Skip to content

/ Legal — Privacy

Privacy policy.

LAST UPDATED · MAY 25, 2026

TasteTrail ("the App," "we," "us," or "our") is operated by Nishant Joshi, an individual based in New Jersey, USA, doing business as "TasteTrail." This Privacy Policy explains what information we collect through the TasteTrail mobile application and related backend services (collectively, "the Service"), how we use it, who we share it with, and the choices you have.

By using the Service, you consent to the practices described below. If you do not agree, please do not use the Service.

01

Information we collect

Account information

  • Email address: required to create an account and sign in. The App uses passwordless authentication — we send a one-time code (OTP) to your email and never receive, store, or process a password.
  • Username: a public 3–30 character handle you choose (letters, numbers, underscore, hyphen). Displayed with your reviews, collections, and shared content.
  • Full name (optional): a private display name shown in your own profile. Not required and not shown publicly unless you choose to share content.
  • OAuth profile data: if you sign in with Google or Apple, we receive your email and basic profile info from that provider. We never receive your Google or Apple password. If you use Apple's "Hide My Email" relay, we only ever see the relay address.

User-generated content

  • Reviews: rating (1–5 stars), optional text, and up to 5 optional photos per review. Reviews are publicly viewable and attributed to your username.
  • Favorites: recipes and restaurants you save, kept on your account so they sync across devices.
  • Collections: user-curated groups of recipes/restaurants with an optional name, description, and cover photo. Collections are private by default; sharing one generates a public link (see §3.3).
  • Shopping lists: ingredient items you add manually or import from a recipe.
  • Photos: review photos and collection covers you upload are stored in Supabase Storage. Review photos live in a public bucket so they can render alongside the reviews; URLs are not directory-listable but are not secret.

Preference & personalization data

During onboarding (or in Preferences later) you may tell us your dietary preferences, food intolerances, favorite cuisines, cooking skill, and cooking frequency. We use this to personalize recommendations.

Intolerance and allergy entries are treated as personal data and are used purely as a filter — they are not a medical safety guarantee and are not shared with third parties.

Location data

With your explicit permission, we use your device's foreground location to find nearby restaurants. We do not run background location tracking. Coordinates are used per request and are not written to our database beyond what is needed to fulfill that request.

If you deny location access, restaurant discovery features will be limited, but other app features will remain available.

Automatically collected data

  • Product analytics (Amplitude): screen views, taps, search terms, feature usage. We do not send review text, photo contents, or your email to Amplitude.
  • Crash reports (Sentry, when enabled): exception stack traces and minimal device context. We disable Sentry's default PII collection.
  • Push notification token (OneSignal): an opaque device token used to deliver notifications, only if you grant permission.
  • Device & technical data: app version, OS version, device model, language — used for debugging and compatibility.

Third-party API data

  • Spoonacular: recipe queries are sent to Spoonacular through our backend. Only the recipes you explicitly save (favorites, collections, shopping-list imports) are persisted on our side.
  • Google Places: restaurant searches are sent through our backend to Google Places. We persist only what you save (favorites, collections).
  • Google Gemini: when generating step-by-step images for a recipe, the recipe step text is sent to Google's Gemini API. The resulting images are cached in our Storage so we don't regenerate them on every view.
02

How we use your information

  • Provide and operate the App (auth, search, reviews, collections, shopping lists).
  • Personalize recommendations based on your preferences.
  • Sync your data across the devices you sign in on.
  • Send transactional messages (OTP codes, notifications you opt into).
  • Diagnose crashes and improve performance.
  • Detect abuse and enforce the Terms of Service.
  • Comply with legal obligations.
03

How we share your information

Service providers

We use the following processors to run the Service. Each receives only the data needed for its function:

  • Supabase — Postgres database, authentication, file storage. Privacy policy: supabase.com/privacy.
  • Spoonacular — recipe search and metadata.
  • Google Places & Google Gemini — restaurant data and AI generation of recipe step images.
  • Amplitude — product analytics. amplitude.com/privacy.
  • OneSignal — push notification delivery. onesignal.com/privacy_policy.
  • Sentry (when enabled) — crash reporting.

Publicly visible content

Reviews, ratings, attached review photos, and your username are publicly visible inside the App. Do not put anything in them you would not want anyone to see.

Share links

When you share a recipe, restaurant, or collection, we generate a short code that resolves through our website at tastetrail.nishantjoshi.me. Anyone with the link can view the target. We log an aggregate click count per link.

Legal disclosures

We may disclose information if required by law, subpoena, or court order, or where we believe disclosure is necessary to protect rights, safety, or to investigate fraud or abuse.

Business transfers

If the Service is ever transferred to another operator, your information may transfer as part of that transaction. We will notify you of any material change in ownership through the App.

No sale of personal information

We do not sell your personal information and we do not show third-party advertising.

04

Content moderation

Photos you upload are automatically screened on our backend before becoming visible. The screening pipeline includes file-format validation, decompression-bomb protection, and an open-source NSFW image classifier. Uploads that fail screening are rejected.

You can report any review, photo, collection, or user that violates the Terms by emailing contact@nishantjoshi.me. We aim to act on reports within 24 hours and may remove content or suspend accounts that violate the Terms.

05

AI-generated content

Some recipe step images are generated on demand by Google Gemini. To generate them we send the recipe step text to Google's API. Generated images may contain inaccuracies — they are illustrative and not a substitute for the written instructions or for professional advice.

06

Data stored on your device

If you save recipes for offline use, the recipe data and a copy of its images are stored locally on your device (via SQLite and the device file system). Offline data never leaves your device unless you re-sync actions you took while offline (e.g., reviews you wrote without connectivity). All on-device data is removed when you sign out or uninstall the App.

07

Your choices & rights

Access & update

You can view and edit your profile, preferences, favorites, reviews, collections, and shopping lists from within the App at any time.

Delete your account

You can delete your account in-app from Settings → Account. Deletion removes your profile, reviews, photos, favorites, collections, and shopping lists. Backups are purged within 30 days. Anonymous aggregate analytics events may persist.

Export

Email contact@nishantjoshi.me for a copy of the personal data tied to your account.

Notifications & location

You can revoke push notification or location permissions at any time from your device's system settings.

Regional rights (GDPR, UK GDPR, CCPA)

Depending on where you live, you may have additional rights such as access, rectification, erasure, portability, restriction, objection, and the right to lodge a complaint with a supervisory authority. To exercise any of these, email contact@nishantjoshi.me.

08

Data security

All traffic between the App, our backend, and Supabase is encrypted in transit (TLS). Authenticated requests are verified with signed JWTs. Storage uploads are constrained by per-user folder rules. Uploaded images are validated and moderated server-side before being made visible. No system is perfectly secure, so we cannot guarantee absolute security.

09

Data retention

  • Account, profile, preferences: until you delete your account.
  • Reviews, photos, collections, shopping lists: until you delete them or your account.
  • AI step-image cache: up to 90 days, or until the source recipe is removed from our cache.
  • Analytics events: in line with the provider's retention defaults.
  • Crash reports (Sentry, when enabled): up to 90 days.
  • Backups after account deletion: purged within 30 days.
10

Children's privacy

The Service is not directed to children under 13 and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.

11

International data transfers

Our backend and the providers listed in §3.1 operate in the United States and other regions. If you use the App from outside the United States, your information will be processed in the United States and possibly elsewhere. By using the Service you consent to those transfers.

12

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last Updated" date above and, where appropriate, by notifying you in-app. Continued use of the Service after a change means you accept the updated Policy.

13

Contact

Questions or requests about this Policy:

/ Acknowledgment

By using TasteTrail, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and sharing of your information as described herein.