Ishta Privacy Policy
Last updated: July 21, 2026
This Privacy Policy explains how Ishta ("Ishta," "we," "us," or "our") collects, uses, shares, and protects information when you use the Ishta mobile app and related services.
If you have questions about this Privacy Policy or your data, contact us at team@joinishta.app.
Information We Collect
Account and authentication information. We collect information needed to create, secure, and operate your account, including your account identifier, email address, authentication provider information, and sign-in metadata from email one-time-password sign-in, Google Sign-In, or Apple Sign-In.
Profile information. We collect profile information you provide, such as username, display name, bio, avatar image, profile visibility preference, follower/following relationships, and pending follow requests.
User content and social activity. We collect content and activity you create in Ishta, including food posts, dish names, ratings, reviews, comments, mentions, votes, reports, blocks, saved wishlist items, invite links and invite redemption activity, notification records, and related timestamps.
Photos, camera, and photo library. If you choose to add a food photo or avatar, Ishta may access your camera or photo library after you grant permission. We use these permissions only to let you take or select images for your posts or profile. Uploaded images are stored so they can be shown in the app according to the app's visibility rules.
Location information. With your permission, Ishta may access your device's approximate or precise foreground location to rank nearby restaurants higher in search and center map results. Ishta does not request background location access and does not use device location to set a profile city, rank users, or rank posts in the Feed.
Restaurant and search information. We collect restaurant search queries, selected restaurants, Google place identifiers, place metadata, map viewport data, and related restaurant interaction data to provide search, map, rating, and wishlist features.
Analytics, diagnostics, and device information. We collect app usage, screen, lifecycle, diagnostic, and error information to understand product usage, fix bugs, and improve reliability. This includes Feed impression and interaction information such as the post and ranked session, position, source, visible duration, opens, shares, and Not interested choices. It may also include device and app information such as app version, operating system, device model, locale, event timestamps, route names, and error details. We redact common secret, token, password, and authorization fields before sending analytics events.
Age Assurance
On iOS 26 or later, Ishta uses Apple's Declared Age Range API before loading the app to check whether your declared age range meets Ishta's minimum age of 13. Apple provides Ishta only a broad declared age range, not your exact date of birth.
Ishta uses the response only on your device for the current app launch. We do not store or otherwise persist the response, include it in analytics, or transmit it to Supabase, PostHog, or any other Ishta service. If the response indicates that you are under 13, Ishta blocks access to the app.
How We Use Information
- Provide account access and authentication.
- Create and display profiles, posts, photos, comments, ratings, votes, wishlists, follows, invites, and notifications.
- Personalize the Feed using your follows and eligible Ishta activity, including authored, wishlisted, and upvoted posts, together with post freshness, quality, social proof, and creator diversity. Comments and downvotes are not used to infer your food preferences, and device location is not used to rank Feed posts.
- Personalize restaurant search, maps, and social recommendations.
- Enforce privacy, visibility, security, rate-limit, and abuse-prevention rules.
- Maintain, troubleshoot, analyze, and improve Ishta.
- Communicate with you about support, security, or service-related issues.
- Comply with legal obligations and enforce our rights.
How We Share Information
We do not sell personal information.
Other Ishta users may see your profile, posts, photos, ratings, comments, follows, badges, and related activity according to product features and your visibility settings.
Service providers process information for us, including Supabase for authentication, database, storage, realtime, and edge functions; PostHog for analytics and error tracking; Google for Google Sign-In, Maps, Places, and image safety checks; Apple for Apple Sign-In; and Resend/Supabase SMTP for authentication emails.
Legal, safety, and business purposes may require disclosure if necessary to comply with law, respond to lawful requests, protect users or the service, prevent abuse, or complete a merger, acquisition, financing, or sale of assets with appropriate safeguards.
Third-Party Services
- Supabase: authentication, database, storage, realtime, and edge functions.
- Google: Google Sign-In, Maps, Places, and Vision SafeSearch services.
- Apple: Apple Sign-In and Declared Age Range on supported iOS versions.
- PostHog: analytics and error tracking.
- Resend and Supabase SMTP: authentication email delivery.
Data Retention and Deletion
We keep information for as long as needed to provide Ishta, maintain security, comply with legal obligations, resolve disputes, and enforce agreements.
Identifiable raw Feed impression and interaction events are deleted or aggregated after 90 days. A post you mark Not interested remains excluded from your Feed until you choose Undo, the post is deleted, or your account is deleted. This choice does not hide the post elsewhere in Ishta.
You can request account deletion from inside the app. When your account is deleted, Ishta deletes your authentication account, private Feed impression and interaction history, Feed Not interested exclusions, and account-owned avatar and post image storage objects. Some records may be deleted, anonymized, or retained when needed for security, integrity, fraud prevention, legal compliance, backups, or to preserve non-personal aggregate metrics.
To request account deletion outside the app, contact team@joinishta.app with the email address associated with your account.
Security
We use administrative, technical, and organizational safeguards designed to protect information. Information is transmitted using modern cryptography such as HTTPS where applicable. No system is perfectly secure, and we cannot guarantee absolute security.
Your Choices
- Update profile information and visibility settings in the app.
- Report posts, comments, and profiles.
- Mark a Feed post Not interested and use Undo to show it in Feed again.
- Block and unblock accounts.
- Grant or revoke camera, photo library, and location permissions through your device settings.
- If you revoke permissions, some features may stop working or have reduced functionality.
- Sign out of your account.
- Request account deletion in the app or by contacting team@joinishta.app.
Children's Privacy
Ishta is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to Ishta, contact us at team@joinishta.app.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date and provide additional notice when appropriate.