Back to home

Privacy Policy

Last updated: 22 September 2026

1. Introduction

Crumbify ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our mobile application ("the App") and website at crumbify.co.uk ("the Site"). Crumbify is operated by Crumbify LTD, a company registered in England and Wales (company number 17288992), registered office 60 Millmead Business Centre, Millmead Road, London, United Kingdom, N17 9QU. Crumbify LTD is the data controller for personal data processed through the Crumbify app and this website.

2. Information We Collect

When you use Crumbify, we may collect:

  • Account information: Name, email address, and username when you create an account via Apple Sign In, Google Sign In, or email OTP, plus a profile photo if you choose to upload one. Signing in with Apple or Google shares your name and email address with us so we can create your account; it does not give us access to anything else in your Apple or Google account.
  • Restaurants you add: When you share a TikTok or Instagram post into Crumbify, paste in a Google Maps list link, or search and add a place manually, we resolve the shared link to a restaurant and store that restaurant, your been-to and want-to-try status, and any score or note you attach. For a TikTok share, we read the caption via TikTok's public oEmbed service, and TikTok photo posts may be fetched from TikTok's embed pages; if a caption does not identify a place, the post's images are run through Google Vision text detection instead. For an Instagram share, the caption is extracted by our processor, Supadata. We store only the source (TikTok, Instagram, or Google Maps), the link you shared, the resolved restaurant, and the import status; we never store the caption text or the text read from an image. Crumbify does not connect to delivery-platform accounts or APIs, and it does not read your order history from screenshots.
  • Reviews and private notes: Scores out of 10 and personal notes you write about places you have been to.
  • Profile photo: If you upload an avatar, it is resized and re-encoded before upload and normally scanned by Google Vision SafeSearch to detect inappropriate content before being stored (see Content Moderation below).
  • Posts and photos: When you post about a place to your profile wall or the Home feed, with an optional photo, we store it and normally run automated safety screening (Google Vision SafeSearch) before it is shown to others (see Content Moderation below). You can also choose, post by post, to share it to the public Trending tab as well.
  • Social activity: Reactions and comments on posts, friend connections and requests, groups you create or join and their shared lists, photos, comments, and reactions, and leaderboard participation.
  • Contacts you choose to match: If you use the optional find-friends step, and only with your permission, we read the phone numbers and email addresses in your device contacts; we never read names or photos. Each value is converted to a one-way SHA-256 hash on your device before anything leaves it, and only those hashes (up to 2000 at a time) are uploaded to check for matching Crumbify accounts, up to 200 matches are returned, and blocked users are excluded. A hash of your own sign-up email is stored the same way so other people can find you. This step is optional and can be skipped, and the hashes are kept only while your account exists.
  • Location: With your permission, we read your approximate device location in the foreground to power the Discover map and to search nearby places via Google Places. Your coordinates are sent to our servers only to run that search and are not stored there, and the last location fix is cached on your device for up to 7 days. Location permission is optional and is only ever requested once, during onboarding.
  • Advertising identifiers: We show ads via Google AdMob and, with your consent, use your device advertising identifier to personalise them. You can decline via the in-app consent prompt and, on iOS, the App Tracking Transparency prompt.
  • Usage analytics: Device and usage analytics about screens visited and features used in the App, collected via PostHog against a pseudonymous account ID only (no names, emails, or review content), and EU-hosted. The website separately collects anonymous performance metrics via Vercel Speed Insights.
  • Push notifications: If you enable notifications, we store a push token on your profile so we can deliver them. Notifications can include first-party content such as a friend's display name, a group name, or a place name. Turning notifications off removes the stored token.
  • Founding-member checkout: If you buy a founding-member place through the website, Stripe processes the payment and we store your email address to grant the tier to your account. We never see or store your card details.
  • Referral link visits: See section 9 below.

3. What We Do NOT Collect

  • We never access, store, or see your delivery-platform or other third-party account passwords.
  • We do not connect to delivery-platform accounts or APIs, and we do not read order history from screenshots. Places are added by sharing a TikTok or Instagram post into the app, pasting a Google Maps list link, or manual search.
  • We never upload your contacts' names, photos, or readable phone numbers or email addresses; contact matching uses one-way hashes computed on your phone.
  • We never share your personal data with third parties for their own marketing purposes.
  • We do not sell your data to advertisers or data brokers.
  • We do not track or display what you spend on food - Crumbify's stats are counts and percentages only. (Subscription pricing is shown at purchase, as any store requires.)

4. How We Use Your Information

  • Run the Home feed: showing friends' posts, reactions, comments, and leaderboards, plus the public Trending tab for posts you choose to share there.
  • Power Discover: the map, nearby places, and taste-matched recommendations.
  • Maintain your Reviews history: been-to places, want-to-try lists, scores, and private notes.
  • Enable Social features: friends, groups, shared lists, and shared photos.
  • Run your Profile wall: posts, achievements, and tiers, and the monthly Challenge.
  • Moderate uploaded content (avatars, post photos) for safety.
  • Process reports submitted by users about inappropriate content or behaviour.
  • Show ads to free-tier users via Google AdMob, personalised only if you consent (see the Advertising section).
  • Grant and manage Crumbify Premium and founding-member access.
  • Measure referral-link effectiveness (see section 9).
  • Improve and maintain the App and Site.

5. Data Storage and Security

Cloud data is stored with our cloud database provider, using row-level security (RLS) policies that enforce per-user data isolation. All API communication uses HTTPS with TLS.

  • Auth tokens are stored on-device only using secure storage.
  • Passwords are never stored - authentication uses Apple/Google Sign In or email OTP.
  • Every photo you upload (avatars, post photos, group photos, review photos, collection covers) is resized and re-encoded before upload, which removes embedded photo metadata such as location tags.
  • Avatars and feed-post photos are stored at public links, meaning anyone with the link can view the image. Group photos and private review photos are private and served through short-lived signed links. Collection covers are stored privately and shown according to the collection's visibility.
  • Avatar and post-photo moderation logs are automatically deleted after 30 days.
  • Account deletion removes your cloud data as described on our delete-account page.

6. Third-Party Services

  • Supabase: Provides the database, authentication, and storage for the App and website.
  • Google Places: Used to search for and fetch restaurant details (photos, ratings, addresses) when you add a place or use Discover.
  • Google Vision API: SafeSearch moderation for uploaded avatar images and post photos, and text detection used as a fallback over a shared TikTok post's thumbnail or slide images when its caption does not identify a place. Instagram posts are never sent to Google Vision.
  • TikTok: When you share a TikTok post into Crumbify, we read the caption via TikTok's public oEmbed service, and photo posts may be fetched from TikTok's embed pages, solely to resolve the place you shared.
  • Supadata: A third-party processor we use to extract the caption from an Instagram post you share, solely to resolve the place you shared.
  • Resend: Sends our transactional emails: sign-in codes, founding-member verification codes, and trial-ending reminders. We do not send marketing email, other than the single launch notification waitlist members signed up for.
  • Expo: Delivers push notifications using the token stored on your profile while notifications are enabled.
  • PostHog: Product analytics, EU-hosted, keyed to a pseudonymous account ID only, never your name, email, or review content.
  • RevenueCat: Manages Crumbify Premium subscriptions. Receives an anonymous account ID only, never your email, name, or advertising identifiers.
  • Google AdMob: Displays ads to free-tier users. Shows the Google consent (UMP) prompt and, on iOS, the App Tracking Transparency prompt; ads are non-personalised unless both consents are given, and you can decline and still use the App. Premium users see no Google ads.
  • Stripe: Processes founding-member payments on the website only. We never see or store your card details.
  • Sentry: Error monitoring for the App and website, EU-hosted, to help us find and fix bugs. Configured to send no personal details, with automatic redaction of emails and tokens; the user reference attached is your account ID only. Sentry session replay records a masked visual replay of the screens, taps, and navigation in your session. It records every session in which an error occurs and one in ten other sessions. All text, images, and vector graphics are masked on your device before the recording leaves it, so the replay never contains what you typed or looked at. We use replays to reproduce crashes and bugs. Sentry is EU-hosted and keeps replays for 90 days, then deletes them.
  • Vercel: Hosts the website and collects anonymous performance metrics via Speed Insights.

7. Social Features and Visibility

Crumbify includes social features with the following visibility controls:

  • You can set your profile to private, hiding your posts and reviews from non-friends.
  • Friend requests require mutual acceptance.
  • You can block or report any user. Blocked users cannot see your profile or send requests.
  • Group membership and shared group content are visible to other group members only.
  • A post you make goes to your Home feed by default, where friends see it in the Friends tab. You can choose, per post, to also share it to the public Trending tab, where it is visible to any signed-in Crumbify user.
  • You can unfriend, leave groups, or delete your account at any time.

8. Content Moderation

We run automated SafeSearch screening (Google Vision) on uploaded avatars and post photos and reject images it flags as adult, violent, or racy. Automated screening is not perfect and may occasionally be unavailable, so you can also report any content or user in the app; reports are reviewed and actioned. Moderation logs are retained for 30 days, then automatically deleted.

If we permanently ban an account for abuse, we keep one-way SHA-256 hashes of that account's email address and device identifier for as long as the ban stands, and a hash of the IP address used at the time of the ban for 30 days, so the same person cannot immediately re-register. The raw email address, device identifier and IP address are not stored for this purpose, and all of these hashes are deleted when a ban is lifted.

9. Referral Link Tracking

Some creators share tracking links in the form crumbify.co.uk/referral?code=CODE. When someone visits such a link, we record the referral code and the visitor's device platform (iOS, Android, or other), and store a salted SHA-256 hash of the visitor's IP address before redirecting them to the relevant app store. The raw IP address is never stored, only the hash, and only one record is kept per unique visitor per code. We use this solely to measure how many people a creator's link brings in, on the basis of our legitimate interest in measuring marketing effectiveness.

10. Cookies on This Site

The website at crumbify.co.uk uses one essential cookie: a login session cookie for the admin area, valid for one hour and never set for ordinary visitors. We also use cookieless Vercel Speed Insights for performance metrics and the salted IP hash described in section 9 for referral-link measurement. We do not use any advertising or tracking cookies on the website, and we do not send marketing email, other than the single launch notification waitlist members signed up for.

11. Advertising

Free-tier users see ads via Google AdMob: banners on the Home and Social tabs, native ads in the Discover scroll, and an occasional full-screen ad in the collections story viewer. We show the Google consent (UMP) prompt and, on iOS, the App Tracking Transparency prompt; ads are non-personalised unless you give both consents, and you can decline and still use the App. Crumbify Premium removes all Google ads.

Separately, clearly labelled "Sponsored" restaurant cards may appear in the App. These are not personalised; they are chosen by simple rotation from a campaign list rather than from your data, carry a gold "Sponsored" label, and involve no per-user tracking. They appear for everyone, about half as often for Crumbify Premium members.

12. GDPR and Your Rights

We rely on different legal bases depending on the processing: your contract with us to provide the App, your consent for optional features such as contacts matching, location, and personalised ads, and our legitimate interests for security, moderation, and measuring marketing effectiveness. Under GDPR and UK data protection law, you have the right to:

  • Access all data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion of your account and all associated data.
  • Object to processing of your data.
  • Withdraw consent for optional data collection at any time.
  • Request that we restrict processing of your data in certain circumstances.
  • Receive a copy of your data in a portable, machine-readable format (the in-app export described below).

You can withdraw contacts and location permissions at any time in your device settings, and change your advertising choices via the in-app privacy options and, on iOS, in Settings under Privacy and Security, Tracking.

To exercise any of these rights, use the in-app account settings, where you can request a JSON export of your data through the device share sheet (very large exports are truncated, with an email route for the full copy), or contact us at the email below. You also have the right to complain to the Information Commissioner's Office at ico.org.uk.

13. International Transfers

Sentry and PostHog are EU-hosted. Some of the providers listed in section 6, including Google, RevenueCat, Expo, Stripe, Supadata, and TikTok, may process data outside the UK. Where that happens, we rely on UK data protection safeguards for the transfer, such as adequacy regulations or standard contractual clauses and the UK International Data Transfer Addendum.

14. Data Retention

  • Account data is retained until you delete your account.
  • Import history (the shared link, the resolved place, and the status): while your account exists.
  • Hashed contact-matching identifiers: while your account exists.
  • Push notification token: while notifications are enabled, removed when you turn them off.
  • Notification history (a record of notifications we sent you): while your account exists.
  • Avatar and post-photo moderation logs: 30 days.
  • Ban records: hashed email address and device identifier for as long as the ban stands; hashed IP address for 30 days.
  • Pre-launch waitlist sign-up IP address and browser details: deleted 30 days after sign-up (the email itself is covered below).
  • Trial-ending reminder scheduling records: 30 days.
  • Founding-member emails: retained while the founding benefit exists, so the tier can be restored by verifying that email.
  • Pre-launch waitlist emails: kept until launch so we can send the launch notification you signed up for; contact us any time to be removed.
  • Referral-link records: kept as a salted IP hash (never reversible to an address) for up to 12 months from the click, then deleted.
  • Sentry session replays (masked): 90 days.
  • When you delete your account, your cloud data is removed as described on our delete-account page.

15. Children's Privacy

Crumbify is not intended for children under 16. We do not knowingly collect personal information from children under 16. If we discover that a child under 16 has provided us with personal information, we will delete it.

16. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes via in-app notification or email. Your continued use of the App after changes constitutes acceptance of the updated policy.

17. Contact Us

If you have questions about this Privacy Policy, or want to reach our data protection contact, email us at support@crumbify.co.uk.