What we collect
When you create an account: your email address, a password (we never store it in readable form — see Security below), and optionally your phone number and home city. If you use "Enable location" during onboarding or when posting, your device's coordinates are sent to our server for that single request only, to find restaurants near you — we do not store your precise location.
When you use EatRate: the photos, ratings, captions, and dish names you post; an optional second "reaction" photo of yourself, which you can skip or remove at any time; estimated or self-reported nutrition information for what you post; who you add as a friend; which posts you cheer or report; and basic usage timestamps (like when you last posted, used to enforce posting limits).
How we use it
- To create and secure your account, and to show your name/photo on posts you share — visible to your friends and to other EatRate users browsing that restaurant's page or the nearby feed, not only your friends.
- To find restaurants near you when you search or post — your coordinates are used in that moment and discarded, not saved to your profile.
- To estimate calories and nutrition for what you post — see "Who we share it with" below for what that involves.
- To run the points/rewards program: tracking your reviews at designated points-partner restaurants so we know when you've earned enough points for a gift card.
- To prevent abuse — for example, rate-limiting how often you can post or attempt to log in.
- To contact you about your account if you gave us a phone number (optional, and only for that purpose).
Who we share it with
We do not sell your personal data. A few things happen server-side that are worth being specific about:
- Restaurant data: when you search nearby, we query Google Places, Yelp, and/or OpenStreetMap to find real restaurants. We send them a location, not your identity or account data.
- Nutrition estimation: if you don't name a dish specifically enough for us to match it to a known menu item, we may send your food photo (never your reaction photo) to an AI vision provider to estimate calories and macros, and may send the dish name to USDA's public nutrition database. Neither of these receives your name, email, or account details.
- Business insights: if a restaurant owner claims their listing, we may generate a short AI-written summary of aggregate review trends (average rating, common themes) using an AI provider. We send restaurant-level review data for this — not your name, email, or account details. The restaurant's own analytics dashboard does show them the same reviews (with your name and rating) that are already visible to any EatRate user browsing their page — nothing private is newly exposed to them by having a dashboard.
- Menu scanning: if a restaurant owner photographs their menu to list it, that photo is sent to the same AI vision provider to read the item names, prices, and categories. This only applies to a business owner's own menu photo, not to anything a diner posts.
- Reports: if you report a post, that reason may be emailed to our moderation inbox so a human can review it.
Security
Passwords are hashed with PBKDF2-SHA256 (200,000 iterations) and a unique random salt per account — we cannot look up or recover your actual password, even internally. Sessions use cryptographically random tokens stored in an HttpOnly cookie, which JavaScript can't read. All traffic is served over HTTPS.
Your choices
- You can delete any post you've made at any time from your profile or the feed. Your reaction photo specifically can also be removed on its own, without deleting the rest of the post.
- You can edit your name, username, home city, and profile photo at any time.
- You can request a copy of your data or deletion of your account by emailing us (below) — see also our in-app data export/delete tools if available on your version of the app.
Children's privacy
EatRate is not directed at children under 13, and we don't knowingly collect data from anyone under 13.
Changes
If this policy changes in a material way, we'll update the date at the top of this page. Continued use of EatRate after a change means you accept the update.
Contact
Questions about this policy or your data: aymanveerani@gmail.com