Privacy Policy

Last updated 22 August 2026

This explains what Tastbudz LLC ("Tastbudz", "we", "us") collects when you use Tastbudz, why we collect it, who else sees it, and what you can ask us to do about it.

The short version

  • Your profile and your ratings are public by default. You can change both in Settings.
  • We run no third-party analytics, tracking or advertising. There is no Google Analytics, no advertising pixel, no session recording and no fingerprinting on Tastbudz. We do keep our own counts — how many people used the site on a given day, which broad parts were read, and what was searched for — as daily totals on our own servers. Two first-party cookies support this: one is the same fixed value for every visitor and only tells us a browser was already counted today; the other holds a random identifier so we can tell that a browser has returned on a later day, which is how we measure whether Tastbudz is useful enough that people come back. Neither is used for advertising, neither leaves Tastbudz, and neither is combined with your name or email unless you create an account — see “How we count visitors” below for exactly what that identifier can and cannot do.
  • Share links. Sharing from Tastbudz gives you a short tbudz.me link. We count how many times each link is opened, as daily totals, without recording who opened it. If you create an account after opening a friend’s link we record that they introduced you, so we can thank them; nothing else about your visit is tied to the link.
  • We never store your raw IP address in our database. Where we need it for abuse prevention, we store a salted hash of the network block and delete it after 30 days.
  • Photo metadata is stripped on upload. GPS coordinates, camera serial numbers and timestamps are removed before a photo is stored.

1. Information you give us

Creating an account. Your email address, a username, a display name and a password (stored only as a hash — we never see or keep the password itself). If you sign in with Google, we receive your Google account identifier, email address, name and whether Google has verified that email; we do not receive or store your Google password, and we do not keep Google access tokens.

Your profile. Optionally a short bio, a city and state, and a profile picture.

Preferences. Your privacy settings, an optional spice tolerance, and any dietary preferences you select. Some dietary options may reveal information about your religion (for example halal or kosher) or your health (for example gluten free or dairy free). We use them only to tailor what we show you, and they are not displayed on your profile.

A note on email addresses. Alongside the address you give us, we store a normalised form of it — lower-cased, with provider-specific aliases such as +tags removed. This lets us tell that two sign-ups belong to the same mailbox, which is how we prevent one person from quietly operating several accounts. It means an alias will not create a separate identity here.

2. What you contribute

Ratings (an overall score plus optional taste, presentation and value scores), the notes you write, the date you say you visited, photos you upload, dishes and restaurants you submit, corrections you propose, lists you create, and which ratings you have marked helpful.

Ratings keep their history. Re-rating a dish does not overwrite your earlier rating — it supersedes it. The earlier version, including its note and photos, is retained so that the record of what you thought at the time stays intact.

Photos. When you upload a photo we strip its embedded metadata before storing it. That removes GPS coordinates, camera make, model and serial number, timestamps and any embedded thumbnail. The only field we deliberately keep is the orientation flag, without which photos display rotated. Note that the original file is uploaded directly to our storage provider and the metadata is removed immediately afterwards, so the unmodified file exists briefly before it is overwritten. Stripping metadata does not change the picture itself — anything visible in the image is still visible.

3. Technical and usage information

IP addresses. We do not store your IP address in our database. When you submit content, we record a salted, one-way hash of your network block (the first three parts of an IPv4 address) so we can detect abuse coming from one source without being able to recover the address. Those records are deleted automatically after 30 days. Your IP is also used transiently, in memory, to enforce rate limits, and may appear in server logs when a request is rejected for hitting an authentication rate limit.

Activity signals. We record certain events tied to your account: when you follow a link to an ordering provider, when you earn an achievement, when gamification features are shown to you, when you searched on a given day, and — once, at signup — how you found Tastbudz (for example, an invitation, or arriving from a search engine or social platform) and a coarse market area (for example, San Diego) resolved from your IP address or the restaurant you were viewing, never precise coordinates. We use these to understand which dishes, restaurants and markets draw interest and to decide what to build next. These records do not currently expire.

Session activity. Separately, we record what happens on a page so we can tell whether the site is any good at its job: which dish you tapped from a list of results and what else was in that list, when a link out to a restaurant's own site or phone number is followed, and when a rating is begun. These records carry no account and no visitor identifier. They are grouped by a random key derived fresh each day, so events from one visit can be read together and events from different days cannot be connected — not as a matter of policy, but because the key is not the same key. Signing in does not change what is recorded: the same row is written either way.

We keep these raw records for 13 months and then delete them; the daily totals derived from them are kept. What they are for is ordinary and worth stating plainly: knowing which dish someone picked out of ten is the only way to tell whether the ten were in a sensible order.

Location. Tastbudz shows dishes near you. Your location may come from three places: your browser's location service if you allow it (those coordinates stay in your browser and are sent only as search parameters, never stored on your account); an approximate city derived from your IP address; or the city on your profile. You can override all of these with the city picker. The IP lookup is resolved either by our content delivery network as it serves the page, or on our own servers from a local database — either way your IP is not sent to a third-party geolocation service, and we do not store it. We use the result to pick a sensible default city and, if you are outside the area our menus cover, to say so once.

No third-party analytics or tracking. We do not use analytics platforms, advertising networks, tracking pixels, session-recording tools or device fingerprinting, and no third party receives your activity on Tastbudz.

Our own aggregate counts. So that we can tell whether the service is working and what is missing from it, our servers keep a small set of daily totals: how many signed-in accounts were active on a calendar day, how many pages were served and to which broad part of the site, and which search terms were typed — including the ones that found nothing, which is how we learn what to add.

These are counts, and their shape is what protects you. For a signed-in account, our daily active-user total records at most that the account was active on a given date — not what was read or from where; the separate activity signals described above are the only account-tied records that carry a specific action, and are limited to the list given there. Counts of pages served and of searches by anonymous visitors carry no account, no identifier and no IP address at all, so they cannot be traced back to a person, by us or by anyone we might be compelled to answer. We do not build a profile of you or follow you across other websites. The one per-visitor record we do keep — the return-visit identifier described just below — holds nothing but a random token and a pair of dates; it is never disclosed or sold, and it is not personal information unless and until you attach it to an account by signing up.

How we count visitors. We use two first-party cookies for this, and they do different jobs.

The first expires at midnight and holds a single fixed character, identical for every visitor — it can only tell us “this browser has already been counted today”, cannot distinguish you from anyone else, and cannot be read by any other website. It backs the fully anonymous page- and search-count totals described above.

The second, newer cookie holds a random identifier and lasts up to 12 months, renewed each time you visit. It lets us recognize that the same browser has returned on a later day, which is the only way to answer questions like “do people come back to Tastbudz” and “how many distinct browsers visit in a month”. This identifier is not your name, email or account — until you sign in, we have no way to connect it to who you are — and it is never sent to or readable by any other website. If you sign up for an account while this cookie is present, we record, once, that this browser converted into that account and carry forward only the coarse arrival information described above (how you found Tastbudz, and a coarse market area); we do not attach your prior anonymous browsing to your new account.

You can clear this cookie at any time in your browser settings, which resets you to a new, unlinked identifier — this is the mechanism for opting out of return-visit counting. What this buys is still limited, and worth being plain about: we can see how many browsers return, not how many people. Two devices are two; a browser you clear is a new one; a shared computer is one.

4. How we use information

To operate your account and authenticate you; to publish your contributions and compute dish ratings; to show you relevant dishes and restaurants near you; to send you the two emails we send — address verification and password reset; to prevent spam, manipulation of ratings, and abuse; to moderate content; and to fix problems and improve the service.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

5. What other people can see

By default your profile and your ratings are public. A public profile shows your username, profile picture, bio, city and state, your counts (dishes rated, restaurants, helpful votes) and your follower and following lists. Your ratings appear on dish pages with your username attached.

Your display name and email address are never shown on your public profile. Your dietary preferences, spice tolerance and lists are private.

You can turn both off in Settings. Making your profile private reduces it to your username and picture. Making your ratings private hides them from everyone but you — they still count toward each dish's average, without being attributed to you publicly.

6. Who else processes your data

We use these providers to run Tastbudz. Each receives only what it needs:

  • Amazon Web Services — hosting, our database, and storage for uploaded images (in the United States).
  • Resend — sends the verification and password-reset emails. Receives your email address and display name.
  • Google — if you use “Sign in with Google”, Google authenticates you and we exchange your identity token with them. The Google sign-in button and our map view load code from Google, so Google can see your IP address and which page you are on when they appear.
  • Cloudflare — provides the anti-bot check on the sign-up and forgot-password forms. Cloudflare receives your IP address for that check.
  • Komoot (Photon) — powers restaurant address lookup when you add or edit a restaurant, and postal-code suggestion. When you type into those fields, your search text is sent to Komoot, along with your approximate coordinates when you have shared them, so results can be ranked by distance. City and place search (the location picker in the navigation bar and your profile) is served entirely from our own database — nothing you type there is sent to a third party.

We may also disclose information if we are legally required to, or where necessary to investigate abuse or protect the rights and safety of our users. If Tastbudz is acquired or merges with another company, information may transfer as part of that transaction; we will give notice before your information becomes subject to a different policy.

7. Cookies and browser storage

We use no advertising or analytics cookies, and nothing we store is readable by another website. What we do store in your browser:

  • Sign-in tokens — kept in your browser's local storage so you stay signed in. Cleared when you sign out.
  • Your chosen city — a cookie lasting one year, so the site opens where you left it.
  • An in-progress contribution — kept locally so a half-finished rating survives a page reload.
  • A visit counter — a cookie set the first time you arrive on a given day and expiring at midnight, holding one fixed character that is identical for every visitor. It lets us count how many browsers arrived without recording anything about who they belong to. It is not an identifier and nothing about it is stored on our servers.
  • A return-visit identifier — a cookie holding a random value, lasting up to 12 months and renewed on each visit, so we can tell that a browser has come back on a later day. See “How we count visitors” in section 3 for exactly what it does and does not let us know. Clearing your cookies resets it.

Google and Cloudflare may set their own cookies within the sign-in and anti-bot widgets, governed by their own policies.

8. How long we keep things

Account information and your contributions are kept while your account is open. Abuse- prevention records are deleted after 30 days. Expired sign-in tokens are cleared automatically.

Ratings, superseded rating versions, photos, account-tied activity signals and moderation records do not currently expire on a schedule. If you want something removed, ask us — see below.

The session-activity records described in section 3 are deleted after 13 months. They carry no account and no visitor identifier, so there is nothing in them to connect to you once the day's grouping key has rotated.

The return-visit identifier and the daily activity it records for anonymous browsers are deleted after 13 months of inactivity; signed-in account activity signals are retained as described above.

9. Your choices and rights

You can edit your profile, change your privacy settings, adjust your food preferences and change your password in Settings. You can delete a photo you attached to a rating, and delete lists you created.

Access, correction, deletion and a copy of your data are available on request. Self-service account deletion and data export are not built yet — until they are, write to privacy@tastbudz.com and we will action it.

When we delete an account we remove or anonymise the information that identifies you. Ratings you left may be retained in an anonymised form, without your name attached, because dish averages other people rely on are built from them.

If you live in California, you have the right to know what personal information we collect and how we use it, to request deletion or correction, and not to be discriminated against for exercising those rights. We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing to opt out of on that front. Use the address above to make a request; we will verify it against the email on your account.

10. Security

Traffic is encrypted in transit. Passwords are stored only as hashes. Sign-in sessions can be revoked, and changing your password signs out your other devices. Access to production data is limited to those who need it.

No service can promise perfect security. If you believe your account has been accessed by someone else, change your password and write to us.

11. Children

Tastbudz is not intended for children under 13, and we do not knowingly collect information from them. If you believe a child under 13 has given us personal information, write to privacy@tastbudz.com and we will delete it.

12. Where your data is held

Tastbudz is operated from the United States and your information is stored and processed there. If you use it from elsewhere, you understand your information is transferred to the United States, where privacy laws may differ from those where you live.

Tastbudz is intended for people in the United States. Our restaurant and menu coverage is United States only, we do not market or offer the service to people outside it, and we do not monitor or profile the behaviour of visitors from other countries — as noted above, we run no third-party analytics, advertising or tracking of any kind, and our own record-keeping, including the return-visit identifier described in section 3, is limited to browser-level counts and dates and is never assembled into a picture of an individual or their browsing history. We do not block anyone from reading the site, but it is not aimed at you if you are elsewhere.

13. Changes to this policy

We may update this policy. If a change materially affects how we handle your information, we will give notice by email or in the product before it takes effect. The date at the top of this page shows the last substantive revision.

14. Contact

Questions, requests, or anything that looks wrong — privacy@tastbudz.com. We also welcome corrections to this page itself.

Tastbudz LLC