mypinbite

Privacy Policy

Effective date: 5 August 2026

This Privacy Policy explains how Karim El Atab Dit El Daya ("mypinbite", "we", "us") collects, uses, and protects your information when you use the mypinbite mobile app and website (the "Service"). By using the Service, you agree to this Policy.

Questions? Contact us at privacy@mypinbite.com.

1. Who we are

mypinbite is a community food-discovery app: a map of restaurants and the dishes worth trying — researched and written by mypinbite, with community contributions — and discoverable by everyone. The person responsible for your personal data (the data controller) is Karim El Atab Dit El Daya, contactable at privacy@mypinbite.com.

2. Information we collect

a) Information you give us

  • Account data: your email address and a password (passwords are stored securely by our authentication provider — we never see them in plain text). If you sign in with Apple or Google instead, there is no mypinbite password: the provider confirms your identity and shares your email address and basic profile details — your name and, for Google, your profile photo — which we use to pre-fill your profile (you can change both at any time). With Apple you can choose to hide your email address; we then receive a private relay address instead, and the Service works normally with it.
  • Profile data: your display name, a public @handle, and an avatar photo (photo optional). Curators may additionally have a bio and a linked Instagram handle.
  • Content you create: places, dishes, reviews, ratings, and photos you publish (curators); the places you save (Favourites / Want-to-try) and the dishes and reviews you like; shared lists you create or join, the places you add to them, and the visited marks you set; list invites you send and answer; and the people you follow.
  • Decide quiz: if you use the "What should I eat?" quiz, we store your answers and the resulting shortlist, linked to your account, to improve recommendations.
  • Reports: if you flag a place, review, dish, or profile, we store the report (what you flagged and the reason you chose) linked to your account so our moderators can act on it.

b) Information collected automatically

  • Usage & device data: basic technical information needed to operate the app (e.g. app version, device type, and logs from our backend provider).
  • Crash diagnostics: if the app hits an error, it sends us a technical crash report — the error message and stack trace, your app version, and platform. Crash reports are not linked to your account and contain no content you wrote.
  • Product analytics (PostHog): we collect which screens you visit and product events — for example that a search ran (including the search text) and how many results it returned, quiz steps, and onboarding progress — linked to a random identifier that is connected to your account ID when you sign in. We also record session replays: a visual playback of the screens you moved through, in which everything you type is masked and never recorded. Analytics are hosted in the EU and used only to understand and improve the product — never for advertising.
  • Locationonly if you grant permission — to center the map on your area, show places near you, and sort results by distance. We use it only while you are using the app (when-in-use); we do not track your location in the background. You can decline or revoke this in your device settings, and the app still works without it (the map simply frames all places instead).
  • Search queries: the text you type into search is sent to our AI providers (see §6) to interpret natural-language queries (e.g. "cheap date-night sushi in Marina") into structured filters and to match them against places by meaning. We send only your query text, not your identity.
  • Push notificationsonly if you grant permission — we store your device's push token (an identifier issued by Apple/Expo for delivering notifications) linked to your account, so we can notify you about things like list invites, people joining your lists, and new followers. The token is deleted when you sign out, and you can stop notifications at any time in your device settings — the in-app notification inbox keeps working either way.
  • Local storage: we store your login session on your device so you stay signed in.

c) Photos If you add a photo, the app asks permission to access your photo library; we only upload the image(s) you choose.

d) Research records about people who aren't users Our catalog is researched from public sources. As part of that research we keep internal records about the food writers whose public coverage we read: their name, public handle, where they published, and our own paraphrase of what they said. These records are never displayed in the app or on the website — they exist so we can stand behind our editorial content and, if a writer later chooses opt-in attribution, honour the provenance of their picks. We rely on our legitimate interest in editorial research over publicly available information. If you are such a writer and want your records corrected or removed, contact privacy@mypinbite.com and we will act on it.

We do not use advertising trackers, and we do not process payments in the Service.

3. How we use your information

We use your information to:

  • create and manage your account and keep you signed in;
  • provide the core Service (show the map, dishes, reviews, search, saves, likes, shared lists, invites, follows, and the decide quiz);
  • show the content you post (reviews, photos, community places, shared-list additions) under your profile — and, for curators who join the opt-in attribution programme, attribute their published picks to them;
  • understand how the app is used and improve it (see the analytics section above);
  • maintain safety and integrity (prevent abuse, review reports, fix crashes, enforce our Terms);
  • communicate with you about the Service (e.g. account or security notices);
  • comply with legal obligations.

4. Legal bases (where applicable)

Where the UAE PDPL, GDPR, or similar laws apply, we rely on: performance of a contract (to provide the Service you request), your consent (e.g. for location access), our legitimate interests (to operate, secure, and improve the Service), and legal obligation (to meet legal requirements).

5. What is public vs. private

  • Public: every account has a public profile — your display name, @handle, and avatar — which other users can find in people search and view. Curators' profiles additionally show their bio, Instagram link, and everything they publish (places, dishes, reviews, ratings, photos).
  • Private: your email address is never shown publicly. Your saved places (Favourites / Want-to-try) and your quiz answers are visible only to you. Likes and upvotes are displayed only as totals. We do not show other users whom you follow or who follows you; follows are used to build your own Following feed.
  • Shared lists sit in between: the list's name, its places, who added what, visited marks, and the member list (each member's public profile) are visible to every member of that list. Pending invitees are shown to members until the invite is answered. Anyone who has a list's invite link can see a small preview — the list's name, owner name, and member count — before joining, so share invite links only with people you trust.
  • Administrators can access user emails only through restricted internal tools for legitimate operational reasons.

6. How we share information

We don't sell your personal data. We share it only with:

  • Service providers who run our infrastructure on our behalf:
  • Supabase — database, authentication, and file storage (hosted in the EU — Ireland). Crash reports are stored here too.
  • MapTiler — map tiles (their maps include OpenStreetMap data). Map requests may reveal your approximate map view to the tile provider.
  • Anthropic — interprets your natural-language search queries into filters, and drafts place descriptions and tags when a place is added. Only the query or place text is sent (no account or location data). Per Anthropic's API terms, this input is not used to train their models.
  • Voyage AI — computes text embeddings for semantic search: receives your search query text and the text of place listings, nothing else.
  • PostHog — product analytics and session replay, as described in §2, hosted in the EU.
  • Foursquare — when you search for a place to add, the place-name query is sent to Foursquare's places database to find matches.
  • Sign-in providers (Apple, Google) — only if you choose Sign in with Apple or Sign in with Google: your sign-in happens directly with that provider, which confirms your identity to us and learns that you use the Service. Their handling of your data is governed by their own privacy policies.
  • App stores (Apple App Store, Google Play) for app distribution.
  • Authorities, if required by law or to protect rights, safety, or the integrity of the Service.

7. Data retention

We keep your information for as long as your account is active or as needed to provide the Service. You can delete your account at any time in the app (Profile → Delete account). Doing so permanently deletes your account, profile, saved places, likes, follows, quiz sessions, list memberships and invites, and the shared lists you own — and, for curators, the places, dishes, and photos you published. Reports you filed are kept (for safety) but are disconnected from your identity; crash reports are never linked to it. Analytics events and session replays are retained by our analytics provider for a limited period. Residual copies may persist in our service providers' backups for a limited period, and we may retain information where required for legal reasons.

8. Security

We use industry-standard measures, including database Row-Level Security, encrypted connections, and restricted administrative access, to protect your data. No system is 100% secure, but we work to safeguard your information.

9. Your rights

Depending on your location, you may have the right to: access a copy of your data, correct it, delete it, object to or restrict certain processing, withdraw consent, and port your data. To exercise any of these, email privacy@mypinbite.com. You may also lodge a complaint with your local data-protection authority.

You can edit your profile and delete your account directly in the app at any time (Profile → Edit profile, Profile → Delete account) — no need to contact us, though you can also exercise any of these rights by email.

10. International transfers

Our backend and analytics are hosted in the EU (Ireland). If you access the Service from another country (for example the UAE, where the app is focused), your data is transferred to and processed there. Where required, we use appropriate safeguards for such transfers.

11. Children

The Service is not directed to children under 13, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.

12. Third-party links

The Service may link to third-party sites (e.g. a curator's Instagram, a restaurant's site). We are not responsible for their privacy practices; review their policies separately.

13. Changes to this Policy

We may update this Policy. We will post the new version with a revised effective date and, for material changes, provide additional notice in the app.

14. Contact

Karim El Atab Dit El Dayaprivacy@mypinbite.comhttps://mypinbite.com