What Plated keeps, and where.
Last updated 7 September 2026
Plated is a dinner planner for a household. Your recipes, plans, photographs and household stay in your own iCloud account. Plated runs one small server, and this page says exactly what it holds.
In your iCloud
Recipes, meal plans, grocery lists, household members, gatherings, photographs, posts to your Table and cooking history are saved on your device and synced through your private iCloud database using Apple’s CloudKit. The developer cannot read any of it.
If you join a household, the plan, the grocery list, the cookbook and the people list are shared with the other members of that household through iCloud, and each member’s own iCloud keeps a copy. Leaving takes your recipes with you and removes the rest from your phone. The household keeps its copy of the recipes you shared with it, including the ones you brought when you joined.
When you share a Table, CloudKit shares your posts with the people you invited and nobody else. A Table guest never sees the plan, the grocery list or the cookbook.
On Plated’s server
Plated keeps a directory so the app can answer one question: which of your contacts already use Plated. iOS no longer offers a way to answer that on the device, so the directory is the one part of Plated that is not in your iCloud. It holds:
- A salted hash of your phone number, never the number itself. The salt lives only on the server, so the table cannot be turned back into a phone book.
- The first name you already show your household.
- Your Apple account identifier, and a token that lets your phone ask the directory questions.
- An opaque push-notification token issued by Apple, the app version and build, its release channel, whether iOS currently allows notifications, your News preference and the last time that registration was refreshed. Plated uses these to deliver invitations, decide whether a service notice can reach that installation and diagnose delivery failures.
The directory is used for two things. When you look for contacts already on Plated, the phone numbers from your address book are sent to the server over an encrypted connection, hashed there, compared, and not stored. People who are not on Plated are never kept. When somebody invites you and your number is in the directory, the server sends a notice to your phone saying who it is from, which it can do because it holds a push token for each phone you have signed in on. The invitation link itself is never stored. What stays behind is a record that the invitation happened: who sent it, the hashed number and the time, so that no host can turn invitations into a mailing list. The server is hosted by Supabase in the United States.
When somebody shares a seat
Plated records the inviter, a salted hash of the invited phone number, the inviter’s first name, the delivery result and the time of the invitation. If the invited number already belongs to a Plated account, its private CloudKit share link is sent to the server only to compose that immediate notification and is not stored. The remaining invitation metadata is retained for 30 days for abuse limits and operational troubleshooting, then deleted.
On this website
If you join the waitlist, plated.food stores the email address you typed and the time you typed it. It is used only to announce when Plated is available and remains until you ask Plated to delete it. Write to the address at the bottom of this page to be removed.
What Plated never collects
Plated contains no analytics, no advertising, no tracking and no third-party SDKs. Nothing you do in the app is measured, profiled or sold.
Permissions Plated asks for, and why
- Sign in with Apple establishes who owns the table and registers you with the directory above. Plated never receives your password.
- Contacts are read on your device to fill a seat. Numbers leave the phone only when you ask who is already on Plated, as described above, and are not stored.
- Location is used only to request a local forecast from Apple’s WeatherKit. It is passed to Apple to answer that request and is not stored by Plated.
- Calendar: when you sync a gathering, Plated writes the event to a calendar you choose, on your device.
- Reminders: when you send a grocery list, Plated writes those items to your own Reminders list.
- Photos you add to a recipe or a post are stored with it in your own iCloud account.
- Notifications let Plated tell you about a seat shared with you or a rare service or release notice. Your choice is optional. News from Plated starts off and must be turned on separately; allowing Table or cooking notifications does not subscribe you to founder announcements. Plated stores the delivery details described above, and removes a device token when Apple reports that it is no longer valid.
Every one of these is optional. Decline any of them and the rest of Plated keeps working; the feature that needed it stays quiet rather than nagging you.
Children
Plated is rated 4+ and does not knowingly collect information from children.
Deleting your data
Your Plated data lives in your iCloud account. Deleting the app removes the local copy. To remove the synced copy, delete Plated’s data from iCloud in Settings, then your name, then iCloud, then Manage Account Storage. To remove your entry from the directory or the waitlist, write to the address below and it will be deleted.
Changes to this policy
If this policy changes, the revised version will be posted at this address with a new date at the top.
Questions about privacy in Plated: privacy@getplated.food