English · Español

BiteVote Privacy Policy

Effective date: July 12, 2026

BiteVote helps a household or small group decide what to eat. This policy describes the data the app collects, why it is used, and how deletion works. The data controller is ProspectOre LLC (Oregon, USA), the maker of BiteVote ("BiteVote", "we", "us").

Data We Collect

How We Use Data

We use this data to operate the group picker, sync your group across devices, send requested notifications, enable Pro organizer features, automatically screen submitted content for objectionable material, review reported group content, block abusive members from rejoining a group, diagnose crashes, prevent abuse, and understand whether the core product flow works. Screening works in two ways: photos shared to the wider community are checked and must pass before they are ever published, while text and photos shared within your own group are screened automatically after they are submitted and are promptly removed if they violate our rules. We do not sell personal data and we do not use collected data to track you across third-party apps or websites.

Legal Bases

Where privacy law requires a legal basis, BiteVote relies on contract necessity to provide the app, legitimate interests to secure, debug, and improve the service, consent for optional notifications and device location prompts, and legal obligation for deletion, audit, tax, and app-store compliance records.

Third-Party Services

The app uses Firebase services for authentication, database storage, messaging, analytics, diagnostics, performance, remote configuration, and abuse protection. Account restore can use Sign in with Apple, Google Sign-In, or Firebase passwordless email-link auth. Nearby restaurant discovery uses Apple MapKit on Apple platforms and Google Places and Google Maps on Android. Purchases and entitlement verification use Apple App Store or Google Play services for the platform where you obtained the app. Transactional emails — the parent-managed teen consent link and account deletion notifications — are delivered through Resend, which processes the recipient email address for that purpose. Submitted content is screened for objectionable material — text via OpenAI's moderation service and images via Google Cloud Vision SafeSearch; community-shared photos are additionally screened by both Google Cloud Vision (safety, face detection, content classification) and OpenAI's image moderation, and must pass before publication.

Data Residency

Your data is stored on Firebase servers in the United States. If we expand to additional regions in the future, we will update this policy and notify users before any change to where data is stored.

International Transfers

BiteVote uses Apple and Google/Firebase infrastructure that may process records in the United States or other countries where those providers operate. For users outside the United States, that means personal data may be transferred internationally for authentication, storage, security, diagnostics, purchases, and support. Where required, BiteVote relies on the providers' transfer safeguards, such as data processing terms and standard contractual clauses.

Data Security

We protect your data with encryption in transit and at rest through our infrastructure providers, access controls, App Check attestation, automated abuse protection, and the de-identification steps described above. No method of transmission or storage is completely secure, but we work to protect your information and, if a data breach affecting your personal data occurs, we will notify affected users and the relevant authorities as required by applicable law.

Children

BiteVote does not let minors create independent accounts and does not serve targeted advertising. Parent-managed teen profiles are created by an adult in the group for meal voting only, are intentionally minimal, limited to ages 13 to 17, and can be removed through account or group cleanup flows.

The parent-managed teen-profile feature relies on verified consent from the managing parent or guardian. The adult always initiates the profile and confirms it through a verification link before any teen data is activated; the teen does not self-consent. We apply this parent-controlled process in regions with higher digital-consent ages as well as in the United States.

Data Retention

Active group content remains until a group member deletes it or an account deletion removes content authored by that account. Closed or abandoned picker sessions may be deleted by scheduled lifecycle cleanup after 90 days. A community photo you shared remains published until you remove it (Settings > Community photos) or we remove it; community photos are licensed to the community and are not removed by account deletion — deleting your account permanently severs the link between you and your shared photos, which remain published anonymously; a shared photo that fails automated screening is either deleted immediately or held privately for human review for at most 30 days and then deleted. Short-lived operational cache records expire automatically. Encrypted operational backups of our database are kept for disaster recovery on a rolling basis: each backup becomes eligible for automatic deletion 14 days after it is created and our storage provider purges it shortly thereafter, so content removed by a deletion also ages out of backups, normally within about two weeks of its removal from live systems. Diagnostics and usage data are retained per our providers' standard retention; our own operational audit events are retained for a bounded period and then expire; the minimal Terms-acceptance record and the security/anti-evasion records described under "Account and Data Deletion" are retained for as long as needed for those purposes.

Account and Data Deletion

You can delete your account in the app from Settings > Delete Account. When you are signed in, the app immediately submits a verified deletion request and signs you out; the server processes downstream deletion on its scheduled run, normally within 24 hours and always within 30 days. If you cannot sign in, you can submit a verified request that we process within 30 days (see below). Deletion removes your group membership, deletes restaurants and dishes authored by your account, removes notification tokens and parent-managed proxy members tied to your account, permanently deletes the private record linking you to community photos you shared (the de-identified photos themselves remain published anonymously under the community license unless you removed them first from Settings > Community photos), revokes your BiteVote-managed entitlement state, records minimized server-side audit events, and deletes your Firebase Auth account.

Some information is retained after deletion, for the reasons below:

The signed-in app submits deletion through BiteVote's protected requestAccountDataDeletion service. If you cannot sign in, email privacy@prospectorellc.com to request deletion. We will verify that you control the account before acting and process verified requests within 30 days. Do not email passwords, sign-in links, authentication tokens, or other secrets.

Access and Export

You can request a copy of your account and group-member data by emailing privacy@prospectorellc.com. BiteVote does not have a self-serve export screen in v1, so verified requests are fulfilled manually from Firebase records within the legally required response window.

Your California Privacy Rights

If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you rights over your personal information. In the past 12 months we collect these statutory categories: identifiers (account, device, and network identifiers described above), customer records (name, email), commercial information (subscription/purchase status), internet or network activity (diagnostics and usage), geolocation (coarse location), and user content (photos and text you submit). We collect it from you and your device, use it for the purposes described in this policy, and disclose it only to the service providers named in "Third-Party Services" for those purposes. Precise geolocation is not collected; coarse location and other data used for security are the only data that could be considered "sensitive," and we use them only as needed to provide and secure the service.

You have the right to know and access the personal information we hold, to delete it, to correct it, to opt out of any sale or sharing, and to limit the use of sensitive personal information. We do not sell or share your personal information as those terms are defined under the CPRA, and we do not use or disclose sensitive personal information for purposes beyond providing and securing the service. We do not discriminate against you for exercising these rights. To exercise a right, use in-app account deletion or email privacy@prospectorellc.com; you may use an authorized agent, and we will verify the request against your account before acting.

Your EEA and UK Rights

If you are in the European Economic Area or the United Kingdom, you have the right to access, rectify, erase, restrict, and object to the processing of your personal data, the right to data portability, and the right to withdraw consent at any time (without affecting processing already carried out). Note that de-identified, anonymized community photos are no longer linked to you and fall outside these rights once the link is severed on account deletion, as described above. You also have the right to lodge a complaint with your local supervisory authority. The controller is ProspectOre LLC (Oregon, USA); to exercise any of these rights, email privacy@prospectorellc.com.

Other US State Privacy Rights

If you are a resident of another US state with a comprehensive consumer-privacy law (such as Oregon, Virginia, Colorado, Connecticut, Texas, or Utah), you have rights to access, correct, delete, and obtain a portable copy of your personal data, and to opt out of targeted advertising, sale, and certain profiling. We do not sell your data, serve targeted advertising, or engage in such profiling. Exercise these rights the same way — in-app deletion or privacy@prospectorellc.com.

Do Not Track and Cookies

BiteVote is a native app and does not use website cookies. It uses Firebase SDKs (Analytics, Crashlytics, Performance) rather than cross-site trackers, and does not respond to browser Do-Not-Track signals because it does not track you across other apps or websites.

Changes to This Policy

We may update this policy. If we make a material change, we will update the effective date above and, where appropriate, notify you in the app or by other reasonable means before the change takes effect.

EU Digital Services Act Contact

For EU Digital Services Act notices about illegal content or moderation decisions, contact dsa@prospectorellc.com. Communications may be sent in English. Urgent privacy and deletion requests should still use privacy@prospectorellc.com.

Language

This English page is the current public policy. Any translated summary is provided for convenience; if a translation conflicts with this policy, this English version controls.

Contact

For privacy, deletion, access, export, or correction questions, email privacy@prospectorellc.com.