flavly Privacy Policy
Effective date: 3 August 2026 (revised — personalized recommendations and dietary preferences, account-deletion response time unified to 7 days, in-app deletion, error-monitoring and third-party services detail)
Flavly ("we", "us", "our") is a dish recommendation app for Krakow, Poland. This policy explains what data we collect, why, and your rights under the EU General Data Protection Regulation (GDPR).
1. Data Controller
Flavly is operated by Przemyslaw Warias. For privacy inquiries, contact: contact@flavly.pl
2. Data We Collect
Account data (via Google or Apple Sign In):
- Name and email address provided by your identity provider
- We do not store your password — authentication is handled by Google/Apple via OAuth
Location data:
- Your GPS coordinates when you grant location permission, used to find nearby restaurants and dishes
- Coordinates you search with are stored with your search history (see §6 for retention) and, if you enable personalized picks, as the anchor location of your current picks slate; your device additionally caches your location briefly
- You can use the app with a manual location instead of GPS
Search and usage data:
- Search queries you submit (e.g., "ramen near me")
- Dishes you view and save (used for aggregate quality signals and, if you opt in, for personalized picks — see §3)
- Dish ratings you provide (1–5 stars)
- Photos you upload (menu photos, dish photos)
- Reports you submit about incorrect restaurant data
- App feedback you provide
Restaurant submissions:
- If you add a restaurant through the app, we collect the details you provide: restaurant name, address and map location, website and menu links, venue attributes, and up to 10 photos of the menu or venue
- Submissions are linked to your account so we can notify you when the restaurant goes live
- Please photograph menus and food only — do not include identifiable people in submission photos
Taste profile data (only if you turn on personalized recommendations):
- The choices you make in the setup quiz — cuisines, dishes, dietary needs, and preferences you select — and the taste signals derived from them
- Cuisine and taste preferences you state elsewhere in the app
- Your in-app activity used to refine the profile — dishes you save, searches you run, and dishes you view
- Dietary preferences. Dietary needs you set (for example vegetarian, gluten-free, or halal) are used as filters to exclude dishes that don't fit, across the app. Because such selections can indicate health or religious information, we treat them as sensitive: they are processed only with your explicit consent, used solely to filter and rank dish recommendations, and never shared or sold (see §4). Our dietary information is derived from menu descriptions and may be incomplete — always confirm allergen information directly with the restaurant
Device data:
- Push notification tokens (if you enable notifications)
- Device type and preferred language
- Crash reports (technical error data only, no personal content)
Beta program data:
- If you join the closed beta via TestFlight or Discord, we may use your account email to send you onboarding messages, known-issue updates, and feedback prompts during the beta
- Bug reports and beta correspondence are retained for 12 months
- The beta-cohort email list is dissolved 30 days after the beta concludes
3. How We Use Your Data
- Dish recommendations: Your location and search queries are used to find relevant dishes near you
- Community ratings: Your dish ratings contribute to aggregate scores visible to all users (your individual rating is not publicly attributed to you)
- Rate limiting: We track search counts per hour to prevent abuse
- Notifications: If enabled, we send meal reminders and dish suggestions based on your preferences
- Personalized picks: If you opt in, your quiz answers, stated preferences, and in-app activity are combined into a taste profile used to generate your personal dish picks — see §3a for the detail, including how to turn it off
- Service improvement: Aggregated, anonymized usage patterns help us improve search quality
- Content moderation: Authorized administrators may review and moderate user-submitted content (photos, reports). Moderation actions are logged for security and integrity purposes under Art. 6(1)(f) GDPR; logs are retained for 90 days
- Restaurant submissions: Submissions you make are reviewed by our team. If approved, we use the details and links you provided to add the restaurant, and the photos you submitted to extract menu items automatically (see §5 for how photos are processed). Not every submitted restaurant is added. If the restaurant goes live and you have notifications enabled, we send you a one-time notification
3a. Personalized Recommendations ("For You")
Personalized recommendations are off by default. Nothing in this section happens unless you turn them on by completing the setup quiz.
If you turn it on, we build a taste profile to suggest dishes we think you'll enjoy. The profile is derived from:
- the choices you make in the setup quiz — cuisines, dishes, dietary needs, and preferences you select;
- your in-app activity — dishes you save, searches you run, and dishes you view.
Turning the feature on also applies to your existing activity from before you turned it on, so your first recommendations are useful straight away.
We use this only to select and rank dish recommendations for you. We do not use it for advertising, we do not sell it, and we do not share your profile with restaurants or other third parties. Your recommendations are generated on our own servers from our own data — your taste choices and activity are not sent to third-party AI providers to build this profile.
Turning it off. Open Profile → Personalized recommendations and switch it off — one tap, at any time, no email required. When you do, we stop building your profile and delete your current recommendations. Turning it off does not delete your underlying activity (saves, searches, views), which follows the retention rules in §6.
Why we ask for explicit consent. Food choices can indirectly reflect sensitive information — for example, dietary needs tied to religion or health. We therefore treat this as consent-based processing rather than something we do automatically, and we record when you gave that consent so you can see and withdraw it.
4. Legal Basis for Processing
- Contract performance (Art. 6(1)(b) GDPR): Processing your searches, location, and ratings is necessary to provide the dish recommendation service
- Consent (Art. 6(1)(a) GDPR): Push notifications and location access require your explicit opt-in
- Consent (Art. 6(1)(a) GDPR): Personalized recommendations. When you turn on personalized recommendations, we process your taste choices and in-app activity to build a taste profile (see §3a). You give that consent by turning the feature on, and can withdraw it at any time in the app
- Explicit consent for sensitive preferences (Art. 9(2)(a) GDPR): Dietary and allergy selections can reveal health or religious information, so we process them only with your explicit consent, solely to filter and rank dish recommendations
- Legitimate interest (Art. 6(1)(f) GDPR): Crash reporting and aggregated analytics to maintain and improve the service
- Voluntary community contribution (Art. 6(1)(f) GDPR): Restaurant submissions you choose to make are processed on the basis of our and our users' legitimate interest in a complete, accurate restaurant catalog; submitting is entirely optional
5. Data Sharing
We do not sell your personal data. We share data only with trusted service providers in the following categories, all of which process data under appropriate agreements:
- Cloud hosting providers (EU-based where possible) — database, API, and web hosting
- Content delivery and security providers — EU/global edge for DDoS protection, TLS termination, and request routing
- Authentication providers — Google and Apple handle sign-in; we receive only your name and email
- AI service providers (OpenAI) — to interpret and match your natural-language searches, the text of your query is sent to OpenAI acting as our processor. We do not send your account identifier or your precise location with it. In addition, photos you submit when adding a restaurant (and menu photos you upload) are sent to OpenAI, acting as our processor, for automated menu extraction — identifying dish names, prices, and categories. Location metadata (EXIF) is stripped from photos before they are stored or sent, and your account identifier is not sent with them. OpenAI does not use data submitted through its API to train its models. Please do not type names, addresses, contact details, or information about another person into a search, and do not include identifiable people in photos.
- Error monitoring — technical crash data only, processed on the basis of our legitimate interest in keeping the service working (Art. 6(1)(f) GDPR). Crash reports carry no account identifier; request bodies are not attached, and search text, coordinates, and share-link tokens are automatically redacted from error reports before sending
- Mapping and geocoding (OpenStreetMap) — when you view a map, tiles load from OpenStreetMap's servers, which receive your IP address and the map area shown. When you type an address in the location picker, the address text is sent to the OpenStreetMap Nominatim geocoding service to find its coordinates; when you drop a pin on the map, the pin's coordinates are likewise sent to Nominatim to display the address. Your account identifier is not sent with any of these
- Image hosting — illustrative images on some screens load from Unsplash, and if you sign in with Google your profile picture loads from Google's image servers; these hosts receive your IP address, not your account identity
- Push notification services — delivery of notifications to your device
- Restaurant data providers — public restaurant information enrichment (your personal data is not sent)
- Beta distribution and community platforms (Apple TestFlight, Discord) — if you join the closed beta, these platforms process your installation and community participation under their own privacy policies
- Internal communication tools — we may forward feedback, reports, and moderation events to internal tooling for triage; payloads are scrubbed of personal data before sending
A full list of current sub-processors is available upon request at contact@flavly.pl.
6. Data Storage and Retention
- Your account is stored as long as it is active
- Search logs are retained while your account is active and removed entirely on account deletion
- Photos you upload are stored until you delete them. After account deletion, photos are retained as anonymous community content with no link to your account; freetext captions are removed
- Reviews you write are similarly anonymized after account deletion (rating and dish kept; freetext title and body removed) under the content license in our Terms §4
- Reports and in-app feedback you submit follow the same pattern: structured fields are kept for product-quality signals; freetext descriptions are removed and the row is detached from your account on deletion
- Restaurant submissions that are declined, withdrawn, or abandoned — together with any photos from them that were never published — are permanently deleted within 30 days. Approved submissions become part of the public restaurant catalog; the extracted menu items and published photos are retained as community content under the content license in our Terms §4
- Your taste profile and personalized recommendations are kept while the feature is on; turning it off, or deleting your account, removes them. Your setup-quiz answers and dietary selections are kept until you retake the quiz, change them, or delete your account — account deletion removes them permanently
- Data is hosted in the European Union
7. Your Rights (GDPR)
You have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten") — account deletion removes your account and personal data; community content you contributed (ratings, photos) is anonymized rather than deleted by default. See §8 for details and how to request full removal of specific items
- Restrict processing
- Data portability — receive your data in a structured format
- Object to processing based on legitimate interest
- Withdraw consent at any time (e.g., disable notifications, revoke location access, or turn off personalized recommendations in Profile)
- Object to profiling — personalized recommendations involve building a taste profile. You can decline it entirely (it is off by default) or turn it off later; no decision with legal or similarly significant effects is made about you automatically
To exercise any right, email contact@flavly.pl. We will respond within 30 days. Account-deletion requests are faster: they are completed within 7 days (see §8).
8. Account Deletion
When you request deletion, we permanently remove your profile, search history, saved dishes and lists, taste profile, quiz answers, dietary selections, notification preferences, and push tokens.
Reviews you wrote and photos you uploaded will be retained as anonymous community content — disconnected from your account, with the freetext titles, bodies, and captions you wrote removed — under the content license in our Terms §4. The rating value, photo image, restaurant link, and dish link remain so other users continue to benefit. Reports and in-app feedback you submitted are handled the same way: structured fields kept for product quality, freetext descriptions removed. Restaurant submissions follow the same pattern: pending or declined submissions and their unpublished photos are permanently deleted, while restaurants and menu items already published from an approved submission remain in the catalog, disconnected from your account.
You can delete your account directly in the app: Profile → Delete account. Deletion is carried out immediately. Alternatively, email contact@flavly.pl with the subject Account deletion, sent from the address registered with the account — emailed requests are completed within 7 days.
If you also want specific reviews or photos removed entirely (rather than anonymized), list them in your deletion email and we will remove those items in addition to anonymizing the rest.
9. Cookies and Local Storage
The web version of Flavly uses browser local storage (not cookies) to store:
- Your authentication session
- Saved dishes and local ratings
- Language preference and font preference
- Cached location (refreshed periodically)
- Cached restaurant, photo, and rating data plus local app-usage counters (so screens paint instantly)
- Which in-app announcements you have already seen (so a welcome message or tour is not shown twice), and the app version first seen on this device
- Interface state such as your last-used tab and search-count for prompt timing
No third-party tracking cookies are used, and we embed no advertising or marketing analytics. Fonts are served from our own domain — no third-party font service is used. Some content still loads from the third-party services described in §5 (map tiles, illustrative images, your sign-in provider's profile picture), and the only third-party telemetry is the error monitoring described in §5.
10. Children
Flavly is not directed at children under 16. We do not knowingly collect data from children under 16, and personalized recommendations (§3a) are not intended for them either. If you believe a child has created an account, contact us and we will remove it.
11. Changes to This Policy
We may update this policy. Significant changes will be communicated via the app. The "effective date" at the top reflects the latest revision.
12. Contact
For any privacy-related questions:
Email: contact@flavly.pl
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Polish Data Protection Authority (UODO): uodo.gov.pl