Privacy Policy
Last updated: 10 August 2026
Dipper is a food discovery and social dining app. This policy explains exactly what data we collect, why we collect it, who processes it, how long we keep it, and how you can get it deleted.
The short version. We do not sell your data. We do not show ads. We do not track you across other apps or websites, and we do not build advertising profiles. You can browse and use the randomizer without an account at all.
1. Who we are
Dipper is operated by the developer of the Dipper mobile application ("we", "us"). For any privacy question, or to exercise any right described below, contact support@dipper-app.com.
2. What we collect and why
| Data | Why we collect it | Kept until |
|---|---|---|
| Email address and sign-in identity (including Google sign-in) | To create and secure your account and let you sign back in | You delete your account |
| Display name, username, avatar image | So other members of your groups can recognise you | You delete your account, or edit it yourself at any time |
| Groups, memberships, invitations, chat messages, votes | To run the shared dining features you chose to use | You delete your account or the group is deleted. Messages you wrote become anonymous rather than being shown under your name |
| Bundles and randomizer history | To remember your saved lists and spin results | Stored on your device; cloud copies are removed with your account |
| Search terms and, with your permission, your precise location | To find places near you. Sent to our server, which queries HERE and Google on your behalf | Used for the request and briefly cached. We do not log your location history |
| Reviews, photos, price votes, reports and blocks you submit | To power community content and keep the app safe | You delete the item or your account. Safety reports may be retained longer where needed to act on abuse |
| Push notification token, installation identifier, timezone | To deliver notifications at sensible times and to limit API abuse | You sign out or delete your account |
| Device attestation tokens (Play Integrity) | To confirm requests come from a genuine Dipper install and protect our API budget | Checked at request time only; never stored |
| Crash diagnostics | To find and fix crashes | Per Firebase Crashlytics retention. Contains no account identifier and no personal content |
| Support messages you send us | To answer you | Until your issue is resolved, then removed with your account |
3. Location
Dipper asks for location only to search for places near you, and only while you are using the app. We do not collect location in the background. You can refuse the permission and still use Dipper — you will simply need to type an area to search instead. You can withdraw the permission at any time in your device settings.
Your coordinates are sent to our own server, which forwards a search request to HERE and Google. We do not keep a history of where you have been.
4. Who processes your data
We use a small number of service providers, each acting on our instructions:
- Supabase — accounts, database, file storage, and realtime chat delivery.
- Google Firebase — crash reporting (Crashlytics), push delivery (Cloud Messaging), and abuse prevention (App Check / Play Integrity).
- HERE and Google Places — place search and place details. They receive the search request; they do not receive your account identity.
We do not sell or rent personal data, and we do not share it with advertisers or data brokers.
5. What other people can see
Some things are public or shared by design, so it is worth being clear:
- Your display name, username and avatar are visible to other users.
- Reviews and photos you post about a place are visible to everyone, including people without an account.
- Chat messages and votes are visible to the other members of that group.
- Reports you file are visible only to us, never to the person you reported.
6. Your choices and rights
- Use Dipper without an account. Discovery and the randomizer work in guest mode.
- Access and export. Request a copy of your data from Profile → Settings.
- Correction. Edit your profile in the app at any time.
- Deletion. Delete your account and its data from Profile → Settings → Delete Account. Full instructions are on our account deletion page.
- Notifications. Turn push notifications off in your device settings or in the app.
- Location. Deny or revoke the permission in your device settings.
Depending on where you live you may have additional rights over your personal data, including the right to object to processing or to lodge a complaint with your local data protection authority. Email us and we will help.
7. Security
Sign-in sessions are held in encrypted device storage. All network traffic uses HTTPS; the app refuses unencrypted connections. Database access is enforced per-user at the database layer, so one account cannot read another account's private data. Requests to our search API must carry a valid device attestation.
8. Children
Dipper is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will remove it.
9. International transfers
Our database is hosted in the Asia Pacific (Tokyo) region. Our service providers may process data in other countries. Where required, transfers rely on appropriate safeguards such as the European Commission's standard contractual clauses.
10. Changes to this policy
If we make a material change we will update the date at the top of this page and, where the change is significant, notify you in the app before it takes effect.
11. Contact
Questions, requests, or complaints: support@dipper-app.com.