1. Who this policy applies to
This Privacy Policy explains how Cravae ("Cravae", "we", "us") handles personal data when you use the Cravae website, progressive web app, native apps, and related services. Cravae is intended for people aged 18 or older.
2. Personal data we may process
- Account data: email address, authentication identifiers, account timestamps, and basic profile information.
- Taste DNA and preferences: diet type, cuisines, restaurant vibes, spice preferences, budget, allergies, ingredients to avoid, food goals, and similar settings you provide.
- Location: device coordinates when you allow location access, or an area/city you enter manually, so Cravae can rank nearby food and restaurant options.
- Food activity: searches, chat messages, recommendations, saved items, restaurant views, feedback, and preference signals used to operate and personalise the service.
- Menu analysis: menu text, uploaded menu images, filenames, analysis results, and private storage references.
- Health and nutrition context: if you enable Health Sync or calorie-aware recommendations, daily calories consumed, active calories burned, protein, carbohydrates, fat, steps, targets, goals, connection status, and derived values such as remaining daily calories/macros. Cravae does not need your complete HealthKit or Health Connect record to generate a food recommendation.
- Billing data: plan, subscription/order identifiers, payment status, amount, currency, and billing events. Cravae does not receive or store your full card number, UPI PIN, or banking credentials from Razorpay or an app store.
- Technical and security data: device/browser information, IP-derived security signals, error logs, rate-limit identifiers, and service usage needed to operate, secure, diagnose, and prevent abuse.
- Optional analytics: if you allow analytics, product events and page usage may be processed through configured analytics services.
3. Why we use personal data
We use personal data to provide and personalise Cravae, answer food questions, analyse menus, rank nearby restaurants, maintain history and saved items, provide Health Sync features you enable, manage accounts and subscriptions, process support requests, prevent fraud or abuse, diagnose failures, comply with law, and improve product quality.
4. AI processing and personalisation
Cravae uses configured AI providers to generate requested recommendations and menu analysis. We may send the provider your food request together with the minimum context reasonably needed to answer it, such as location, relevant Taste DNA preferences, menu text/image content, and—only when you enable calorie-aware recommendations—selected or derived daily nutrition context such as remaining calories or macros. We do not intentionally send your complete HealthKit or Health Connect history to an AI provider.
AI output can be inaccurate. See our Health & Nutrition Disclaimer for important limits.
5. Service providers and disclosures
Depending on the features you use and our current configuration, personal data may be processed by service providers that help us operate Cravae, including:
- Supabase for authentication, databases, and private file storage;
- Vercel or other hosting/CDN providers for delivery of the service;
- Google Places/Maps, Geoapify, or similar location/data providers for restaurant and geographic information;
- configured AI providers such as Google Gemini or OpenAI for AI-assisted responses and analysis;
- Razorpay and, for native purchases, Apple or Google for payment processing;
- PostHog and Vercel Analytics when optional analytics is enabled and you consent;
- Sentry or comparable error-monitoring services when configured; and
- email delivery providers such as Resend when configured.
We may also disclose data when required by law, to protect users or the service, or as part of a business reorganisation subject to appropriate safeguards.
6. Health data protections
Health and fitness data is used only to provide user-facing health/fitness or food-personalisation features you choose. We do not sell HealthKit or Health Connect data, use it for targeted advertising, or use it to build advertising profiles. You can disconnect health permissions at the operating-system level and turn off calorie-aware recommendations in Cravae.
7. Cookies, local storage, and analytics choices
Cravae uses storage that is necessary for authentication, security, preferences, and core product functionality. Optional analytics is disabled until you choose to allow it. You can change that choice on the Privacy choices page. See the Cookie & Storage Policy for details.
8. Retention
We keep account and feature data while your account is active and as reasonably needed to provide the service. You can delete individual content where the product provides that control or permanently delete your account from Settings. Deletion removes account-linked data from active Cravae systems subject to technical dependencies; limited records may be retained where required for security, fraud prevention, payment/accounting obligations, legal claims, or provider backup/log rotation.
9. Your controls and rights
Depending on applicable law, you may have rights to access information about processing, obtain a copy of your data, correct or update data, request erasure, withdraw consent, and raise a grievance. Cravae provides account export and permanent account deletion in Settings. Optional analytics consent can be withdrawn through Privacy choices, and health permissions can be changed through Cravae and your device settings.
10. International processing
Our service providers may process data in countries other than the country where you live. Where required, we use appropriate contractual, technical, and organisational safeguards and follow applicable restrictions on cross-border processing.
11. Security
We use measures designed to protect personal data, including authenticated access, private storage for menu uploads, transport encryption, access controls, rate limiting, and security/error monitoring where configured. No online system can guarantee absolute security.
12. India privacy framework
For users in India, we aim to handle digital personal data consistently with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as their provisions come into force. Nothing in this policy limits rights that cannot lawfully be waived.
13. Contact and grievance requests
Privacy contact: hello@cravae.com.
Grievance contact: Cravae Grievance & Privacy Contact — hello@cravae.com.
14. Changes to this policy
We may update this policy as Cravae changes or legal requirements evolve. Material changes will be reflected by updating the date above and, where appropriate, by providing additional notice in the service.