Privacy Policy
Last updated
1. Summary¶
This summary is provided for convenience and does not form part of this policy. EatWhat may be used without an account. Photographs taken in the application remain on your device unless cloud backup is enabled. Personal data is processed in order to suggest restaurants and to maintain your food diary. Personal data is not sold, rented or used for advertising.
2. Personal data we collect¶
We collect the following categories of personal data, and no others:
- Account identifiers — a Hong Kong mobile telephone number, verified by one-time code. No password, email address or third-party social account is used. A display name is optional and is disclosed only to persons with whom you split a bill.
- Food diary entries — dish names, restaurant, price, payment method, three ratings, notes and reviews, district and nearest MTR station, and the time of the meal.
- Photographs and receipt images — held on your device by default; see clause 4.
- Location data — a foreground position fix obtained with your permission, or a district you select yourself.
- Bill-splitting data — bill and item descriptions, amounts, the allocation between participants, and settlement records. For participants who hold no EatWhat account we store a name and a cryptographic hash of a telephone number, and not the number itself.
- Submitted social-media content — where you send a post to us by direct message, the message identifier, your Instagram account identifier, the post address and any text you include.
- Waitlist data — the email address and language preference submitted on this website. No IP address and no browser information is recorded with it.
- Usage data — as described in clause 6.
3. Purposes of use¶
Personal data is used to rank restaurants by reference to your location, the time of day and your previous entries; to maintain your diary, spending totals and insights; to calculate bill splits; to identify restaurants in content you submit; to measure use of features by means of counts rather than the content of anything you have written; and to apply usage limits and prevent abuse. Data you elect to share is disclosed to the recipients you choose: a diary entry marked visible to friends is readable by your accepted friends, and a bill link is readable by any person who holds it.
4. Photographs and receipt images¶
Each photograph is re-encoded as a JPEG, which removes EXIF metadata including GPS coordinates and device model, and is stored in the application's documents directory rather than in a system cache. Cloud backup is a paid feature. Where it is enabled, the copy held on your device is not deleted: the cloud copy is a backup and not a substitute. Backups are held in a private storage bucket under a path bound to your account identifier, and local file paths are never transmitted.
5. Location data¶
Location is requested only while the application is in the foreground; background location is not collected. When you request a suggestion, your position, or the centre of the district you selected, is transmitted with that request in order to identify nearby restaurants, and it is not recorded in any database table. Where local data is insufficient and a Google Places search is performed, Google receives a search coordinate and radius and no identifier relating to you. Diary entries record district and MTR station only, and never coordinates. Weather data is requested by your device directly from the Hong Kong Observatory, which accordingly receives your device IP address.
6. Usage data and analytics¶
We use PostHog to measure use of the application and of this website. Events carry counts, flags and enumerated values — whether an entry has a note, not its text; whether a position was obtained, not the position — and coordinates are excluded from analytics, which is verified automatically on every change to the source. Screen recording in the application masks all text inputs and all images and captures no console or network content. This website is not recorded. The website sets one first-party PostHog cookie containing an anonymous identifier. No consent banner is presented, and the website functions if that cookie or the analytics request is blocked.
7. Automated processing of submitted content¶
Where you submit a social-media post to us by direct message, we retrieve the post on our server. Where the post contains a video, we download that video temporarily, reduce its resolution, and transmit the video in full, including its audio track, for up to three minutes of its duration; where the post contains still images, we transmit one image for each. In either case the media is transmitted together with the public description of the post, and any text you send with it, to the model google/gemini-3.7-flash through the Vercel AI Gateway, which routes the request to Google, for the purpose of identifying restaurant, address and dish names. No account data is transmitted with the request. The downloaded video, the reduced copy and any sampled image are deleted as part of the same operation and cannot be retained. We retain the address of the post, its public description, the restaurants, addresses and dishes identified, and the token counts. The model provider carries out processing that we do not control; content you would not wish a third party to process should not be submitted. We do not read the comments on a post. No cloud model is used for receipt recognition, and receipt images remain on your device.
8. Service providers and transfer outside Hong Kong¶
Personal data is held principally by Supabase and is handled in accordance with the Personal Data (Privacy) Ordinance (Cap. 486). Each provider below is engaged to perform part of the service and may process personal data only for that purpose. All are located outside Hong Kong, and personal data may accordingly be stored or processed outside Hong Kong. The providers engaged are:
- Supabase
- Vercel
- PostHog
- Resend
- Twilio
- Instagram (Meta)
- Zernio
- OpenRouter
- Google (Gemini)
- Google Places
- Hong Kong Observatory
- Expo
- Apple App Store
- Google Play
9. Retention¶
Retention differs by category:
- Diary entries and bills — until deleted by you, or until your account is deleted.
- Retrieved media and sampled frames — deleted on completion of the processing described in clause 7, without exception.
- Google Places content — thirty days, after which it is withheld at the point of reading.
- Waitlist data — until you ask us to remove it, by reply to the confirmation message or in writing to privacy@eatwhat.land.
- Restaurant records derived from submitted content — retained, as they form part of the restaurant database and cease to relate to you.
- Settlement records — the bill ledger is append-only. Following deletion of your account, settlements you recorded against another person's bill are retained without your name.
10. Security¶
Access to each table is restricted by row-level security, so that a user may read only their own records; the photograph bucket is private and access is bound to the account identifier; session credentials are held in the operating system keychain or keystore and not in the application database; and all transmission is over HTTPS. No system can be guaranteed secure and no such guarantee is given. In the event of a breach affecting personal data we will act in accordance with the Ordinance and notify affected users where appropriate.
11. Your rights, and how to contact us¶
You are entitled to request access to, correction of, and erasure of your personal data. Account deletion is available in the application under Me, and removes cloud photographs and the records held on the device as well; step-by-step instructions, and a list of what deletion does and does not cover, are published at eatwhat.land/delete-account. A request for a copy of your data, or for access to or correction of it, should be sent to privacy@eatwhat.land, as may any other question concerning privacy. A complaint may be made to the Office of the Privacy Commissioner for Personal Data.