Overview
Swipe Dining LLC, a Connecticut limited liability company, operates the Swipe mobile application ("we," "our," or "the app"). Swipe is a nutrition tracking app for college dining halls. We are committed to protecting your privacy and being transparent about how your data is used.
Information We Collect
Information you provide:
- Dietary preferences, allergen settings, selected health conditions, wellness preferences, and any age, gender, height, weight, activity level, or nutrition targets you enter
- Feedback, support messages, school requests, and optional contact information you submit
- Favorite food items and food journal entries
- Meal photos you explicitly choose to submit for optional AI portion estimates, where this feature is available
Information collected automatically:
- Usage analytics (screens viewed, features used, dining locations, and a persistent app identifier) via PostHog, subject to your app version and analytics choice
- Device information (model, OS version) for bug fixes via Sentry
- Network metadata, such as IP addresses, received by hosting and service providers when the app makes requests
How We Use Information
We use your information to:
- Display personalized allergen warnings and health scores
- Save your preferences and journal entries
- Respond to support requests, prevent abuse, and deliver menu data and optional features
- Improve app performance and fix bugs
Data Storage
- Your profile and journal are stored locally. Apple Health and Personal Dashboard can optionally export journal entries, as described below. Earlier app versions also sent some food interactions and health-preference properties to analytics; see the analytics disclosure below.
- Updated app versions save a local agreement record containing the document version, acceptance time, app version, and eligibility acknowledgment. This is an installation record, not verified identity or verified parental consent. Device backups may include local app data.
- We do not sell your personal information, and we do not share it with third parties for advertising or marketing purposes
- We do transmit limited data to our service providers (listed below under Third-Party Services and Data Transmitted to Servers) solely to operate and improve the app
- Menu and nutrition data comes from publicly available university dining sources
Apple Health
On iPhone, Swipe can save the food you log to Apple Health. This is turned off by default and only starts after you enable it in Settings and grant permission; you can turn it off at any time in Swipe or in the Health app.
- We only write, never read. Swipe does not request or receive read access to your Health data. We cannot see your steps, weight, workouts, or anything else stored in Health.
- What is written: the nutrition of journal entries you create in Swipe — calories, protein, carbohydrates, fat, saturated fat, fiber, sugar, sodium, cholesterol, calcium, iron, potassium, and vitamin D — saved as food entries under the date you logged them.
- Where it goes: writes go directly from your device into Apple Health. Health data is never transmitted to our servers, and is never shared with analytics, advertising, or marketing services.
- Deleting: removing a journal entry in Swipe also removes the matching entry from Apple Health. Turning the setting off stops future writes; entries already saved to Health remain until you delete them in the Health app.
Personal Dashboard
Older versions of Swipe offered an optional connection to a personal dashboard you run yourself. It was off by default and required your own access token. The current release no longer offers these connection controls in Settings. Previously configured installations may still send journal updates while the saved connection is enabled and its token is valid. To stop an existing connection, revoke its token at your dashboard; contact us if you need help. Without a configured token, nothing is sent.
- What is sent: your journal entries — the food name, its nutrition, the serving count, the meal and date, and where you logged it — along with the entry's identifier so edits replace the earlier copy rather than duplicating it. Editing an entry re-sends it; deleting one tells the dashboard to delete it.
- Where it goes: only to the dashboard endpoint the app is configured with, authenticated by your token. It does not pass through our servers, and it is never shared with analytics, advertising, or marketing services.
- Your token stays on your device. It is stored only on the phone you entered it on and is not bundled into the app or transmitted anywhere except as the credential on requests to your own dashboard.
- History: Older versions offered a one-time “Sync all history” action. That action sent existing journal entries only when selected; the current Settings screen no longer offers it.
- Independent of Apple Health. This feature sends only what you logged in Swipe. Swipe has no read access to Apple Health, so no data from Apple Health is included, and enabling one feature does not enable the other.
Because the dashboard is operated by you and not by us, data you send there is covered by whatever hosting you have chosen for it, not by this policy.
Optional Meal Photo Estimates
Where available, photo scanning estimates portions of a selected food or suggests foods from your selected UConn menu. Camera access does not itself authorize an upload. The first time you scan, Swipe explains what is shared and asks you to agree. After you agree, photos you take in the scanner are sent for analysis as soon as you take them, without asking again. You can turn photo sharing off at any time from the scanner’s camera screen (Photo sharing is on → Turn off), and Swipe will ask again before sending another photo. This choice is stored only on your device. You can use manual food logging without this feature.
- What is sent: a resized meal photo, candidate menu item names and serving sizes, and a plate diameter if you enter one. Your journal, health profile, and allergen settings are not included. Avoid including people or personal information in your photo.
- Who processes it: our Supabase backend forwards the request through Vercel AI Gateway to Google. Requests are restricted to Google routes that do not use your photo or menu details to train AI models. If an eligible route is unavailable, the scan fails instead of switching to a different provider.
- Provider retention: this is not a zero-retention service. Vercel and Google may keep a copy of the request, including the photo, for a limited time under their own policies, for example to detect abuse or investigate problems. Swipe has no direct access to those copies. Contact us about data rights requests; provider-held copies are subject to the provider’s policies and applicable law.
- Storage: Swipe does not store uploaded photos or scan responses in its database or application logs. Temporary camera files are deleted after the image is prepared; the photo then exists only in the app’s memory, where it is shown beside the estimate so you can compare them, and it is cleared when you retake it, add the food to your journal, or close the scanner. The app does not save these photos to your photo library.
- Usage controls: our backend stores daily request counts and a daily rotating salted hash of the requesting IP address to limit abuse and cost. Old counters are removed on subsequent scan requests after their day is more than one day old. Hosting providers may separately retain ordinary request metadata under their service policies.
- Saving results: nothing is saved until you tap Add to journal. In a full-plate scan, confident matches start selected and you can untick any of them; uncertain or unmatched foods are never selected for you. Only the entries selected when you confirm are saved to your on-device journal. Existing optional Apple Health and Personal Dashboard settings also apply to those entries. Photos are not included in those exports.
Portions are estimates, not measurements. Photo analysis cannot establish ingredients, allergens, or whether food is safe for an allergy. See Vercel's privacy policy and Google's data governance information.
Third-Party Services
The app uses the following services, each with their own privacy policies:
Optional meal photo analysis also uses Vercel AI Gateway and Google, as described above.
PostHog
Usage analytics linked to a persistent app identifier, not verified student identity. This is pseudonymous data, not anonymous data. It can include screen views, actions, dining locations, device details, and network metadata.
Sentry
Crash reporting and error monitoring. Collects device model and OS version to help us diagnose and fix bugs.
Supabase
Menu data storage and backend API. Stores scraped dining hall menu and nutrition data, crowdsourced reports, and feedback submissions. Data is hosted in the United States (AWS us-east-1).
Analytics controls and version differences: Older app versions enabled analytics by default and could send food names, search text, selected health conditions, and counts or flags about dietary and wellness preferences. The revised app makes analytics off by default, requires a new opt-in through Settings → Help Improve Swipe, and removes these sensitive properties from analytics calls. Until you install that update, turn off Help Improve Swipe to stop optional analytics. Turning it off does not erase previously received data; contact us about access or deletion. Our private administrative dashboard displays aggregated activity from PostHog, not verified student counts.
Crash reporting through Sentry is separate from optional analytics and has no in-app off switch. Reports can include errors, stack traces, app version, device details, and diagnostic context. Do not put sensitive information in support messages unless needed for your request.
The following services also receive requests or support distribution. Direct product searches can disclose your query or barcode and network metadata to the database provider:
- USDA FoodData Central: U.S. government nutrition database used for barcode/product lookups
- Open Food Facts: Community-maintained open-source product database used as a supplemental nutrition source
- Expo / EAS (Expo Application Services): Build, deployment, and over-the-air update infrastructure for the mobile app
- Apple App Store & Google Play: App distribution platforms, each with their own privacy policies
Security Measures
We use industry-standard safeguards to protect data transmitted to or stored on our servers:
- Encryption in transit: All network traffic between the app and our servers uses TLS 1.2 or higher (HTTPS)
- Encryption at rest: Data stored in Supabase (PostgreSQL) is encrypted at rest using AES-256
- Access controls: Administrative access is restricted to authorized operators using credentials or authenticated sessions.
- Least-privilege principle: Menu reads and some submissions are public endpoints with validation and abuse controls. Administrative operations require authorization
- Secrets management: Server secrets are kept out of the public app bundle. Public client identifiers are not secret credentials
- Dependency monitoring: We monitor third-party libraries for known vulnerabilities and apply updates in a timely manner
No system is perfectly secure. We cannot guarantee the security of information transmitted over the internet, but we commit to using reasonable safeguards and to notifying affected users in the event of a breach (see Breach Notification below).
International Data Transfers
Our servers and service providers are located in the United States. Specifically:
- Supabase: Data is stored in AWS us-east-1 (Northern Virginia, USA)
- PostHog: Analytics events are processed in the United States (us.i.posthog.com)
- Sentry: Crash reports are processed in the United States
If you access the app from outside the United States, including from the European Economic Area, United Kingdom, or other jurisdictions with data-protection laws, your information will be transferred to, stored, and processed in the United States. Where required by law, we rely on appropriate safeguards for international transfers, such as the EU Standard Contractual Clauses (SCCs) incorporated into our service-provider contracts.
Data Transmitted to Our Servers
To operate the app, the following categories of data are transmitted to our servers (hosted by Supabase) or to the third-party services listed above:
- Crowdsourced reports: Missing menu items, food/restaurant requests, and menu corrections you choose to submit
- Optional meal photo analysis: the photo and menu context you consent to share, plus request metadata needed to process and limit requests, as described under Optional Meal Photo Estimates
- Feedback and bug reports: Content you submit through in-app feedback forms, including optional contact information if you provide it
- Identifiers and diagnostics: Persistent app identifiers, app/device/OS details, and error context used for diagnostics and optional analytics
- Usage events: Screen views, feature interactions, and app performance metrics, including the older-version analytics differences described above (PostHog)
- Request metadata: IP addresses and request timing processed by hosting providers and abuse controls
Your full profile and journal are not automatically backed up to Swipe servers. Optional exports, feedback you submit, photo uploads, and older-version analytics are the exceptions described above. Selected feedback summaries and developer replies may appear in Developer Responses; do not include sensitive information in feedback.
Data Retention
- Feedback, crowdsourced reports, and bug reports: Retained for up to 24 months from submission, after which they are deleted or anonymized
- Usage analytics: Retained for up to 24 months in identifiable form; may be kept indefinitely in aggregated or anonymized form for trend analysis
- Crash and error logs: Retained for up to 90 days
- On-device data (preferences, journal): Retained until removed from app storage; operating-system backups and copies exported to Apple Health or your dashboard may remain separately
- Aggregated/anonymized data: May be retained indefinitely as it cannot be linked to any individual
You may request earlier deletion of data tied to you at any time using the contact information below.
Your Rights (CCPA, GDPR, and Similar Laws)
Depending on your jurisdiction (including California, the European Union, the United Kingdom, and Connecticut), you may have the following rights regarding your personal information:
- Right to access: Request a copy of the personal information we hold about you
- Right to deletion: Request that we delete personal information tied to you
- Right to correction: Request correction of inaccurate information
- Right to data portability: Request your data in a machine-readable format
- Right to opt out of analytics: Disable optional analytics in Settings → Help Improve Swipe. This does not disable Sentry crash reporting
- Right to non-discrimination: We will not deny service, charge different prices, or provide a lower quality of service because you exercised any of these rights
We do not sell personal information, so there is no separate "right to opt out of sale."
To exercise any of these rights, email contact@swipedining.com with the subject line "Data Rights Request." We will respond within 30 days (or 45 days under CCPA, with notice).
Breach Notification
In the event of a data breach that affects your personal information, we will notify affected users within 72 hours of discovery, via in-app notification, email (if you have provided one), or a notice posted on swipedining.com. Notices will describe the nature of the breach, the categories of information involved, and steps we are taking in response.
Children's Privacy
Swipe is designed primarily for college-age users. The app does not knowingly collect information from children under 13, in compliance with the Children's Online Privacy Protection Act (COPPA). Users between 13 and 17 must have verifiable consent from a parent or legal guardian to use the app. If you believe a child under 13 has provided us with personal information, please contact us and we will delete it promptly.
Changes to This Policy
We may update this policy from time to time. Changes will be posted on this page with an updated date at the top. Where required, we will provide notice and obtain separate consent before new uses of sensitive information. Acknowledging this policy does not itself authorize optional photo uploads or exports.