Privacy Policy

Last updated: 2026-07-16

This Privacy Policy explains what personal data Cravedit collects, why we collect it, the legal basis we rely on, who we share it with, how long we keep it, and the rights you have. Please read it together with our Terms of Use. We have written it in plain language and tried to be specific about what really happens in the app.

1. Who we are

Cravedit is a crowdsourced map of where to find energy drinks, with community-checked prices and stock. The app is a mobile application (iOS and Android) backed by our own servers.

The controller responsible for your personal data is:

Evangelos Leivaditis ("Cravedit", "we", "us", "our")
Koliatsou 127, Corinth, Greece

Privacy contact: privacy@cravedit.com
Community: our Discord server at https://discord.gg/JWpCkJsG6v

We have not appointed a Data Protection Officer (one is not legally required for processing at our scale), and an EU representative under Article 27 GDPR is not required because the controller is established in the EU (Greece). For any data-protection matter, contact us at privacy@cravedit.com.

2. The data we collect, why, and our lawful basis

We group the data by category. For each category we explain what it is, why we use it, and the lawful basis under the GDPR. "Contract" means we need it to provide the service you asked for; "Consent" means you can give or withdraw permission; "Legitimate interests" means we have a genuine business reason that is balanced against your rights; "Legal obligation" means the law requires it.

A. Account data

What: your email address and password (registered through Supabase Auth — your password is handled by Supabase and never reaches our own servers); if you choose "Sign in with Google", Google returns your email address, name and profile picture; a display name; and, if you add them, an optional profile bio, social links and an avatar photo.

Why: to create and secure your account, sign you in, show your public profile, and contact you about your account.

Lawful basis: Contract (account creation and sign-in); Consent (optional Google sign-in, optional bio/links/avatar); Legitimate interests (account security).

B. Location data

What: when you grant location permission we use your precise GPS location to centre the map on you. Importantly, when you make a contribution — a price, stock or "does it exist" vote, adding or suggesting a store or a drink, or a drink-request photo — your precise coordinates are currently attached to that contribution so it can be placed on the map. We also derive and store: a fuzzed "current location" offset by roughly 1 km; a coarse region of about 1 km together with a region label; your country; and a fuzzed signup-location anchor used to detect fraud.

Why: to show nearby drinks, to place your contributions on the map accurately, to power local leaderboards and regional features, and to detect fraud and location spoofing.

Lawful basis: Consent (device location permission, which you can turn off at any time); Contract (placing the contributions you choose to submit); Legitimate interests (fuzzing for privacy, fraud and spoof detection).

C. Photos

What: your profile avatar, and the photo you take when you request a missing drink. These photos may show faces, storefronts, labels or other surroundings.

Why: avatars personalise your profile; drink-request photos let our reviewers verify a real, missing product before granting a reward.

Lawful basis: Consent (you choose to upload or capture each photo); Contract (processing your reward request).

D. Contributions and activity

What: your votes, your store and drink suggestions, your favourites, and which stores you view.

Why: to build and improve the map, to award points fairly, and to personalise what you see.

Lawful basis: Contract (the core map service); Legitimate interests (improving and securing the service).

E. Economy data

What: your points ledger, and your VIP subscription purchase and the related app-store transaction id.

Why: to run the points and VIP features, and to keep financial records.

Lawful basis: Contract (the features you use); Legal obligation (keeping accounting and tax records); Legitimate interests (preventing reward fraud).

F. Anti-fraud and security data

What: device information, a device fingerprint and install id; a hashed phone number (only if you use the invite or referral flow); your IP address (held transiently, for about one minute, only for rate-limiting); abuse and anti-spoof signals; and a trust score used in automated moderation and ban decisions.

Why: to keep rewards and leaderboards fair, to stop spam, bots, multi-accounting and spoofing, and to protect the service and other users.

Lawful basis: Legitimate interests (security, fraud prevention, fair play); Legal obligation where we must act on abuse. See Section 9 for how the trust score is used and your right to human review.

G. Moderation data

What: reports you make about other users, including the reason you select and any free text you write.

Why: to review and act on reports and keep the community safe.

Lawful basis: Legitimate interests (safety and moderation).

H. Notifications

What: in-app alerts only. We do not use a third-party push service.

Why: to tell you about rewards, replies, moderation outcomes and app news.

Lawful basis: Consent or Legitimate interests, depending on the alert.

I. Usage analytics (optional — OFF by default)

What: only if you opt in, anonymous app-usage and device data — for example screens viewed, in-app events, app version, device model and a coarse location derived from your IP — collected via Google Analytics for Firebase.

Why: to understand which features are used and improve the app. We do not use it for advertising.

Lawful basis: Consent. Analytics is OFF until you turn it on (the first-run prompt, or Settings → About & legal → Usage analytics), and you can turn it back off at any time. The data is processed by Google and may be stored in the United States (see sections 4 and 5).

J. Crash diagnostics

What: if the app crashes, technical crash data — the error and stack trace, app version, device model and OS, and a Google-generated installation identifier — collected via Google Crashlytics (part of Firebase). Separate from the in-app crash log you can choose to send us from Settings.

Why: to detect and fix crashes and keep the app stable.

Lawful basis: Legitimate interests (app stability). Crash diagnostics are ON by default; you can turn them off in Settings → About & legal → Automatic crash reports. The data is processed by Google and may be stored in the United States (see sections 4 and 5).

K. Advertising (Google AdMob — removed entirely by VIP)

What: Cravedit shows advertising served by Google AdMob — for users in the EEA and the UK the provider is Google Ireland Limited. There are two kinds: (a) small display ads (a small banner at the top of the screen, and occasional clearly-labelled ad cards inside product lists), and (b) optional rewarded ads you actively choose to watch to earn game points ("watch an ad to earn"). To select, show and measure ads, Google processes device identifiers including your device's Advertising ID, your IP address, and coarse ad-relevance signals such as device type and approximate (IP-derived) location. Whether Google may show you personalised ads or only non-personalised ones is governed by the consent popup the app shows before any ad is loaded — you can change or withdraw that choice at any time in Settings → Privacy options. For rewarded ads we ourselves receive only an anonymous completion callback ("this user finished watching an ad") so we can credit your points; we never receive, build or use any profile of your ad interests. VIP subscribers see no ads at all.

Why: ad revenue keeps Cravedit free; rewarded ads additionally offer an optional way to earn a capped number of game points.

Lawful basis: Consent (personalised ads in the EEA/UK — given, changed or withdrawn via the in-app consent popup); Legitimate interests (showing non-personalised ads when you decline personalisation, and verifying that a rewarded ad was really completed to prevent reward fraud). Rewarded ads additionally never run unless you tap to watch one. See also Google's privacy policy and Google's advertising explainer.

Apart from the Google AdMob advertising described in Section 2.K — always consent-gated for personalisation and removed entirely by VIP — we do not run other third-party advertising trackers in the app; analytics stays off unless you opt in, and you can switch off crash diagnostics.

3. Device permissions

The app asks for these permissions. You can grant or revoke each one in your device settings at any time; some features will not work without them.

4. How we share your data (processors and sub-processors)

We do not sell your personal data. We share it only with service providers ("processors") who handle data on our instructions, and where the law requires. The main providers and what each receives:

The providers listed above are the full, current list of our sub-processors, together with what each receives and where it is located. We update this section, and give notice, before a new sub-processor starts processing your data.

We may also disclose data to comply with the law, enforce our Terms, or protect our rights, users or the public; and to a successor in the event of a merger, acquisition or asset sale (you will be told if this happens).

5. International data transfers

Some of our providers are located outside your country, including in the United States. When we transfer personal data out of the EEA or the UK, we rely on appropriate safeguards — primarily the European Commission's Standard Contractual Clauses (SCCs), and the UK Addendum or International Data Transfer Agreement where the UK applies — together with additional protection measures where needed. You can ask us for more detail using the contact in Section 12.

6. How long we keep your data (retention)

We keep personal data only as long as we need it.

When we no longer need data, we delete or anonymise it.

7. Your privacy rights

Depending on where you live, you have some or all of the rights below.

If you are in the EEA, the UK or a similar regime, you have the right to: access a copy of your data; receive it in a portable format; have inaccurate data corrected (rectification); have data erased; restrict our processing; object to processing based on legitimate interests; and withdraw any consent you gave (this does not affect processing already carried out). You also have the right to lodge a complaint with your data protection authority — but we would appreciate the chance to help first.

If you are in California (CCPA/CPRA), you have the right to: know and access the personal information we collect; delete it; correct it; and not be discriminated against for exercising your rights. We do not sell your personal information. If you choose to watch a rewarded ad and have allowed personalised ads, the advertising identifiers sent to Google (Section 2.K) may count as "sharing" for cross-context behavioural advertising under California law — you can opt out of that at any time in Settings → Privacy options (our "Do Not Share" control). We do no other "sharing", and you may still contact us. Some of the information we collect is "sensitive personal information" under California law (for example precise geolocation and financial account or identifier details). We use it only for the purposes described in this Policy — to provide and secure the service, place your contributions, process purchases and rewards, and prevent fraud — and not to infer characteristics about you, so the right to limit the use of sensitive personal information does not apply; we do not sell or share it. Some financial, security and anti-fraud records are exempt from deletion under the law.

How to exercise your rights:

We will verify your request (usually via your account email) and respond within the time the law allows — generally one month under the GDPR, or 45 days under the CCPA, with an extension where permitted. You may use an authorised agent where the law allows.

8. Children

Cravedit is intended for people aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has given us personal data, contact us and we will delete it.

9. Automated decisions and profiling

We use automated systems to keep the platform fair and safe. In particular, we calculate a trust score from your activity and anti-fraud signals, and this score can feed automated moderation actions, including limiting features or banning an account, and weighting how much your votes count.

You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. If an automated action has significantly affected you, you can ask for human review, express your point of view and contest the decision by contacting privacy@cravedit.com.

10. Security

We take reasonable technical and organisational measures to protect your data. Passwords are handled by Supabase Auth and never reach our servers; phone numbers in the invite flow are stored only as a hash; IP addresses are held only transiently; and access to personal data is limited. No system is perfectly secure, so we cannot guarantee absolute security.

11. Changes to this policy

We may update this Policy as the app evolves or the law changes. If we make material changes we will update the "Last updated" date and, where appropriate, notify you in the app. Continuing to use Cravedit after a change means you accept the updated Policy.

12. Contact us

Questions or requests about your privacy:

Evangelos Leivaditis
Email: privacy@cravedit.com
Community: https://discord.gg/JWpCkJsG6v

Governing law for this Policy: Greece.