Craves working name

Privacy Policy

Draft v0.1 · 20 September 2026 · not yet in effect

Who we are. Craves is operated by [YOUR NAME or COMPANY], [CITY], Texas, USA. Contact: privacy@craves.studio. We are the controller of the personal data described here.

What Craves does. Craves recommends a restaurant to you or to a group of friends, learns from your feedback, and lets you log and share meals with friends you choose.

1. Information we collect

CategoryWhatWhyLegal basis (GDPR, where it applies)
AccountEmail address, display name, username, password hash or the identifier from Sign in with Apple / GoogleCreate and secure your accountContract
Taste profileYour onboarding answers (favourite restaurants, food-choice priorities, openness to new foods, spice preference, photo-quiz choices, how often you eat out with others)Personalise recommendationsContract
Dietary preferencesVegetarian, vegan, gluten-free and similar lifestyle preferencesFilter recommendationsContract
Sensitive dietary data (optional)Food allergies; religious dietary rules such as halal or kosherExclude unsafe or unsuitable restaurants for you and any group you joinExplicit consent, which you can withdraw in Settings at any time. Health-related and belief-related data are “special category” data under GDPR and “sensitive personal information” under California and Texas law.
LocationYour approximate or precise location only while you use the app to request a recommendationFind restaurants near youConsent via the OS permission prompt; you can use the app with a typed location instead
ActivityThe recommendations you receive and accept or reject; the visits you log (restaurant, date, “would you go back”, optional dish, optional photo, optional vibe tags); reactions on friends’ postsImprove your recommendations, build your history and your year-end recap, show posts to friends you chooseContract; legitimate interest in improving the service
Friends and groupsFriend connections you make; optional hashed phone contacts if you choose “find friends from contacts” (we never upload raw contact lists); group membershipsLet you connect and decide togetherConsent (contacts); contract (friends, groups)
Device and diagnosticsPush notification token, device type and OS version, app version, crash reports, coarse usage events (screen opened, button tapped)Send notifications you enabled; keep the app workingLegitimate interest

We do not collect precise location in the background, contacts’ names or emails, payment card data, or advertising identifiers.

2. How we use information

To decide where you eat; to learn what you like from your feedback; to run group decisions using each member’s filters; to show your posts to the friends you select; to send the post-visit follow-up notification you opted into; to create an optional year-end recap; to keep the service secure; to measure what works, in aggregate.

We do not sell personal information and do not share it for cross-context behavioural advertising. We do not use your data to train general-purpose AI models.

3. Where your information goes (processors)

ProviderPurposeData involved
Supabase (hosted Postgres, auth, storage), USADatabase, login, photo storageAll categories above, encrypted in transit and at rest
Google Maps Platform (Places API)Live restaurant ratings, review counts and opening hours at the moment you ask for a recommendationYour approximate location and the restaurant lookups; we store none of Google’s content except restaurant identifiers
Anthropic (Claude API)Generating the one-sentence explanation of a recommendationA summary of your taste profile and the candidate restaurants’ attributes; no name, email, contacts, or precise location
Expo push service, Apple APNs, Google FCMDelivering notificationsPush token
[Cloud Run / Fly.io]Running our recommendation serviceRequest data in transit
Meta (Instagram)Only if you choose to share a card to Instagram StoriesThe image you chose to share, sent from your device

Restaurant catalogue data comes from Foursquare OS Places and OpenStreetMap (© OpenStreetMap contributors, ODbL); this is data about restaurants, not about you.

4. What friends and others see

By default your logged visits are visible to accepted friends only. You can set each visit to private. Your dietary preferences and sensitive dietary data are never shown to other users, never included in share cards, and are used in a group decision only as a filter without revealing who set it. Public sharing happens only when you export a card to another platform.

5. Retention and deletion

Delete your account in the app under Settings → Account → Delete, or at craves.studio/delete-account. Deletion removes your account, profile, history, photos and friend connections within 30 days, and revokes Sign in with Apple / Google tokens.

6. Your rights

Depending on where you live, you may have the right to access, correct, export, delete or restrict the use of your data, to withdraw consent, and to object to processing. Texas (TDPSA), California (CCPA/CPRA) and other US state laws, and the GDPR in the EU/UK, give you these rights; we honour them for everyone. Use Settings → Privacy → Export my data, or email privacy@craves.studio. We respond within 45 days (30 days in the EU/UK). We will not discriminate against you for exercising your rights. If you are in the EU/UK you may complain to your supervisory authority.

7. Children

Craves is not directed to children under 13 (16 in the EU) and we do not knowingly collect their data. [Store age rating: 12+/Teen due to user-generated content; confirm.]

8. Security

Encryption in transit (TLS) and at rest; sensitive dietary data stored in a separately encrypted column; row-level access controls so users can read only their own and their friends’ permitted data; least-privilege API keys; no Google Maps or Anthropic keys in the mobile app.

9. International transfers

Data is stored in the United States. If you use Craves from the EU/UK, transfers rely on the providers’ standard contractual clauses.

10. Changes

We will notify you in the app before material changes take effect. Version history: v0.1 draft, 20 September 2026.