English · Español
BiteVote Privacy Policy
Effective date: July 12, 2026
BiteVote helps a household or small group decide what to eat. This policy describes the data the app collects, why it is used, and how deletion works. The data controller is ProspectOre LLC (Oregon, USA), the maker of BiteVote ("BiteVote", "we", "us").
Data We Collect
- Account identifiers: Firebase Auth UID, group ID, member ID, Sign in with Apple, Google Sign-In, or passwordless email-link auth linkage, provider profile name/email when provided, and email address when you use email-link account restore or submit an account-recovery deletion request.
- Email addresses in specific flows: the managing parent or guardian's email address when they add or confirm a parent-managed teen profile (used to send and verify the consent link), and email addresses used for account-restore or deletion-request notifications.
- Device and network signals for security: a hashed (non-reversible) device identifier used to prevent a removed or blocked member from evading a block by rejoining, and your IP address, which is used transiently for rate-limiting and abuse prevention and is stored only as a short-lived hash, never in raw form.
- Group content: group name, member display names, saved restaurants, saved dishes, picker candidates, votes, meal history, and the map coordinates of places you save or add (place coordinates, not your device location).
- Photos: photos you attach to meals or saved places (visible to your group), and — only if you explicitly opt in — a photo of a restaurant shared with the wider BiteVote community. Community photos are screened and de-identified before publication: metadata including any embedded location is stripped, the image is re-encoded, photos with any detectable face are refused, and no name or account identity is ever shown with a published community photo. By sharing a community photo you grant BiteVote a perpetual, worldwide, royalty-free license to publish it anonymously to the community. We keep a private record linking you to your shared photos solely so you can remove them; that private record is deleted when your account is deleted, and the photos themselves remain published anonymously unless you removed them first.
- Moderation records: reports you submit about group content or members, blocklist entries created by group owners, and related reason/details text.
- Parent-managed minor profiles: minimal proxy member records such as display name, avatar, managing adult UID, the managing parent or guardian's email address, and parental consent metadata when an adult adds a minor to a group.
- Location: approximate (coarse, roughly city-block level) device location only when you use nearby restaurant discovery. BiteVote does not request or collect precise location.
- Notifications: APNs and Firebase Cloud Messaging tokens, plus notification preferences.
- Purchase status: App Store or Google Play subscription and entitlement state for Pro organizer features, including the store transaction or purchase-token identifiers needed to verify and manage your subscription.
- Diagnostics and usage: Firebase Crashlytics crash reports, Firebase Performance traces, Firebase Analytics events, Remote Config fetches, and App Check signals.
How We Use Data
We use this data to operate the group picker, sync your group across devices, send requested notifications, enable Pro organizer features, automatically screen submitted content for objectionable material, review reported group content, block abusive members from rejoining a group, diagnose crashes, prevent abuse, and understand whether the core product flow works. Screening works in two ways: photos shared to the wider community are checked and must pass before they are ever published, while text and photos shared within your own group are screened automatically after they are submitted and are promptly removed if they violate our rules. We do not sell personal data and we do not use collected data to track you across third-party apps or websites.
Legal Bases
Where privacy law requires a legal basis, BiteVote relies on contract necessity to provide the app, legitimate interests to secure, debug, and improve the service, consent for optional notifications and device location prompts, and legal obligation for deletion, audit, tax, and app-store compliance records.
Third-Party Services
The app uses Firebase services for authentication, database storage, messaging, analytics, diagnostics, performance, remote configuration, and abuse protection. Account restore can use Sign in with Apple, Google Sign-In, or Firebase passwordless email-link auth. Nearby restaurant discovery uses Apple MapKit on Apple platforms and Google Places and Google Maps on Android. Purchases and entitlement verification use Apple App Store or Google Play services for the platform where you obtained the app. Transactional emails — the parent-managed teen consent link and account deletion notifications — are delivered through Resend, which processes the recipient email address for that purpose. Submitted content is screened for objectionable material — text via OpenAI's moderation service and images via Google Cloud Vision SafeSearch; community-shared photos are additionally screened by both Google Cloud Vision (safety, face detection, content classification) and OpenAI's image moderation, and must pass before publication.
Data Residency
Your data is stored on Firebase servers in the United States. If we expand to additional regions in the future, we will update this policy and notify users before any change to where data is stored.
International Transfers
BiteVote uses Apple and Google/Firebase infrastructure that may process records in the United States or other countries where those providers operate. For users outside the United States, that means personal data may be transferred internationally for authentication, storage, security, diagnostics, purchases, and support. Where required, BiteVote relies on the providers' transfer safeguards, such as data processing terms and standard contractual clauses.
Data Security
We protect your data with encryption in transit and at rest through our infrastructure providers, access controls, App Check attestation, automated abuse protection, and the de-identification steps described above. No method of transmission or storage is completely secure, but we work to protect your information and, if a data breach affecting your personal data occurs, we will notify affected users and the relevant authorities as required by applicable law.
Children
BiteVote does not let minors create independent accounts and does not serve targeted advertising. Parent-managed teen profiles are created by an adult in the group for meal voting only, are intentionally minimal, limited to ages 13 to 17, and can be removed through account or group cleanup flows.
The parent-managed teen-profile feature relies on verified consent from the managing parent or guardian. The adult always initiates the profile and confirms it through a verification link before any teen data is activated; the teen does not self-consent. We apply this parent-controlled process in regions with higher digital-consent ages as well as in the United States.
Data Retention
Active group content remains until a group member deletes it or an account deletion removes content authored by that account. Closed or abandoned picker sessions may be deleted by scheduled lifecycle cleanup after 90 days. A community photo you shared remains published until you remove it (Settings > Community photos) or we remove it; community photos are licensed to the community and are not removed by account deletion — deleting your account permanently severs the link between you and your shared photos, which remain published anonymously; a shared photo that fails automated screening is either deleted immediately or held privately for human review for at most 30 days and then deleted. Short-lived operational cache records expire automatically. Encrypted operational backups of our database are kept for disaster recovery on a rolling basis: each backup becomes eligible for automatic deletion 14 days after it is created and our storage provider purges it shortly thereafter, so content removed by a deletion also ages out of backups, normally within about two weeks of its removal from live systems. Diagnostics and usage data are retained per our providers' standard retention; our own operational audit events are retained for a bounded period and then expire; the minimal Terms-acceptance record and the security/anti-evasion records described under "Account and Data Deletion" are retained for as long as needed for those purposes.
Account and Data Deletion
You can delete your account in the app from Settings > Delete Account. When you are signed in, the app immediately submits a verified deletion request and signs you out; the server processes downstream deletion on its scheduled run, normally within 24 hours and always within 30 days. If you cannot sign in, you can submit a verified request that we process within 30 days (see below). Deletion removes your group membership, deletes restaurants and dishes authored by your account, removes notification tokens and parent-managed proxy members tied to your account, permanently deletes the private record linking you to community photos you shared (the de-identified photos themselves remain published anonymously under the community license unless you removed them first from Settings > Community photos), revokes your BiteVote-managed entitlement state, records minimized server-side audit events, and deletes your Firebase Auth account.
Some information is retained after deletion, for the reasons below:
- Shared group history, such as meals recorded for the group, may remain for other group members unless the entire group removes that content.
- If you were blocked or banned from a group, the moderation records and the hashed device identifier that enforce that block are retained with your identifier so a deleted-and-recreated account cannot evade it, on the basis of our legitimate interest in security and, where applicable, legal obligation. Group moderation history may retain your identifier for the same reason; our own operational audit logs have your account identifier removed.
- We keep a minimal record that you accepted our Terms of Service (the version and date, with no photo linkage) as proof of that agreement, including the community photo license.
The signed-in app submits deletion through BiteVote's protected requestAccountDataDeletion service. If you cannot sign in, email privacy@prospectorellc.com to request deletion. We will verify that you control the account before acting and process verified requests within 30 days. Do not email passwords, sign-in links, authentication tokens, or other secrets.
Access and Export
You can request a copy of your account and group-member data by emailing privacy@prospectorellc.com. BiteVote does not have a self-serve export screen in v1, so verified requests are fulfilled manually from Firebase records within the legally required response window.
Your California Privacy Rights
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you rights over your personal information. In the past 12 months we collect these statutory categories: identifiers (account, device, and network identifiers described above), customer records (name, email), commercial information (subscription/purchase status), internet or network activity (diagnostics and usage), geolocation (coarse location), and user content (photos and text you submit). We collect it from you and your device, use it for the purposes described in this policy, and disclose it only to the service providers named in "Third-Party Services" for those purposes. Precise geolocation is not collected; coarse location and other data used for security are the only data that could be considered "sensitive," and we use them only as needed to provide and secure the service.
You have the right to know and access the personal information we hold, to delete it, to correct it, to opt out of any sale or sharing, and to limit the use of sensitive personal information. We do not sell or share your personal information as those terms are defined under the CPRA, and we do not use or disclose sensitive personal information for purposes beyond providing and securing the service. We do not discriminate against you for exercising these rights. To exercise a right, use in-app account deletion or email privacy@prospectorellc.com; you may use an authorized agent, and we will verify the request against your account before acting.
Your EEA and UK Rights
If you are in the European Economic Area or the United Kingdom, you have the right to access, rectify, erase, restrict, and object to the processing of your personal data, the right to data portability, and the right to withdraw consent at any time (without affecting processing already carried out). Note that de-identified, anonymized community photos are no longer linked to you and fall outside these rights once the link is severed on account deletion, as described above. You also have the right to lodge a complaint with your local supervisory authority. The controller is ProspectOre LLC (Oregon, USA); to exercise any of these rights, email privacy@prospectorellc.com.
Other US State Privacy Rights
If you are a resident of another US state with a comprehensive consumer-privacy law (such as Oregon, Virginia, Colorado, Connecticut, Texas, or Utah), you have rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, sale, and certain profiling. We do not sell your data, serve targeted advertising, or engage in such profiling. Exercise these rights the same way — in-app deletion or privacy@prospectorellc.com.
Do Not Track and Cookies
BiteVote is a native app and does not use website cookies. It uses Firebase SDKs (Analytics, Crashlytics, Performance) rather than cross-site trackers, and does not respond to browser Do-Not-Track signals because it does not track you across other apps or websites.
Changes to This Policy
We may update this policy. If we make a material change, we will update the effective date above and, where appropriate, notify you in the app or by other reasonable means before the change takes effect.
EU Digital Services Act Contact
For EU Digital Services Act notices about illegal content or moderation decisions, contact dsa@prospectorellc.com. Communications may be sent in English. Urgent privacy and deletion requests should still use privacy@prospectorellc.com.
Language
This English page is the current public policy. Any translated summary is provided for convenience; if a translation conflicts with this policy, this English version controls.
Contact
For privacy, deletion, access, export, or correction questions, email privacy@prospectorellc.com.