Privacy Policy
Privacy Policy
Fava (the “Service”) lets users record notes about restaurants they have visited and share them with the audience they choose. This policy explains how the Service handles user information.
Information we may collect
- Account information, including display name, bio, profile image, display language, email address, and authentication identifiers
- Restaurant records, including restaurant, cuisine, amount, party size, atmosphere, tags, notes, visibility, date created, and visit photos
- Following relationships
- Location information, with permission, for nearby maps, restaurant search, help creating visit records, and optional nearby want-to-go suggestions
- Notification preferences, a device push identifier, device platform, and minimal delivery history used to avoid repeated suggestions
- Images selected or captured for receipt analysis, visit records, and profile images
- Usage, crash, diagnostic, security, and support information
- Payment and sale information, including product ID, purchase time, entitlements, refund or revocation status, transaction identifiers, sale setup, price tier, the accepted Creator Terms version and time, and information needed to calculate and pay Creator proceeds
Bounded product analytics
To improve the Service, Fava may record a limited set of actions: saving a visited restaurant from search, saving or visiting a restaurant from another user's recommendation, creating a collection or adding a restaurant to one, and creating a draft sale package. These actions may be linked to the account and the relevant restaurant, record, collection, or package.
These analytics records do not store search text, partial keystrokes, result impressions, precise device location, movement history, photos, note text, or arbitrary free-form data. User-linked analytics records are deleted after 90 days. Account deletion removes both actions performed by that user and actions attributed to that user's source records. Weekly or monthly aggregates that contain at least three contributors and do not identify an individual may be retained longer to analyze Service trends.
Authentication with external accounts
When you sign in with X, Fava retains only the fact that X is the authentication provider and a Fava-internal identifier derived from the X identifier using a server-only secret. Fava does not store, copy, or publish the raw X identifier, X username, or X display name in your Fava profile.
Fava does not request your X password, the email address registered with X, posts, Direct Messages, or follower/following lists. X access tokens and secrets are not retained as account information. Short-lived authentication material is encrypted and removed immediately after use or after expiration. The operator's personal X account information is not embedded in the sign-in screen or user data.
How we use information
- Provide and maintain food maps, profiles, restaurant search, and visit records
- Create a draft record from a receipt image
- Provide following and visibility controls
- Authenticate users, prevent abuse, and protect the Service
- Handle reports, blocks, support requests, and account deletion
- Improve quality, investigate failures, and comply with law and these terms
- Use bounded action records and non-identifying aggregates to understand whether search, recommendations, and collections help users
- Send nearby want-to-go suggestions at lunch or dinner only when the user enables them
- Configure place-collection sales, verify purchases, provide purchased editions, handle refunds or revocations, calculate Creator proceeds, and perform identity, tax, and payout operations
Visibility of records
Each record uses the visibility selected by the user. The initial release supports private records and records visible to followers. Fava is not designed as an anonymous public review board.
Before a follow relationship is established, profiles generally show limited information such as name, bio, and record count. When viewing another person's visit note, the visit year may be shown instead of the exact date.
A follow link or QR code contains an internal user ID needed to identify the account to follow.
When a follower-visible restaurant record is shared outside Fava, the link contains an unguessable sharing identifier. The web page shows only limited information such as restaurant name, address, the author's display name, and a Google Maps link. It does not show the visit note, photos, amount, visit date, or other record details. Full details are available only after signing in to Fava and after the current follow relationship, visibility, and block status have been checked. Revoking the link, deleting the record, or making the record private also makes the shared link unavailable.
Location
Location is used only for nearby map context, restaurant search, and assistance when creating a visit record. You can disable location access in your device settings.
Nearby want-to-go suggestions are off by default. If you enable them, Fava stores only the latest location acquired while you use the app and uses it to choose an optional lunch or dinner suggestion. Fava does not create a route or location timeline and does not collect location in the background. A stale location is not used for a notification. Turning the feature off or deleting the account removes the notification preference, latest location, and push identifier.
Receipts and photos
A receipt may be analyzed to extract details such as restaurant name, date, and amount. A draft created from a receipt is not shared until the user reviews and saves it. Visit and profile photos are stored only when the user chooses or captures them.
Payments and Creator sales
Native-app purchases use Apple In-App Purchase or Google Play Billing. Fava does not directly store card numbers or security codes. It stores information needed to provide the product and handle support, such as entitlements, product IDs, transaction identifiers, and refund or revocation status.
For Creators selling place collections, Fava may process acceptance records for the Creator Terms, price tiers, information needed to calculate Net Sales and Creator proceeds, identity and tax verification, payout accounts, transfers, and fraud prevention. If a third party performs identity verification or payouts, Fava provides the information needed for that service. The provider and any additional handling will be disclosed before production sales begin.
Service providers
Fava may use Google Cloud, Firebase, Google Maps Platform, Document AI, Expo push delivery, Apple, Google, LINE, X, and app-store distribution services for authentication, maps, restaurant information, image analysis, storage, diagnostics, notifications, and delivery.
Disclosure
We do not disclose user information to third parties except with consent, when required by law, or to service providers as necessary to operate the Service.
Retention and deletion
We retain information only for as long as necessary for the purposes described above. User-linked bounded product analytics records are deleted after 90 days. When an account is deleted, related data is deleted or anonymized within a reasonable period, except where retention is required by law or reasonably necessary for security and abuse prevention. Weekly or monthly aggregates with at least three contributors that do not identify an individual may be retained longer to analyze Service trends.
Your choices and rights
You can edit or delete records and request access, correction, or deletion of account information through the app or support. Depending on your jurisdiction, additional rights may apply. Contact us to exercise those rights.
Children
Minors must obtain permission from a parent or guardian before using the Service.
Changes and contact
Material changes will be announced in the app or on the official website. Contact support@favamaps.com with privacy questions.