Gustopicks — Privacy Policy

Gustopicks — Privacy Policy

Effective date: 2026-06-27 · Last updated: 2026-06-27 · Version 1.0

This Privacy Policy describes how personal data is collected, used, disclosed, and protected in connection with the Gustopicks mobile application for iOS (the "App"), the website at https://gustopicks.com (the "Site"), and related services (together, the "Service").

The party responsible for your personal data is "Gustopicks" ("we", "us", "our", or the "App"). You can reach us at [email protected].

Legal notice / disclaimer. This document is a comprehensive working draft prepared for review by qualified legal counsel before publication. It is not final legal advice. The whole document should be reviewed and approved by a lawyer (and reconciled with the current GDPR/UK GDPR/CCPA-CPRA/KVKK regulatory text and your App Store privacy "nutrition label") before it is relied upon or published.


Table of Contents

  1. Who We Are — Identity & Contact
  2. Scope of This Policy
  3. Personal Data We Collect (Categories, Sources)
  4. Why We Process Your Data — Purposes & Lawful Bases
  5. Recommendations & Profiling (Personalization Only)
  6. Who We Share Data With — Sub-Processors & Recipients
  7. International Data Transfers
  8. How Long We Keep Your Data — Retention
  9. How We Protect Your Data — Security Measures
  10. Your Rights (GDPR / UK GDPR) and How to Exercise Them
  11. Your Rights as a California Consumer (CCPA/CPRA)
  12. Children's Privacy
  13. Cookies, SDKs & Tracking Technologies
  14. Changes to This Policy
  15. How to Contact Us & Complaints
  16. Apple App Store-Specific Terms

1. Who We Are — Identity & Contact

1.1 Data Controller

Gustopicks is a social restaurant-ranking and trusted-discovery application. Restaurants are logged, compared through pairwise "duels", and turned into a personal ranking; users follow friends and curators, save and share places, and build a personal taste profile. Privacy is treated as a product principle: we do not sell your personal data, we do not run third-party advertising, we do not use third-party analytics or tracking SDKs, and we do not collect an advertising identifier (IDFA).

The party responsible for deciding why and how your personal data is processed is:

1.2 EEA / UK Representative

Where we have no establishment in the European Union or the United Kingdom and one is required under Article 27 GDPR / Article 27 UK GDPR, we may appoint a representative who can be contacted in addition to (not instead of) us:

1.3 Privacy Contact

Privacy queries are handled by Gustopicks at [email protected]. A Data Protection Officer ("DPO") is appointed only where legally required and is currently not appointed.


2. Scope of This Policy

This Policy applies to personal data we process when you:

This Policy does not cover the practices of Apple Inc. (e.g., the App Store, your Apple ID, Sign in with Apple, or your device operating system), which are governed by Apple's own privacy policy. It also does not cover third parties whose content or services may be referenced inside restaurant records (for example, map data); their handling of any data is governed by their own terms.

Because Gustopicks is a native mobile application and not primarily a website, references in this Policy to "the App" cover the iOS application; the Site is informational.


3. Personal Data We Collect (Categories, Sources)

We collect only the data we need to run the Service. "Personal data" means any information relating to an identified or identifiable individual. We do not collect data for cross-app tracking, advertising, or data-broker purposes. The table below lists each category we collect, examples, and the source of the data.

# Category Examples / contents Source
a Account & identity Account identifier; display name and username (you enter these yourself during profile setup); city/neighborhood preference; short bio; account type; profile visibility setting; verified-curator status and curator details (if applicable) Provided by you
b Email address Your email, used for account, authentication, and service communications. If you use Sign in with Apple, this may be an Apple private-relay address (a forwarding address Apple provides) Provided by you / from Sign in with Apple (email scope only)
c Authentication data Sign in with Apple identity token / authorization code; or email + password credentials; or an anonymous (guest) session identifier. An Apple refresh token is stored server-side (service-role access only) solely to revoke the Apple grant when you delete your account (see §6.2) Provided by you / from Apple
d Coarse (approximate) location Reduced-accuracy ("coarse") location, collected only when you enable it and only while you are using the App ("when in use"). Used to surface nearby trusted restaurants and to personalize discovery. We do not use precise location, background location, or "always" location Your device, with your permission
e Photos Profile avatar and communal restaurant photos you choose to upload via the system photo picker. Images are downscaled and compressed on your device before upload Provided by you
f User content (UGC) Restaurant visits/logs; pairwise "duel" comparisons; personal rankings and derived scores; lists and saved/"want-to-go" items; private and public notes; comments and reactions; reports you file. Each log carries a visibility you choose (private / friends-only / public). Some user content is also used to personalize recommendations Created by you
g Messages Content of 1:1 and group chats with friends — message text, sender, participants, and shared restaurant cards. Messages are private to the conversation participants, are friends-only, and are never surfaced in the feed or share cards Created by you
h Social-graph data Mutual friendships, curators you follow, and users you block Created by you
i Push notification token Your Apple Push Notification service (APNs) device token and notification preferences — collected only if you opt in to push notifications Your device, with your permission
j Technical / log data Minimal technical and infrastructure logs needed to run the Service securely (e.g., IP address, timestamps, and request metadata inherent to our backend hosting). Our application request logs record only the request method and path — never authentication headers, API keys, tokens, or message bodies Automatically / our infrastructure

Data we receive about you from others (GDPR Art. 14). Because Gustopicks is a social app, other users may create content that references you — for example, a friend may invite you to "go together", add you as a companion to a restaurant visit, send you a message, mention you in a list, or file a report. In those cases we obtain the relevant categories of personal data (such as your account identifier and the content created about you) from that other user. We process it for the same purposes and on the same lawful bases set out in §4, and the source is the other Gustopicks user.

Special-category data. We do not intentionally collect special-category / sensitive personal data (e.g., data revealing health, religious or philosophical beliefs, political opinions, racial or ethnic origin, sexual orientation, or biometric/genetic data — including the "özel nitelikli" categories under KVKK Art. 6). We ask you not to include such data in restaurant logs, notes, photos, or messages. Note that free-text restaurant content (for example dietary/allergen notes, or kosher/halal preferences) could by inference reveal sensitive information; please avoid posting it. Where any such data is nonetheless provided by you, we rely on your explicit consent (and you may delete it at any time).

No advertising or analytics SDKs. The App imports only Apple-native frameworks. There are no third-party advertising, analytics, attribution, crash-SDK, or tracking libraries. Our internal analytics is a debug-only console logger and a no-op in release builds; crash reporting is console-only with no external service.


4. Why We Process Your Data — Purposes & Lawful Bases

For every purpose we identify the lawful basis under Article 6(1) GDPR / UK GDPR. (Equivalent bases under Türkiye's KVKK are noted in brackets for users in Türkiye.) Where we rely on legitimate interests (Art. 6(1)(f)), we describe the specific interest pursued; you may object to that processing (see §10).

# Purpose Data used Lawful basis (GDPR Art. 6 / KVKK)
1 Create and operate your account; authenticate you Account & identity, email, authentication data Contract — Art. 6(1)(b) (necessary to provide the account you request) [KVKK 5/2-c]
2 Provide core features — restaurant logging, the duel/ranking engine, scores, lists, maps, want-to-go, feed User content, account & identity, photos Contract — Art. 6(1)(b) [KVKK 5/2-c]
3 Social features — friends, curator follows, comments, reactions, and friends-only messaging Social-graph data, user content, messages Contract — Art. 6(1)(b) [KVKK 5/2-c]
4 Nearby discovery using your location Coarse location Consent — Art. 6(1)(a) (you turn location on; you can revoke it any time) [KVKK 5/1 — açık rıza]
5 Personalized "For You" recommendations (see §5) User content, coarse location, ranking signals Legitimate interests — Art. 6(1)(f) (interest: providing a relevant, useful discovery experience), and, for the location signal, Consent — Art. 6(1)(a) [KVKK 5/2-f / 5/1]
6 Push notifications Push token, notification preferences Consent — Art. 6(1)(a) (opt-in; you can turn them off) [KVKK 5/1 — açık rıza]
7 Safety, moderation & content filtering — report/block records, proactive content filtering User content, social-graph data, reports Legitimate interests — Art. 6(1)(f) (interest: protecting users and keeping the community safe), and legal obligation where applicable — Art. 6(1)(c) [KVKK 5/2-f / 5/2-ç]
8 Security, fraud and abuse prevention, service integrity Technical/log data, authentication data Legitimate interests — Art. 6(1)(f) (interest: protecting the Service and our users from abuse) [KVKK 5/2-f]
9 Customer support & responding to your requests (including data-subject requests) Account & identity, email, relevant content Contract — Art. 6(1)(b) and legitimate interests — Art. 6(1)(f), and legal obligation — Art. 6(1)(c) for rights requests [KVKK 5/2-c / 5/2-f / 5/2-ç]
10 Legal compliance — tax/accounting records, responding to lawful requests, retaining moderation/abuse records As required Legal obligation — Art. 6(1)(c), and legitimate interests for establishing/defending legal claims — Art. 6(1)(f) [KVKK 5/2-ç / 5/2-e]
11 Account deletion and revoking the Apple sign-in grant Apple refresh token, account data Contract — Art. 6(1)(b) and legal obligation — Art. 6(1)(c) [KVKK 5/2-c / 5/2-ç]

Marketing. We do not currently send marketing or promotional messages and we do not use your data for advertising. If we ever introduce marketing communications, we will rely on your consent (Art. 6(1)(a)), obtain a separate opt-in (and, for users in Türkiye, register the consent with the İleti Yönetim Sistemi as required under Law No. 6563), and provide an easy opt-out in every message.

Providing data is, in part, necessary. Providing your email and basic account data is necessary to create an account and use the core Service; if you do not provide it you can use limited guest functionality only or cannot use the account-based features. Location, photos, and push notifications are entirely optional — declining them does not block the core Service.


5. Recommendations & Profiling (Personalization Only)

Gustopicks uses automated logic to organize and personalize your experience — for example, the duel-based ranking engine that turns your pairwise comparisons into a personal ranking and a derived 10-point score, the feed that surfaces relevant friend and curator activity, and "For You"/"Near you" discovery that may use your user content and (if enabled) your coarse location.

This is profiling for personalization only. It is not a solely-automated decision that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR / UK GDPR. These features rank and recommend restaurants; they do not make decisions about your rights, eligibility, credit, employment, or similar. We do not make any "AI recommendation accuracy" claims beyond what the features actually do, and scores are clearly labeled by context (for example, personal vs. circle vs. global score). You can influence personalization by adjusting your content and turning location off, and you have the right to object to legitimate-interests-based personalization (see §10).


6. Who We Share Data With — Sub-Processors & Recipients

We share personal data only with the limited set of service providers ("sub-processors") needed to run the Service, and with recipients where required by law. We require our processors to provide protection for your data that is equal to or greater than that required by this Policy and applicable law, and to process data only on our instructions.

6.1 Categories of recipients

6.2 Named sub-processors

Sub-processor Role Data involved
Supabase Backend platform — managed PostgreSQL database, authentication (GoTrue), object storage, and edge functions. Hosts and processes essentially all user data on our behalf All categories in §3
Apple Inc. Sign in with Apple (authentication / identity token); Apple Push Notification service (APNs) (delivery of opt-in push notifications using your device token); MapKit (maps and restaurant search) Authentication data, email (via Sign in with Apple), push token, coarse location for map/search

A current list of sub-processors is available on request at [email protected]. The Apple refresh token described in §3(c) is stored within our backend with service-role-only access and is used only to call Apple's token-revocation endpoint when you delete your account; on deletion the stored token row is removed.

6.3 We do not sell or "share" your data

We do not sell your personal data, and we do not "share" it for cross-context behavioral advertising (as those terms are defined under the CCPA/CPRA — see §11). We have no third-party advertising networks, no third-party analytics/tracking SDKs, no data brokers, and no payment processors integrated into the App.


7. International Data Transfers

Your personal data may be processed in, or transferred to, countries outside your home country, including outside the European Economic Area (EEA), the United Kingdom, and Türkiye — in particular by our hosting provider (Supabase) and by Apple. Our user data is hosted by Supabase (on AWS) in the region eu-central-2 (Zurich, Switzerland).

Where such transfers occur, we ensure an appropriate level of protection by relying on one or more of the following safeguards under Chapter V GDPR / UK GDPR:

For transfers from Türkiye, hosting in Switzerland (eu-central-2 / Zurich) is a cross-border transfer abroad (yurt dışı aktarım) governed by KVKK Art. 9 (as amended, in force 1 June 2024). Because no Board adequacy decision (yeterlilik kararı) covering this destination has yet been announced, the legal basis for the transfer is the data subject's explicit consent (açık rıza) or a standard contract approved by the Personal Data Protection Board (Kurul onaylı standart sözleşme) — and, where a standard contract is used, we make the required notification to the Personal Data Protection Authority within the prescribed period.

You may request a copy of the relevant safeguards by emailing [email protected]. The transfer destination and mechanisms are: data is hosted by Supabase in eu-central-2 (Zurich, Switzerland); for EEA/UK transfers the basis is the Switzerland adequacy decision (SCCs/UK IDTA used for any non-adequate onward transfer); for Türkiye transfers the basis is explicit consent or a Board-approved standard contract under KVKK Art. 9, pending any future Board adequacy decision.


8. How Long We Keep Your Data — Retention

We keep personal data only for as long as necessary for the purposes described in this Policy, and then delete, anonymize, or restrict it. As a general rule, your account data and content are retained while your account is active, and are deleted when you delete your account (see below). Where the purpose for processing no longer exists, we delete or anonymize the data.

Data category Retention Notes
Account, profile, user content, lists, rankings, messages, photos While the account is active; deleted on account deletion Server-side cascade deletion removes your personal data
Coarse location Used transiently for the relevant feature; not retained as a location history Not stored as a location history
Push token While push is enabled and the device is registered; removed on disable/deletion
Technical / security logs Retained for a short period (around 30 days) for security and abuse prevention, then deleted
Moderation / abuse records (reports) Retained for moderation history even after the reported user's deletion, where lawful Necessary to keep the community safe and meet App Store obligations
Records required by law (e.g., tax/accounting, legal claims) For the period required by applicable law (e.g., per Türkiye tax/commercial law and Law No. 5651 traffic/log requirements) Kept only as long as the legal obligation requires
Backups Personal data persists in encrypted backups for a limited rotation window (around 30 days) before being overwritten Backups are cycled and overwritten within a reasonable period

Account deletion. When you delete your account (Settings → Account → Delete account), we run an authoritative server-side cascade that deletes your messages, conversation memberships, reactions, comments, notifications, social invites, reports you triggered as a subject, list items and lists, feed events, relationships, rankings, duels, visits, invite codes, device/push tokens, privacy settings, your profile row, your stored avatar, and finally your authentication record (which in turn removes your Apple credentials and sign-in identities). Before deletion, we revoke the Sign in with Apple grant. Shared/communal restaurant catalog entries are not personal data and are not deleted; moderation records about a deleted user may be retained as noted above.

As a general rule, account data and content are retained while your account is active and removed on deletion; security and log records are kept for a short period (around 30 days); and encrypted backups are cycled and overwritten within a reasonable period (around 30 days). These periods may be adjusted where applicable law requires a longer retention term.


9. How We Protect Your Data — Security Measures

We implement technical and organizational measures appropriate to the risk, including:

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a personal-data breach is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, affected individuals, in line with applicable law (including GDPR Art. 33–34 and KVKK Art. 12).


10. Your Rights (GDPR / UK GDPR) and How to Exercise Them

If you are in the EEA or the UK (and, broadly equivalent rights apply under KVKK Art. 11 for users in Türkiye), you have the following rights regarding your personal data:

How to exercise your rights

Many rights can be exercised directly in the App:

You can also exercise any right — or ask questions — by emailing [email protected]. We will respond within one month of receiving your request (extendable by up to two further months for complex or numerous requests, with notice), in line with Art. 12(3) GDPR. For users in Türkiye, we respond to KVKK Art. 11 requests within 30 days, and you may submit requests in writing or by the methods specified under KVKK Art. 13. We may need to verify your identity before acting on a request.

Complaints. If you believe we have not handled your data properly, you can complain to your local data protection supervisory authority. For example:

We would, however, appreciate the chance to address your concerns first.


11. Your Rights as a California Consumer (CCPA/CPRA)

This section applies to California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"). It supplements the rest of this Policy.

11.1 Notice at collection

We collect the categories of personal information described in §3 for the purposes and from the sources described in §3 and §4. We do not sell personal information and do not share it for cross-context behavioral advertising. Retention is described in §8.

11.2 Categories of personal information collected (last 12 months)

Mapped to the statutory categories under Cal. Civ. Code §1798.140(v):

We do not intentionally collect "sensitive personal information" as defined by the CPRA; we ask you not to post it (see §3).

11.3 Your California rights

"Do Not Sell or Share My Personal Information." We do not sell your personal information and do not share it for cross-context behavioral advertising. Because we do not sell or share, we are not required to provide an opt-out link; if our practices ever change, we will add a "Do Not Sell or Share My Personal Information" / "Your Privacy Choices" mechanism and honor opt-out preference signals.

How to exercise CCPA rights. Use the in-app tools (account deletion, data export, profile correction) described in §10, or email [email protected]. We will confirm receipt within 10 business days and respond within 45 days (extendable by another 45 days with notice). We may need to verify your identity, and you may use an authorized agent (with proof of authorization). We do not offer financial incentives for personal information. For California minors, see §12.

California "Shine the Light" (Cal. Civ. Code §1798.83): we do not disclose personal information to third parties for their own direct-marketing purposes.


12. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect personal data from them. You must be at least 13 years old to use Gustopicks — and at least 16 years old (or the higher minimum digital-consent age set by your country in the EEA) where local law requires. For users in Türkiye, use by minors is subject to applicable parental-consent considerations under Turkish law.

If you are a parent or guardian and believe a child under the applicable minimum age has provided us personal data, contact [email protected] and we will delete it. For California residents, we do not knowingly sell or share the personal information of consumers under 16; should our practices ever change, we would obtain the opt-in consent the CCPA requires (and parental consent for under-13s, consistent with COPPA).


13. Cookies, SDKs & Tracking Technologies

Gustopicks is a native iOS application, not a website, and does not use third-party advertising, analytics, attribution, or tracking SDKs, and does not collect an advertising identifier (IDFA). We do not engage in "tracking" as defined by Apple's App Tracking Transparency framework, so we do not display the App Tracking Transparency prompt; our App Store privacy disclosures reflect this.

The only device-level identifiers we use are operational, not advertising-related:

Our informational Site may use only strictly necessary cookies required for it to function; it does not run advertising or third-party tracking cookies. If we ever introduce non-essential cookies, we will request consent where required.


14. Changes to This Policy

We may update this Policy from time to time — for example, to reflect changes in the Service, our sub-processors, or the law. When we make material changes, we will update the effective date at the top and notify you by appropriate means (for example, an in-app notice or message), and, where required, obtain your consent. We will keep the "last updated" date current and review this Policy at least annually. Your continued use of the Service after an update takes effect constitutes acceptance of the revised Policy, to the extent permitted by law.


15. How to Contact Us & Complaints

For any privacy question or to exercise your rights, contact:

No EEA, UK, or Türkiye (KVKK) representative and no DPO are currently appointed; privacy queries are handled directly at the email above.

You also have the right to complain to a supervisory authority as described in §10 (e.g., the ICO in the UK, your national EEA authority, or the KVKK in Türkiye).


16. Apple App Store-Specific Terms

The Gustopicks App is distributed through the Apple App Store and your use is also subject to Apple's applicable terms. The following App Store-related points are reflected in our practices and in our separate End User License Agreement / Terms of Service:


End of Privacy Policy. This is a working draft for legal review; obtain counsel's approval before publication.