Sofra holds something personal — your family's food life. Here's how it's protected, in plain terms.
Every request requires you to be signed in via Google Sign-In or email/password, handled by Google Firebase Authentication. No anonymous access to data.
Meals, dishes, and restaurants live under your household and are readable only by its members. Server-side security rules enforce this — not just the app.
All data travels over HTTPS/TLS between your device and Google's servers.
Profile photos are stored per-user; only you can upload or replace your own, and uploads are limited to images under 1 MB.
Edit or delete any meal, dish, or photo anytime. Delete your account from Settings to remove your personal data.
We do not sell your personal information, and there are no third-party advertising trackers in the app.
Access is enforced by server-side security rules on the database and file storage — the app can't bypass them, and neither can anyone else.
The Android app requests only what it uses — internet, notifications, camera and photo access for meal/profile pictures. It does not request "draw over other apps," device admin, location, contacts, SMS, or call permissions.
Found a security issue? Please email [email protected] and we'll respond promptly.