Privacy Policy
What data What’s For Dinner Tonight handles, and what happens to it.
Last updated: July 16, 2026
This is the formal policy. If you’d rather read why the app is built this way, see Privacy by architecture.
What we collect
Nothing. We have no accounts, no analytics SDKs, no advertising, and no tracking. There is no database of you, your meals, or anything you send us.
Some features can’t run on your phone, so the app sends a small amount of data out to make them work — a meal name to suggest ingredients, or a photo you chose to take so it can be read for groceries. Those requests are answered and discarded; nothing is retained. Each one is listed below, so you can see exactly what leaves your device and when.
Where your data lives
Everything you create in the app — meals, household members, dinner logs, photos, queue entries, settings — is stored:
- Locally on your device, in iOS’s standard private app storage, accessible only to you.
- In your personal iCloud account, mirrored automatically through Apple’s CloudKit framework, in your iCloud private database. Apple stores it; we have no access to it.
When you create or join a household, the meals, people, and dinner logs you’ve chosen to share are mirrored to a CloudKit shared zone visible only to the household members you’ve invited. Nobody can see or join your household without an explicit invitation from you.
What leaves your device, and why
Four features send data to our service at api.donbon.com, which runs on Cloudflare Workers and uses Anthropic’s Claude API to generate the result. Each request is processed and thrown away — we keep no copies.
- Capture the Fridge — the single photo you chose to take, of your fridge, pantry, counter, a grocery bag, or a receipt. It’s read for the food in it and the list comes back for you to review. The photo is not stored. Only the photo you picked is sent; the app cannot see the rest of your photo library.
- Suggest ingredients — the meal’s name, and the cuisine if you’ve set one.
- Suggest instructions — the meal’s name, its ingredients, and cuisine or cooking time if you’ve set them.
- Meal photos — the meal’s name, to find a suitable stock photo.
We don’t send your name, your account, your device identifier, your other meals, your household, your shopping list, or your history. We have no identity for you to send.
Apple Intelligence (Ask WFD)
The “Ask WFD” voice feature uses Apple’s Foundation Models framework, which runs entirely on-device. Your voice input, transcription, and the responses never leave your iPhone. We do not see, log, or transmit anything from this feature.
Restaurants and location
If you use the restaurant finder, the app sends your current location and what you’re looking for, so nearby results can be returned. Depending on your settings this goes either to Apple’s MapKit — handled on your device by Apple — or, for Plus users, directly from your device to Yelp. We are not in the path for the Yelp request and keep no record of where you’ve been. See Yelp’s privacy policy.
Photos
When you add a meal, the app may fetch a stock photo based on the meal’s name — either from TheMealDB (a free public recipe database, queried directly from your device) or through our service. The only data sent is the meal name.
You can also attach your own photo from your iOS Photos library to a meal. That photo stays in your iCloud and is shared only with household members who already have access to your household. It is never sent to us.
Recipe URL import
If you use “Import from URL” to bring a recipe into your library, the app makes a network request to the URL you supplied to fetch the recipe’s structured data. The URL you typed is sent only to the website you specified. We do not see this URL or the response.
In-App Purchases
The Plus tier is processed by Apple’s StoreKit framework. We never see your payment information. Apple handles the transaction and provides us only an anonymous receipt confirming that you purchased Plus.
Third-party services
These are the only companies involved, and none of them receives anything about who you are:
- Anthropic — generates the suggestions and reads the photos you take. Privacy policy
- Cloudflare — runs our service. Privacy policy
- Yelp — restaurant results, if you’re using the Yelp source. Privacy policy
- TheMealDB — public recipe database, for stock photos and recipe ideas.
- Apple — iCloud sync, StoreKit purchases, MapKit. Privacy policy
We don’t sell your data, share it for marketing, or use it to advertise to you.
Children’s privacy
What’s For Dinner Tonight is not directed at children under 13, and we do not knowingly collect data from anyone, of any age.
Your rights
Delete any meal, photo, or your whole library at any time from within the app. Deletions sync through iCloud and remove the data from your account. Deleting the app removes the local copy; deleting your iCloud data removes the rest. We hold nothing to delete on our side.
Changes to this policy
If how the app handles data changes, this page and the date above will be updated, and the change noted in the app’s release notes.
Contact
Questions about this policy? Email Don Bonaddio at don.bonaddio@gmail.com.