This page provides a complete disclosure of SafeEats™ data collection, security, and privacy practices in accordance with Google Play Data Safety requirements, the EU Digital Services Act, and general app store compliance standards.
1. Data Collection Summary
| Data Type | Collected? | Purpose | Shared? |
|---|---|---|---|
| Search queries (restaurant name/location) | Retrieve inspection data from government APIs | ||
| Approximate location (city/zip) | Filter restaurants by proximity | ||
| Precise GPS location | Only if user explicitly grants permission | ||
| Account email & name | Authentication only | ||
| Camera captures | On-device only; images uploaded to AI for analysis, not stored | ||
| Cached inspection records | Performance cache from public government data | ||
| Analytics (anonymous) | Aggregate usage statistics | ||
| Device contacts / SMS / call log | Never accessed | ||
| Photos / media files | Never accessed | ||
| Microphone / audio | Never accessed | ||
| Advertising identifiers | No advertising SDKs present |
✅ = Yes / ❌ = No. "Shared" means data is transmitted to a third-party service for processing.
2. App Permissions
INTERNET
Required to fetch restaurant inspection data from government APIs and display results.
Required for core functionACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION
Used to show nearby restaurants. Only requested when the user taps 'Use my location'. User can decline and search by city name instead.
Optional — user-initiated onlyCAMERA
Used only for the optional QR/menu scanner feature. The camera is activated solely when the user taps the Scan button and is released immediately when the scanner closes. No photos are saved to the device.
Optional — user-initiated only3. Security Practices
- All network communication uses HTTPS/TLS encryption (no cleartext HTTP traffic).
- Backend API access requires authenticated session tokens — unauthenticated requests are rejected.
- Server-side input sanitization on all SoQL/database queries to prevent injection attacks.
- SSRF protection: user-supplied URLs are stripped and rebuilt against trusted base domains.
- No sensitive data (passwords, tokens) stored in localStorage — authentication is handled via secure HTTP-only session cookies managed by the platform.
- Camera stream is released immediately when the scanner view closes — no background camera access.
- No JavaScript interfaces exposed to untrusted content (WebView security).
4. Third-Party Services & SDKs
SafeEats™ does not use any advertising SDKs, ad-tracking SDKs, analytics SDKs, or social SDKs. The only third-party services used are:
Google Places API
Enriches restaurant listings with addresses, phone numbers, and coordinates. Governed by Google's Privacy Policy.
Government Health APIs (US, UK, Canada, France, Netherlands)
Public open-data endpoints queried at request time. No credentials exchanged.
AI/LLM Service (OpenAI/Google/Anthropic)
Used for restaurant sign/menu scanning and AI-assisted research for regions without live APIs. Image data is processed and not retained.
5. Advertising & Tracking
- No advertising SDKs (no Google AdMob, Facebook Audience Network, or any ad SDK).
- No ad-tracking identifiers collected (no GAID, IDFA, or AAID).
- No behavioral or interest-based advertising.
- No social SDKs (no Facebook, Twitter, or Instagram SDKs).
- No push notification SDKs for marketing purposes.
- No data sold or shared with third parties for advertising or commercial purposes.
6. Local Storage & Cookies
SafeEats™ uses browser localStorage (not HTTP cookies) for the following:
- Consent preference — remembers whether you allowed location/cookies (key:
safeeats_consent_v1) - Favorite restaurants — your saved restaurant list stays on your device
- Search cache — recent search results cached to avoid re-fetching on back-navigation
- Theme preference — dark/light mode follows your system setting
All localStorage data is stored on-device and is never transmitted to our servers. Clearing browser data or uninstalling the app removes all of it.
7. Data Retention & Account Deletion
Cached restaurant data: Retained until superseded by newer data from the source government API (typically 24–48 hours for live sources).
User accounts: Retained for the lifetime of your account. You can delete your account at any time via the in-app Account Deletion button (located in the app footer), which permanently removes your email, name, and authentication tokens.
Analytics events: Anonymous usage events (e.g., "search performed") are retained in aggregate and are not linked to your identity.
8. Children's Privacy (COPPA)
SafeEats™ is rated for all ages and is not directed at children under 13. The app does not knowingly collect personal information from children. No data is collected that would trigger COPPA requirements. The app does not use behavioral advertising, interest-based targeting, or contact collection of any kind.
9. Government Data Sources
SafeEats™ queries the following official government health inspection APIs at request time. These are public open-data endpoints — no authentication credentials are exchanged.
Additional regions without live APIs use AI-assisted research of public records or link directly to the official health department portal. See our Coverage page for details.
10. Compliance Checklist
- Privacy Policy published and accessible in-app (also at /privacy).
- Terms of Use published and accessible in-app (also at /terms).
- In-app account deletion available (footer → Delete Account).
- Location permission requested only on user action, with decline option.
- Camera permission requested only on user action, with decline option.
- Consent banner shown on first visit for location/cookie usage.
- No background data collection — all API calls are user-initiated.
- No data sold to or shared with third parties for commercial purposes.
- App content rating: All ages (no violence, mature content, or gambling).
- Target audience: General audience (not directed at children).
- No deceptive behavior, impersonation, or misleading claims.
- All government data sources are publicly documented and verifiable.
See also: Privacy Policy · Terms of Use · Contact