Privacy Policy
Last updated: 26 June 2026
The binding version is the Polish one (Terms §14.4). EN/DE are courtesy translations.
Version: privacy:0.4.0 | Last updated: 26 June 2026
This document covers the Feasty consumer app. Personal data of restaurateurs collected through the B2B Claim verification flow and the Feasty Business panel is governed by a separate privacy policy — it will be available at business.feasty.com.pl once published (planned before the first B2B monetisation). Until the dedicated B2B privacy policy is published, restaurateurs may contact the Controller at contact@feasty.com.pl regarding the processing of their data in the B2B Claim procedure — we respond individually with the full scope of information required by Art. 13 GDPR.
Definitions
For the purposes of this Privacy Policy, the following terms have the meanings set out below:
- Controller (Administrator) — the entity that determines the purposes and means of processing Users' personal data, i.e. Radosław Rodak (Art. 4(7) GDPR).
- Personal Data — any information relating to an identified or identifiable natural person within the meaning of the GDPR.
- GDPR (RODO) — Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
- DSA — Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services (Digital Services Act).
- AI Act — Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence.
- User — any person using the services provided through the Application.
- Processor — an entity to which the Controller entrusts the processing of personal data on its behalf (Art. 4(8) GDPR).
- Hash — the output of a one-way cryptographic function that transforms input data into a fixed-length string, used among others to secure data and verify its integrity.
- SHA-256 — a hash function that converts any text into a string of 64 hexadecimal characters.
- API — an application programming interface enabling communication between the Application and external systems, services or applications.
- Apple Private Relay — a privacy service offered by Apple that can hide the User's real IP address by routing traffic through intermediary servers.
- SSO (Single Sign-On) — logging into the Application using an existing account with an external provider (e.g. Google or Apple), without creating a separate login and password.
- Cookies — IT data, in particular small text files, stored on the User's terminal device.
1. Data Controller
The controller of your personal data is Radosław Rodak, a natural person operating under the Polish "non-registered business activity" scheme (Art. 5(1) of the Act of 6 March 2018 — Entrepreneurs' Law), correspondence address: ul. Boya-Żeleńskiego 34, 20-435 Lublin, Poland. The Application currently operates in an early-access, free phase and does not generate revenue. Upon exceeding the non-registered business threshold or commencing registered business activity, this Privacy Policy will be updated with registration numbers (NIP, REGON, KRS) along with a version bump requiring renewed consent.
For matters relating to the protection of personal data, please contact us at: contact@feasty.com.pl.
Data Protection Officer (DPO). The Controller has not appointed a Data Protection Officer because none of the conditions under Art. 37(1) GDPR are met: the Controller is not a public authority; the core processing activities do not consist of operations requiring regular and systematic monitoring of data subjects on a large scale, nor large-scale processing of special categories of data (Art. 9) or data on criminal convictions (Art. 10). This determination will be reassessed when the non-registered business threshold is crossed or when features that change the scale of processing are launched.
2. Data we collect
Depending on how you use the Feasty app, we process the following categories of data. For each item we indicate whether providing the information is mandatory (required to create an account or use the feature) or optional (you can use the Application without providing it — Art. 13(2)(e) GDPR).
Account data
- your name and display name — mandatory (required to create an account). Source of data: obtained from the identity provider (Apple ID or Google account) on first sign-in when you use SSO; or provided by you manually during registration with a one-time email code (GDPR Art. 14 — where data is sourced from a third party such as an identity provider).
- email address — mandatory (required for authentication). Source of data: obtained from Apple ID or Google account on SSO, or provided by you directly during email-code sign-in. Apple Private Relay: if you chose "Hide My Email" when signing in with Apple ID, we receive a relay alias (e.g. abc123@privaterelay.appleid.com) instead of your real address — communication is routed through Apple, we never see the underlying address.
- city — set automatically (not entered by you manually — the App has no city-edit field). Source of data: derived by our server functions from the towns where you review restaurants most often (the city comes from the address of the venues you rate; refreshed periodically). Until you post a review, your city stays unset. It is used solely to localise rankings and Prestige ranks to your city (basis: GDPR Art. 6(1)(f) — legitimate interest).
- profile photo — optional. Source of data: your Google avatar (when you use Google SSO and consent on first sign-in), or an image you upload manually from your device's gallery.
- bio — optional (provided by you manually)
- salted SHA-256 hash of your phone number — optional; if you choose to add a phone to your account. The raw phone number never leaves your device.
Activity data
- your restaurant reviews (rating, text, photos)
- your restaurant lists (e.g. "Favorites", "Want to go")
- your likes on other users' reviews
- your follows (who you follow, who follows you)
- history of Matchmaker sessions
Technical data
- push notification tokens
- device identifiers (for authentication and abuse prevention)
- application error logs (with personal data scrubbed)
Location data
Your approximate GPS location — only at the moment when you search for nearby restaurants or start a Matchmaker session. We do not store a history of your location.
Contacts from your phone's address book (optional)
If you use the "Find friends" feature we will ask for one-time permission to access your phone's address book. You can revoke this permission at any time in your device's system settings (iOS Settings → Feasty → Contacts / Android Settings → Apps → Feasty → Permissions).
Once permission is granted:
- from each entry in the address book we read the phone number and the contact's name (we skip email, address, notes, and contact photo); the name stays only on your device — it labels the match ("friend from your contacts") and is never sent to the server, which only ever receives hashes of the numbers
- numbers are hashed locally on your device using SHA-256 with an additional salt — raw numbers never leave your phone
- only the hashes are sent to the server in a single request in which the server checks which of those hashes correspond to phone numbers of other Feasty Users (we compare your hashes against hashes stored by other Users at registration)
- hashes are not stored on the server after the request — the response contains only the match list; the list of submitted hashes is discarded
- hashes of your contacts are never shared with other Users — only you see the result of the lookup
Purpose: to show you which of your address-book contacts are already on Feasty so you can follow them without manually searching. The feature is fully optional — the Application works without this permission, the only consequence being the absence of the "Find friends from contacts" screen.
Legal basis: Article 6(1)(a) GDPR (User consent expressed by granting the system permission). Revoking the permission in system settings is equivalent to withdrawing consent — from that moment the feature stops working and any earlier matches are no longer displayed.
Analytics data (what we do NOT collect)
Feasty intentionally does NOT use behavioral analytics tools such as Google Analytics for Firebase, Mixpanel, Appsflyer or Adjust. We do not profile your habits, do not build marketing behavior models, do not sell data to third-party advertisers.
We collect only:
- application error logs (Sentry) — technical data (stack trace, app version, device model, OS) with personal data scrubbed (email, location, review content)
- anonymous usage counters (Cloud Functions rate-limit counters) — used solely to prevent abuse
- anonymous traffic metrics for B2B partners (see "Anonymous metrics for B2B partners" below)
No behavioral tooling means we do NOT ask you for cookie/tracking-SDK consent banners (ePrivacy / Polish Electronic Communications Law (PKE) art. 399). Should we enable analytics in the future, we will ask for your explicit consent before activation.
Anonymous metrics for B2B partners
When you tap "Call", "Reserve", "Directions", "Menu", "Share", a delivery link or add a place to your "Saved" list, we increment an anonymous counter of how many such actions happen per restaurant per day. The counter:
- Does NOT store your identity — the database holds only the count of actions per restaurant per day per button type, with no UID, IP address or other identifier.
- Does NOT build your history — we do not know "Anna tapped Call on 3 restaurants before choosing the 4th", we do not build per-user conversion funnels, we do not run tracking-based ads.
- Is used solely by the restaurateur of that specific venue, so they can see "how many people this week wanted to call my restaurant via Feasty". Conceptually equivalent to a simple visitor counter at the door.
Restaurateurs who have claimed their venue in Feasty Business (B2B Claim procedure, manually reviewed by an administrator) see daily aggregated statistics of THEIR restaurant in their dashboard panel:
- number of taps on the listed buttons (summed per day / week / 30 days)
- distribution of "occasion" tags (e.g. date, with friends) and "atmosphere" tags (e.g. cosy, photogenic) derived from published reviews of their venue — aggregated statistically, never containing the content of individual reviews or identifiers of their authors.
Under the Premium plan, restaurateurs additionally see anonymised industry comparisons — the median score and tag distribution across a set of at least 5 similar venues in the same cuisine and area. The restaurateur NEVER sees the names of competitors. We do not disclose the composition of the comparison set either — we only show "compared with 5-9 / 10-19 / 20+ similar venues". Your venue may be used in comparisons presented to other B2B partners in your category and location — but only as an anonymised median, never by name.
If a category (tag) would contain fewer than 5 unique review authors, the owner panel shows "Insufficient data" instead of a percentage — this protects authors of individual reviews from identification (k-anonymity threshold, Art. 4(5) GDPR).
Legal basis: counters are anonymous aggregates within the meaning of GDPR Recital 26 — without person-level identifiers they do not allow direct or indirect identification of a User (k-anonymity threshold of 5 applies to tag distribution). To the extent that the moment of the tap might be momentarily linked to your session on the server side before the counter is incremented, the legal basis is Art. 6(1)(f) GDPR (legitimate interest of the controller in metric integrity + interest of restaurateurs in receiving aggregated traffic).
Right to object (Art. 21 GDPR): you may object at any time to your anonymous taps being counted in B2B metrics by writing to contact@feasty.com.pl. Once your objection is recorded, future interactions stop being counted (we flag the account so the server honours the objection on every subsequent counter increment). The objection cannot apply retroactively — the counters are already anonymous and contain no identifier that could be removed.
Matchmaker
Matchmaker is a feature for choosing a restaurant together — you and your friends join a single session via a 6-character code and swipe through 20–30 nearby venues to quickly pick a place for a shared meal.
Session data processed:
- Your display name and profile photo — visible to other members of the session (who joined via the code).
- Your approximate location at the moment the session is created — used solely to fetch the list of nearby restaurants and not stored after the session closes.
- Your swipes (yes / no per restaurant) — visible to other members only as "matches"; the full list of your "no" swipes is not shown to anyone.
- Place identifiers (Google place_id) chosen for the session — remain in the session document.
Sessions are stored as single documents in the database and automatically closed after 24 hours of inactivity. A complete session (members + swipes) is deleted within 30 days of being closed. You can manually delete any session you have created.
We do not use Matchmaker data for profiling or to train any models — it operates strictly in real time for session participants.
Legal basis: Art. 6(1)(b) GDPR (contract performance — providing the social feature you knowingly joined).
Feasty AI — generated restaurant summaries
The Application uses a generative AI model (Vertex AI Gemini, hosted exclusively in the europe-west1 region — Belgium) to produce two types of summaries visible on the restaurant screen:
- Restaurant summary (Level A) — a short, neutral description ("what guests say about this restaurant") generated from an aggregate of public reviews published by the community. It contains no identifying details of the review authors and no verbatim quotes.
- Personalised intro (Level B) — a single sentence such as "Two people you follow recommend this cuisine" shown only to you. It is produced by sending placeholder tokens to the model (e.g. friend_1, friend_2, tag_cozy) instead of real names or identifiers — raw personal data of your friends never reaches the model.
Guarantees enforced by our processing:
- Origin labelling (AI Act Art. 50): every generated summary carries a visible label "✦ Text generated by Feasty AI" — we do not pretend to be a human author. A modelMeta field (provider, model, region, timestamp) is stored as proof of origin.
- Processing in the EU region: all requests to the model are executed in the European region (europe-west1) — no transfer of review content to the US for training or running the model. Corporate-level transfers by the provider (Google as a US entity) are described in section 5 "Transfers outside the European Economic Area" (Art. 44–49 GDPR).
- Negative-claim filter: the instructions given to the model explicitly forbid formulating accusations of legal violations (expired food, fraud) based on single reviews — protecting restaurateurs from AI-generated defamation.
- Owner right of reply and takedown: a restaurateur who has claimed a venue may add a short note under the AI summary or request its permanent removal if they consider the content untrue. An administrator decides within 7 days.
- Your opt-out (Art. 21 GDPR): in Settings you can enable "Exclude my reviews from Feasty AI" — your reviews remain public (still readable by humans), but the model will stop using them as input. The opt-out flag is honoured by the server IMMEDIATELY on the next model call — your reviews are not included in any new generation from the moment the objection is recorded (in line with Art. 21(3) GDPR). The "up to 24h" window applies solely to the refresh of already-cached summaries shown on the restaurant screen — existing text remains visible until the next regeneration, but no new processing of your data takes place on the model side.
- No automated decisions about you: the AI does NOT decide your rank, karma, feature access, suspension or any legal status. Summaries are purely informational text.
Audit logs: every generation is recorded in an internal audit collection (aiOutputAudits) with the SHA-256 hash of the model instruction (the raw instruction is never stored), a truncated result (≤ 4096 chars), model metadata and a 90-day retention period. Purpose: internal quality audit and documentation for defending against potential restaurateur claims (AI Act §11.2).
Legal basis for Level A generation (restaurant summary from public community reviews): Art. 6(1)(f) GDPR — legitimate interest of the controller and Users in receiving a synthetic overview of content that Users publish as public Content in the application. Reviews passed to the model come from already-public Content; the Art. 21 objection (described above) excludes a given person's contribution from the aggregate.
Legal basis for Level B generation (personalised intro for you, built from placeholder tokens representing people in your social network and their public activities): Art. 6(1)(f) GDPR — legitimate interest of the User (you) in receiving a personalised recommendation based on the public activities of your network + legitimate interest of the people in your network in having their publicly expressed opinions help other Users choose restaurants (consistent with the inherently public nature of reviews and follows in the app). Data of people in your network is passed to the model only as placeholder tokens (e.g. friend_1, friend_2) — Vertex AI never receives their names or identifiers. Any such person may at any time exercise the Art. 21 objection against their contribution — their data is then excluded from both Level A and Level B.
Legal basis for audit logging: Art. 6(1)(c) GDPR (legal obligation arising from AI Act Art. 50 — origin transparency for AI-generated content) and Art. 6(1)(f) GDPR (legitimate interest of the controller in defending against claims related to AI-generated content).
Photos in reviews
Photos you attach to restaurant reviews are stored in Cloud Storage in the European-region bucket. To clarify:
- We do not use AI for automatic facial recognition of persons visible in photos (neither for moderation, indexing nor any other purpose). Photos do not feed any biometric-recognition model.
- Photo moderation operates in two layers: (1) automated — Google Cloud Vision SafeSearch inspects every uploaded photo for ADULT (sexual content / nudity), VIOLENCE (violence, weapons, blood) and RACY (suggestive content) categories. SafeSearch returns only per-category likelihood labels — it does not identify persons, does not recognise faces, does not extract biometric data nor perform OCR. Photos with detected unsafe content are automatically routed to the administrator queue and hidden from display. (2) manual — user reports (DSA Art. 16 Notice & Action) flow into the same administrator queue, independently of the automated layer.
- Photos featuring third parties: by publishing a photo containing the likeness of another person you declare that you have an appropriate legal basis for its publication, in particular the consent of the person depicted where required (Art. 81 of the Polish Copyright Act). The Controller does not pre-screen the legality of published content but may act upon a report. A person whose likeness was published without a legal basis may request removal by writing to contact@feasty.com.pl — we will remove or restrict access to the content without undue delay, usually within a few business days and no later than 30 days.
- Retention in the anonymisation scenario: in the default "anonymise reviews" flow we immediately delete your profile photo from storage (avatars/{uid}/*); photos attached to the review body itself remain visible as social-content elements (with the author changed to "Former user"). If you choose "full erasure", all photos (profile + review) are permanently deleted. The legal basis for content remaining in the Application is Art. 6(1)(b) GDPR (performance of the social-services contract) and Art. 6(1)(f) GDPR (the Controller's legitimate interest in maintaining the integrity of social content).
Split the bill
The "Split the bill with friends" feature helps you divide the cost of a shared meal. Within it we process:
- Receipt photo — when you take or upload a photo of a receipt, it is sent solely to read the items and prices via an AI model (Vertex AI Gemini, europe-west1 region — Belgium). We delete the image immediately after reading it and do not keep it as content in the Application. The reading is only a first draft — you can correct items and prices manually.
- Split worksheet — the items, the "who ordered what" assignment and the tip are stored as a private, temporary document available only to you (it disappears automatically after 30 days). You tag Feasty users by a reference to their account; a non-Feasty person is added by name only (no account, no contact, no notifications).
- Split notifications — if you send the split, each participant who is a Feasty user receives an in-app notification. Whoever owes sees only their own share and whom to pay back (not the full breakdown). Whoever paid, and whoever ran the split, receive an aggregated summary of amounts (who owes how much) — without the itemised list of what was ordered. These notifications expire automatically. People who aren't on Feasty are not notified. You can turn these off in settings.
- It is a calculator, not a payment. Feasty only calculates who should pay how much — it does not process any payments, store card details, or transfer money.
Legal basis: Art. 6(1)(b) GDPR (performance of the contract — providing a feature you knowingly use). We do not use this data for profiling or to train models.
Feasty Events — group outings
The "Feasty Events" feature ("Propose an outing") helps you plan a get-together with friends. Within it we process:
- Participants. You can invite only people you mutually follow. For each event we store a reference to the participant's account, a cached copy of their name and photo (to render the invitation), and their RSVP status (invited / going / declined / change proposed). In "Let's decide together" mode, co-participants see one another (name, photo, votes) inside the Matchmaker session — a deliberate part of jointly planning an outing you were invited to.
- Time and place. The date, time and chosen venue (picked directly or chosen together via Matchmaker).
- Notifications. The invitation, plan changes and re-confirmation requests reach participants in the app (and as a push notification, if enabled). You can turn these off in settings.
- Ephemeral. An event is a temporary document, deleted automatically within 30 days of the meeting time. We do not build a lasting record of who you go out with or where, nor do we use this data for profiling or to train models.
- Reservation and settlement (optional). If the organizer books a table for the group, only the organizer's contact details (booking on the group's behalf) are shared with the restaurant — never the other guests' data. Cost-splitting works through "Split the bill" (a calculator — see above; Feasty does not intermediate payments).
Legal basis: Art. 6(1)(b) GDPR (performance of the contract — providing a social feature you knowingly use).
Venue Faces
A venue owner may invite you to appear on their listing as a "Venue Face" — e.g. head chef, owner or manager. The feature works only with your consent:
- What we show — your name and profile photo (pulled live from your profile) together with the role indicated by the venue. We neither create nor store any new photo.
- Only after you accept — you receive the invitation in the app and become visible on the listing only once you accept it.
- Withdraw at any time — choosing "Unpin" immediately removes you from the venue's listing. We retain only a record of the consent being given and withdrawn as proof of accountability (Art. 7(1) GDPR) — it contains no photo.
Legal basis: Art. 6(1)(a) GDPR (consent) and Art. 81 of the Polish Act on Copyright and Related Rights (dissemination of likeness with authorisation).
Shared lists
Your own lists (other than the default "Favorites" and "Want to go") can be shared with friends:
- Invitation — you can invite someone you follow; they become a co-author of the list only after accepting the invitation.
- What co-authors see — the list name, its contents, who added each entry, and who else belongs to the list. All co-authors have an equal right to add and remove places.
- Notifications — we notify you in the app about an invitation and about a new place being added; you can turn these off in settings.
- Leaving — you can leave a list at any time ("Leave"); when the last person leaves, the list is deleted.
- Responsibility — you are responsible for the places and descriptions you add to a shared list yourself. The Controller provides a mechanism to report content that is unlawful or in breach of the Terms and takes moderation action (removal or visibility restriction); any co-author can report inappropriate content.
Legal basis: Art. 6(1)(b) GDPR (performance of the contract). The recipients of data visible on a shared list (e.g. your name as the author of an entry) are the other co-authors of that list. The notice-and-action mechanisms are described in Art. 16 DSA.
3. Purposes and legal bases of processing
Service delivery (Art. 6(1)(b) GDPR — contract performance)
- creating and maintaining your account
- enabling sign-in and authentication (including via SSO)
- publishing and editing your reviews and lists
- providing social features (follows, likes, Matchmaker)
- sending notifications related to activity on your account
Security and abuse prevention (Art. 6(1)(f) GDPR — legitimate interest)
- verifying user authenticity (invite-only system)
- rate-limiting API calls
- detecting and blocking spam, fake reviews and abuse attempts
- collecting error logs to fix technical issues
Product communication (Art. 6(1)(a) GDPR — consent)
- sending notifications about new features (you can disable these at any time in settings)
Pre-registration waitlist (Art. 6(1)(a) GDPR — consent)
If, before creating an account, you leave your email on the "Request access" screen, we process this data for a single purpose: sending you one notification with an invitation to the app when we open the next access wave. Data collected: email address, timestamp of the entry, timestamp and version of this Privacy Policy at the moment of consent, source of the request, hashed (SHA-256 with a server-side pepper) IP address for spam-source auditing, truncated user-agent. Legal basis: your explicit consent (Art. 6(1)(a) GDPR). Without ticking this consent in the form, we do not store your email at all — server-side validation rejects the request.
Waitlist data is not combined with registered users' data, is not used for analytics or profiling, and is not transferred to any third parties. The invitation email is sent personally from the Controller's address.
Retention: until (a) we send you an invitation code and you register — the entry is then deleted and the consent migrates to the consent log tied to your account; OR (b) a decision not to grant access — the entry is manually deleted; OR (c) at most 12 months from the entry date without an invitation being sent. You may withdraw consent and request deletion at any time by writing to the address in section 1 — the entry will be deleted within 30 days.
4. Recipients of data
Your data may be transferred to the following categories of recipients (processors operate under data processing agreements concluded with us):
- Google LLC / Google Ireland Limited — Firebase (authentication, database, file storage, server functions, FCM notifications), Google Maps Platform (restaurant search runs through our server functions — your location is passed without identifying information), Vertex AI (Gemini, europe-west1 region — restaurant summary generation), Google Cloud Vision API (SAFE_SEARCH_DETECTION feature — photo moderation as described in section 2 "Photos in reviews"; the API receives the image bytes and returns only category likelihood labels, with no persistence of the image on Google's side), Google Workspace (handling of inbound e-mail correspondence to our contact addresses contact@/moderation@/legal@ — GDPR rights requests, DSA appeals and moderation reports land on Google's servers). Privacy policy: https://policies.google.com/privacy. EU-US Data Privacy Framework certification: https://www.dataprivacyframework.gov/.
- Expo (650 Industries, Inc.) — push notification delivery. Privacy policy: https://expo.dev/privacy. DPF certified: yes.
- Resend (Resend, Inc.) — transactional email delivery (sign-in codes, welcome / DSA / appeal / moderation notifications). Resend receives the recipient email address, message body and delivery metadata (bounce, delivery status); it does not persist message bodies beyond the standard diagnostic retention window. Privacy policy: https://resend.com/legal/privacy-policy. Sub-processor AWS SES — processing in EU / US regions per Resend-side configuration.
- Sentry (Functional Software, Inc.) — pseudonymized error log collection (an account identifier is attached, without name or email). Privacy policy: https://sentry.io/privacy/. DPF certified: yes. Processing region: EU — the Feasty project is hosted on Sentry's EU instance (*.de.sentry.io ingest endpoint). Event data (error logs) is stored in the EU region; some metadata and operational data relating to the service may be processed outside the EEA, in particular in the US, under the transfer mechanisms of GDPR Chapter V. Status as of the effective date of this Policy version: Sentry is active for production builds with a correctly configured DSN — application errors are forwarded to the Sentry EU instance. For test builds without a DSN (e.g. local Expo Go, CI builds), a local fallback applies: error logs are stored in our errorLogs Firestore collection (region europe-central2 — Warsaw). In both paths personal data is stripped before transmission via a redaction layer (review text, emails, exact geo coordinates).
- Public authorities — only where required by a legal obligation (court, prosecutor, PUODO or law-enforcement order).
5. Transfers outside the European Economic Area
Some of our service providers, including Google LLC, Sentry and Resend, as well as selected infrastructure providers (e.g. Expo), are based or operate infrastructure outside the EEA, in particular in the United States. Personal data may therefore be transferred outside the EEA. Transfers are made in accordance with Chapter V of the GDPR, in particular on the basis of:
- a European Commission adequacy decision (Art. 45 GDPR — EU-US Data Privacy Framework)
- Standard Contractual Clauses (Art. 46(2)(c) GDPR) as a supplementary mechanism
6. Retention periods
We retain your data for the following periods:
- account and related content — until you delete your account
- error logs — up to 90 days
- database backups — 14 days (daily backups per our disaster recovery policy)
- technical data (rate-limit counters, idempotency markers) — automatically purged after 30 days
- data export counters (P2B Art. 9 — accelerated B2B export; 1 export per 24 hours per restaurant owner) — 24 hours
- Feasty AI model audit logs — 90 days (internal generation-quality audit + documentation for defending against potential restaurateur claims under AI Act Art. 50 content-origin transparency; the instruction content is SHA-256 hashed, the raw instruction is never stored — see "Feasty AI" in section 2)
After account deletion, we delete or fully anonymize your data according to the scenario you select (see section 7). Maximum erasure request fulfillment time: up to 30 days. In practice most operations complete within seconds (a cascading server-side process triggered after Firebase Auth deletion); the 30-day window covers edge cases (backups expire after 14 days, the last technical markers after 30 days).
Exception: consent logs (GDPR Art. 17(3)(e))
We retain anonymized consent logs (e.g. exclusion of reviews from Feasty AI summaries, objection to B2B counters, acceptance of Terms and Privacy Policy at a given version) for 6 years after the last change. This is required by GDPR Art. 7(1) ("the controller shall be able to demonstrate that the data subject has consented") and falls under the right-to-erasure exception of GDPR Art. 17(3)(e) (data necessary for the establishment, exercise, or defense of legal claims). After account deletion only the bare event metadata remains in the log (consent type, granted/withdrawn status, timestamp, policy version) — the last identifying field (IP hash) is stripped. The 6-year period matches the limitation period for consumer claims under Polish law (KC art. 118).
7. Your rights
In connection with the processing of your personal data, you have the following rights:
- right of access (Art. 15 GDPR) — you can check what data we process, obtain a copy and learn the purposes and recipients
- right to rectification (Art. 16 GDPR) — you can edit account data directly in the app settings
- right to erasure ("right to be forgotten", Art. 17 GDPR) — you can delete your account from within the app (Profile → Settings → Delete account). We offer two scenarios:
Anonymize reviews (default)
Your account is deleted, while your reviews are anonymized (author changed to "Former user"). The profile photo is removed immediately; photos within the review body remain visible as social content. Social content remains visible to the community but cannot be linked back to you.
> ⚠️ Important caveat — limits of anonymization. The system automatically removes only the link between the review and your profile (author, identifier). We do NOT automatically redact the review text itself or photo contents — if you placed identifying information inside the body of a review (e.g. "I, Jan Kowalski…", "I was here with my wife Anna", your face on the photo), it remains visible despite the author label change. Within the meaning of GDPR Art. 4(5) the operation will then be pseudonymization (identifiers embedded in Content), not full anonymization. Recommendation: if full unidentifiability matters to you, before closing your account manually delete the specific reviews containing identifying information, or choose the Full erasure scenario below — in both cases Content is permanently deleted.
Full erasure (Art. 17 GDPR)
Your account and all related reviews, photos (profile + review), lists are permanently deleted.
- right to restriction of processing (Art. 18 GDPR) — you can request temporary blocking of your data; it remains stored but is not actively used
- right to data portability (Art. 20 GDPR) — you can request your data in a structured, commonly used format
- right to object to processing based on our legitimate interest (Art. 21 GDPR). In particular:
- processing for security and abuse prevention purposes (section 3) — objection requires an individual balancing assessment to determine whether the controller's interest in service integrity overrides yours,
- counting your anonymous taps into B2B metrics (section 2) — we accept the objection without balancing (mechanism described in section 2),
- inclusion of your reviews in Feasty AI summary generation (section 2) — opt-out available directly in the app Settings.
- right to withdraw consent at any time (Art. 7(3) GDPR) — without affecting the lawfulness of processing performed on the basis of consent before its withdrawal. Withdrawing consent is as easy as granting it (a Settings toggle or an email to contact@feasty.com.pl).
Response deadlines
Under Art. 12(3) GDPR we respond to every request concerning your rights within 1 month of receipt. In complex cases or when we receive a large volume of requests we may extend this deadline by a further 2 months (up to 3 months in total), informing you of the extension with justification within the initial one-month period.
Exception: for account-deletion requests, the technical execution of data deletion takes up to 30 days (in practice — seconds, see section 6).
To exercise any of these rights, contact us at contact@feasty.com.pl.
8. Right to lodge a complaint
You have the right to lodge a complaint with the President of the Personal Data Protection Office (PUODO) if you believe that the processing of your data violates GDPR:
Urząd Ochrony Danych Osobowych
ul. Stanisława Moniuszki 1A, 00-014 Warszawa, Poland
www.uodo.gov.pl
9. Data security
We apply adequate technical and organizational measures to protect your data against unauthorized access, loss or modification:
- encrypted connections (TLS 1.2+)
- database-level access rules (Firebase Security Rules — including automated adversarial rule tests)
- segregation of private data (email, phone) from public data (profile)
- automated backups with a 14-day restore window
- real-time error logging and monitoring
Personal data breach notification (Art. 34 GDPR)
In the event of a personal data breach likely to result in a high risk to your rights and freedoms (e.g. leak of identifying data, unauthorised access to your private data), we will inform you without undue delay — via a push notification in the app and/or an email to the address associated with your account. The information will describe the nature of the breach, the likely consequences, the measures we have taken or propose to take, and the contact details of the Controller's point of contact (contact@feasty.com.pl). No Data Protection Officer is appointed — see section 1.
Independently of notifying users, we report every breach to the President of the Personal Data Protection Office (PUODO) within 72 hours of becoming aware of it (Art. 33 GDPR).
10. Minimum age
Feasty is available to persons aged 16 and over. We do not knowingly collect data from persons under 16. If we discover an account belongs to a person under that age, we will delete it immediately.
11. Automated decisions and profiling
We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
For fair restaurant ranking, every review is weighted by an aggregation algorithm. Your review's weight depends on (a) account age and review history, (b) your prestige rank (Standard / Elite / Connoisseur), (c) whether the visit was verified (geo-tagged photo or confirmed stamp), and (d) the review's own age (reviews older than two years count for about 15% of fresh ones). These weights affect only restaurant ranking — never decisions about your account, access to the service, or any legal consequences. Full ranking parameters are publicly disclosed to restaurant owners as required by P2B Regulation (EU 2019/1150) Art. 5.
Prestige-rank qualifying criteria (Art. 13(2)(f) GDPR — meaningful information about the logic of profiling)
The prestige rank is computed fully rule-based (NOT using AI or statistical models), based on deterministic thresholds applied per city, separately:
- Connoisseur — top 1% of Users in the city by active-review count,
- Elite — next 2–10% of Users in the city,
- Standard — everyone else.
Quality gate (entry condition for any tier above Standard, both required):
- at least 200 karma points (karma = a fully rule-based, deterministic sum of points awarded for published reviews (10–48 pts depending on completeness: photos, dish description, body length, visit verification; verified creators attaching a video review: +15 pts), likes on your review from another User (+1 pt), "helpful" votes on your review (+5 pts), first-ever review of a restaurant in the database ("Pioneer", +25 pts), and another User adopting your "Want to go" list ("Curator", +20 pts). Points are also deducted on like withdrawal (−1) or "helpful" vote withdrawal (−5). Values current as of the effective date of this Policy. Any change that materially modifies how karma is earned (e.g. adding a new rewarded behaviour category, removing an existing one, or changing values by an order of magnitude) requires a Policy update and re-consent. Minor point-value adjustments (e.g. karma-economy balancing) may be made by the Controller without a version bump — the current table is available on request at contact@feasty.com.pl),
- at least 10 published reviews.
City threshold: if fewer than 50 qualifying Users exist in a given city (meeting both quality criteria above), nobody in that city receives a rank above Standard — this protects badge meaning in low-activity cities.
Recompute cycle: the rank is re-evaluated once per week (Sunday cron). Promotion to a higher rank is immediate upon first exceeding the threshold. Demotion (loss of rank) only takes effect after a 14-day grace period — protects against weekly fluctuations in city ranking position.
Notification: we notify you of grace-period start via a push message; demotion at grace expiry is silent. Promotions are silent on the push channel (the UI surfaces the new pill anyway).
Current thresholds (200 / 10 / 50 / 14 days) are the defaults and may be tuned by the Controller in the config/prestige Firestore document. Any change that materially alters the qualification logic triggers an update of this Policy (version bump + re-consent).
12. Policy changes
This privacy policy may be updated periodically to reflect changes in how the Application works, in the law, or in how data is processed. The version and last-updated date are shown at the very top of this document. Material changes (changes to the scope of data, legal bases, categories of recipients or mechanisms for exercising your rights) will be communicated with appropriate advance notice via the Application, email or another available channel. Where applicable law requires your consent or confirmation that you have read the changes, we will ask you to take the appropriate action before continuing to use certain features of the Application. The current version accepted by you is stored in the consent log (section 6, "Exception: consent logs") — you can request an extract at any time by writing to contact@feasty.com.pl.