The short version
We collect the minimum needed to run socialdish, your email, restaurant name, and the photos you upload. We never sell your data. We don't use your content to train AI models. You can delete everything we have on you in two clicks, anytime.
An Arabic version of this page is available and is provided for convenience. If the two differ, this English version prevails.
What we collect
When you sign up
- Your Google account info:name, email address, profile picture. (We only get this because you click "Continue with Google". We never see your Google password.)
- Your restaurant info: restaurant name, cuisine, city, only what you type into the onboarding form.
- Your brand voice preferences: the preset you pick and any style notes you write.
When you use the product
- Photos you upload for AI enhancement.
- Generated content: the images, videos, captions, and hashtags we make for you.
- Usage stats: how many generations you make per month, which features you use. Used for billing enforcement and product improvement.
When you subscribe
- Billing info handled by our payment provider, we only see your subscription status and the last 4 digits of your card. See What we don't collect below.
What we don't collect
- Your full credit card number. Ever. Cards are handled entirely by our payment provider, we only see the last 4 digits and the brand (Visa/MC/etc.) so we can show them in your billing dashboard.
- Your Google password.We use Google OAuth, you authenticate with Google, they tell us "yes this person is who they say they are", we never see the password.
- Browsing data outside socialdish.We don't track you across the web. No third-party advertising pixels.
- Your location (beyond the city you tell us during onboarding).
- Your phone's contacts, photos library, or anything else.
How we use it
- To run the product, generate your photos, videos, and captions.
- To enforce your subscription, count how many generations you've made this month against your plan's quota.
- To send essential emails, receipts, cancellation confirmations, payment failures. (No marketing emails unless you explicitly opt in.)
- To improve the product, aggregate, anonymized stats about which features get used.
- To debug problems, when something breaks, we look at logs that contain your user ID so we can fix it.
What we don't use it for: selling to data brokers, ad targeting, training AI models, or sharing with anyone outside the third-party processors listed below.
Where your data lives
| Type of data | Where it's stored | Region |
|---|---|---|
| Account info, brand profile, generation history | Neon (Postgres database) | Frankfurt, Germany 🇩🇪 |
| Generated images and videos | Vercel Blob storage | USA 🇺🇸 |
| Subscription & billing | Lemon Squeezy (Merchant of Record) & Stripe | USA / EU 🇺🇸 🇪🇺 |
| Application servers | Vercel (edge network) | Global, closest to user |
| Your session cookie | Your own browser | Your device |
Some data crosses borders (e.g. between EU and US) for normal service operation. We rely on the standard contractual clauses and DPAs that our processors offer.
Third parties we work with
We use these companies to actually run socialdish. They each have their own privacy policy, we've linked to them. We've picked vendors with strong privacy track records.
| Company | What they do | Their policy |
|---|---|---|
| Google (Auth + Gemini) | Sign-in & AI image/video generation | Privacy |
| Anthropic (Claude) | Caption, menu and prompt AI | Privacy |
| Replicate | Video generation (Seedance 2.0, by ByteDance) | Privacy |
| Pollinations.ai | Free-tier image generation (text-to-image) | pollinations.ai |
| Lemon Squeezy & Stripe | Payment processing (card data) | Privacy |
| Neon | Database hosting (Frankfurt) | Privacy |
| Vercel | Application hosting + asset storage | Privacy |
What the AI providers see (and don't do with it)
When you generate a photo or video, your uploaded image leaves our servers and goes to the AI provider for processing. Here is exactly what each one does with it:
- Google Gemini (paid tier). Receives your image + prompt. Google legally states (in their paid API terms) that data is not used to train their AI models. They keep logs for limited time for debugging and abuse detection.
- Anthropic Claude.Receives your image + the description prompt. Anthropic's API terms state data is not used for training and is deleted after the request completes.
- Pollinations.ai. We only send a text description (never the actual uploaded image), Claude reads your photo first and describes it. Pollinations is a free service with a less formal privacy posture; treat anything sent through Pollinations as semi-public.
- Replicate (Seedance 2.0 video, a ByteDance model). Receives your image + motion prompt. Stores generated videos on their CDN for approximately 30 days for caching, then deletes. If Seedance is unavailable we may fall back to Higgsfield or Google Veo for the same request.
Your rights
You can do all of the following from your dashboard, anytime, without asking us:
- Access your data, see everything we have on you in the dashboard.
- Download your data, Settings → Data & Privacy → Download my data. You'll get a JSON file with every record we have about you.
- Correct your data, edit your brand profile and restaurant info anytime in Settings.
- Delete your account, Settings → Data & Privacy → Delete my account. We wipe your account and cascade-delete every related record. This is permanent and can't be undone.
- Opt out of email marketing, we don't send any marketing emails unless you opt in. If we ever do, every email has an unsubscribe link.
If you're in the EU, UK, or California, you have additional rights under GDPR / UK GDPR / CCPA. Email Moe@bmotion.ai and we'll honor any request within 30 days.
How long we keep data
| Data | Retention |
|---|---|
| Account info | Until you delete your account |
| Generated photos & videos | Until you delete them or your account. 90 days after cancellation, then deleted. |
| Subscription & payment history | 7 years (UAE tax retention requirement). Stored with our payment provider. |
| Server logs (debugging) | 30 days |
| AI provider logs (their side) | Per each provider's policy, typically 30 days for Google, immediate deletion for Anthropic |
Security
The basics that protect your data:
- Everything is encrypted in transit, HTTPS on every page, including all API calls.
- Database is encrypted at rest, Neon encrypts the disk where your data lives.
- Passwords are hashed, never stored in readable form. You can sign in with Google (we never see a password at all), with a one-time email link, or with an email and password. If you set a password, it is stored only as a salted scrypt hash, which cannot be reversed back into your password.
- Sessions expire after extended inactivity. Auth tokens rotate.
- Payments handled by our payment provider, which is PCI-DSS Level 1 certified (the highest security standard for payments).
If we ever discover a data breach, we'll notify affected users within 72 hours (as required by GDPR and good ethics).
Children
socialdish is a B2B service for restaurant owners. We do not knowingly collect data from anyone under 16. If we discover we've done so, we delete it immediately.
Changes to this policy
We'll update this page when our practices change. The last updateddate at the top reflects the most recent change. For material changes, we'll email you at least 30 days in advance.
Contact
Privacy questions: Moe@bmotion.ai
Data requests (access, deletion, export): Moe@bmotion.ai (we respond within 30 days, usually within 3 business days)
Anything else: Moe@bmotion.ai