Privacy Policy
Last updated: 2026-07-16
This Privacy Policy explains what personal data Cravedit collects, why we collect it, the legal basis we rely on, who we share it with, how long we keep it, and the rights you have. Please read it together with our Terms of Use. We have written it in plain language and tried to be specific about what really happens in the app.
1. Who we are
Cravedit is a crowdsourced map of where to find energy drinks, with community-checked prices and stock. The app is a mobile application (iOS and Android) backed by our own servers.
The controller responsible for your personal data is:
Evangelos Leivaditis ("Cravedit", "we", "us", "our")
Koliatsou 127, Corinth, Greece
Privacy contact: privacy@cravedit.com
Community: our Discord server at https://discord.gg/JWpCkJsG6v
We have not appointed a Data Protection Officer (one is not legally required for processing at our scale), and an EU representative under Article 27 GDPR is not required because the controller is established in the EU (Greece). For any data-protection matter, contact us at privacy@cravedit.com.
2. The data we collect, why, and our lawful basis
We group the data by category. For each category we explain what it is, why we use it, and the lawful basis under the GDPR. "Contract" means we need it to provide the service you asked for; "Consent" means you can give or withdraw permission; "Legitimate interests" means we have a genuine business reason that is balanced against your rights; "Legal obligation" means the law requires it.
A. Account data
What: your email address and password (registered through Supabase Auth — your password is handled by Supabase and never reaches our own servers); if you choose "Sign in with Google", Google returns your email address, name and profile picture; a display name; and, if you add them, an optional profile bio, social links and an avatar photo.
Why: to create and secure your account, sign you in, show your public profile, and contact you about your account.
Lawful basis: Contract (account creation and sign-in); Consent (optional Google sign-in, optional bio/links/avatar); Legitimate interests (account security).
B. Location data
What: when you grant location permission we use your precise GPS location to centre the map on you. Importantly, when you make a contribution — a price, stock or "does it exist" vote, adding or suggesting a store or a drink, or a drink-request photo — your precise coordinates are currently attached to that contribution so it can be placed on the map. We also derive and store: a fuzzed "current location" offset by roughly 1 km; a coarse region of about 1 km together with a region label; your country; and a fuzzed signup-location anchor used to detect fraud.
Why: to show nearby drinks, to place your contributions on the map accurately, to power local leaderboards and regional features, and to detect fraud and location spoofing.
Lawful basis: Consent (device location permission, which you can turn off at any time); Contract (placing the contributions you choose to submit); Legitimate interests (fuzzing for privacy, fraud and spoof detection).
C. Photos
What: your profile avatar, and the photo you take when you request a missing drink. These photos may show faces, storefronts, labels or other surroundings.
Why: avatars personalise your profile; drink-request photos let our reviewers verify a real, missing product before granting a reward.
Lawful basis: Consent (you choose to upload or capture each photo); Contract (processing your reward request).
D. Contributions and activity
What: your votes, your store and drink suggestions, your favourites, and which stores you view.
Why: to build and improve the map, to award points fairly, and to personalise what you see.
Lawful basis: Contract (the core map service); Legitimate interests (improving and securing the service).
E. Economy data
What: your points ledger, and your VIP subscription purchase and the related app-store transaction id.
Why: to run the points and VIP features, and to keep financial records.
Lawful basis: Contract (the features you use); Legal obligation (keeping accounting and tax records); Legitimate interests (preventing reward fraud).
F. Anti-fraud and security data
What: device information, a device fingerprint and install id; a hashed phone number (only if you use the invite or referral flow); your IP address (held transiently, for about one minute, only for rate-limiting); abuse and anti-spoof signals; and a trust score used in automated moderation and ban decisions.
Why: to keep rewards and leaderboards fair, to stop spam, bots, multi-accounting and spoofing, and to protect the service and other users.
Lawful basis: Legitimate interests (security, fraud prevention, fair play); Legal obligation where we must act on abuse. See Section 9 for how the trust score is used and your right to human review.
G. Moderation data
What: reports you make about other users, including the reason you select and any free text you write.
Why: to review and act on reports and keep the community safe.
Lawful basis: Legitimate interests (safety and moderation).
H. Notifications
What: in-app alerts only. We do not use a third-party push service.
Why: to tell you about rewards, replies, moderation outcomes and app news.
Lawful basis: Consent or Legitimate interests, depending on the alert.
I. Usage analytics (optional — OFF by default)
What: only if you opt in, anonymous app-usage and device data — for example screens viewed, in-app events, app version, device model and a coarse location derived from your IP — collected via Google Analytics for Firebase.
Why: to understand which features are used and improve the app. We do not use it for advertising.
Lawful basis: Consent. Analytics is OFF until you turn it on (the first-run prompt, or Settings → About & legal → Usage analytics), and you can turn it back off at any time. The data is processed by Google and may be stored in the United States (see sections 4 and 5).
J. Crash diagnostics
What: if the app crashes, technical crash data — the error and stack trace, app version, device model and OS, and a Google-generated installation identifier — collected via Google Crashlytics (part of Firebase). Separate from the in-app crash log you can choose to send us from Settings.
Why: to detect and fix crashes and keep the app stable.
Lawful basis: Legitimate interests (app stability). Crash diagnostics are ON by default; you can turn them off in Settings → About & legal → Automatic crash reports. The data is processed by Google and may be stored in the United States (see sections 4 and 5).
K. Advertising (Google AdMob — removed entirely by VIP)
What: Cravedit shows advertising served by Google AdMob — for users in the EEA and the UK the provider is Google Ireland Limited. There are two kinds: (a) small display ads (a small banner at the top of the screen, and occasional clearly-labelled ad cards inside product lists), and (b) optional rewarded ads you actively choose to watch to earn game points ("watch an ad to earn"). To select, show and measure ads, Google processes device identifiers including your device's Advertising ID, your IP address, and coarse ad-relevance signals such as device type and approximate (IP-derived) location. Whether Google may show you personalised ads or only non-personalised ones is governed by the consent popup the app shows before any ad is loaded — you can change or withdraw that choice at any time in Settings → Privacy options. For rewarded ads we ourselves receive only an anonymous completion callback ("this user finished watching an ad") so we can credit your points; we never receive, build or use any profile of your ad interests. VIP subscribers see no ads at all.
Why: ad revenue keeps Cravedit free; rewarded ads additionally offer an optional way to earn a capped number of game points.
Lawful basis: Consent (personalised ads in the EEA/UK — given, changed or withdrawn via the in-app consent popup); Legitimate interests (showing non-personalised ads when you decline personalisation, and verifying that a rewarded ad was really completed to prevent reward fraud). Rewarded ads additionally never run unless you tap to watch one. See also Google's privacy policy and Google's advertising explainer.
Apart from the Google AdMob advertising described in Section 2.K — always consent-gated for personalisation and removed entirely by VIP — we do not run other third-party advertising trackers in the app; analytics stays off unless you opt in, and you can switch off crash diagnostics.
3. Device permissions
The app asks for these permissions. You can grant or revoke each one in your device settings at any time; some features will not work without them.
- Precise location: to centre the map on you and to attach accurate coordinates to the contributions you choose to submit. See Section 2B.
- Camera: to take a drink-request photo and, if you wish, an avatar photo.
- Photo library: to choose an existing photo for your avatar or a drink request.
- Notifications: to show you in-app alerts about rewards, replies and updates.
4. How we share your data (processors and sub-processors)
We do not sell your personal data. We share it only with service providers ("processors") who handle data on our instructions, and where the law requires. The main providers and what each receives:
- Supabase — authentication. Receives your email, password and identity details. Hosted in the United States.
- Amazon SES — sends our account emails. Receives your email address and the message content.
- Google — "Sign in with Google" and Google Play billing. Receives sign-in and purchase data needed to authenticate you and process Android purchases.
- Google Analytics for Firebase — optional, used only if you opt in to usage analytics. Receives anonymous usage + device data to measure how features are used. Hosted by Google (United States).
- Google Crashlytics (Firebase) — crash diagnostics (on by default, you can opt out). Receives crash reports + device/app data when the app crashes. Hosted by Google (United States).
- Google AdMob (Google Ireland Limited for users in the EEA/UK) — advertising: a small banner at the top of the screen, labelled ad cards in product lists, and optional watch-to-earn rewarded ads. Receives device identifiers (including the Advertising ID), IP address and coarse ad-relevance signals; whether ads may be personalised is controlled by the in-app consent popup (Settings → Privacy options); VIP removes all ads. Hosted by Google (United States). See Section 2.K.
- Apple — App Store billing. Receives purchase data needed to process iOS purchases.
- Cloudflare R2 — stores your uploaded photos and serves map tiles.
- Photon / Komoot (Germany) — converts coordinates into place names. Receives only coarsened (reduced-precision) coordinates.
- OpenFreeMap — serves map tiles. Receives your IP address and the map area you are viewing.
- Discord — if you tap our community link, your use of Discord is governed by Discord's own privacy policy, not this one.
The providers listed above are the full, current list of our sub-processors, together with what each receives and where it is located. We update this section, and give notice, before a new sub-processor starts processing your data.
We may also disclose data to comply with the law, enforce our Terms, or protect our rights, users or the public; and to a successor in the event of a merger, acquisition or asset sale (you will be told if this happens).
5. International data transfers
Some of our providers are located outside your country, including in the United States. When we transfer personal data out of the EEA or the UK, we rely on appropriate safeguards — primarily the European Commission's Standard Contractual Clauses (SCCs), and the UK Addendum or International Data Transfer Agreement where the UK applies — together with additional protection measures where needed. You can ask us for more detail using the contact in Section 12.
6. How long we keep your data (retention)
We keep personal data only as long as we need it.
- Account: if you delete your account it is first soft-deleted with a 30-day grace period (so you can change your mind by logging back in); after that we anonymise it. Anonymising means we remove your profile and avatar and detach your identity.
- Price and stock votes: automatically deleted after 120 days.
- Financial records: purchases and VIP transactions are kept longer where we must for legal, accounting, tax and anti-fraud reasons.
- Your contributions to the shared map: store suggestions, price/stock and other votes, and new-drink requests are kept after account deletion in de-identified form, because removing them would damage the map for everyone. When we de-identify them we strip your precise location and delete any photos you uploaded, and they are no longer linked to you.
- Anti-abuse: to stop someone from farming rewards by deleting and recreating an account, we keep a one-way, irreversible fingerprint derived from your verified phone number. It cannot be turned back into your phone number and is kept only to prevent fraud.
- IP addresses: held only transiently (about one minute) for rate-limiting and are not stored long term.
When we no longer need data, we delete or anonymise it.
7. Your privacy rights
Depending on where you live, you have some or all of the rights below.
If you are in the EEA, the UK or a similar regime, you have the right to: access a copy of your data; receive it in a portable format; have inaccurate data corrected (rectification); have data erased; restrict our processing; object to processing based on legitimate interests; and withdraw any consent you gave (this does not affect processing already carried out). You also have the right to lodge a complaint with your data protection authority — but we would appreciate the chance to help first.
If you are in California (CCPA/CPRA), you have the right to: know and access the personal information we collect; delete it; correct it; and not be discriminated against for exercising your rights. We do not sell your personal information. If you choose to watch a rewarded ad and have allowed personalised ads, the advertising identifiers sent to Google (Section 2.K) may count as "sharing" for cross-context behavioural advertising under California law — you can opt out of that at any time in Settings → Privacy options (our "Do Not Share" control). We do no other "sharing", and you may still contact us. Some of the information we collect is "sensitive personal information" under California law (for example precise geolocation and financial account or identifier details). We use it only for the purposes described in this Policy — to provide and secure the service, place your contributions, process purchases and rewards, and prevent fraud — and not to infer characteristics about you, so the right to limit the use of sensitive personal information does not apply; we do not sell or share it. Some financial, security and anti-fraud records are exempt from deletion under the law.
How to exercise your rights:
- In the app: use the account-deletion option in Settings to delete your account.
- By email: contact privacy@cravedit.com for access, portability, correction, restriction, objection or to withdraw consent.
We will verify your request (usually via your account email) and respond within the time the law allows — generally one month under the GDPR, or 45 days under the CCPA, with an extension where permitted. You may use an authorised agent where the law allows.
8. Children
Cravedit is intended for people aged 18 and over. We do not knowingly collect personal data from anyone under 18. If you believe someone under 18 has given us personal data, contact us and we will delete it.
9. Automated decisions and profiling
We use automated systems to keep the platform fair and safe. In particular, we calculate a trust score from your activity and anti-fraud signals, and this score can feed automated moderation actions, including limiting features or banning an account, and weighting how much your votes count.
You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. If an automated action has significantly affected you, you can ask for human review, express your point of view and contest the decision by contacting privacy@cravedit.com.
10. Security
We take reasonable technical and organisational measures to protect your data. Passwords are handled by Supabase Auth and never reach our servers; phone numbers in the invite flow are stored only as a hash; IP addresses are held only transiently; and access to personal data is limited. No system is perfectly secure, so we cannot guarantee absolute security.
11. Changes to this policy
We may update this Policy as the app evolves or the law changes. If we make material changes we will update the "Last updated" date and, where appropriate, notify you in the app. Continuing to use Cravedit after a change means you accept the updated Policy.
12. Contact us
Questions or requests about your privacy:
Evangelos Leivaditis
Email: privacy@cravedit.com
Community: https://discord.gg/JWpCkJsG6v
Governing law for this Policy: Greece.
CRAVEDIT