Privacy Policy

Last updated August 8, 2026

Atlas Gourmand collects about as little as a restaurant app can and still work. There are no advertisers, no cross-site tracking and no data brokers involved. This page explains exactly what we hold, why we hold it, and how to make us delete it.

1. Who is responsible for your data

Atlas Gourmand is run by an individual sole proprietor based in New York, who is the data controller for the purposes of the UK and EU General Data Protection Regulation. Contact: elise@atlasgourmand.com.

2. What we collect

If you never create an account, we hold no personal information about you beyond the technical basics in section 6 — you can browse the whole map without telling us anything.

If you create an account, we hold:

  • Your email address. It is your identity here and where sign-in codes go.
  • Your name and profile picture, if you set them. If you sign in with Google, we receive the name and picture on your Google account and use them to pre-fill your profile. We do not receive your Google password, contacts, calendar or anything else.
  • A username, if you choose one.
  • The restaurants you save. Only you can see your saved list.
  • Whether you have asked for marketing email, when you asked, and where you asked from. See section 5.
  • Whether and when you accepted these documents, and which version.

If you ask us to cover an area we do not yet map, we keep the email address and ZIP code you gave us, so we can tell you if we get there.

3. Location

If you tap the locate button or use the distance filter, your browser asks your permission and then gives the page your coordinates. Those coordinates are used inside your browser to center the map and work out what is near you. They are not sent to our servers, and we never store them. If you say no to the browser prompt, everything else still works.

One honest caveat: a distance filter is written into the page address, so if you share or reload a link that contains one, those coordinates travel in the URL and will appear in ordinary web-server request logs at our hosting provider.

Searching by neighborhood, place or ZIP is different — the text you type is sent to our server, which looks it up on your behalf. See section 7.

In plain termsYour GPS position stays in your browser. We do not collect it or keep it.

4. Why we use it, and our legal basis

Under UK and EU data protection law we have to name a lawful basis for each use:

  • Running your account and saving your restaurants — necessary to provide the service you asked for (performance of a contract).
  • Sending sign-in codes and essential account notices — same basis. Without these you cannot log in.
  • Marketing email — your consent, and only your consent.
  • Keeping the service up and preventing abuse — rate limiting, blocking automated traffic, diagnosing faults. Our legitimate interest in a service that works and is not being attacked.
  • Understanding roughly how the site is used — aggregate page-view statistics. Our legitimate interest in knowing which parts of the app people actually use. This is cookieless and does not identify you.
  • Keeping a record that you consented, or accepted the terms — our legal obligation to be able to demonstrate consent, and our legitimate interest in being able to show what you agreed to.

5. Marketing email

We only send marketing email if you have positively opted in. The box is never pre-ticked, it is separate from accepting the Terms, and signing up alone is never treated as permission.

You can withdraw consent at any moment — the unsubscribe link in any marketing email, or an email to us — and it is as easy to withdraw as it was to give. Withdrawing does not affect your account or the sign-in codes you need to log in, and it does not make anything we sent beforehand unlawful.

When you withdraw, we stop sending and record that you withdrew. We keep the record of your consent and its withdrawal even after you unsubscribe — that record is how we prove we had permission, and how we make sure you do not get added back by mistake.

6. Technical information

Like every website, ours receives your IP address and browser user-agent with each request; our hosting provider logs these briefly for security and diagnostics. We use your IP address to apply rate limits. We do not build a profile from it.

We use Vercel Analytics for aggregate page-view counts. It sets no cookies and does not track you across other websites.

We also use PostHog to understand how the app itself is used — which screens people open, where sign-up gets abandoned, which filters get used — so we can fix what does not work. We run it cookie-free: it stores nothing on your device, and before you log in the events of a visit are tied only to a random identifier that lasts no longer than the open page. Once you log in, usage is linked to your account ID — never your email or name — so we can see how features serve returning members. The text you type into search boxes and your precise map location are stripped from these events before they are sent. Analytics requests go to our own domain and are forwarded to PostHog from there.

For a sample of visits PostHog also records a session replay — a reconstruction of the screens and taps in a visit — which we use to find broken flows. Replays are tied to the same identifier as the events above, and anything you type into an input is masked in your browser before the recording leaves it.

Cookies and local storage. We use no advertising cookies, and nothing on this site follows you to other websites. What we do store on your device:

  • Sign-in cookies — set once you log in, so you stay logged in. Strictly necessary.
  • Your last view and filters — so the app reopens where you left it.
  • Two “you have already seen this” flags — so the critics teaser and the “add to home screen” hint do not nag you twice.
  • A restaurant you tried to save before logging in — held only long enough to survive the trip through the sign-in screen, then discarded.
  • The marketing choice you made at sign-up — the box you ticked or left unticked, held the same way for the trip through the sign-in screen, then discarded.

Clearing your browser storage clears all of these.

7. Who else sees anything

We do not sell your personal information, we do not share it for advertising, and we do not give it to data brokers. A small number of companies process data on our behalf, under contract, to run the service:

  • Supabase — the database, sign-in system and picture storage. Holds your account and saved restaurants.
  • Vercel — hosting and aggregate analytics.
  • PostHog — product analytics, in the United States. Receives the usage events and session replays described in section 6, tied to a temporary random identifier or, once you log in, your account ID. Never your email, name, typed text or precise location.
  • Brevo — sends our email, including sign-in codes and any marketing you opted into.
  • Cloudflare — domain and email routing.

Separately, some services your browser contacts directly will see your IP address, simply because your device is loading something from them:

  • OpenFreeMap — supplies the map tiles.
  • DuckDuckGo — supplies the small site icons shown beside restaurants and publications.
  • Google — only if you choose to sign in with Google.

When you search for a neighborhood or address, our own server passes the text to OpenStreetMap’s Nominatim service and, for street addresses, the United States Census geocoder. Because our server does the asking, those two services never see your IP address — they see ours. The text of the query is not stored against your account.

We may also disclose information if the law genuinely requires it, or to protect against fraud or a threat to someone’s safety.

In plain termsNobody buys your data from us, because we do not sell it. The companies listed above only handle it to make the app run.

8. Where your data goes

We are based in the United States and our database and hosting are in the United States. If you are in the United Kingdom or the European Economic Area, using Atlas Gourmand means your personal information is transferred to the US.

For those transfers we rely on the European Commission’s Standard Contractual Clauses, and the UK Addendum where the UK GDPR applies — these are the contractual safeguards our providers (Supabase, Vercel, Brevo and Cloudflare) offer for exactly this purpose. You can ask us for more detail about them at any time.

9. How long we keep things

  • Your account and saved restaurants — until you delete your account, or ask us to.
  • Sign-in codes — they expire within hours and are single-use.
  • Coverage-request emails and ZIPs — until we reach that area, or you ask us to remove yours.
  • Consent and terms-acceptance records — kept while you have an account and for a reasonable period afterwards, because their whole purpose is to evidence what you agreed to.
  • Server logs — short-term, per our hosting provider’s retention.

10. Your rights

If you are in the UK or the European Economic Area, you have the right to: get a copy of the personal data we hold about you; have it corrected; have it deleted; restrict or object to how we use it (including objecting to anything based on legitimate interests); receive it in a portable, machine-readable form; and withdraw consent at any time where we rely on consent.

Everyone gets these, wherever you live. We are not going to make you prove you are European before we delete your account.

To exercise any of them, email elise@atlasgourmand.com from the address on your account. We will respond within 30 days. We will not charge you or treat you differently for asking.

If you are unhappy with how we have handled your data you can complain to your local supervisory authority. In the UK that is the Information Commissioner’s Office; in the EEA it is the data protection authority in the country where you live. We would rather you came to us first, but that right is yours regardless.

In plain termsEmail us and we will send you your data, fix it, or delete it. No forms, no fee.

11. If you are in California

California residents have the right to know what personal information we collect and why, to request a copy, to have it corrected or deleted, and not to be discriminated against for asking. Section 2 sets out the categories we collect — identifiers such as your email address and name, and your saved-restaurant activity — and section 4 explains why.

We do not sell personal information, and we do not share it for cross-context behavioral advertising — as those terms are defined by the CCPA as amended by the CPRA. We have never done so. There is therefore no “Do Not Sell or Share My Personal Information” process to offer you.

Use the same address — elise@atlasgourmand.com — to make a request.

12. Security

Sign-in uses one-time codes or Google — there are no passwords for anyone to steal from us. Your data sits behind row-level security in our database, so one account cannot read another’s. Traffic is encrypted in transit.

No service can promise perfect security, and we will not pretend otherwise. If a breach ever affects your personal data, we will notify you and the relevant regulator as the law requires.

13. Children

Atlas Gourmand is not for children under 13, and we do not knowingly collect their data. In countries where the minimum age for consenting to online services on your own is higher than 13, users below that age need a parent or guardian’s consent — see the Terms of Service. If you believe a child has given us personal information, email us and we will delete it.

14. Changes to this policy

If we change this policy we will update the date at the top. If a change materially affects your rights, we will tell you directly — by email or in the app — rather than quietly editing this page.

15. Contact

Anything at all about privacy: elise@atlasgourmand.com. A person reads it.