Privacy Policy
Last updated: August 13, 2026
TopDishy ("we", "us") operates topdishy.com and the TopDishy mobile app. This policy explains what we collect, how we use it, and the controls you have. If you have questions, email [email protected].
1. Information We Collect
1a. Account information
- Email address and display name.
- Avatar and short bio, if you upload them.
- Sign-in identifiers from your chosen provider (Google, Apple, or Facebook), if you sign in that way. We store the provider name and the provider-issued user ID so we can recognize you on return visits. We do not receive your provider password.
- A password, if you create an account with an email address and password instead of using a provider. We store it only as a salted one-way hash, never in a form we or anyone else can read back, and we email you a verification link to confirm the address is yours.
- Preferred language.
- A record that you confirmed you meet our minimum age of 13. We ask for your date of birth once, when you first sign in, and use it only to work out whether you meet that age. We do not store the date. All we keep is the outcome of the check (that it was passed), which we keep for as long as the account exists.
1b. Content you create
- Reviews (notes, photos, optional receipt image, restaurant transaction ID).
- Personal stack rankings of dishes within a category.
- Critic feed posts, if you have a critic subscription.
- Bookmarks, follows, blocks, and content reports.
- Direct messages you send to other members.
1c. Location
We use location only to find dishes and restaurants near you and to order results by distance. When you ask for nearby results, we request your device's precise location (GPS-level coordinates) from your browser or operating system, and use it to determine your city and region. You can decline the location prompt and still use the app by setting a location manually. We cache your last coordinates or chosen area in your browser's local storage so the app remembers them, and we do not store a running history of your movements.
1d. Payments
Subscription payments are processed by Stripe (web), Apple (in-app purchases on iOS), or Google Play (in-app purchases on Android). We do not see or store your full card number. We receive a customer or transaction identifier and the resulting subscription state (active, past due, canceled, current period end) so we can grant access.
1e. Mobile push tokens and device identifiers
If you allow notifications on the mobile app, we register a push token with Expo so we can send you transactional notifications (e.g., a reply to your review). We store the token and platform (iOS or Android), together with a per-install device identifier (the Android app set ID known as SSAID, or the iOS identifier-for-vendor) whose only job is housekeeping: when your device issues a new push token, the identifier lets us find and delete the stale one so you don't receive duplicate notifications. This identifier is not used for advertising and is deleted with your account. Revoke notifications at any time in your device's settings.
Separately, the mobile app includes an install-measurement service (Singular) that uses your device's advertising identifier, the Android advertising ID or the iOS Advertising Identifier (IDFA), to tell us which ad, if any, led to your install. This one is used for advertising measurement; it is a different identifier from the housekeeping one above, it is controlled by your device settings, and on iOS it is only available if you allow tracking when the app asks. See Section 4 for what is shared and Section 7 for how to turn it off.
1f. Operational data
Our servers log routine request metadata (IP address, user agent, request ID, timestamps) for security, debugging, and abuse prevention. Errors are sent to Sentry with your user ID attached so we can correlate a problem with the account that hit it; on the web app Sentry may also capture a session replay (a reconstruction of what was on screen, with all typed text, input values, and images masked out) so we can reproduce the problem. Replays are recorded for every session in which an error occurs, and for a small random sample of ordinary sessions in which nothing goes wrong. Product events (sign up, sign in, review submitted, subscription started) are sent to PostHog so we can understand which features are used, and page-load and request timings are reported to New Relic so we can spot performance problems.
1g. Phone number (optional; friend finding)
If you choose to find friends by phone from the Find Friends screen, you can add a phone number to your account. We send a one-time verification code to it by SMS, then store the number only as a one-way cryptographic hash, never as plaintext, so we can verify it's yours, keep one account per number, and let friends who already have your number find you. You can turn off phone discoverability, or remove your number entirely, at any time in Settings. Adding a phone number is never required to use TopDishy and is never requested during sign-up or sign-in.
1h. Contacts (optional; on-device matching, not stored)
If you choose "Find friends from contacts," we read the phone numbers in your device's address book on your device and send them to our server for a single, one-time lookup to find which of them already have a TopDishy account. We do not save your contacts. The submitted numbers are used only for that match and are discarded immediately afterward. We do not keep the phone numbers of the people in your address book, and we do not build a social graph from them. On the mobile app this requires the operating-system contacts permission, which you can decline (you can still paste numbers manually). You can also send a friend a pre-filled invite text; the message opens in your own Messages app and is only sent if you send it.
2. How We Use Information
- To run the Service: authenticate you, show you nearby dishes, publish your reviews, and compute community rankings.
- To process subscriptions and in-app purchases.
- To send transactional messages (sign-in notices, replies, subscription receipts, account-change confirmations). We do not send marketing email.
- To moderate content and prevent abuse (see Section 5).
- To debug, secure, and improve the Service through error and product-event telemetry.
- To measure our own advertising (whether an ad led to a sign-up or an app install), as described in Sections 4 and 6. You can turn this off (Section 7).
3. The Ballot-Box Principle: Your Rankings Are Private
Your individual stack rankings are private by default. Other users, businesses, and our admin tools cannot see how you personally ranked a given dish. Only the aggregated community ranking is public. There are exactly two ways your individual ranking can become visible to someone else:
- You generate a share link for a category and send it to someone. You can revoke the link at any time.
- You hold an active critic subscription, in which case rankings you publish under your critic profile are public on-platform.
Reviews you write are public by default and attributed to your display name. Photos you attach to reviews are public. Bookmarks, follows, and your block list are private.
4. Third Parties We Share Data With
We do not sell your personal information for money. We do share a limited set of data for advertising measurement: with Reddit (on the web and in the app) and with Singular, the install-measurement service built into the mobile app, both described below. Under California law that counts as "sharing" for cross-context behavioral advertising, and you can turn it off at any time in Settings → Do Not Sell or Share My Personal Information (no account required). Apart from those two, everything below is a processor acting on our instructions so the Service can function:
- Google, Apple, Facebook: sign-in. We exchange tokens with whichever provider you chose at sign-up.
- Stripe: web subscription payments and billing.
- Apple App Store / Google Play: in-app subscription purchases on mobile.
- Amazon Web Services: hosting, database, and image storage (S3). Your photos are stored here.
- AWS Rekognition: automated image moderation. Every uploaded photo is scanned before it is stored.
- OpenAI: automated text moderation, dish-category classification, and the AI photo-edit tool. Review text, the text of every direct message (screened before it is delivered; see Section 5), dish names, and any photo you choose to run through the AI edit tool when composing a post are sent for these purposes; we do not send your email or other identifiers. OpenAI processes this content as our service provider, on our instructions.
- Google Maps Platform: geocoding and map tiles.
- Sentry: error tracking. Includes user ID and request metadata when an error occurs.
- PostHog: product analytics. Includes user ID and event metadata, plus a randomly generated analytics identifier kept in your browser's local storage so visits from the same browser or app install can be told apart.
- New Relic: web performance monitoring. The web app reports page-load and request timings with browser metadata, and New Relic sets its own cookies to group the measurements from one browsing session.
- Reddit: advertising measurement. When we run Reddit ads, a Reddit pixel on our web pages (including when those pages are displayed inside the TopDishy mobile app, which is how the app shows most screens) reports page-visit and sign-up events so we can measure whether the ads work; it may set its own cookie, governed by Reddit's privacy policy. Additionally, if you arrive from a Reddit ad and create an account, our servers report that sign-up to Reddit directly, including the ad-click identifier from the link you followed, your IP address and browser user-agent, and, where we have it, your email address. The email and IP are sent only as a SHA-256 hash rather than in the clear; a hash is not anonymous, it still identifies you to anyone holding the same address, and Reddit uses it to match the sign-up to an ad. This is used for advertising measurement only. We never send your name or your content. If you did not come from a Reddit ad, our servers report nothing about your sign-up to Reddit. Note that installs of the mobile app are measured separately, for every install, as described in the next entry.
- Singular: mobile install measurement (an "attribution" service), in the TopDishy app only. It is how we tell whether an ad led to an app install, which the ad platform cannot see by itself. When you install and open the app, Singular receives your device's advertising identifier (Android advertising ID, or the iOS IDFA where you have allowed tracking), your IP address, device and OS details, and the fact that an install, an app open, or an account creation happened. This happens for every install, not only installs that came from an ad. That is how the service can tell ad-driven installs apart from organic ones. Singular passes the result to the ad platform that we are measuring (currently Reddit), which means Reddit may learn that an install occurred and whether it was attributable to one of its ads. We do not send your name, email, or your content to Singular. Turning on Do Not Sell or Share (Section 7) instructs Singular to stop sharing your data for advertising.
- Expo: mobile push-notification delivery.
- AWS End User Messaging: SMS delivery of phone-verification codes, if you add a phone number. Only your own number and the code are sent; your contacts are never sent here.
- Amazon SES: delivery of transactional email (address verification, password reset, account-change notices). Your email address and the message text are processed to send it.
- Cloudflare: DNS and edge protection.
We may also disclose information when required by valid legal process or to protect the safety of users or the public.
5. Content Moderation
Photos are scanned by AWS Rekognition before they reach our storage; images flagged for nudity, violence, drugs, hate symbols, or similar prohibited categories are rejected and not stored. Review text is screened by an automated moderation API at the time of submission. You can also report any review, photo, profile, dish, or restaurant from the app, and you can block other users to hide their content from your view.
Direct messages are handled differently from public content. No one at TopDishy reads them routinely, but every message is screened automatically before it is delivered: the text is checked by an automated moderation system run for us by OpenAI (see Section 4), and a message that system flags is never delivered. Messages are not end-to-end encrypted: they are stored on our servers, and a person at TopDishy may read a specific message when it is reported, when we must comply with valid legal process, or when investigating abuse; not otherwise. When you report a message we store a copy of its text at that moment, so the report can still be assessed if the sender later unsends it. Blocking someone stops messages between you in both directions, and push notifications about new messages never contain the message text.
6. Cookies and Local Storage
The web app stores a sign-in token and your saved location in your browser's local storage, plus an HTTP-only refresh-token cookie used to keep you signed in. PostHog keeps a randomly generated analytics identifier in local storage (Section 4), and New Relic sets performance cookies (Section 4). If you arrive via one of our ads, we also keep that link's campaign tags (e.g. utm_source) in local storage for up to 30 days and, if you then create an account, record them with it so we can tell which campaigns brought new users. Reddit's measurement pixel (Section 4) is the only third-party advertising tag on our web pages, and the Singular install-measurement service (Section 4) is the only advertising component built into the mobile app; we do not run third-party ad networks, we show no ads, and we do not sell personal information for money. If you turn on Do Not Sell or Share My Personal Information, the pixel stops running, those campaign tags are deleted from local storage, and the app instructs Singular to stop sharing your data for advertising.
7. Your Rights and Controls
- Access and update. Edit your display name, avatar, bio, and language in Settings.
- Delete your account. Use the in-app delete option (Settings → Account → Delete account) on web or mobile. Deletion clears your email, display name, avatar, and bio, removes linked sign-in identities, and signs you out everywhere immediately. Your reviews and rankings are retained in a de-identified form so that community rankings and fraud-prevention records remain intact. If you need everything purged for a legal reason, email us.
- Request a copy of your data. Email [email protected].
- Do Not Sell or Share My Personal Information. California residents (and anyone else who wants to) can stop us sharing data for advertising measurement at Settings. It applies on the device you set it on, and to your account everywhere once you are signed in. It takes effect immediately: the Reddit pixel stops, stored campaign tags are deleted, no sign-up of yours is reported to Reddit, and the mobile app instructs Singular to stop sharing your data for advertising, an instruction the app remembers for later launches. One limit worth stating plainly: the install measurement described in Section 4 runs when the app first opens, so an install that happened before you set this on that device may already have been measured. We do not require an account, and we will not discriminate against you for using it.
- Push notifications. Toggle in your device's OS settings.
- Subscription management. Cancel a Stripe subscription from Settings; cancel an Apple or Google in-app subscription from your respective store account.
8. Data Retention
We keep account data while your account is active. After deletion, identifying fields are cleared as described in Section 7. Review and ranking content is retained de-identified because removing it would distort community rankings that other users rely on. Operational logs are kept for a limited period sufficient for debugging and abuse investigation.
Direct messages are kept until a participant removes them. Unsending a message clears its text; deleting a conversation removes it from your own view and leaves the other participant's copy intact; and deleting your account clears the content of every message you sent and ends your access to those conversations. A message is personal data of both people in it, so we do not destroy the other participant's record of an exchange on one participant's request.
The date of birth used for the age check is never written down in the first place, so there is nothing to retain or delete. The record that the check was passed is kept for as long as the account exists, because it is what lets us avoid asking again.
9. Security
We use HTTPS in transit, encrypted storage at rest, AWS Secrets Manager for credentials, and private-subnet databases. No system is perfectly secure; if we become aware of an incident affecting your data, we will notify you as required by law.
10. Children
The Service is not directed to children under 13, and we do not knowingly collect data from them. Everyone is asked to confirm their date of birth when they first sign in, and an account that does not meet the minimum age of 13 is closed rather than allowed to continue. We check the date and do not keep it (see Section 1a). If you believe a child has created an account, contact us and we will remove it. If you think your account was closed because you entered the wrong date, email [email protected].
11. International Use
TopDishy is operated from the United States. If you use the Service from outside the U.S., you understand that your information will be processed in the U.S. and other countries where our service providers operate.
12. Changes to This Policy
We may update this policy. If we make a material change, we will update the date above and, where appropriate, notify you in the app.
13. Contact
Questions, deletion requests, or data-access requests: [email protected].