This policy explains how DishCost handles information when you use our website, application, and AI connector. If you connect DishCost to ChatGPT, Claude, or another compatible assistant, the assistant can read the DishCost data you approve.
Information we collect
- Account information: name, email address, login records, and account plan.
- Restaurant information: ingredients, prices, price history, recipes, quantities, selling prices, weekly orders, and settings that you enter or import.
- Billing information: subscription status and identifiers from Stripe. We do not store full payment-card numbers.
- Usage information: pages visited, feature use, approximate technical request data, and connector events described below.
AI connector data
The connector requests offline access, recipe-read, and ingredient-read scopes. It can list recipes and ingredients, read recipe costs and ingredient price history, analyze menu margins for eligible accounts, and calculate an unsaved recipe cost. It cannot create, edit, or delete records, manage billing, or start a subscription.
When you call a connector tool, DishCost sends the requested result to the assistant you connected. That provider handles the result under its own terms and privacy policy. DishCost does not send your data to an assistant until you authorize the connection and use a tool.
How we use information
We use information to operate and secure DishCost, calculate recipe and menu costs, provide support, process subscriptions, send account messages, improve the product, and comply with law. We do not sell personal information or restaurant data.
Connector telemetry
We record whether authorization started, completed, or was denied; whether a connector became active; the source platform; tool name; success or failure; latency; and a bounded error code. We may use a one-way client identifier hash to measure repeat use.
Connector telemetry does not include prompts, access tokens, authorization codes, client secrets, raw tool inputs or outputs, recipe or ingredient names, prices, quantities, or other restaurant content.
Service providers and other recipients
We use service providers to host and protect the application, store data, process payments, send account email, and measure product use. These may include Cloudflare, Stripe, Loops, PostHog, Google when you choose Google sign-in, and the AI provider you connect. We may also disclose information when required by law or as part of a business transfer.
Retention and security
We keep account and restaurant records while your account is active and until they are deleted. OAuth access and refresh records remain until they expire, are revoked, or are removed with the account. We retain connector event history only while it is useful for security and product measurement, then delete or aggregate it. Legal, fraud-prevention, and backup obligations may require limited records to remain longer.
We use access controls, encrypted network connections, scoped authorization, and account-bound queries. No internet service can guarantee absolute security.
Your choices
You can disconnect DishCost in the connected assistant's settings. Disconnecting stops future access but does not delete your DishCost account or copies already present in an assistant conversation. Delete conversations through that provider.
To revoke connector tokens, access or correct your information, or delete your account and DishCost data, email hello@dishcost.com from your account email. We may need to verify the request.
Contact
DishCost, 1007 N Orange St, 4th Floor, #3006, Wilmington, DE 19801, United States.
hello@dishcost.com