← Support

Privacy Policy · Effective August 4, 2026

Foodies is a social network. What you publish is stored on our servers in France so that other people can see it. Your direct messages are end-to-end encrypted and we cannot read them.

Foodies ("the app") is published by Hugo Moriceau ("we", "us"), the data controller for the purposes of the EU General Data Protection Regulation (GDPR). This policy explains what we store, why, for how long, and what you can require of us. Contact: hugomoriceau@icloud.com.

1. What we store, and why

DataWhyLegal basis
Account — a Sign in with Apple identifier (or a guest identifier), display name, username, bio, avatar, creation date. To create your account, sign you in, and show you to other people. Performance of our contract with you, Art. 6(1)(b).
Content you publish — photos, videos, dish titles, captions, hashtags, comments, collections, events, and the likes, saves and follows you make. This is the service: publishing it to other users is the point of the app. Performance of our contract with you, Art. 6(1)(b).
Approximate location — the free-text city you type on your profile, and, only if you open the "Nearby" feed and allow it, a coarse coordinate from your device. We ask iOS for reduced accuracy, request a single reading rather than tracking you, and round it to two decimal places (about 1 km) before it leaves your device. We never receive a precise position, and we do not store the coordinate — it is used to rank that one request. To show where you cook, and to rank the "Nearby" feed around you. Your consent, given in the iOS permission prompt, Art. 6(1)(a). Refuse it and every other part of Foodies still works; only "Nearby" is unavailable.
Device token for notifications — an Apple-issued identifier for your device, stored only if you allow notifications. To send you a notification when someone follows you, likes or comments on your dishes, or messages you. Your consent, given in the iOS permission prompt, Art. 6(1)(a). Decline, or turn it off later, and it is deleted.
Subscription status — whether your account has an active Foodies Pro entitlement. To unlock the features you paid for. We receive no payment details and no receipt data. Performance of our contract with you, Art. 6(1)(b).
Direct messages — ciphertext only, plus your device's public key. To deliver messages between you and the person you are writing to. Performance of our contract with you, Art. 6(1)(b).
Safety data — reports you file, accounts you block, and content refused by our automated moderation filter. To keep the network usable and to meet our platform obligations. Our legitimate interest in a safe service, Art. 6(1)(f).
Profile visits — which accounts opened your profile, and a visit count. To show you who viewed your profile. You can switch this off in Settings. Our legitimate interest in a social feature you can disable, Art. 6(1)(f).

We do not store your email address: Sign in with Apple gives us an opaque identifier and we keep only that. We run no analytics or telemetry, no crash-reporting SDK, no advertising network, no advertising identifier (IDFA), and we do not track you across other apps or websites.

2. End-to-end encrypted messages

Direct messages are encrypted on your device before they are sent, using Apple's CryptoKit (X25519 key agreement, HKDF-SHA256, ChaCha20-Poly1305). The private key never leaves your device; it is held in the iOS Keychain. Our server stores and relays only ciphertext and cannot decrypt it. If you lose the device, past messages cannot be recovered — not by you, and not by us.

3. Where your data is, and who else receives it

Our servers are operated by Contabo GmbH in Lauterbourg, France (European Union), acting as our processor. Your data is stored in the EU and we do not transfer it to a third country.

Other recipients:

We do not sell, rent or otherwise share your personal data, and we do not use it to train machine-learning models.

4. How long we keep it

5. Your rights

Under the GDPR you may ask us to:

Write to hugomoriceau@icloud.com and we will answer within one month. If you are not satisfied with how we handle your request, you may lodge a complaint with your national data protection authority — in France, the CNIL.

6. Children

Foodies is rated 12+ and is not directed at children under 13, who may not create an account. If you believe a child has provided us with personal data, contact us and we will delete it.

7. Security

All traffic between the app and our servers uses HTTPS/TLS. Direct messages are additionally end-to-end encrypted, as described above. Server access is restricted to the publisher. No system is perfectly secure; if a breach is likely to affect your rights we will notify the competent authority and you, as required by Art. 33 and 34.

8. Changes to this policy

If we change what we collect or why, we will update this page and the App Store privacy label before that change ships, and revise the effective date above.

9. Contact

Hugo Moriceauhugomoriceau@icloud.com