Skip to main content
← Crumble

Privacy policy

Last updated: 2026-07-23

Crumble is a social food-tracking app operated from the Netherlands. This policy explains what personal data we process when you use Crumble, why, and the rights you have under the EU General Data Protection Regulation (GDPR) and the Dutch implementing act (UAVG).

Who we are

Crumble is run by a private individual in the Netherlands, not by a registered company. That person is the data controller and can be reached at contact [at] crumble [dot] me; for anything specifically about your data, use privacy [at] crumble [dot] me. Both are read by the same person — the one who makes every decision described in this policy.

There is no formal Data Protection Officer, because Crumble's processing does not meet the Article 37 GDPR threshold that would require one. If you write to either address, the person who decides what happens to your data is the person who reads it.

What we collect

  • Account data. Your email address and Google profile name when you sign in via Google OAuth, plus the username, display name, avatar emoji, and optional home location you set during onboarding.
  • Content you create. Spots, reviews (rating, notes, photos), wishlist entries, comments, likes, friend connections, and custom tags. You author this — it would not exist without your action.
  • Photos. Images you upload to a review or avatar. We compress images client-side and strip EXIF metadata server-side (including GPS coordinates) before storage.
  • Location data. Coordinates of spots you save (when you allow location, drop a pin, or pick a place from search). Your home location, if you set one, is stored against your account. We do not continuously track your device location.
  • Technical data. Your IP address (visible to Cloudflare for routing and abuse prevention before the request reaches our server), user-agent, and timestamps of requests. These are processed in transient access logs.
  • Session data. A signed session cookie (crumble_session), an OAuth state cookie (oauth_state) used during sign-in, and short-lived cookies that carry an invite, a share link, a campaign QR code or an in-progress sign-up across the Google round-trip. See the cookie policy for the full list and durations.
  • Usage analytics (on by default; you can opt out). Pages viewed, when, and rough device/browser information, labelled with your account ID and username so we can tell which features are actually used. Collected by analytics software we deploy and run ourselves — see "Analytics" below.
  • Dietary preference (optional, only if you set one). Labels such as vegetarian, vegan, halal, kosher or gluten-free, used to filter the map and tag places. You choose whether to set this. Depending on the label, it may say something about your beliefs or your health, so leave it blank if you would rather not record that.
  • Email and push preferences. Which of our emails and notifications you want, plus delivery outcomes (bounces, unsubscribes) and, if you enable notifications, a push subscription from your browser.

We use no advertising trackers, no ad networks, and no fingerprinting, and we do not sell or share your data. Our analytics is first-party software we run ourselves rather than a third-party analytics service; it is cookieless and runs on by default, and you can opt out at any time.

Why we process it (legal basis)

  • Performance of contract (Art. 6(1)(b) GDPR) — we need your account, content, and session data to actually run the service you signed up for.
  • Consent (Art. 6(1)(a)) — for any optional dietary preference you choose to set. You can withdraw consent at any time via your profile; withdrawal does not affect processing already carried out.
  • Legitimate interests (Art. 6(1)(f)) — for security, abuse prevention, and rate-limiting (e.g. friend-request spam, login brute force), and for our cookieless first-party usage analytics and client error reports (labelled with your account) which help us see which features are used and find crashes. These run on by default; you can object (opt out) at any time via "Manage cookies" in the cookie policy, and opting out takes effect on your next page load. Each interest is balanced against your rights and limited to what is necessary.

Who we share it with (data processors)

We use a small number of sub-processors. They process data only on our instructions, under written agreements:

  • Crumble's EU server — the application, its database, your photos, and the maps all run on a single server we operate in the EU. Your account and your content are not held by any third-party cloud.
  • Cloudflare, Inc. — only the network layer that carries requests to us, and the Turnstile anti-bot widget on the sign-in page. Your IP is briefly visible to Cloudflare in transit, after which only the in-EU server processes the request. Cloudflare does not host your content.
  • Google LLC — only for the Google OAuth sign-in flow. We receive your email and profile name from Google after you authorise the consent screen. We do not use Google Analytics, Firebase, or AdSense.
  • TomTom — our primary place-search provider. When you search for a somewhere to review, your search text and the approximate map area are sent to fetch venue suggestions. We do not send your account identifier.
  • Foursquare Labs, Inc. — a fallback place-search provider, used only when the primary search returns nothing usable. Same data as above, same caching (search responses are cached for up to 29 days). We are working to remove this dependency.
  • OpenStreetMap Foundation (Nominatim) — used for reverse-geocoding pin-drop locations into a country code. Only the coordinates are sent.
  • Protomaps — map tiles normally come from our own server. If it is unavailable your browser falls back to Protomaps' hosted tiles, and map fonts and icons load from their public asset host. That means your browser's IP and the tiles you request become visible to them for those requests.
  • Brevo (Sendinblue, France) — delivers our email: the welcome message, friend requests, level-ups, trip recaps and the digest. Your email address, display name and the contents of that message are processed to send it, and delivery outcomes (opens where measured, bounces, unsubscribes) come back to us. Every email carries a one-click unsubscribe, and you can switch each type off in your profile.
  • OpenRouter, and through it Google Gemini — used only by the AI features of Crumble Plus, which is not yet released. If you use them, the photo you scan (a dish photo, or a receipt, which may show what you ordered and what it cost) is sent to be read and described. Photos sent this way are not used to train anyone's models, and the feature only runs when you deliberately start a scan.
  • Push delivery services — if you enable notifications, your browser registers with its vendor's push service (Google, Apple, Mozilla, depending on your browser) and we store the resulting subscription so we can send you a notification. Turning notifications off deletes it.
  • Analytics hosting — our analytics software is deployed on rented infrastructure rather than on our own server. Only usage analytics lives there, and only we can read it.

Artificial intelligence

Crumble Plus includes two AI features, neither of which is released yet: a dish-photo scanner that guesses what a dish is, and a receipt scanner that reads the items and prices off a photographed receipt so the review form can be pre-filled.

They run only when you start a scan yourself. The image you submit is sent to OpenRouter, which passes it to Google Gemini, and the result comes straight back to your review form. A photographed receipt can contain more than the dish — the venue, the time, what else was ordered, sometimes the last digits of a card — so only scan receipts you are comfortable sending. We do not send your name, email, or account ID with the image, the image is not stored by us beyond the review you attach it to, and it is not used to train models.

We use no AI to make decisions about you, and nothing you write is fed to a model to profile you. There is no automated decision-making in the sense of Art. 22 GDPR anywhere in Crumble.

Analytics

Unless you opt out in the consent banner, we record which pages and features you use, when, and rough device information, labelled with your account ID and username. This runs on analytics software we deploy and operate ourselves — it is not Google Analytics or any other third-party analytics service, it sets no cookies, the data is never sold or shared, and no advertising network can see it. We use it to find out which parts of Crumble are worth keeping.

It is on by default and you can opt out at any time through "Manage cookies" on the cookie policy page. The same switch controls the crash reports we use to find bugs.

International transfers

Your account, your content and your photos stay on our server in the EU. Brevo is French and TomTom is Dutch, so email and place search stay inside the EEA too.

Some processing does leave the EEA: Google and Cloudflare for sign-in and anti-bot, Foursquare as the search fallback, and OpenRouter and Google Gemini for the unreleased Plus scanning features, all in the United States. Those transfers rely on the EU Standard Contractual Clauses and, for Google and Cloudflare, their EU–US Data Privacy Framework certification.

How long we keep it

  • Account, spots, reviews, photos: for as long as your account exists. Deleting your account removes them.
  • Session cookies: 30 days; refreshed on use.
  • Consent cookie: 1 year, then we re-prompt.
  • Tunnel + server access logs: retained for short windows (typically days, not months) for security and rate-limit forensics.
  • Usage analytics: kept while your account exists, unless you opt out. Opting out stops new collection.
  • Email and push: your preferences last as long as your account. Push subscriptions are deleted when you turn notifications off. Unsubscribe and bounce records are kept so we do not email you again by accident.
  • Backups: the database is backed up daily and older backups are rotated out over the following weeks. A deletion is applied to the live database immediately; backups still holding your data age out on that rotation and are not used to bring it back.

Your rights

Under the GDPR you can request, free of charge:

  • Access to the personal data we hold about you (Art. 15).
  • Rectification of inaccurate data (Art. 16). You can edit most fields directly in the app.
  • Erasure — the "right to be forgotten" (Art. 17). Email privacy [at] crumble [dot] me from the address tied to your account and we will delete it within 30 days.
  • Restriction of processing (Art. 18) and objection to processing based on legitimate interest (Art. 21).
  • Portability (Art. 20) — a machine-readable export of your data on request.
  • Withdraw consent or opt out of analytics at any time via the cookie banner ("Manage cookies"); this does not affect prior lawful processing.
  • Lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, autoriteitpersoonsgegevens.nl) or your local supervisory authority.

Children

Crumble is not intended for users under 13. If you believe a child has created an account, contact us and we will remove it.

Security

See our security disclosure policy for how to report vulnerabilities. Photos have EXIF GPS metadata stripped on upload. Sessions are HMAC-signed. Friend ACLs are enforced server-side on every endpoint that exposes user content.

Changes

Material changes will be announced in-app and the "last updated" date above will move forward. If a change requires fresh consent, the cookie banner will reappear.

Contact

Privacy questions, deletion requests, or right-of-access requests: privacy [at] crumble [dot] me.

Privacy · Terms · Cookies · Security
Privacy · Terms · Cookies · Security · Businesses ·