Your data.
Your rules.
Weeknight Dinners is subscription-funded. We have no data brokerage and no investors pushing us toward monetizing your attention. This page explains exactly what we collect, what we don’t, and why the distinction matters.
This policy is being actively drafted. The commitments below are firm; detailed legal terms will be added as Weeknight Dinners moves out of beta.
Privacy by
design.
Most privacy policies are damage control. They describe data collection practices that exist to serve a business model, then explain the minimum you’re legally entitled to know about them. We want to write a different kind of policy.
Our thinking here is inspired by Signal. Signal’s privacy model is built on a simple principle: the best way to protect data is to not have it in the first place. Their privacy policy is famously short because there is genuinely little to say — they collect almost nothing, and what little they do collect is technically constrained so they cannot share it even if compelled. Signal’s privacy director has described this as “privacy by design” — architectural decisions that make privacy the default, not a setting.
Weeknight Dinners is not Signal. We are a planning app, not an encrypted messaging app — we store recipes, calendars, and posts, and that data lives on our servers. But the philosophy is the same: collect only what we need, be explicit about what that is, build no business around the surplus, and tell you the truth about all of it.
The subscription model is our structural protection. Signal is a nonprofit funded by donations; Weeknight Dinners is funded by subscribers. In both cases, the financial model removes the incentive that drives surveillance capitalism. We don’t need your data — we need your monthly subscription.
What we collect.
What we don’t.
Signal’s privacy policy lists three things they store: your phone number, your registration date, and the date you last connected. That’s it. We store more than that — Weeknight Dinners is a richer application — but the exercise of listing both sides is worth doing.
Email address
Required for authentication and account recovery.
Name and profile photo
Used to identify you to people in your shared household or friend group. Only shown to people you follow or who follow you.
Recipe URLs and titles you save
The core function of the app. We store a reference to the recipe, not the recipe content itself (see Content Policy).
Meal calendar entries
Which recipes you've scheduled for which days. This is the planning layer of the app.
Posts, photos, and comments you share
Content you explicitly publish to your household or friend group. Visible only to people you've connected with.
Authentication tokens and session data
Technically required to keep you logged in.
Advertising identifiers or device fingerprints
We don't track you across the web for ads.
Location data
Weeknight Dinners never requests or stores your location.
Contact lists
We never ask for access to your phone or email contacts.
Recipe content from external websites
We store a URL and title. The content lives on the creator's site. See the Content Policy.
Data for training AI models
Your personal data is never used to train any model. See the AI Policy.
What we can
and can’t see.
Signal can make a remarkable claim: they technically cannot read your messages, because the encryption happens on your device and they never hold the keys. Weeknight Dinners cannot make the same claim — we are not an end-to-end encrypted messaging app, and it would be dishonest to imply otherwise.
What we can say honestly is this: your data lives in a database we operate (via Supabase), and in principle, we could query it. We choose not to, and we have no business model that would incentivize us to. But if you need a cryptographic guarantee rather than a promise, we are not that product — and you should know that.
We will tell you what we can’t do, and what we won’t do, and we will not conflate the two. Most privacy policies don’t bother making this distinction. We think it matters.
What we genuinely cannot see: the content of recipes on external websites you visit through the app (those load in your browser, on the creator’s servers, not ours), and private messages between users (Weeknight Dinners has no DM feature and no plans to add one).
Where it
lives.
Weeknight Dinners stores data in PostgreSQL on AWS infrastructure, managed by Supabase. Authentication is handled by Supabase Auth via Google OAuth. All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Row-level security policies in the database ensure that queries can only return data belonging to the authenticated user.
The third-party services that touch your data, and what they receive:
Supabase
Database, authentication, and edge function runtime. Your data lives here. Supabase is contractually prohibited from using it for their own purposes.
Vercel
Hosts this marketing website only. Vercel does not have access to app user data.
Apple App Store / Google Play
Distribute the app binary. They collect their own data under their own policies; Weeknight Dinners does not share user data with them.
Google (OAuth)
If you sign in with Google, Google authenticates you and returns your email and name. We store those. Google does not receive your Weeknight Dinners data.
Not used
for training.
Your personal data is never used to train AI models — ours or anyone else’s. The AI processing Weeknight Dinners performs is for recipe indexing quality (filtering, identifying, and associating content), which operates on public page content, not on your account or behavior.
See the AI Policy for the complete picture.
Never sold.
Never shared.
Weeknight Dinners does not sell your data. Weeknight Dinners does not share your data with advertisers, analytics companies, data brokers, or any third party for commercial purposes. Full stop.
The only circumstances under which we would disclose data are:
- To run the service — passing data to the third-party processors listed above (Supabase, Apple/Google for app distribution, Google for OAuth) so the app can function
- If legally required by a valid court order or subpoena — and in that event, we will notify you unless prohibited by law
- To investigate a reported violation of our Terms of Service that affects another user's safety
- With your explicit consent
Signal has demonstrated in court that minimal data collection means minimal data production. When the government subpoenaed Signal in 2016, they could produce only two data points: the account creation date and the date of last connection. We aspire to the same situation — a subpoena of Weeknight Dinners should yield as little as possible, because we should be storing as little as possible.
Access, export,
delete.
In-app self-service controls coming before general availability.
You have the right to access all data Weeknight Dinners holds about you, receive a portable export of it, correct inaccuracies, and request permanent deletion. While Weeknight Dinners is in beta, these requests are handled manually — contact us via the feedback form and we will respond within 30 days.
When Weeknight Dinners exits beta, self-service data export and account deletion will be available directly in the app. Deletion means deletion — not deactivation, not soft-delete that persists indefinitely.
How long
we keep it.
Formal retention schedule to be published before general availability.
Active account data is retained for as long as your account is open. When you delete your account, your personal data is removed from production systems within 30 days. Encrypted backups rotate on a 90-day cycle; deleted data will be fully purged when the last backup containing it rotates out.
Non-identifiable aggregate data (total recipes indexed, total users, etc.) may be retained indefinitely for operational purposes. This data cannot be traced back to any individual account.
Questions
about your data.
If you have questions about this policy, want to request your data, or want to delete your account, reach out through the feedback form. We will respond within 30 days.
This policy was last updated May 2026. Changes that materially affect your rights will be communicated to active users by email before they take effect.