← CraveMatch

Privacy Policy

CraveMatch (the “Service”) handles your personal information with care and complies with applicable laws, including Korea’s Personal Information Protection Act. This policy explains what the Service collects and how that information is used, stored, and deleted.

1. Information we collect

  • Location (required): GPS coordinates at the moment you search, used only to generate recommendations. The precise coordinates are not stored on the server after the request is processed. There are two exceptions: the de-identified demand statistics below keep an area code covering roughly 5km for 21 days, and registering a venue with CraveMatch Chef stores the coordinates at the moment of registration as that venue’s location, held on your account until you delete it (registering the venue again replaces them).
  • De-identified demand statistics: for the restaurant analytics service (CraveMatch Chef) we record exactly four things at the moment you search — (1) a food category from a fixed list (e.g. “Soup & stew”), (2) an area code covering roughly 5km, (3) the hour, and (4) a value derived using a random key that belongs to that one day’s records. A new key is generated each day, so the same person is a different value on a different day, and the key is deleted together with that day’s records after 21 days. We do not record your search text, your coordinates, or any identifier. Searches that do not match the fixed list, and searches in which health or medical wording is detected, are not recorded at all. These records are deleted after 21 days.
  • Goal profile (optional): the health goal you enter, your answers, and the generated meal plan. Stored on your device (browser storage) by default and synced to the Service’s own server when you sign in.
  • Health data (optional): with your permission on the native app, today’s and the last 7 days’ step counts, active calories, and workouts are read from Apple Health. If you additionally connect them in the goal-plan flow, your weight and height (including the last 90 days’ weight change) are read as well. All of it is read on your device, held in memory, and never stored on the Service’s server — today’s activity is sent with each search and shapes only that search’s recommendations, while the weekly activity and your weight and height travel only inside the plan-generation request, to skip questions the data already answers and set targets from real numbers. The physical-changes readout on the Goals tab is read fresh from Apple Health each time the tab opens and is stored nowhere.
  • Account information (optional): the email address and account identifier provided when you sign in with Apple/Google/Discord or sign up with email.
  • Search queries: the queries you enter are used during AI processing to generate recommendations. The text itself is not stored on the server. It does stay on your device, so “recent searches” can offer it back to you along with the venues it returned; you can clear that list from the Saved tab.
  • Your last few result lists: so that a run of broad searches (“혼밥”, “places to go with friends”) stops returning the same restaurants, the place-database identifiers of the venues your last four searches showed are sent along with the next search. They are identifiers in a public place database rather than names or coordinates, and they are used only to order the list of candidates. They are not stored or logged on the server, are not passed to Anthropic or any other third party, and are discarded when that request finishes. The copy kept on your device is cleared together with “recent searches”.
  • Saved places and visits (optional): the name, cuisine, address, and coordinates of restaurants you save or mark as visited, and the thumbs up or down you leave on them. Stored on your device and synced to the Service’s own server when you sign in. They also feed the taste signal that shapes later recommendations.
  • Friend features (optional): your username (handle) and display name, your friend list, friend requests in both directions, your block list, restaurant invites you send or receive (an invite carries the place details and any note you write), and records that someone answered your invite or friend request. Usernames are searchable by other users. A block is recorded only on the blocker’s side and is never disclosed to the person blocked.
  • Abuse reports: when you report another user we record both parties’ account identifiers, the reason you wrote (up to 500 characters), and the time, in a separate log an operator reviews. Reporting also blocks the person. This log has no automatic expiry and survives account deletion — section 4 says exactly what is kept and what is removed.
  • Share links: sharing a place stores a snapshot of it (name, cuisine, address, coordinates, photos, rating, why it fits, and so on) on the server, along with your username if you have claimed one. Anyone who knows the resulting /s/ address can open it without signing in — that is what sharing is for. After 180 days the link stops opening, and the snapshot is deleted on a later sweep.
  • Purchase data: when you buy a subscription in the App Store we store the product id, transaction identifier, expiry, and auto-renew flag from the transaction Apple signed. We also keep a separate table mapping that transaction identifier to your account, so a renewal or refund notice arriving later can be applied to the right one. Payment details such as card numbers are handled by Apple and never reach the Service.
  • Usage counters: to enforce the daily search limit we record the time of each search, to the minute, in a file named after a value derived one-way from your account identifier when you are signed in, or from a random per-install device identifier when you are not. A file untouched for 24 hours is deleted.
  • Search outcome log (operations): so we can tell whether the pipeline is broken and where, each search records which tier answered, how many results came back, how long it took, the failure reason when there was one, the language, and the time to the minute. It records no search text, no coordinates, and no account or device identifier. Deleted after 21 days.
  • IP address: to stop a flood of requests from one place, IP addresses are counted in memory only. No data file the Service writes contains one.

2. How we use it

  • Personalized restaurant recommendations and meal plans
  • Service features such as saved places and search history
  • Service quality improvement and error handling

3. Third parties and processors

  • AI recommendations: Anthropic (your query, coordinates, goal profile, and taste signal (the cuisines you rated up or down and the names of places you loved) are included in API requests; health activity data (steps, active calories) is included for paying users only. When a goal plan is generated, the weekly activity, workouts, and the weight and height you connected are included in that request. Some searches run through a web search executed on Anthropic’s servers)
  • Place search: Kakao (search keywords and coordinates)
  • Place enrichment and place-name lookup: Google (the name, address, and coordinates of recommended venues, and the place name from your query when it contains one)
  • Account authentication: Supabase (email and account identifier at sign-in)
  • Map display: MapTiler or CARTO (opening a map makes your device fetch tiles from them directly, so the map area you are viewing and your IP address reach that provider)
  • Payments: Apple (App Store purchases are processed by Apple. The Service only verifies the transaction Apple signed and sends Apple no information about you)

Restaurant businesses using the analytics service (CraveMatch Chef) receive only aggregated results from the de-identified demand statistics above. Individual records and search text are never provided in any form, and a category is shown only once enough distinct searchers are behind it (10 for food categories, 20 for diet-related ones). A business can only view results for the area around the venue it registered.

Saved places, visit history, and goal profiles are stored on the Service’s own server, not with a third party. Each processor handles information only to the extent needed for its purpose.

4. Retention and deletion

Account data is deleted immediately when you delete your account — the goal profile and meal plan, saved places and visits, friendships, requests and blocks, invites and notifications in both directions, your venue registration and the area it reserved, the table linking purchases to your account, and your usage counters, along with every reference to you left in other people’s files. A request already in flight when you left can write something a moment later, so the sweep runs once more shortly afterwards. Data stored on your device can be deleted by you at any time.

The following is not removed when you delete your account.

  • Abuse reports: kept. Both parties’ account identifiers are replaced with a value that cannot be turned back into an account (it begins “deleted:”), but the reason text somebody wrote is left exactly as it was — so a reason that names you by username still names you. A report about you must not be erasable by closing your account, and dropping the reports you filed would erase someone else’s record of what happened to them while they are still here. This log has no automatic expiry.
  • Share link snapshots: kept. The link is public and already in other people’s hands, so deleting it would only break their page. The username attached to it is removed, because deletion frees that username for someone else to claim and the credit would eventually point at them. The snapshot itself expires 180 days after it was created.
  • De-identified demand statistics and the search outcome log: neither carries an account identifier, so there is no way to tell which rows were yours. Finding out would mean rebuilding the very link those logs are designed to prevent. Both are deleted after 21 days.
  • Usage counters accumulated while signed out: keyed to a device identifier the server cannot tie back to your account. They are deleted 24 hours after your last search.

Retention at a glance: de-identified demand statistics and the search outcome log, 21 days; usage counters, 24 hours; share link snapshots, 180 days; all other account data, until you delete your account; abuse reports, no expiry.

5. Your rights

You can request to access, correct, or delete your information at any time, and the in-app “Delete account” feature removes your account and the data linked to it. What section 4 lists — abuse reports, share link snapshots, and the statistics and operational logs that carry no account identifier — is not removed by that step.

6. Privacy officer

Operated by: OwlFlow Studio
Operators: Yugeon Park, Junhyuk Suh
Privacy officer: Yugeon Park
Contact: [email protected]

Effective date: August 4, 2026