Privacy Policy

Last updated: August 5, 2026

Food Loot (the "Service") is a restaurant review app, available as a mobile application and through this website, www.foodloot.app. This policy describes the data processed by the Service and the rights you have over it.

The short version: no ads, no ad-tech, no sale of data, no analytics on this website. Food Loot collects the minimum it needs to work — an optional account, the reviews and lists you choose to sync, and short-lived technical logs. If you use "find friends", your phone number and your contacts' numbers are never sent to us in readable form, and your contacts' names are never sent at all.

1. Who runs Food Loot

The Service is published by a private individual based in France. For any question about this policy or to exercise your rights, write to contact@foodloot.app.

2. Data we process

2.1 Account (optional)

Food Loot works without an account. If you create one — to sync your reviews and lists across devices — we process:

Your email address is used solely to operate the account: confirmation, sign-in, and password reset. It is never used for marketing and never shared.

2.2 Your content

Reviews, photos, and saved place lists are stored on your device first. When you are signed in, they are also synced to our servers so they can follow you across your devices. Review photos are stored under unguessable random identifiers. Your content stays yours — see the Terms of Use.

2.3 Location

The "around you" features send your approximate position to our servers to answer that one query (finding nearby places), only when you use them and only after you grant the system-level location permission. Your position is not stored in any profile and is not used to build any movement history; at most it transits the short-lived technical logs described below.

2.4 Finding friends from your contacts (optional)

Food Loot can tell you which of the people in your address book already use the app. The feature is entirely optional: it never runs unless you start it, declining it leaves every other part of the app working, and you can turn it off again at any time from your profile.

Your own phone number. You may enter your number so that friends who already have it can find you. It is not sent to us. Your device converts it into an irreversible token first, using a cryptographic protocol (an oblivious pseudorandom function) in which our server helps compute the token without ever seeing the number or anything we could turn back into it. We store only that token, linked to your account. Entering a number is optional — you can run the feature without it, in which case you simply will not be findable this way.

Your contacts. The names and phone numbers in your address book stay on your device. We never receive them. Your device turns each number into a token by the same method and sends only those tokens, so that we can tell it which ones belong to accounts. Your contacts' names are never uploaded: the app matches a result back to a name locally, on your device.

Contacts who are not members. For numbers that match no account, we keep the token — and nothing else, not the number and not a name — so we can tell you if that person joins later. These tokens cannot be reversed into phone numbers without the secret key, which we hold and use only to run the matching described here.

Turning it off. The "disable contact discovery" switch in your profile stops you appearing in anyone's results and stops the related notifications. Deleting your account deletes your token along with the rest of your data. We record when you gave consent and to which version of the wording, as our accountability record under GDPR article 5(2).

No background sync. The app never uploads your address book in the background: discovery runs only when you ask for it, and only for as long as that one check takes.

2.5 Who you follow

If you follow other users, we store the follow relationship so we can build your wall from the reviews of the people you follow. Follows are not published as a public profile page.

2.6 Technical logs

Like any online service, our servers automatically receive technical data (IP address, user agent, request paths, timestamps). These logs are kept for a maximum of 30 days, for security purposes only (abuse detection, attack prevention), and are then deleted automatically.

2.7 Crash reports

The app uses Sentry (Functional Software, Inc.), configured with its European Union data centre, to receive crash reports: device model, operating system version, and the technical state of the app at the moment of the crash. These reports are used exclusively to find and fix bugs, and are retained by Sentry for 90 days. See Sentry's privacy policy.

3. What we don't do

4. Where your data lives

The Service is hosted on a server operated by Scaleway (Online SAS) in the European Union. Transactional email (account confirmation, password reset) is sent through Infomaniak, a Swiss provider. Both are bound by data-processing terms consistent with the GDPR.

5. How long we keep data

6. Your rights

Under the General Data Protection Regulation (GDPR) and the French Data Protection Act, you have the right to access, rectify, and erase your data, and the rights to object to and restrict its processing, as well as a right to portability. To exercise any of these rights, contact contact@foodloot.app.

You also have the right to lodge a complaint with the French supervisory authority, the CNIL: www.cnil.fr.

7. Changes to this policy

This policy may evolve to reflect changes in the Service or in regulation. The date of the latest update appears at the top of this page.