Sufra Privacy Policy
Effective date: 15 August 2026
Sufra is a private meal-sharing app for families and close friends. You post a photo of what you're eating; only the people at your private "tables" can see it. There are no public feeds, no discovery, no strangers.
This policy explains what Sufra stores, where, and how you delete it. It is written to be read, not skimmed past.
What Sufra stores
When you use Sufra, we store:
- Your email address and password — used only to sign you in. Passwords are handled by Firebase Authentication; Sufra never sees or stores your password itself.
- Your display name — the name your family sees at the table.
- Your meal posts — the photo, an optional dish name, an optional recipe, the meal type (dinner, lunch, …), and when you posted it.
- Reactions and votes — the emoji you leave on family members' plates, and your one weekly vote in the Sunday ballot.
- Table membership — which tables you belong to and your seat's color.
- A push notification token — a device identifier used solely to deliver notifications like "someone posted" to your phone. Stored only if you enable notifications.
Some data never leaves your phone: notification preferences, which plates you've opened today, and small bookkeeping markers. Deleting the app removes them.
Photos and location metadata
Meal photos are resized and re-encoded on your phone before upload, which removes location (GPS) and other camera metadata in the normal case. In the rare case that re-encoding fails, the original photo is uploaded so your post isn't lost — that original may retain camera metadata. Photos are only ever visible to members of the table they were posted to.
Where your data lives
Sufra stores data with Google Firebase (Authentication, Cloud Firestore, and Cloud Storage). The database and photo storage for this project are located in Google Cloud's nam5 multi-region in the United States. Push notifications are delivered through Expo's push notification service, which processes your push token to route notifications to your device.
Firebase and Expo act as processors; they do not use your content for their own purposes.
What Sufra does NOT do
- No analytics or tracking SDKs. Sufra does not measure, profile, or fingerprint you.
- No ads. Ever.
- No sale or sharing of your data. Your data is not sold, rented, or shared with anyone beyond the storage and notification processors above.
- No public content. Everything you post is visible only to members of your tables.
Who can see your data
Only signed-in members of a table can see that table's meals, names, and reactions — enforced server-side by Firebase security rules. Nobody outside your tables, including other Sufra users, can see anything of yours.
Deleting your data
Settings → Delete account permanently erases, for everyone:
- your sign-in (email/password account),
- your profile and display name,
- every meal you posted — photos included — at every table, including tables you had already left,
- every reaction you gave, and the reactions others left on your meals,
- your ballot votes,
- your seat at every table and any stored push tokens.
Deletion is immediate and cannot be undone. If the connection drops partway, sign in and run it again — it finishes the job.
What remains after deletion: the table itself (its name and invite code) stays for the family members still using it, and Sufra keeps small aggregate records of shared moments — "the whole table ate together on this date" and "this week's crowned dish" — which may contain internal references (a random account ID, a meal ID) that no longer point to anything once your account is gone. These records identify no one.
If you can't access the app, email the address below and we will delete your account for you.
Children
Sufra is meant for families. Tables are invite-only, so children only ever share meals with people their family invited. Accounts should be created by, or with the consent of, a parent or guardian.
Changes
If this policy changes, the effective date above changes with it, and the current version is always at this URL.
Contact
Questions or deletion requests: help@sufra.info