Legal

Privacy Policy.

This policy explains what data Dinner Table collects, how we use it, who can access it, and how you can ask us to delete it.

Last updated: July 8, 2026

1. Who we are

Dinner Table (“we”, “us”, “our”) operates the Dinner Table member platform at members.dinnertable.com and the related mobile experience. This policy applies to all Dinner Table accounts and any data we collect through the app or our website.

2. Data we access and collect

We only collect what we need to run the Dinner Table community experience for you and your family. Specifically:

  • Account & authentication data — your email address and password (stored only as a salted hash).
  • Google User Data (Google OAuth) — If you choose to sign in or register with Google, we access and collect your basic Google profile information via standard Google OAuth scopes (openid, email, and profile). This includes your primary Google email address, your verified name, and your Google profile photo URL.
  • Profile information — name, optional avatar, region (coarse, e.g. “Austin, TX”), and any bio or links you choose to add. You control what is visible to other members in Account → Privacy.
  • Family content you create — family members you add, goals, meeting notes, budgets, jobs, and snapshots. This content belongs to you.
  • Community activity — posts, comments, RSVPs, and messages you send inside the app.
  • Billing data — handled by Stripe. We store a customer ID and subscription status; we never see or store your full card number.
  • Device & usage data — basic logs (IP address, browser/OS, pages visited, error reports) used to keep the service secure and reliable.

We do not collect precise GPS location, contacts, SMS, photos outside of files you explicitly upload, or any data from children under 13.

3. How we use your data

We use the data above only to:

  • Create and secure your account and sign you in.
  • Specific use of Google user data: Information obtained through Google APIs is used strictly to authenticate your identity, safely create your Dinner Table profile, and securely log you into the platform. We do not use your Google user data for any other purpose.
  • Provide the core features of Dinner Table — your family dashboard, meetings, goals, the resource library, community feed, events, and the Spork AI assistant.
  • Send transactional messages you’ve asked for (meeting reminders, password resets, RSVP confirmations, member-support replies).
  • Process subscription payments through Stripe.
  • Improve reliability and prevent abuse (rate limiting, fraud detection, debugging crashes).

We do not use your data for advertising and we do not run third-party ad tracking inside the app.

4. Google API Services User Data Policy (Limited Use Compliance)

Dinner Table’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, with respect to Google user data obtained through Google OAuth:

  • Authentication only. We use Google user data solely to authenticate you, create your Dinner Table account, and sign you in. It is not used for any secondary purpose.
  • No sale of data. We do not sell, rent, or license Google user data to any third party under any circumstances.
  • No advertising. We do not use Google user data to serve advertisements, including personalized, retargeted, or interest-based advertising.
  • No unauthorized transfers. We do not transfer Google user data to third parties except (a) as necessary to provide or improve the Dinner Table service through vetted service providers acting on our behalf under contract (currently Supabase for authentication storage and Cloudflare for secure delivery), (b) to comply with applicable law, or (c) as part of a merger, acquisition, or sale of assets with notice to you.
  • No AI / LLM training. Google user data is never used to develop, train, improve, or fine-tune generalized or personalized artificial intelligence or machine-learning models, including the Spork AI assistant or any third-party AI service we integrate with.
  • No human reading. We do not allow humans to read Google user data unless (i) we have your affirmative consent for specific messages, (ii) it is necessary for security purposes (such as investigating abuse), (iii) it is necessary to comply with applicable law, or (iv) the data has been aggregated and anonymized so it cannot be used to identify any individual user.

5. Data sharing

We do not sell your personal data, and we do not share it with unauthorized third parties. We share data only in these limited cases:

  • With other members, as you choose. Your profile fields, posts, comments, and RSVPs are visible to other signed-in members according to the toggles in Account → Privacy.
  • With service providers (“processors”) that run the platform on our behalf, under contract and only for the purpose of operating Dinner Table: Supabase (database, authentication, file storage), Cloudflare (hosting, edge delivery), Stripe (payments), Resend (transactional email), Google AI / Lovable AI Gateway (Spork assistant responses), and Vimeo (video hosting).
  • When required by law — to comply with a valid legal request, or to protect the rights, safety, and property of Dinner Table and our members.

6. Where and how your data is stored

Your data is stored in managed Postgres databases and object storage operated by Supabase on infrastructure located in the United States. Application traffic is served over HTTPS/TLS; the app and all API endpoints redirect insecure requests to HTTPS. Passwords are hashed (never stored in plain text), and row-level security policies enforce, at the database, that one member’s data is not readable by another unless you have explicitly chosen to share it.

Backups are encrypted at rest. Access to production systems is limited to authorized staff using multi-factor authentication.

7. Data retention & deletion

We keep your account and the content you create for as long as your account is active. You can ask us to delete your data at any time:

  • Self-serve: sign in and go to Account → Delete account. This removes your profile, family content, posts, comments, RSVPs, and Spork chat history within 30 days.
  • By email: write to privacy@dinnertable.com from the email on your account and ask us to delete it. We will confirm and complete deletion within 30 days.

You may also revoke Dinner Table’s access to your Google account at any time via Google Account → Security → Third-party access. Revoking access signs you out of Google-based sign-in but does not on its own delete your Dinner Table account — use the options above to delete your data.

After deletion we may retain a minimal record (e.g. an invoice or a suppression-list entry showing you asked to be deleted) only where required by tax, accounting, or anti-abuse laws. Backups containing your data are purged on our normal rotation, typically within 60 days.

8. Your rights

Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to or restrict certain processing. You can exercise any of these rights by emailing privacy@dinnertable.com. We will respond within 30 days.

9. Children

Dinner Table accounts are for adults (18+). Parents may record information about their own children inside their private family dashboard, but children do not have Dinner Table accounts and we do not knowingly collect personal data directly from anyone under 13.

10. Security

We use HTTPS everywhere, hashed passwords, row-level security in the database, and least-privilege access for staff. No online service is 100% secure, but if we ever discover a breach that affects your data, we will notify affected members and the relevant authorities as required by law.

11. Changes to this policy

When we make material changes to this policy we will update the “Last updated” date above and, where appropriate, notify you by email or an in-app notice before the changes take effect.

12. Contact

Questions about this policy or your data? Contact us or email privacy@dinnertable.com.