Privacy Policy
Effective date: 13 September 2026
This Privacy Policy explains how Karim El Atab Dit El Daya ("mypinbite", "we", "us") collects, uses, and protects your information when you use the mypinbite mobile app and website (the "Service"). By using the Service, you agree to this Policy.
Questions? Contact us at privacy@mypinbite.com.
1. Who we are
mypinbite is a community food-discovery app: a map of restaurants and the dishes worth trying — written by mypinbite, with community contributions and, once the programme is live, vetted curators — and discoverable by everyone. The person responsible for your personal data (the data controller) is Karim El Atab Dit El Daya, contactable at privacy@mypinbite.com.
2. Information we collect
a) Information you give us
- Account data: your email address and a password (passwords are stored securely by our authentication provider — we never see them in plain text). If you sign in with Apple or Google instead, there is no mypinbite password: the provider confirms your identity and shares your email address and basic profile details — your name and, for Google, your profile photo — which we use to pre-fill your profile (you can change both at any time). With Apple you can choose to hide your email address; we then receive a private relay address instead, and the Service works normally with it.
- Profile data: your display name, a public @handle, and an avatar photo (photo optional). Curators may additionally have a bio and a linked Instagram handle.
- Content you create: places, dishes, reviews, ratings, and photos you publish (curators); the places you save (Favourites / Want-to-try) and the dishes and reviews you like; shared lists you create or join, the places you add to them, and the visited marks you set; list invites you send and answer; the people you follow; and, when you add or review a place, any connection to that place you declare (owner, staff, family, PR, friend).
- Food diary: if you log a visit, we store the place, the date, an optional note, and up to six photos per entry. Diary photos are kept in private storage, separate from the public place photos. If you tag other members on an entry ("shared memories"), each of them receives an invitation and, once they accept, the entry appears in their diary too.
- Where you heard about a place: when you save a place for later you can add an optional note or link about where you heard of it (a friend, an article, a video). It is stored with your save, never on the place itself.
- Decide quiz: if you use the "What should I eat?" quiz, we store your answers and the resulting shortlist, linked to your account, to improve recommendations.
- Reports: if you flag a place, review, dish, or profile, we store the report (what you flagged and the reason you chose) linked to your account so our moderators can act on it.
b) Information collected automatically
- Usage & device data: basic technical information needed to operate the app (e.g. app version, device type, and logs from our backend provider).
- Crash diagnostics: if the app hits an error, it sends us a technical crash report — the error message and stack trace, your app version, and platform. Crash reports are not linked to your account and contain no content you wrote.
- Product analytics (PostHog): we collect which screens you visit and product events — for example that a search ran (including the search text) and how many results it returned, quiz steps, and onboarding progress — linked to a random identifier that is connected to your account ID when you sign in. We also record session replays: a visual playback of the screens you moved through, in which everything you type is masked and never recorded. Analytics are hosted in the EU and used only to understand and improve the product — never for advertising.
- Location — only if you grant permission — to center the map on your area, show places near you, and sort results by distance. We use it only while you are using the app (when-in-use); we do not track your location in the background. You can decline or revoke this in your device settings, and the app still works without it (the map simply frames all places instead).
- Search queries: the text you type into search is sent to our AI providers (see §6) to interpret natural-language queries (e.g. "cheap date-night sushi in Marina") into structured filters and to match them against places by meaning. We send only your query text, not your identity.
- Push notifications — only if you grant permission — we store your device's push token (an identifier issued by Apple/Expo for delivering notifications) linked to your account, so we can notify you about things like list invites, people joining your lists, and new followers. The token is deleted when you sign out, and you can stop notifications at any time in your device settings — the in-app notification inbox keeps working either way.
- Local storage: we store your login session on your device so you stay signed in.
c) Photos If you add a photo, the app asks permission to access your photo library; we only upload the image(s) you choose.
d) Research records about people who aren't users Parts of our catalog were originally researched from public sources; that research programme ended on 31 August 2026, and new places now come from our own visits and additions, from the community, and, once the programme is live, from vetted curators. From the earlier research we retain internal records about the food writers whose public coverage we read at the time: their name, public handle, where they published, and our own paraphrase of what they said. These records are never displayed in the app or on the website — they exist so we can stand behind our editorial content and account for its provenance. We rely on our legitimate interest in keeping editorial research records over publicly available information. If you are such a writer and want your records corrected or removed, contact privacy@mypinbite.com and we will act on it.
We do not use advertising trackers, and we do not process payments in the Service.
3. How we use your information
We use your information to:
- create and manage your account and keep you signed in;
- provide the core Service (show the map, dishes, reviews, search, saves, likes, shared lists, invites, follows, and the decide quiz);
- draw the story cards you ask for (see §6, Vercel);
- show the content you post (reviews, photos, community places, shared-list additions) under your profile — and, for curators (vetted food bloggers who publish under their own name), attribute their published picks to them;
- understand how the app is used and improve it (see the analytics section above);
- maintain safety and integrity (prevent abuse, review reports, fix crashes, enforce our Terms);
- communicate with you about the Service (e.g. account or security notices);
- comply with legal obligations.
4. Legal bases (where applicable)
Where the UAE PDPL, GDPR, or similar laws apply, we rely on: performance of a contract (to provide the Service you request), your consent (e.g. for location access), our legitimate interests (to operate, secure, and improve the Service), and legal obligation (to meet legal requirements).
5. What is public vs. private
- Public: every account has a public profile — your display name, @handle, and avatar — which other users can find in people search and view. Curators' profiles additionally show their bio, Instagram link, and everything they publish (places, dishes, reviews, ratings, photos).
- Private: your email address is never shown publicly. Your saved places (Favourites / Want-to-try), your notes about where you heard of a place, your food diary (entries, notes, and photos), and your quiz answers are visible only to you. A diary entry you tag people on is shown to those people once they accept; a note attached to a place on a shared list is visible to that list's members. Likes and upvotes are displayed only as totals. We do not show other users whom you follow or who follows you; follows are used to build your own Following feed.
- Shared lists sit in between: the list's name, its places, who added what, visited marks, and the member list (each member's public profile) are visible to every member of that list. Pending invitees are shown to members until the invite is answered. Anyone who has a list's invite link can see a small preview — the list's name, owner name, and member count — before joining, so share invite links only with people you trust.
- Administrators can access user emails only through restricted internal tools for legitimate operational reasons.
6. How we share information
We don't sell your personal data. We share it only with:
- Service providers who run our infrastructure on our behalf:
- Supabase — database, authentication, and file storage (hosted in the EU — Ireland). Crash reports are stored here too.
- MapTiler — map tiles (their maps include OpenStreetMap data). Map requests may reveal your approximate map view to the tile provider.
- Anthropic — interprets your natural-language search queries into filters, and drafts place descriptions and tags when a place is added. Only the query or place text is sent (no account or location data). Per Anthropic's API terms, this input is not used to train their models.
- Voyage AI — computes text embeddings for semantic search: receives your search query text and the text of place listings, nothing else.
- PostHog — product analytics and session replay, as described in §2, hosted in the EU.
- Foursquare — when you search for a place to add, the place-name query is sent to Foursquare's places database to find matches.
- Vercel — hosts our website (mypinbite.com) and draws the story cards you can share from the app. When you tap "Share as a story" or "Recommend this place as a story", the place details, your note or the place's description, and the photo you chose (your own diary photo via a short-lived private link, or the place's public cover photo) are sent to our website, drawn into an image, and returned to your phone. The card is not stored.
- Apps you share to — if you choose to share a story card to Instagram or another app, the image is handed to that app on your device and nothing is sent by us. Instagram is told that the card came from mypinbite (Meta requires an app identifier for story sharing). We receive nothing back, and the receiving app's own privacy policy governs what happens next.
- Sign-in providers (Apple, Google) — only if you choose Sign in with Apple or Sign in with Google: your sign-in happens directly with that provider, which confirms your identity to us and learns that you use the Service. Their handling of your data is governed by their own privacy policies.
- App stores (Apple App Store, Google Play) for app distribution.
- Authorities, if required by law or to protect rights, safety, or the integrity of the Service.
7. Data retention
We keep your information for as long as your account is active or as needed to provide the Service. You can delete your account at any time in the app (Profile → Delete account). Doing so permanently deletes your account, profile, saved places, likes, follows, quiz sessions, food diary entries and photos, list memberships and invites, and the shared lists you own — and, for curators, the places, dishes, and photos you published. Reports you filed are kept (for safety) but are disconnected from your identity; crash reports are never linked to it. Analytics events and session replays are retained by our analytics provider for a limited period. Residual copies may persist in our service providers' backups for a limited period, and we may retain information where required for legal reasons.
8. Security
We use industry-standard measures, including database Row-Level Security, encrypted connections, and restricted administrative access, to protect your data. No system is 100% secure, but we work to safeguard your information.
9. Your rights
Depending on your location, you may have the right to: access a copy of your data, correct it, delete it, object to or restrict certain processing, withdraw consent, and port your data. To exercise any of these, email privacy@mypinbite.com. You may also lodge a complaint with your local data-protection authority.
You can edit your profile and delete your account directly in the app at any time (Profile → Edit profile, Profile → Delete account) — no need to contact us, though you can also exercise any of these rights by email.
10. International transfers
Our backend and analytics are hosted in the EU (Ireland). If you access the Service from another country (for example the UAE, where the app is focused), your data is transferred to and processed there. Where required, we use appropriate safeguards for such transfers.
11. Children
The Service is not directed to children under 13, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
12. Third-party links
The Service may link to third-party sites (e.g. a curator's Instagram, a restaurant's site). We are not responsible for their privacy practices; review their policies separately.
13. Changes to this Policy
We may update this Policy. We will post the new version with a revised effective date and, for material changes, provide additional notice in the app.
14. Contact
Karim El Atab Dit El Daya — privacy@mypinbite.com — https://mypinbite.com