RestaurantApp is a personal food diary. This page explains what data is kept, where and why, in the same order you'd ask about it.
Without an account, your diary never leaves your phone. The app works fully in local mode: the diary lives in a database on the device itself and the photos in its storage. If you never sign in, nothing you write is sent to any server.
The only thing that leaves the phone, with or without an account, is what the map needs in order to work: see The map and place search.
Who is responsible
The data controller is Mateo Álvarez, who develops and publishes RestaurantApp as an individual. Contact: maty892010@gmail.com.
What data is processed
If you use the app without an account
The restaurants, dishes, visits, notes, tags and photos you enter are stored only on your device and are not transmitted. If you uninstall the app without making a backup, that data is lost and cannot be recovered, because nobody else has it.
If you have your phone's own system backups turned on (iCloud on iPhone, Google backup on Android), your phone may include the app's data in them. That is handled by your system account, under its own terms; RestaurantApp has no access to those backups.
The map and place search
The map and the restaurant search run on Google Maps Platform, whether or not you have an account. To make them work, your phone sends the following directly to Google:
- the map's own requests as you move or zoom it, like any app with a Google map;
- the text you type when searching for a place, and the coordinates of the area you're searching in —the map's, or your location if you ask for it— so results are nearby;
- the coordinates of a point you tap on the map, to turn them into an address;
- your location when you open quick log, to find the places to eat right next to you;
- the request for a place's photos, if you choose to use one of them.
As with any connection, Google also receives your IP address and technical information about the device. It never receives your diary: not your notes, your ratings or your photos. What Google does with those requests is governed by Google's privacy policy. The legal basis is providing the service you request when you use the map; if you don't use it, none of this is sent.
If you create an account
| Data | What for | Legal basis (GDPR) |
|---|---|---|
| Email address | Identifying the account, signing in and recovering access | Performance of a contract |
| Google name and profile picture, if you sign in with Google | Filling in your initial profile | Performance of a contract |
| Username, display name, bio and avatar | Letting other people find and recognise you | Performance of a contract |
| Your diary: restaurants, dishes, visits, notes, ratings, tags, dates and prices | Syncing it across your devices and sharing what you mark as shared | Performance of a contract |
| Photos you add to your dishes and visits | The same: syncing them and showing them where you put them | Performance of a contract |
| A restaurant's coordinates, if you put it on the map | Drawing it on the map. It's the location of the place, not a record of where you are | Consent (system permission) |
| Friendships, requests, likes, comments and people tags | The social features | Performance of a contract |
| A restaurant's name and area, and the names of your tags, when you ask for tag suggestions | Ranking your own tags by how well they fit that place. Processed on the spot and not stored | Performance of a contract |
| A small copy of a dish photo, the names of your tags and of the dishes you already have at that place, when you use quick log | Suggesting the dish's name, which of your tags fit it and whether it is one you ordered there before. Processed on the spot and not stored; the photo in your diary is a separate copy, yours | Performance of a contract |
| Device notification token (push token) | Sending you the app's notifications | Consent (system permission) |
| Blocks and reports you submit | Handling moderation and keeping a record that it was handled | Legitimate interest in keeping the service safe |
What is requested from Google if you sign in with Google
Only basic profile data: your email address, your name and your profile picture, and only to create your account or recognise you when you sign back in. No access is requested to your contacts, Drive, calendar, Google Photos or any other Google service, and that data is not shared with anyone or used for anything else. Signing in with Google is optional: you can create an account with an email and password, or not create one at all.
What is NOT done
- There is no advertising, no advertising IDs and no ad networks.
- There is no behavioural analytics and no cross-app tracking.
- Data is not sold or handed over to third parties for commercial purposes.
- Your diary is not used to train artificial intelligence models. Tag and dish suggestions use already trained models that only suggest: a name you can change, and tags you already have.
- Your location is not recorded in the background. The location permission is used only while the app is open, to centre the map, place a restaurant or suggest where you are in quick log.
Who sees what you write
Every diary entry has a visibility setting, and it is private by default:
- Private: only you, on your devices.
- Friends: the people whose friend request you've accepted.
- Public: anyone with an account who reaches that entry.
Also, if you tag someone in a visit, that person can see that visit even if it's private — because they were there. They can remove the tag whenever they like, and doing so removes their access.
Comments and likes on an entry are visible to whoever can see that entry. If you comment on someone else's entry, your comment is visible to whoever can see it, according to what they chose.
Sharing as an image creates the image on your own phone: it never goes through any RestaurantApp server. You decide who you send it to and how, and from then on it's subject to the terms of the app you use to send it.
Where it is stored and who processes it
| Provider | What it does | When |
|---|---|---|
| Google (Maps Platform) | The map, place search, addresses and place photos | When you use the map, with or without an account |
| Supabase (database and authentication) | Account, profile, synced diary, friendships, comments and notifications | With an account |
| Cloudflare (Workers, Workers AI, Pages and R2) | Photos, the server the app talks to, tag and dish suggestions, and this website | With an account (the website, always) |
| Google (Firebase Cloud Messaging), Apple (APNs) and Expo | Delivering push notifications to the device | With an account and the permission granted |
| Google (sign-in) | Verifying your identity when you sign in | Only if you choose to sign in with Google |
These providers act as data processors, except Google Maps Platform, which handles map requests under its own terms. Some operate servers outside the European Economic Area; in that case transfers rely on the European Commission's standard contractual clauses or the EU-U.S. Data Privacy Framework, as each provider publishes.
This website uses no cookies, no analytics and no third-party fonts or scripts. If you pick a palette or theme on the home page, it's saved in your own browser and never leaves it.
How long
For as long as the account exists. When you delete it, everything attached to it —profile, synced diary, photos, friendships, likes, comments, notifications and notification tokens— is removed immediately, with no recovery copy. The only thing that survives is reports other people may have filed, without your identifier, because they are the record that they were handled.
The diary on your phone itself is not deleted when you delete your account: it's yours and stays there. To remove it, uninstall the app.
Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction and portability:
- Access and portability: Settings → Backups creates a file with your whole diary and its photos.
- Rectification: in the app itself, by editing whatever you like.
- Erasure: Settings → Account → Delete my account, or the request page if you no longer have the app installed.
- For anything else, write to maty892010@gmail.com.
If you believe your data is not being handled correctly, you can complain to the Spanish Data Protection Agency (aepd.es) or to the data protection authority in your country.
Children
The app is not intended for children under 14, and no data is knowingly collected from people of that age. If you come across such an account, write to us and it will be removed.
Changes
If this policy changes substantially, the date above will reflect it and you'll be notified in the app before the change affects data already collected.
This is a translation of the Spanish original. If the two ever differ, the Spanish version prevails.