Privacy Policy

What Dinsly does with your data

Last updated 16 August 2026

The short version: we collect what's needed to plan your meals, fill your trolley, and bill you — your account details, your food preferences, the plans and carts Dinsly builds for you. We never sell your data. Your food preferences reach the AI models that write your recipes; your name and email never do. You can ask us to delete your account and everything attached to it at any time.

Who we are

Dinsly is operated by Dinsly (ABN 63 664 263 439), based in Australia. This policy explains what we collect through the Dinsly website (dinsly.com.au), the Dinsly Cart browser extension, and the services behind them.

What we collect

Account information. Your email address, and either a password (stored as a one-way bcrypt hash — we cannot read it back) or, if you sign in with Google, the name and profile image Google shares with us.

Household preferences. The things you tell Dinsly so it can plan for you: how many people you're cooking for, which nights you cook, a weekly budget, dietary exclusions and dislikes, what's already in your pantry, and which supermarket you shop at.

Generated content. The meal plans, recipes, and shopping carts Dinsly builds for your household, plus a short history of what you've cooked, favourited, or disliked — this is what lets Dinsly avoid repeating a dinner you skipped last month.

Billing information. Dinsly's subscription is billed through Stripe. We store a reference to your Stripe customer and subscription record and its status (trialing, active, cancelled) — we never see or store your card number; Stripe holds that.

Support requests. If you report a problem, we store your message and — to actually be able to investigate it — a snapshot of your account and plan state at that moment (what week you were on, recent errors the app hit) captured automatically alongside your report, not typed by you.

Browser extension data. The Dinsly Cart extension stores your sign-in session on your device (via Chrome's own storage, not ours) so you don't have to sign in on every retailer visit, and reads the Woolworths/Coles page you're on to add your planned items to your cart. It does not track your browsing beyond those two retailer sites.

Technical information. Standard server logs (timestamps, error rates) and, when you're signed in, the IP address a request came from — used only to apply rate limits that stop abuse, not to profile or track you.

How we use it

To generate and cost your weekly meal plan against real, current supermarket prices; to fill your shopping cart; to remember what you've cooked so Dinsly doesn't repeat itself; to bill your subscription and tell you when a trial or payment needs attention; to reply when you contact support; and to keep the service secure and working.

AI and your data

Dinsly uses third-party AI models (currently Anthropic, OpenAI, or Google, depending on configuration) to write recipes and generate hero images. What those models see is your household preferences — dietary exclusions, budget, pantry items, cuisine style — and the supermarket catalogue, so they can write a recipe that's actually buyable this week. We checked this deliberately: your name, email, and any other directly identifying information are never included in what's sent to an AI provider.

Who we share it with

We share data only with the providers that make Dinsly work, and only what each one needs to do its job:

  • Google — if you sign in with Google, to verify your identity.
  • Stripe — to process your subscription payment. Stripe is PCI-compliant and handles your card details directly; they never pass through Dinsly's servers.
  • Resend — to send account emails (verification, trial reminders, support replies).
  • Anthropic, OpenAI, and/or Google Gemini — to generate recipes and hero images, as described above.

We do not sell your data, and we do not share it with advertisers or data brokers — Dinsly runs no advertising or analytics trackers of any kind, in the app or the extension.

Cookies

Dinsly uses one essential cookie to keep you signed in. We don't use advertising or third-party tracking cookies.

How long we keep it

We keep your account and its data for as long as your account is active, plus a reasonable period afterward to handle billing disputes and comply with our own legal obligations. Support requests and the account snapshot attached to them are deleted along with your account, not kept separately.

Your rights

You can ask us to access, correct, or delete the personal information we hold about you at any time. Account deletion currently goes through a person, not a self-service button — email us (see Contact us, below) from your account's address and we'll action it, including cancelling any active Stripe subscription first so you're never charged after deletion.

Children's privacy

Dinsly is not directed at children and is not intended for use by anyone under 16. We do not knowingly collect information from children.

Security

Passwords are never stored in plain text. All traffic to Dinsly is encrypted. Access to production systems is limited to the people operating the service.

Changes to this policy

If how Dinsly handles your data changes materially, we'll update this page and, for significant changes, let signed-in users know directly.

Contact us

Questions about this policy, or a request to access, correct, or delete your data: privacy@dinsly.com.au