Privacy Policy

Last updated: September 24, 2026

Article 1 (Introduction)

This Privacy Policy ("Policy") explains what information the app "meshitelop" (the "Service"), provided by meshitelop (the "Operator"), collects, and how it is used, stored, and shared with third parties. By using the Service, you agree to the terms of this Policy.

Article 2 (Information We Collect: Account and Profile)

At sign-up, we collect your email address, password, display name, and username. Authentication is handled by a third-party provider (Clerk); the Operator's servers never hold your password itself. Your email is used only for sign-in and is never shown on your public profile.
Your display name, username, bio, profile photo, and selected profile banner are shown publicly to other users.
Your profile photo can be selected from your device's photo library. Doing so uses permission to access the photo you choose.

Article 3 (Information We Collect: Post Photos and Content)

When you create a post, we collect the photo you take (in-app camera only — uploading from your photo library is not supported), the dish name, caption, hashtags, and rating (1–5 stars). Hashtags are shown publicly with your post and can be searched and browsed by other users. Post photos are automatically converted into several sizes (full quality, feed display, detail display, and thumbnail) and stored on our servers; any location metadata (EXIF/GPS) embedded in the photo is automatically stripped before upload.

Article 4 (Information We Collect: Comments and Direct Messages)

We collect the text of comments on posts and direct messages (DMs) between users. DMs are not end-to-end encrypted (E2EE). Messages are encrypted in transit (e.g., via HTTPS), but are stored and processed on our servers as needed to provide the Service. Only the two participants in a conversation can read it.

Article 5 (Information We Collect: Location Data)

Home posts: we determine only your country/region (e.g., Japan, Tokyo) from your current location and display it publicly on the post. Exact coordinates are never stored or shown.
Restaurant posts and Swipe's nearby search: your current location is used temporarily to search for nearby restaurants. This search sends your device's raw coordinates directly to a third-party service (OpenStreetMap's Overpass API). The Operator's own servers do not receive or store this raw location data.
Restaurant post check-in verification: your current coordinates are temporarily sent to the Operator's servers to confirm you are at the venue. Only the distance to the venue (in meters, rounded) is recorded — raw coordinates are not stored.

Article 6 (Information We Collect: Social Data)

We collect your follows/followers, likes, blocks, Swipe save history, notifications, and any reports you file. If you enable push notifications, we also collect the push token (a string that identifies your device for delivery) and the platform (iOS/Android), and store them linked to your account.

Article 7 (Information We Do Not Collect)

The Service does not use any advertising or analytics tracking technology (e.g., Google Analytics, Meta Pixel). We do not collect or verify birthdate or age (see Article 11).

Article 8 (How We Use Information)

We use the information we collect to:
• Provide and operate the Service (posting, feed, DMs, and other core features)
• Search for nearby restaurants and verify check-ins to support post authenticity
• Deliver push notifications
• Provide caption/comment translation
• Respond to abuse and reports
• Provide customer support

Article 9 (Third-Party Sharing)

The Service relies on the following third-party services, each receiving only the data needed for its function:
• Clerk (authentication): email, password, display name, username
• Convex (database/backend): all data described in this Policy
• OpenStreetMap Overpass API: current-location coordinates (sent directly from your device)
• OpenStreetMap Nominatim: public venue identifiers only (no user location)
• Google Cloud Translation API: caption/comment text and target language (only when you tap "translate")
• Expo / EAS: information needed to deliver and update the app
• Expo Push Notification Service (and Apple APNs / Google FCM): push token, notification text (which may include usernames), and accompanying data such as post identifiers
We do not sell your information or share it with third parties for advertising purposes. Because these third-party servers may be located in the United States or other countries, your data may be processed across national borders as part of using the Service.

Article 10 (Content Management and Reporting)

We provide reporting for posts, comments, and users, as well as a feature to block specific users. Reports are reviewed by the Operator and acted on as needed. The fact that you filed a report is not disclosed to the reported user. We do not currently use any automated system to analyze post photos.

Article 11 (Children's Privacy)

The Service is not directed at children under 13. However, we do not currently have a technical mechanism to verify age. If we learn that a user under 13 has used the Service, we will promptly delete the associated data. If you are a parent or guardian and become aware that your child is using the Service, please contact us using the information in Article 16.

Article 12 (Data Retention and Deletion)

When a user deletes their account, the following data is promptly deleted: posts and photos (all sizes), comments, likes, Swipe history, follow/follower relationships, blocks, notifications, restaurant check-in records, and profile information.
Note: Because DMs are stored per conversation, deleting your account deletes the entire message history of every conversation you were part of — including messages sent by the other participant.
Some information may remain in backups for a limited time after deletion for legal-compliance or anti-abuse purposes. Logs and backups held by third-party providers (Clerk, Convex, Google, etc.) are subject to their own respective policies.

Article 13 (Your Rights)

You can view and edit your profile information, and delete your account, at any time from the app's Settings screen. For requests regarding access, correction, or deletion of your data, please contact us using the information in Article 16.

Article 14 (Security)

The Service employs industry-standard technical and organizational safeguards (including encryption in transit), but no system can be guaranteed to be completely secure.

Article 15 (Changes to This Policy)

This Policy may be updated to reflect changes in law or in the Service. We will provide notice of material changes through the app or other appropriate means.

Article 16 (Contact Us)

If you have questions or requests regarding this Policy, please contact us at meshitelop@gmail.com.