Eat the World — Privacy Policy
Effective 10 September 2026
What we collect
- Account: a stable identifier from Sign in with Apple, your
name, which Sign in with Apple provides, and the time you last used the
app. We do not store your email address. You can change your name in
Settings.
- Dining and visit activity: the restaurants and bars you mark
eaten, drunk at or saved; the hotels, gyms and attractions you mark visited
or saved; the days on which you tick Went today at a venue; your star
ratings; and the cuisines, countries and cities derived from them (including
venues' approximate coordinates). Friends see these as newsfeed rows such as
"has eaten at", "was at … today" and "has visited".
- Photos you add: photos of your visits and your profile photo,
with any caption you write. For visit photos, we also store friend tags added
by you or another person who is allowed to view the photo, including who
placed each tag. Photos are re-encoded on your device before upload, so the
EXIF metadata — including where and when the picture was taken — never
leaves your phone.
- Location: your device location powers nearby-venue search.
When you search nearby, look up a city or ask for directions, your precise
coordinates are sent to our server and passed to Google (nearby venues) or
Apple (place search, geocoding, directions) only to answer that request; we
do not keep them. If you switch on Show global location to friends
(off by default), your device sends its position with each sync and we
store only a value rounded to about 10 km — your approximate city, never
your position within it — so it can appear as a dot on friends' maps.
- Notifications: a device push token, if you enable them, and an
in-app notification list (likes, tags, invitations, messages) that names
the friend who acted.
- Private messages: the messages you exchange with accepted
friends, their participants and timestamps, and read/deletion state. Message
content is stored in readable form on our server and is not end-to-end
encrypted. If you report a message, the report stores a copy of that
specific message with the reporter's and sender's identities, its original
timestamp, and the report time so it can be reviewed.
- Event chats: a dinner invitation can open an event chat. We
store its messages, who sent each one and when, who is a member and when
they joined, read state, and who has left. If you report an event-chat
message, the report stores a copy of that message with the reporter's and
sender's identities and timestamps.
- Invitations: the restaurant, date and time of dinner invitations
you send or receive, the guest list and each guest's reply, the calendar
days you mark busy in the app, the calendar timezone you choose in
Settings, and which calendar apps you have chosen to sync with.
- Newsfeed posts: short text posts you choose to share, your account
as their author, their posting times, the friends you tag in them, and the
identities of people who like them. They are stored on our server and shown
to you and your accepted friends. If you tag a friend in a post, the post
also appears on that friend's newsfeed, where it is visible to their
accepted friends, who need not be your friends, and the tagged friend is
notified. A tagged friend can remove the post from their newsfeed; removing
your own post removes it from theirs too. Likes on a post notify its
author. If someone reports a post, the report stores a copy of its text
with the reporter's and author's identities and timestamps.
What stays on your device
If you connect a calendar, events read from it are displayed on your
phone only and are never uploaded to us. Phone numbers you type to invite
someone by text message are handed to your Messages app and are never sent
to us. The calendar feed we host contains your Eat the World invitations
(the restaurant, the time and the names of the people invited) and the
days you have marked busy in the app, and nothing else; if you subscribe
to it from Apple Calendar or Google Calendar, that provider fetches it
under its own privacy policy.
Who can see it
Your activity, ratings, map dots and short newsfeed posts are shared with
friends you have mutually accepted; a post in which you tag a friend is
additionally shown to that friend's accepted friends. A visit photo is
normally visible to its owner and the
owner's accepted friends. Someone who is allowed to view a visit photo may
tag themselves or one of their own accepted friends. A self-tag is accepted
immediately. When someone else is tagged, that person may view the photo while
deciding whether to accept or decline the tag. Accepting publishes a newsfeed
story containing the tagged person's name, a thumbnail and the photo's current
venue or location (if any), and makes the photo visible from that person's
profile and newsfeed to their accepted friends. Those friends need not also be
friends with the photo's owner. The story and full photo share the same likes.
Pending tag details are limited to the photo owner, the person who placed the
tag and the person tagged. Private messages are visible only to their two
participants while they remain accepted, unblocked friends. An event chat
is visible to the person who sent the invitation and to every guest who has
neither declined it nor left the chat, including guests brought along by
other guests, who need not be your friends; each member sees only messages
sent after they joined. The inviter and every guest can see who else was
invited and how they replied. Busy days are visible only to you. A message
or post deliberately reported is also visible to the authorized moderator
handling the report. Your name and profile photo are
visible to anyone who searches for you, so that friends can find you.
Nothing else is public. Blocking a person removes their access. Unfriending
removes access they had solely through your friendship, but it does not remove
access they separately have through an accepted photo tag. An authorized
administrator may access stored account and content data when reasonably
needed for support, security, moderation or enforcement of our Terms.
Third parties
- Google Maps / Places supplies venue search, details and
photos; those queries are handled under Google's privacy policy. The
street-level map in the app loads on your device directly from Google
Maps.
- Apple handles sign-in, push notification delivery, place
search, geocoding and directions; the route map loads on your device
directly from Apple.
- Railway hosts our server, and Backblaze B2 stores the
photos you upload. Our server records the IP address of requests in
ordinary server logs and uses it for rate limiting.
- Z.AI receives each photo you upload, once, so an automated
check can screen it for explicit content before it is stored. It is not
used to train models and is not retained there.
- Reservation platforms: to find how a restaurant takes bookings,
our server reads the restaurant's own website and asks Yelp about
that restaurant by name and location; nothing about you is sent. Tapping
BOOK opens the restaurant's or a reservation platform's website in your
browser, where that site's privacy policy applies.
Service providers may use this data only to provide their services to us
and must protect it consistently with this policy.
We show no ads, use no analytics or tracking SDKs, and never sell or
share your data for marketing.
Deletion
Account and content data is retained while your account and that content
exist, or as needed for safety and legal obligations. Removing an item from
your newsfeed hides the event from feeds but retains its record until account
deletion. Removing an accepted person-tag removes its tag story but does not
delete the original photo; hiding a story does not remove its underlying tag
or photo. A post removed by you or by a moderator stays hidden; its text may
be retained in a report for safety and enforcement.
You can leave an event chat at any time. A sender can hide an event-chat
message from their own view or delete it for everyone; an event chat is
removed when its invitation is cancelled or its host deletes their
account.
You can withdraw optional location and notification permissions in Settings,
decline or remove person-tags, remove photos and feed items, block other users,
or delete your account using the controls described in the app.
A message sender can hide a message from their own history or delete its
text for both participants. A content-free record of a message deleted for
both is retained so retries and notification links cannot attach to a
different message. If the recipient already reported that message, the
moderation copy may be retained for safety and enforcement. Unfriending or
blocking hides the conversation but does not erase it; it returns if both
people later become accepted friends again.
Settings → Delete account permanently removes your account,
your photos, your posts, your private and event-chat messages, your
invitations and busy days, and every record we hold, immediately. You can
also email us to request deletion.
Contact
deanemcrobie@gmail.com