Privacy policy
Last updated: 25 July 2026
The short version
TableSage has no accounts. There is no login, no password and no email address to give us. Your taste profile, your scan history and your photographs live on your phone, not on our servers.
Two things do leave your device, and this policy is mostly about being precise about them: the menu photograph and your taste settings go to the company that reads the menu for us, and a short-lived job record sits on our server long enough to deliver the answer back to you.
Who we are
- Who controls this data
- Mobile Tech Media, LLC
- Entity
- a Wyoming, USA limited liability company
- Registered address
- 1309 Coffeen Avenue, STE 1200, Sheridan, WY 82801, USA
- Privacy contact
- [email protected]
- Site
- https://tablesage.app
This policy covers the TableSage mobile app and the https://tablesage.app website. It was last updated on 28 July 2026.
What we collect
- A device identifier
- A random identifier generated on your device the first time you open the app. It is not your advertising ID and it is not derived from your hardware, so it cannot be used to recognise you in other companies' apps. It is stored in the device keychain and, on iOS, deliberately survives reinstalling the app — that is what lets a pass you paid for still work afterwards. It is a persistent identifier, so we treat it as personal data.
- Menu and dish photographs
- The pictures you take. They are stored on your device. Each one is sent to the company that reads menus for us at the moment you scan, and is not written to storage on our servers at any point.
- Your taste settings
- Dislikes, dietary preferences and any allergens you enter, plus the results of the swipe quiz and how you rated past meals. These are stored on your device. A copy is sent with each scan so that the dishes can be assessed for you.
- Purchases
- Whether you have an active subscription or pass. Handled by the app stores and by our subscription provider. We never see your card details.
- Usage analytics
- Anonymous events describing which screens were opened and which steps were completed, keyed to the device identifier. We do not record your screen and the session-recording feature is not installed.
We do not collect your location, in any form. There is no location permission in the app, and an automated test fails the build if one is ever added. We do not collect your name, your email address, your contacts, or your health records.
What our servers hold, and for how long
When you scan a menu, we create a job record so the result can find its way back to your phone. It holds your device identifier and the finished assessment. Once your phone has collected it, the record is deleted on the next sweep. If it is never collected — you closed the app, you lost signal — it is deleted automatically within 30 days.
We want to be precise about that record rather than flattering. It contains the explanation the app wrote for you, which quotes your own preferences back at you, and it is linked to your device identifier. That is a small amount of personal data sitting on a server, and we would rather say so than claim we hold nothing.
What is not there: your taste profile and your history are not stored on our servers, and the database has no field that could hold them. That is structural rather than a promise. The photograph is passed through in the request and is never written to storage.
We also keep short-lived counters against your device identifier to stop one device from making unlimited scan requests. These are cleared when you delete your data.
How the menu reading works
Reading a menu is done by a large language model operated by OpenAI. When you scan, we send the photograph together with the taste information needed to judge dishes for you: your dislikes, your dietary settings, any allergens you have entered, your flavour preferences and a short list of your recent meal ratings.
The friendly label the app gives your taste type is never sent. Neither is your name, because we do not have one.
We do not use your photographs or your preferences to train our own models, and we do not sell them. We use OpenAI's standard API terms, under which submitted content is not used to train their models, though it may be retained briefly for abuse monitoring. We do not have a zero-retention arrangement and we are not going to imply one.
The app describes what is likely to be in a dish. It does not inspect kitchens and it never certifies a dish as suitable for you. Recipes differ between restaurants and change without notice, so treat what it tells you as the question worth raising with the restaurant, and let the people cooking your food have the final word.
Who else processes your data
We use a small number of companies to run the service. They process data on our behalf, under contracts that limit them to providing that service.
- OpenAI — reading the menu and assessing dishes
- The photographs you take of a menu, and the taste information the app uses to judge dishes for you — your dislikes, dietary settings, any allergens you have entered, your flavour preferences, and a short list of your recent meal ratings. This is sent at the moment you scan and is not stored by us. The label the app gives your taste type is never sent.
- Convex — delivering a scan result back to your phone
- A job record holding your anonymous device identifier and the finished result, so the result can reach the device that asked for it. Hosted in the United States (Northern Virginia). The menu photograph is passed through in the request and is never written to storage. Your taste profile and your history are not present in the database at all — there is no field that could hold them.
- PostHog — product analytics
- Anonymous usage events — which screens were opened, which steps were completed — keyed to your device identifier. Hosted in the European Union, and retained there for up to seven years. Session recording is not used and is not installed.
- RevenueCat — managing subscriptions and passes
- Your anonymous device identifier and your purchase status, so an entitlement can follow you across reinstalls and devices.
- Google (Gmail) — receiving contact messages
- If you write to us through the contact form or by email, the message and the address you gave us arrive in a Gmail inbox and stay there while we deal with it. Nothing about your message is written to our database.
- Apple and Google — app distribution and payment
- Everything relating to the purchase itself. Payment is taken by the store under its own terms; we never see or hold your card details.
That is the complete list. There is no advertising network, no attribution service and no crash-reporting service in the app. We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
Where your data goes
We are based in the United States. Our servers, and this website, are hosted in Northern Virginia, USA, and the company that reads menus for us processes that request in the United States. Analytics are hosted in the European Union.
Where data is transferred out of the European Economic Area or the United Kingdom, we rely on the European Commission's standard contractual clauses, the UK international data transfer addendum, or a provider's certification under the EU–US Data Privacy Framework, as applicable. Write to us if you would like more detail about the safeguards for a particular provider.
Deleting your data
Delete my data, in the app's profile settings, removes your profile, your meal history and your saved photographs from the device, and deletes any outstanding job records from our servers along with the counters described above. It runs the server-side deletion first, so if you are offline nothing is half-deleted.
Two things deliberately survive, and we would rather explain than surprise you.
- Your purchases. Your device identifier is the key your subscription or pass is attached to, so rotating it would revoke something you paid for and break Restore Purchases.
- Analytics already collected. Those events sit with our analytics provider, keyed to the anonymous device identifier, and the button does not reach them. Email us and we will have them erased.
Uninstalling the app removes everything stored on the device. On iOS the device identifier itself remains in the keychain so that your purchases still work if you reinstall. To erase everything we hold, email [email protected].
Your rights
Wherever you are, you can email [email protected] and ask what we hold about your device identifier, ask for it to be corrected, or ask for it to be erased. We aim to respond within one month. Because there are no accounts, we may need you to supply the device identifier from the app's settings so we can find the right records — we cannot identify you any other way, and we will not ask for more information than that.
European Economic Area and United Kingdom
You have the right to access your personal data, to have it corrected or erased, to restrict or object to how we use it, and to receive it in a portable form. Where we rely on your consent, you can withdraw it at any time.
We rely on the following legal bases: performing our contract with you, for the processing needed to make the app work and to deliver a scan you asked for; our legitimate interests, for keeping the service secure, preventing abuse and understanding how the app is used in aggregate; your consent, where you choose to enter dietary or allergen information; and compliance with legal obligations where one applies.
You also have the right to complain to your data protection authority.
California
You have the right to know what we collect and why, to access it, to have it corrected or deleted, and not to be treated differently for exercising those rights. We do not sell personal information and we do not share it for cross-context behavioural advertising, so there is nothing to opt out of — but we honour Global Privacy Control signals regardless.
How your data is protected
Data in transit is encrypted. Your profile and history are held in the device's own storage and are covered by your device's encryption and whatever passcode or biometric lock you use. The device identifier is stored in the operating system keychain.
We should be plain about the limits: the job record that passes through our servers is not end-to-end encrypted, because we have to be able to route it. No system is perfectly secure, and we do not claim otherwise.
If a breach occurs that is likely to present a risk to you, we will notify the relevant supervisory authority within 72 hours where the law requires it, and we will tell affected users where the risk is high.
Cookies and the website
This website sets no cookies. Our analytics run in a cookieless mode: no cookie is written and no identifier is stored in your browser. Because nothing non-essential is placed on your device, there is no cookie banner here — not as a design choice, but because there is nothing to ask you to consent to.
Analytics requests are routed through this domain rather than sent directly to a third-party domain. That is so ad blockers do not silently remove them; it does not change what is collected.
The app itself does not use cookies at all.
Children
TableSage is rated for ages 13 and over, because a menu you photograph may include alcoholic drinks, which the app will read out to you along with everything else. It never recommends them.
The app is not intended for children under 13, and we do not knowingly collect data from them. In parts of the European Economic Area the age of consent for online services is higher — 16 in Germany, 15 in France, 14 in Spain — and where that applies, a parent or guardian should be the one agreeing to this policy. If you believe a child has used the app and you would like their data removed, email us and we will do it.
Changes to this policy
If we change this policy we will update the date at the top. If a change materially affects how your data is handled, we will say so prominently in the app rather than relying on you to re-read this page.
Contact
Questions, requests, or anything that reads wrong to you: [email protected], or the form at https://tablesage.app/contact. Either way it reaches one inbox that a person reads. Your message is not stored in a database — it is relayed and that is all.