider that Cloudflare derives from your IP, and an encrypted (hashed) version of your IP. We do not store your IP in the clear. We use it to enforce the quota, prevent abuse, measure costs and detect failures. This log contains no photos, ingredients or recipes, and it is deleted when you delete your account.

4. Information Stored on Your Device

Plato stores the following data locally on your phone using SharedPreferences. This information never leaves your device:

  • Selected language.
  • Dietary restrictions (vegetarian, low-carb, etc.).
  • Appliances and kitchen basics.
  • Shopping list.
  • Onboarding flags (tutorial seen, disclaimer accepted, tips seen).

Uninstalling the App permanently removes all this information. (On Android you can also clear it from Settings → Apps → Plato → Storage → Clear data.)

5. Third-Party Services

5.1. Cloudflare

Hosts our server and its storage (D1 database and R2 files), where photos and results are kept for at most 48 hours (see 3.1) along with the usage log (see 3.4). Receives the photo, ingredient list, and your IP. May retain request logs for up to 7 days for security. Cloudflare Privacy Policy.

5.2. Anthropic (Claude)

Processes the image and generates recipes. Receives the image (base64-encoded) and prompt data. Retains up to 30 days for abuse monitoring, no model training. Anthropic Privacy Policy.

5.3. Google Fonts

The App downloads the “Plus Jakarta Sans” font from fonts.google.com on first run. Google Privacy Policy.

5.4. App Stores (App Store / Google Play)

If you download Plato from the App Store (Apple) or Google Play (Google), that store collects its own information about you as a store user, beyond our control.

5.5. RevenueCat (subscription management)

To manage the premium subscription we use RevenueCat. RevenueCat processes your purchase history and an App user identifier (anonymous by default; if you sign in with Google, that identifier is derived from your Google account — see 3.3). This data is used solely to know whether your subscription is active and to restore your purchases; it is not used for advertising or cross-app tracking. RevenueCat Privacy Policy.

5.6. Firebase Analytics (Google)

We use Firebase Analytics to understand, in aggregate, how the App is used (screens viewed, actions such as scanning or generating recipes) so we can improve it. It collects usage events, a Firebase-generated installation identifier, and basic technical device data (model, OS version, language). If you signed in, this identifier may be associated with your user identifier. We don't use it for advertising. Firebase Privacy · Google Privacy Policy.

5.7. Google Sign-In / Google Play Services and Sign in with Apple

On Android, sign-in (see 3.3) uses Google Sign-In (Google Play Services). Google provides us an identifier for your account to link your quota; handling of your Google account is governed by the Google Privacy Policy. On iOS we use Sign in with Apple, which gives us an identifier for your Apple ID that is unique to Torhen's apps; it is governed by the Apple Privacy Policy.

6. Subscriptions and Payments

Plato is free to start (includes free scans). It offers an optional premium subscription (Plato Pro) processed through your platform's store —App Store on iOS or Google Play on Android— and managed with RevenueCat (see 5.5). Payment details (card, etc.) are handled directly by the store; we do not retain any of your financial information.

7. Cookies

Plato is a native mobile app, does not use cookies, web beacons, or pixel tracking.

8. Security

All communications between the App and our server are encrypted (HTTPS / TLS 1.2+). The AI provider's API key lives encrypted on the server, never in the App. Despite reasonable precautions, no system is 100% secure.

9. Your Rights

Depending on your jurisdiction, you have the right to:

  • Access: almost all your information lives on your device. On our server we keep your user identifier, your scan counter (see 3.3), the usage log (see 3.4) and, for at most 48 hours, your latest photos and results (see 3.1).
  • Rectification: edit all your preferences within the App.
  • Erasure: in the App, go to Profile → Delete my account. This deletes your usage history on our server, your stored photos and results, and your RevenueCat record, and revokes Apple access (if you used Apple). We keep only the count of free scans already used, tied to an opaque identifier, so the free quota does not reset by deleting and re-creating the account (legitimate interest in preventing abuse). Uninstalling the App removes all your local information. You can also request deletion of your account and data without having the App installed: email contacto@torhen.com from your account's email address and we will do it within 30 days.
  • Object / portability: you can request deletion of the server-side data by writing to our contact email.

EU (GDPR): rights of access, rectification, erasure, restriction, portability, and objection (Arts. 15-21). Legal basis: explicit consent (Art. 6.1.a) and contract execution (Art. 6.1.b).

California (CCPA): right to know, delete, and opt out. We don't sell your data.

Chile (Law 19.628): access, modification, cancellation, and blocking of your data.

To exercise your rights, write to contacto@torhen.com.

10. Children's Privacy

Plato is not directed at children under 13. We don't knowingly collect data from minors. If we discover we collected data from a minor without parental consent, we will delete it immediately.

11. International Transfers

Your data may be processed in the United States (Anthropic, Cloudflare, Google/Firebase, RevenueCat) or on Cloudflare's global network. These providers have Standard Contractual Clauses (SCCs) per GDPR.

12. Changes to This Policy

If we make material changes, the updated version will be available at the same URL and reflected in the App Store and Google Play listings. Continued use of the App constitutes acceptance.

13. Contact

Torhen
Email: contacto@torhen.com

© 2026 Torhen — Plato — All rights reserved.