Ishta Privacy Policy

Last updated: September 12, 2026

This Privacy Policy explains how Ishta ("Ishta," "we," "us," or "our") collects, uses, shares, and protects information when you use the Ishta mobile app and related services.

If you have questions about this Privacy Policy or your data, contact us at team@joinishta.app.

Information We Collect

Account and authentication information. We collect information needed to create, secure, and operate your account, including your account identifier, email address, authentication provider information, and sign-in metadata from email one-time-password sign-in, Google Sign-In, or Apple Sign-In.

Profile information. We collect profile information you provide, such as username, display name, bio, avatar image, profile visibility preference, follower/following relationships, and pending follow requests.

User content and social activity. We collect content and activity you create in Ishta, including food posts, dish names, ratings, reviews, comments, mentions, votes, reports, blocks, saved wishlist items, invite links and invite redemption activity, notification records, and related timestamps.

Photos, camera, and photo library. If you choose to add a food photo or avatar, Ishta may access your camera or photo library after you grant permission. We use these permissions only to let you take or select images for your posts or profile. Uploaded images are stored in private processing storage first. Images attached to eligible public posts, and avatars for public profiles, are then published at stable public web addresses. Other images remain access-restricted.

Location information. With your permission, Ishta may access your device's approximate or precise foreground location to rank nearby restaurants higher in search and center map results. Ishta does not request background location access and does not use device location to set a profile city, rank users, or rank posts in the Feed.

Restaurant and search information. We collect restaurant search queries, selected restaurants, Google place identifiers, place metadata, map viewport data, and related restaurant interaction data to provide search, map, rating, and wishlist features.

Analytics, diagnostics, and device information. We collect app usage, screen, lifecycle, diagnostic, and error information to understand product usage, fix bugs, and improve reliability. This includes Feed impression and interaction information such as the post and ranked session, position, source, visible duration, opens, shares, and Not interested choices. It may also include device and app information such as app version, operating system, device model, locale, event timestamps, route names, and error details. We redact common secret, token, password, and authorization fields before sending analytics events.

Push notification information. Push notification registration and delivery information, after you grant permission and enable push notifications, including your Expo push token, platform, device session identifier and device name when available, app version, and native build version. Push delivery may include the notification title, body, and related routing data.

Age Assurance

On iOS 26 or later, Ishta uses Apple's Declared Age Range API before loading the app to check whether your declared age range meets Ishta's minimum age of 13. Apple provides Ishta only a broad declared age range, not your exact date of birth.

Ishta uses the response only on your device for the current app launch. We do not store or otherwise persist the response, include it in analytics, or transmit it to any Ishta service. If the response indicates that you are under 13, Ishta blocks access to the app.

How We Use Information

  • Provide account access and authentication.
  • Create and display profiles, posts, photos, comments, ratings, votes, wishlists, follows, invites, and notifications.
  • Personalize the Feed using your follows and eligible Ishta activity, including authored, wishlisted, and upvoted posts, together with post freshness, quality, social proof, and creator diversity. Comments and downvotes are not used to infer your food preferences, and device location is not used to rank Feed posts.
  • Personalize restaurant search, maps, and social recommendations.
  • Enforce privacy, visibility, security, rate-limit, and abuse-prevention rules.
  • Maintain, troubleshoot, analyze, and improve Ishta.
  • Communicate with you about support, security, or service-related issues.
  • Comply with legal obligations and enforce our rights.

How We Share Information

We do not sell personal information.

Anyone, including people who are not signed in, may access the limited public profile information, eligible public posts, public post images, and limited public comment previews that you choose to make public. Public content may be cached, linked to, or indexed by conventional search engines. Full comment discussions, connection lists, private activity, follower-only posts, and posts from private profiles require authorized access.

Service providers help us operate Ishta as described below.

We require each third party that receives user data from Ishta to provide the same or equivalent protection of that data as described in this Privacy Policy and required by applicable platform rules and law.

Legal, safety, and business purposes may require disclosure if necessary to comply with law, respond to lawful requests, protect users or the service, prevent abuse, or complete a merger, acquisition, financing, or sale of assets with appropriate safeguards.

Third-Party Services

  • Cloudflare: app hosting and data storage, including account and sign-in information, image processing and delivery, live app updates, and security.
  • OpenAI: automated safety checks on submitted profile, post, and comment text, and food classification using submitted dish names.
  • Google: Google Sign-In, Maps and Places for restaurant search and maps, image safety checks, and Android push notification delivery.
  • Apple: Apple Sign-In, Declared Age Range on supported iOS versions, and iOS push notification delivery.
  • Expo: push notification registration and delivery coordination, including notification titles, bodies, and related routing data.
  • PostHog: app usage analytics and error tracking.
  • Resend: authentication and service email delivery.

Ishta uses Google Maps and Places. The Google Privacy Policy is incorporated into this Privacy Policy for those services.

Data Retention and Deletion

We keep information for as long as needed to provide Ishta, maintain security, comply with legal obligations, resolve disputes, and enforce agreements.

Identifiable raw Feed impression and interaction events are deleted or aggregated after 90 days. A post you mark Not interested remains excluded from your Feed until you choose Undo, the post is deleted, or your account is deleted. This choice does not hide the post elsewhere in Ishta.

You can request account deletion from inside the app. When your account is deleted, Ishta revokes active sessions, removes the account and its private Feed history and exclusions, and deletes account-owned avatar and post image objects from Ishta's active private and public storage. Public cache entries under Ishta's control are purged. Copies previously downloaded, cached, linked, or indexed by third parties may remain outside Ishta's control. Some records may be deleted, anonymized, or retained when needed for security, integrity, fraud prevention, legal compliance, backups, or to preserve non-personal aggregate metrics. Encrypted backup copies may persist for up to 30 days before deletion.

To request account deletion outside the app, contact team@joinishta.app with the email address associated with your account.

Security

We use administrative, technical, and organizational safeguards designed to protect information. Information is transmitted using modern cryptography such as HTTPS where applicable. No system is perfectly secure, and we cannot guarantee absolute security.

Your Choices

  • Update profile information and visibility settings in the app.
  • Choose whether your profile is public or private and whether an eligible post is visible on your public profile or only to followers.
  • Report posts, comments, and profiles.
  • Mark a Feed post Not interested and use Undo to show it in Feed again.
  • Block and unblock accounts.
  • Grant or revoke camera, photo library, and location permissions through your device settings.
  • Enable or disable push notifications in Ishta and grant or revoke notification permission through your device settings.
  • Sign out of your account.
  • Request account deletion in the app or by contacting team@joinishta.app.

If you revoke permissions, some features may stop working or have reduced functionality.

Children's Privacy

Ishta is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to Ishta, contact us at team@joinishta.app.

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date and provide additional notice when appropriate.