Skip to content
FoodThoughts
Sign in
Back

Privacy Policy

Last updated June 2026

Effective date: 24/06/2026

FoodThoughts is a private, invite-only app designed for small groups of friends to share restaurant reviews, save places they like, and organise social plans.

This Privacy Policy explains what personal data FoodThoughts collects, how it is used, who can see it, and what rights users have in relation to their data.

FoodThoughts only collects the data needed to run the app and provide its core features. It does not sell personal data, use advertising cookies, or use personal data for advertising.

Data Controller

FoodThoughts is operated by its owner as a private, non-commercial service.

For the purposes of data protection law, including the GDPR, the operator of FoodThoughts acts as the data controller.

For privacy questions or to exercise your data protection rights, contact:

[email protected]

What Data Is Collected

FoodThoughts collects only the data needed to provide and protect the service.

Account information
This includes your username, email address, and password. Passwords are stored securely in hashed form and are not stored in plain text.

Profile information
This may include your display name, avatar image, foodie rank, badges, and profile preferences.

User-generated content
This includes reviews, ratings, review headlines, favourites, tags, venue suggestions, uploaded photos, and other content you choose to add to the app.

Group and hangout data
This includes group memberships, hangout invites, availability selections, RSVPs, selected venues, scheduled dates and times, and related planning activity.

Notification and email preferences
This may include whether you have opted in to certain emails, such as digest emails, and whether you have enabled browser or device push notifications.

Technical data
This may include limited server logs, IP addresses, browser type, device information, timestamps, and security events. This data is used to keep the app secure, reliable, and working properly.

FoodThoughts does not ask users to provide sensitive personal data. Users should avoid adding sensitive personal information in reviews, comments, photos, profile details, or other content they upload.

How Data Is Used

FoodThoughts uses personal data for the following purposes:

To create and manage user accounts.

To allow users to log in securely.

To display profiles, reviews, ratings, favourites, photos, and other content inside the app.

To support group features, including hangouts, availability sharing, RSVPs, invitations, and event planning.

To send essential service emails, such as account invites, password resets, hangout invites, review requests, and account-related messages.

To send optional notifications or digest emails where the user has enabled them.

To improve security, prevent abuse, fix errors, and maintain the performance of the app.

FoodThoughts does not send marketing emails and does not use personal data for advertising.

Lawful Bases for Processing

FoodThoughts processes personal data under the following lawful bases:

Performance of a contract
This applies where the data is needed to provide the app, manage accounts, display content, and enable group and hangout features.

Legitimate interests
This applies where data is needed to maintain security, prevent abuse, investigate issues, keep the service reliable, and protect the app and its users.

Consent
This may apply where users choose to enable optional features, such as browser push notifications or optional email preferences. Users can disable these features at any time.

Who Can See Your Data

FoodThoughts is a private app, but some information is visible to other signed-in members depending on how the app is used.

Visible to other signed-in members
Your username, display name, avatar, foodie rank, badges, reviews, ratings, favourites, and uploaded restaurant photos may be visible to other signed-in members.

Visible to relevant group or hangout members
Your group membership, hangout participation, availability selections, RSVP status, and related planning activity may be visible to members of the relevant group or hangout.

Not publicly visible
Your email address is not shown publicly inside the app.

Admin access
The app owner or authorised administrators may access account, content, and technical data where needed to operate the app, fix problems, handle reports, maintain security, or respond to privacy requests.

Sharing With Service Providers

FoodThoughts does not sell, rent, or share personal data with advertisers.

Some data may be processed by limited service providers where needed to operate the app.

These include:

Resend
Used to send transactional emails, such as invites, password resets, reminders, and review requests.

Cloudflare
Used for security, traffic routing, caching, and protection against abuse.

Google Places
Used to enrich restaurant and venue information. Personal user data is not intentionally shared with Google Places for this purpose.

FoodThoughts may also use server hosting, storage, backup, or email infrastructure needed to keep the app running securely.

International Transfers

Some service providers may process data outside Cyprus or outside the European Economic Area.

Where this happens, FoodThoughts relies on the safeguards provided by those service providers, such as appropriate contractual protections or recognised transfer mechanisms.

Photos and Uploaded Content

Users may upload photos as part of reviews or restaurant content.

Uploaded images may be processed by FoodThoughts to resize, compress, and convert them for display in the app. This process may remove metadata such as EXIF data, including location metadata, where present.

Users should only upload photos they are comfortable sharing with other members of the app. Users should avoid uploading photos that include private, sensitive, or unnecessary personal information.

FoodThoughts may hide or remove content if needed for safety, privacy, moderation, or security reasons.

Cookies and Local Storage

FoodThoughts uses only essential cookies and basic local preferences.

These may include:

A session cookie to keep users signed in.

A preference cookie or local setting, such as light or dark mode.

Technical storage needed for app functionality.

FoodThoughts does not use advertising cookies, tracking cookies, or third-party analytics cookies.

Storage and Retention

FoodThoughts stores data on access-controlled infrastructure.

Account data and user-generated content are kept for as long as the account remains active or as long as needed to provide the service.

Server logs are kept only for a short period for security, troubleshooting, and system integrity, unless they need to be retained for longer to investigate abuse, security issues, or legal matters.

Backups are kept on a limited rolling basis and are automatically overwritten.

If an account is deleted, personal data linked to that account will be removed or anonymised within a reasonable timeframe, unless limited retention is needed for security, technical, or legal reasons.

Some content may remain temporarily in backups until those backups are overwritten.

User Rights

Under the GDPR, users have rights over their personal data.

These rights may include the right to:

Access the personal data held about them.

Correct inaccurate or incomplete data.

Request deletion of their data.

Request restriction of processing.

Object to certain processing based on legitimate interests.

Receive a copy of their data in a portable format.

Withdraw consent where processing is based on consent.

Lodge a complaint with their local data protection authority.

Requests can be made by contacting:

[email protected]

FoodThoughts will respond within a reasonable timeframe and in line with applicable data protection law.

Account Deletion

Users may request deletion of their account by contacting the privacy email address.

When an account is deleted, FoodThoughts will remove or anonymise personal account data where possible.

Some shared group or hangout history may need to remain in a limited form so that other users’ records still make sense, but the deleted user’s personal identity will be removed or anonymised where reasonably possible.

Security

FoodThoughts uses reasonable technical and organisational measures to protect personal data.

These include password hashing, access controls, HTTPS, limited admin access, and security protections provided by the platform and service providers.

No online service can be guaranteed to be completely secure, but FoodThoughts aims to keep data collection limited and protect the data it does hold.

Children

FoodThoughts is intended for use by invited users only. It is not aimed at children and should not be used by children without appropriate permission from a parent or guardian.

Changes to This Policy

This Privacy Policy may be updated from time to time.

If material changes are made, the effective date at the top of this page will be updated. Where appropriate, users may also be notified inside the app or by email.

Material changes may include changes such as opening self-registration, adding analytics, changing service providers, adding new public profile features, or introducing monetisation features.

Continued use of FoodThoughts after an updated Privacy Policy is published means the updated version applies.

See also our Terms of Use.