← Back to Palate

Privacy Policy

Last updated: September 2026

What Palate Does

Palate builds your dining profile by finding reservations, orders, and receipts across platforms like OpenTable, Resy, DoorDash, Toast, Uber Eats, and others. We use read-only access to your Gmail account to discover dining confirmation emails — we never modify, delete, or send emails on your behalf.

What We Access

When you sign in with Google, we request read-only access to your Gmail. We only search for emails from known dining platforms (OpenTable, Resy, DoorDash, etc.) using specific sender queries. We do not read personal emails, attachments, or any messages unrelated to dining.

From dining emails, we extract:

  • Restaurant name and location
  • Date, time, and party size
  • Order items and amounts (when available)
  • Confirmation numbers

How We Use Your Data

Your dining data is used to:

  • Build your personal dining profile and timeline
  • Identify cuisine preferences, favorite restaurants, and dining patterns
  • Provide personalized dining recommendations (coming soon)

Data Storage & Security

Your data is stored in our database with row-level security, so each account can reach only its own records. The only Google credential we keep is the refresh token that lets Palate keep finding new dining occasions; it is encrypted (AES-256-GCM) and stored server-side, and is never sent to your browser. We do not store Google access tokens.

We do not keep the text of your emails. Once a dining email is processed we keep only the details listed above and the email's Gmail message ID, which stops the same email being counted twice.

We do not sell your personal data. We share it only with the service providers listed below, and only to run Palate. Restaurant data (names, locations, cuisine types) may be shared in aggregate, anonymized form.

Google API Services Usage Disclosure

Palate's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, Palate:

  • Only uses Gmail data to build your personal dining profile — the core functionality you see in the app
  • Does not sell, rent, or provide Gmail data to third parties for advertising, marketing, or any unrelated purpose
  • Does not use Gmail data to serve ads or build advertising profiles
  • Only allows humans to read Gmail data if you explicitly consent, or as required for security, legal compliance, or to investigate abuse

Third-Party Services

We use the following services to operate Palate:

  • Google Gmail API — to discover dining emails (read-only)
  • Google Gemini API — to read the details out of dining emails. For each email from a dining platform we send the subject, sender, date, and up to 2,000 characters of its text. Gemini returns the structured details (restaurant, date, items); it does not store the email or use it to train models.
  • Google Places API — to enrich restaurant information (restaurant name and city only)
  • Supabase — for authentication and database hosting
  • Vercel — for application hosting, and anonymous usage analytics
  • Google Analytics — anonymous usage analytics (pages visited, sign-up steps); no dining or email data
  • Plaid — only if you connect a card, to find dining purchases on it

Your Controls

You can at any time, from Settings:

  • Disconnect Google — Palate revokes its Gmail access with Google and deletes the stored token. Your existing profile stays.
  • Delete All Data — deletes every dining occasion, restaurant match, and profile signal, and disconnects Google so nothing is rebuilt.
  • Delete Account — deletes your account and all associated data, and revokes Palate's access to Google, any connected cards, and any AI apps you connected Palate to.

You can also revoke access from your Google Account permissions page; Palate will then ask you to reconnect.

Retention

We keep your dining data until you delete it or your account. Deletions take effect immediately in our database; encrypted backups roll off within 7 days. Operational logs, which contain account IDs but not email content, are kept for up to 30 days.

Contact

Questions about this policy? Reach us at privacy@thepalate.app.