Craveheads / Policies & support
Privacy Policy
How Craveheads handles account information, community content, location, safety reports and privacy requests.
Effective September 22, 2026
About this policy
Craveheads uses information to provide restaurant discovery, reviews and community features, manage accounts, and keep the service safe. This policy covers the Craveheads app, its moderation operations and this public policy and support website. Contact support@craveheadsapp.com for privacy questions or requests.
Accounts and community information
Supabase provides email and password authentication, account verification, password recovery and session management. Your email and authentication information are not public profile fields. Do not put passwords or authentication codes in your profile, reviews, bug reports or support messages.
We store account identifiers and profile information such as your first name, username, About text, active food interest (Crave), Home Market and profile photo. Community-facing profile fields and your reviews, ratings, review photos and associated dates may be visible to other signed-in users, subject to visibility restrictions. Private settings are not a separate guarantee that information you publish on your profile is private.
We process follows, private saved Places, and helpful or not-helpful votes to provide community lists, bookmarks and scores. Follow relationships and counts may appear in community views. Saved Places are private to your account. Individual voting records are restricted; community features display summaries and derived scores.
Location, search and Place information
You can search manually and choose a Market without providing your phone’s location. When you explicitly use nearby discovery or location-based Market selection, the app requests foreground location permission if needed and uses an available location temporarily. You can deny or revoke this permission in iOS Settings. Craveheads does not silently change your Home Market, keep a Feed GPS history, or use background location tracking.
Restaurant searches first use internal Place records where applicable. When Google Places is needed, the search text and optional nearby coordinates are sent through our backend to Google to retrieve relevant results. Search text and provider response content are not intentionally written to application logs. Google may process requests under its own policies. Opening a Google Maps link also takes you to Google’s service.
For a previously unknown Google Place, you select or confirm an active Craveheads Market. Your phone’s location is not proof of the restaurant’s location. Google coordinates are not used to create that new internal Market assignment or stored for that purpose. Existing Place aliases resolve to their existing shared Place and Market. Some earlier test Places may retain historical geographic assignments until reconciliation. We retain provider Place identifiers to recognize the same Place. Restaurant details that you independently contribute are stored separately from Google-displayed search information.
Google-provided information carries Google and applicable third-party attribution. See Google’s Privacy Policy and Google Maps/Google Earth Additional Terms.
Photos and device information
Craveheads uses Apple’s PhotosPicker to access only images you select for upload. It does not request broad access to your photo library merely to select a review or profile photo. Uploaded images are processed for the app, including image metadata removal, and stored using Supabase Storage with access controls. Photos may still reveal personal information through their visible contents; choose what you share carefully.
In-app bug reports contain the description you enter, optional reproduction steps and expected behavior, and basic app/device metadata: app version and build, iOS version and a generic device model. The signed-in account identifies the report’s owner. The bug-report flow does not automatically attach screenshots, precise location, device logs or your photo library. Bug-report text is private to authorized support/moderation access.
Safety, reports and moderation
We process reports, blocks, reported content and relevant account identities to investigate abuse and enforce the Community Guidelines. Blocking is a private safety control and removes follow relationships between the accounts. It does not erase copies of content already seen or downloaded.
Authorized moderators can access relevant reports and evidence, keep private reasons and notes, send user-visible warnings or suspension messages, and record moderation actions. Audit records include relevant actor and target identifiers, actions, times, reasons and outcomes. Internal notes and reporter identities are not automatically disclosed to the reported user. Users receive only the status, notices or outcome information appropriate to them.
We also use restricted operational information, including request identifiers, quota counters, session verification records and cleanup status, to protect accounts, prevent repeated or stale actions, control abuse and operate the service. There is no guarantee that every report results in removal.
Service providers and website operation
- Supabase supplies authentication, database storage, uploaded-file Storage and backend Edge Functions.
- Google Places and Google Maps provide restaurant search, identification, attributed information and optional Maps links.
- Resend, together with Supabase’s configured email service, delivers transactional authentication and operational emails, including moderator verification messages.
- Cloudflare hosts the public website and moderation web service and routes messages sent to our support email. Support email is forwarded to the operator’s receiving mailbox for handling.
- Apple supplies iOS permission controls, PhotosPicker and app distribution/platform services as applicable. This does not mean Sign in with Apple is offered.
These providers process information needed to supply their services. Network and hosting infrastructure may process IP addresses, request timing, security events and basic technical information even though we have not added analytics. Provider operations and retention are also subject to their own terms and settings.
This public website has no account form, analytics, advertising, tracking scripts, remote fonts or third-party browser assets. Its code does not set cookies or use browser storage. Following external links or sending email uses the destination service or your mail application.
Craveheads does not sell personal information. The current product does not use advertising identifiers or cross-app tracking.
Retention and account deletion
You can initiate permanent account deletion in the app’s Settings after confirming your intent and current password. If you cannot access the app, contact support for help; we may need to verify account ownership. Accepted deletion is permanent and is not a temporary deactivation. Processing is asynchronous: access restrictions and personal-content cleanup begin before background removal of uploaded objects and the authentication account finishes. A processing delay is not a cancellation window.
Deletion removes your account/profile and associated reviews, follows, saved Places and votes through the deletion process. Related personal bug-report data, reports and moderation message content are erased or scrubbed as applicable. Shared restaurant Places and other people’s contributions remain. Minimal deletion tombstones—records that a deletion was requested or completed—and restricted cleanup records can remain so retries and recovery do not recreate deleted accounts.
The current operational design prunes completed moderator approval records and account-action audits after 90 days. That is not a universal 90-day limit for every report, warning, support email, tombstone or backup. Warnings may remain until account deletion, and unresolved safety matters may require further handling. Historical public messages were not always retained. We do not promise an indefinite content archive or a fixed deletion deadline for every provider copy.
Previously downloaded images, screenshots and other people’s copies cannot be recalled. Previously issued temporary signed image links may continue to work until expiry or removal of the stored object. Backups and provider operational records may persist beyond removal from the live app; their cleanup follows applicable operational processes. We do not promise instant erasure from all backups. Access restrictions and removal of a database reference do not by themselves prove all stored image bytes have been deleted.
Information may be preserved or disclosed when required by valid law or court process. Any such exceptional handling is subject to the applicable legal requirement; this does not mean we keep every reported image indefinitely.
Your choices and requests
You can edit available profile fields, remove your own reviews or photos, manage saved Places and follows, block accounts, report content, deny location access, and request account deletion. To ask about access, correction, privacy rights, deletion, or a moderation appeal, email support@craveheadsapp.com. Describe the request and provide only the information needed to identify the issue. Never send your password or authentication codes. Available rights and any legally required response process depend on applicable law.
We will update this page when our practices change and identify the effective date. Questions about this policy are welcome through the same contact.