DinnerRoll — Goose x Goose
Last updated 4 August 2026
DinnerRoll works offline first. Your meals, menus and grocery lists are stored on your device and stay there unless you turn on a cloud feature. There are no accounts, no ads, and nothing is ever sold.
Unless you enable one of the optional cloud features below, all of this is local and never reaches us:
If you turn on Cloud Backup, your meal data is copied to our servers so you can restore it on another device. It's tied to a randomly generated device ID — not your name or any personal identifier.
You can optionally link an email address to your cloud backup so you can recover it on a new device. When you do, we store a one-way hash of your email alongside your backup. We send a verification code to your email to confirm ownership; we do not store the email address in plain text and never use it for marketing or notifications.
If you create or join a Household, your meal data is shared with the other members through our servers. Members are identified by device IDs and by the device name you choose. You can leave a household at any time, and the owner can remove members.
If you post a recipe to the Chef's Guild, that recipe — its text, photo, and the display name you chose — is stored on our servers and shown to other users. You can post anonymously. Recipes may be removed by moderation if they're reported.
When you import a recipe from a URL or an image, that URL or image is sent to our server and processed by a third-party AI service (Google Gemini) to extract the recipe. We do not store the URLs or images after processing.
Some versions of DinnerRoll include anonymous usage analytics, which tell us which features get used and where the app is confusing or broken. This records events such as opening the app, generating a menu, or importing a recipe — never the contents of your meals, menus or grocery lists.
Analytics are tied to a random identifier, not to you, and are never used for advertising or sold to anyone. You can turn them off at any time in Settings → Privacy → Share anonymous usage data. The app works identically with them off.
DinnerRoll asks for camera access so you can photograph a recipe to import it. Photo library access uses the system picker, which grants one-time access to the photos you choose — the app cannot browse your library.
Recipe extraction is processed by Google Gemini. Where usage analytics are enabled, they are processed by PostHog. Both act as processors on our behalf. We do not sell or share your data with anyone else.
To remove everything held on our servers — cloud backup, Guild posts, chef stats and household membership — use the data deletion page. It needs your device ID, which you can copy by long-pressing the version number at the bottom of Settings.
To remove local data, clear the app's storage or uninstall it. You can also email us and we'll handle deletion for you.
DinnerRoll is not directed at children under 13, and we do not knowingly collect data from children.
We may update this policy. Changes appear on this page with a new "last updated" date.
Questions about this policy: goosexgoosecreations@gmail.com