GrubClique Privacy Policy

Effective date: October 5, 2026

GrubClique helps groups compare restaurant preferences and find shared matches. This policy describes the current Android app, web app, and public GrubClique website. It will be updated before any materially different data practice is released.

Accounts and profile information

You may create or access a GrubClique account using email and password or by continuing with Google. Account data can include your email address, unique user ID, permanent username, editable display name, authentication provider, onboarding status, and session information. Supabase provides GrubClique’s authentication and account-data hosting. Google processes information when you choose Google sign-in. GrubClique does not receive or store your plaintext password.

Information we use

GrubClique uses account and profile information; persistent Clique names, invite codes, administrators, and memberships; GrubHunt status and search settings; friend connections; hidden-restaurant preferences; restaurant filters, sorting preferences, and swipe choices; matches; and Clique and GrubHunt chat content to provide account access, group matching, GrubHunt history, preference controls, and communication. Clique administrators can add accepted friends or remove members. Any current Clique member can start or complete a GrubHunt, and each Clique can have up to two active GrubHunts. GrubClique does not display advertising and does not use advertising SDKs.

Contacts and profile choices

The web app lets you save, replace, or remove a profile picture with your account. Pictures are cropped and resized to a small JPEG in your browser before upload; original image metadata is not retained in that resized image. The image is stored in your server-side profile, follows your account across web browsers, and can be displayed to other signed-in users alongside your name in friend, chat, Clique, and participant views. Existing Android versions may still use a device-local picture instead of this synced picture. Removing the picture clears the server-side profile image; temporary browser copies disappear when refreshed. Account deletion removes the saved profile image.

GrubHunt participants can invite accepted friends for the owner to approve or decline. Invitation records store the hunt, invited account, requesting account, status, and request time until the hunt or relevant account is deleted. An approved guest can access that GrubHunt without receiving membership in the parent Clique or access to its other GrubHunts.

Optional website background alerts also cover completed GrubHunts with no matches. Tapping an alert opens the relevant chat, friend requests, or GrubHunt results after sign-in and a current membership check.

If you choose “Find friends from contacts,” the Android app requests access to your contacts. Valid phone numbers are normalized to the international E.164 format and converted to one-way hashes before contact matching; contact names and raw address-book numbers are not uploaded. During a compatibility period, valid +1 numbers also produce a legacy last-ten-digit hash so users on an earlier app version can continue to match. If you save an optional phone number for discovery during onboarding or in Account settings, another signed-in user can find your profile by entering an exact matching number, which is normalized and hashed before lookup. Signed-in users can also find a profile by entering its exact username or account email address. Contact importing can be disabled by revoking Contacts permission in Android settings. You can replace a saved discovery number from Account settings, and deleting your account removes its stored discovery hashes.

Location

GrubClique may request access to your approximate and precise device location while you use the Android or web app. Location is used to determine your general area and retrieve nearby restaurant results. Location access is optional: you may deny the permission or revoke it later in Android settings or your browser’s site settings, although nearby restaurant features may not work correctly without it.

When a Clique member starts a GrubHunt, the area or ZIP code entered, or the coordinates supplied by the device, and the selected radius are sent over an encrypted connection to GrubClique’s backend and Google Places. The resolved search coordinates and radius are stored with that GrubHunt so its participants receive a consistent restaurant pool. They are not added to a profile, used for advertising, or sold. Completing a GrubHunt prevents further swiping but does not immediately delete its stored location or history.

Device and browser storage

GrubClique stores information locally on your device or in your browser to keep you signed in and preserve app preferences. Depending on the platform, this can include authentication session tokens, the active clique and swipe position, notification choices, a locally selected profile image, and a local display copy of the phone number you entered. The server receives only the phone-number hashes described above, not that local display copy. Local information can be removed by signing out where applicable, clearing the saved session, removing the profile image, clearing the app or browser data, or uninstalling the app. Clearing local data does not delete information already stored with your GrubClique account.

Notifications

The website offers optional background notifications for chat messages, friend requests, and matches. Enabling them stores a browser push endpoint and encryption keys associated with your account so alerts can reach that device when the website is closed. Your browser’s push provider (such as Google, Mozilla, Apple, or Microsoft) delivers encrypted alerts. Background notification text is generic and does not include message content or restaurant names. Delivery depends on your browser, device settings, and connectivity. Disable background notifications in Account settings or your browser; signing out unsubscribes that browser, and account deletion removes its saved subscriptions. Delivery jobs are retried for up to one day and removed after delivery or when retries are exhausted. Chat read times are stored with your account to synchronize unread badges across devices. Foreground match alerts may include the matched restaurant name. The Android app’s existing match notifications work while the app is active.

Android versions with the Background notifications control offer opt-in alerts through Google Firebase Cloud Messaging (FCM). When enabled, Firebase processes an app-installation identifier, a delivery token, and configuration data to deliver alerts. GrubClique stores the token with your account ID and last-registration time in Supabase. Alert payloads contain a recipient ID, event ID, event type, and the relevant Clique or GrubHunt identifier so tapping an alert opens the correct destination; they do not contain chat text, restaurant names, or location. Android offers separate controls for friend requests, chat messages, and hunt outcomes, including a one-time no-match completion alert. The app does not include the Firebase Analytics SDK.

Personal GrubHunt filters are stored with your account and hunt so they can be restored across devices and used to calculate completion progress. A hunt-level receipt prevents repeated no-match alerts and is retained while the hunt exists. Android checks a public release policy to determine whether an update is available or required; the version comparison happens on your device. Cached release rules expire after 24 hours without a successful refresh.

You can turn Android background notifications off in Account settings or revoke the system notification permission. Turning them off or signing out suppresses alerts on that installation immediately; server token removal requires connectivity. Account deletion removes saved Android subscriptions. Inactive server registrations expire after 90 days, and delivery jobs are removed after delivery, exhausted retries, or one day. Delivery is subject to connectivity, battery restrictions, and Android settings; a force-stopped app may not receive alerts until reopened. Google’s processing is described in Firebase Privacy and Security.

Issue reports and diagnostics

GrubClique uses privacy-first product analytics to understand visits, short-lived sessions, screens, feature usage, broad device category, referring domain, country when available, and sanitized error types. Analytics uses an app-specific identifier kept only for the current browser session and does not connect events to your GrubClique account or track you across Redxjak apps. Raw IP addresses, full browser identifiers, restaurant names and searches, swipe targets, chat content, contact information, and other text you enter are not stored in analytics. Raw analytics events are retained indefinitely unless this policy changes.

If you submit an issue report in the Android app or on the public website, GrubClique processes the category, title, description, optional reproduction steps, optional contact email and follow-up choice, and any optional screenshot you select. Android reports also include the app version and code, device manufacturer and model, Android version, report source, and submission timestamp. The report does not automatically include your location, chat contents, credentials, or authentication tokens.

Issue-report text and receipt metadata, delivery status, and abuse-prevention records are processed through Supabase. Resend delivers the report to the GrubClique support mailbox. A selected screenshot is passed directly to the email service and is not saved in Supabase Storage. Public website reports use Cloudflare Turnstile and limited network information to identify automated abuse; authenticated app reports are throttled by a protected representation of the account identifier.

How information is shared and retained

GrubClique does not sell personal information. Information is used to provide account, Clique, and GrubHunt features and is visible only where needed for the group experience. A GrubHunt stores a snapshot of its participants: members added to a Clique later cannot see GrubHunts completed before they joined, while earlier participants may retain their own GrubHunt and match history after leaving or being removed from the persistent Clique. Clique administrators can permanently delete a Clique and its GrubHunts, messages, swipes, and shared match history for all members. Contracted service providers may process data for these purposes: Supabase authenticates users, hosts application data, and runs backend functions; Google provides optional sign-in, Places restaurant search, Maps destinations, and the receiving Gmail support mailbox; Resend delivers issue reports; and Cloudflare provides Turnstile abuse prevention on the public report form. Account, profile, friendship, Clique, GrubHunt, preference, match, and chat information may be retained while your account is active and as needed to operate the shared group experience. GrubHunt search location is retained only as described in the Location section.

Issue-report metadata stored in Supabase is deleted after 180 days, and rate-limit records are deleted after 24 hours. Copies delivered to the receiving Gmail mailbox, including screenshots, are retained according to the mailbox owner’s support and deletion practices.

Children’s privacy

GrubClique is intended for adults and is not directed to children under 13. We do not knowingly collect personal information from children.

Security and choices

Data transmitted by GrubClique is sent over encrypted connections. Access to shared clique data is limited using authenticated backend checks and database access controls. Keep clique codes private and share them only with people you trust. You can manage location, contacts, and notification access in Android settings or your browser’s site settings.

Account and data deletion

You may request deletion of your GrubClique account and associated data through the account-deletion page or the Delete account control in the Android or web app. After verifying account ownership, we will delete or anonymize associated account, profile, contact-discovery, friendship, clique, swipe, match, and chat data unless limited retention is necessary for security, fraud prevention, legal compliance, or resolving an active request. Deleting a GrubClique account created with Google does not delete your Google account.

Changes

We will update this policy when data practices, third-party services, or app functionality change. The effective date above identifies the latest revision.

Contact

Questions about this policy can be sent to redxjak@gmail.com. Product problems and suggestions can also be submitted through the GrubClique issue-report form.