socialdish

Privacy Policy · Last updated May 2026

Your data, plainly explained.

No legalese soup. Here's exactly what we collect, where it goes, and what control you have over it.

The Content Operating System for Restaurantsv1.0 · 2026

The short version

If you only read one thing

We collect the minimum needed to run socialdish, your email, restaurant name, and the photos you upload. We never sell your data. We don't use your content to train AI models. You can delete everything we have on you in two clicks, anytime.

An Arabic version of this page is available and is provided for convenience. If the two differ, this English version prevails.

What we collect

When you sign up

  • Your Google account info:name, email address, profile picture. (We only get this because you click "Continue with Google". We never see your Google password.)
  • Your restaurant info: restaurant name, cuisine, city, only what you type into the onboarding form.
  • Your brand voice preferences: the preset you pick and any style notes you write.

When you use the product

  • Photos you upload for AI enhancement.
  • Generated content: the images, videos, captions, and hashtags we make for you.
  • Usage stats: how many generations you make per month, which features you use. Used for billing enforcement and product improvement.

When you subscribe

  • Billing info handled by our payment provider, we only see your subscription status and the last 4 digits of your card. See What we don't collect below.

What we don't collect

  • Your full credit card number. Ever. Cards are handled entirely by our payment provider, we only see the last 4 digits and the brand (Visa/MC/etc.) so we can show them in your billing dashboard.
  • Your Google password.We use Google OAuth, you authenticate with Google, they tell us "yes this person is who they say they are", we never see the password.
  • Browsing data outside socialdish.We don't track you across the web. No third-party advertising pixels.
  • Your location (beyond the city you tell us during onboarding).
  • Your phone's contacts, photos library, or anything else.

How we use it

  • To run the product, generate your photos, videos, and captions.
  • To enforce your subscription, count how many generations you've made this month against your plan's quota.
  • To send essential emails, receipts, cancellation confirmations, payment failures. (No marketing emails unless you explicitly opt in.)
  • To improve the product, aggregate, anonymized stats about which features get used.
  • To debug problems, when something breaks, we look at logs that contain your user ID so we can fix it.

What we don't use it for: selling to data brokers, ad targeting, training AI models, or sharing with anyone outside the third-party processors listed below.

Where your data lives

Type of dataWhere it's storedRegion
Account info, brand profile, generation historyNeon (Postgres database)Frankfurt, Germany 🇩🇪
Generated images and videosVercel Blob storageUSA 🇺🇸
Subscription & billingLemon Squeezy (Merchant of Record) & StripeUSA / EU 🇺🇸 🇪🇺
Application serversVercel (edge network)Global, closest to user
Your session cookieYour own browserYour device

Some data crosses borders (e.g. between EU and US) for normal service operation. We rely on the standard contractual clauses and DPAs that our processors offer.

Third parties we work with

We use these companies to actually run socialdish. They each have their own privacy policy, we've linked to them. We've picked vendors with strong privacy track records.

CompanyWhat they doTheir policy
Google (Auth + Gemini)Sign-in & AI image/video generationPrivacy
Anthropic (Claude)Caption, menu and prompt AIPrivacy
ReplicateVideo generation (Seedance 2.0, by ByteDance)Privacy
Pollinations.aiFree-tier image generation (text-to-image)pollinations.ai
Lemon Squeezy & StripePayment processing (card data)Privacy
NeonDatabase hosting (Frankfurt)Privacy
VercelApplication hosting + asset storagePrivacy

What the AI providers see (and don't do with it)

When you generate a photo or video, your uploaded image leaves our servers and goes to the AI provider for processing. Here is exactly what each one does with it:

  • Google Gemini (paid tier). Receives your image + prompt. Google legally states (in their paid API terms) that data is not used to train their AI models. They keep logs for limited time for debugging and abuse detection.
  • Anthropic Claude.Receives your image + the description prompt. Anthropic's API terms state data is not used for training and is deleted after the request completes.
  • Pollinations.ai. We only send a text description (never the actual uploaded image), Claude reads your photo first and describes it. Pollinations is a free service with a less formal privacy posture; treat anything sent through Pollinations as semi-public.
  • Replicate (Seedance 2.0 video, a ByteDance model). Receives your image + motion prompt. Stores generated videos on their CDN for approximately 30 days for caching, then deletes. If Seedance is unavailable we may fall back to Higgsfield or Google Veo for the same request.

Your rights

You can do all of the following from your dashboard, anytime, without asking us:

  • Access your data, see everything we have on you in the dashboard.
  • Download your data, Settings → Data & Privacy → Download my data. You'll get a JSON file with every record we have about you.
  • Correct your data, edit your brand profile and restaurant info anytime in Settings.
  • Delete your account, Settings → Data & Privacy → Delete my account. We wipe your account and cascade-delete every related record. This is permanent and can't be undone.
  • Opt out of email marketing, we don't send any marketing emails unless you opt in. If we ever do, every email has an unsubscribe link.

If you're in the EU, UK, or California, you have additional rights under GDPR / UK GDPR / CCPA. Email Moe@bmotion.ai and we'll honor any request within 30 days.

Cookies

We use three categories of cookies:

Strictly necessary (always on)

  • Login session cookie, keeps you signed in. Without this you can't use the dashboard.
  • CSRF token, prevents others from impersonating you when you submit a form.

Functional (your choice)

  • Theme preference, remembers if you picked light or dark mode.
  • Cookie consent, remembers your cookie choice so we don't ask again.

Analytics (off by default)

We don't currently use any analytics or tracking pixels. If we ever add them (e.g. PostHog), we'll update this policy and ask your consent in the cookie banner.

How long we keep data

DataRetention
Account infoUntil you delete your account
Generated photos & videosUntil you delete them or your account. 90 days after cancellation, then deleted.
Subscription & payment history7 years (UAE tax retention requirement). Stored with our payment provider.
Server logs (debugging)30 days
AI provider logs (their side)Per each provider's policy, typically 30 days for Google, immediate deletion for Anthropic

Security

The basics that protect your data:

  • Everything is encrypted in transit, HTTPS on every page, including all API calls.
  • Database is encrypted at rest, Neon encrypts the disk where your data lives.
  • Passwords are hashed, never stored in readable form. You can sign in with Google (we never see a password at all), with a one-time email link, or with an email and password. If you set a password, it is stored only as a salted scrypt hash, which cannot be reversed back into your password.
  • Sessions expire after extended inactivity. Auth tokens rotate.
  • Payments handled by our payment provider, which is PCI-DSS Level 1 certified (the highest security standard for payments).

If we ever discover a data breach, we'll notify affected users within 72 hours (as required by GDPR and good ethics).

Children

socialdish is a B2B service for restaurant owners. We do not knowingly collect data from anyone under 16. If we discover we've done so, we delete it immediately.

Changes to this policy

We'll update this page when our practices change. The last updateddate at the top reflects the most recent change. For material changes, we'll email you at least 30 days in advance.

Contact

Privacy questions: Moe@bmotion.ai

Data requests (access, deletion, export): Moe@bmotion.ai (we respond within 30 days, usually within 3 business days)

Anything else: Moe@bmotion.ai