savourd.

Privacy Policy

Last updated 26 September 2026

Who we are

Savourd is an app for reviewing the restaurants, bars and pubs you go to in Manchester. The data controller is Archie Comparelli, trading as Savourd, based in Manchester, United Kingdom. This policy covers the Savourd iOS app, the Savourd web app, and this website.

For anything in this policy, or to exercise any of the rights below, email hello@savourd.co.uk. A person reads it; there is no support queue to get lost in.

You must be 18 or over to use Savourd. Savourd covers pubs, bars and cocktail bars, and we do not knowingly hold data about anyone under 18. If you believe we do, email us and we will delete it.

What we collect, and why

Each item below names the lawful basis we rely on under the UK GDPR.

Your account
Your email address, your handle, and the city on your profile. If you sign in with Apple or Google we receive the account identifier they give us, and the email address you choose to share (Apple’s private relay address counts, if that is what you pick). Optionally a short bio and a profile picture. Lawful basis: Performance of our contract with you — we cannot give you an account without it.
What you write
Your reviews: the place, where you put it in your list, what you said about it, the dishes you named, the tags and the caveat you picked, the visit date if you set one, and any photos you added. Also your “bests”, your want-to-try list, who you follow, who you have blocked, and any reports you send us. Lawful basis: Performance of our contract with you.
Taste preferences
Cuisine, atmosphere and budget preferences you set, used to order what you see. In the web app you can also record dietary needs (vegetarian, vegan, gluten-free, halal, kosher) and choose whether they are visible on your profile. Some of those can reveal a religious belief or a health condition, so we treat them as special category data and rely on your explicit consent, given by entering them. Clear the field and the consent is withdrawn. Lawful basis: Consent (Article 6(1)(a) and Article 9(2)(a)).
Device location
Only when you tap the “near me” control on the map, and only while you are using the app. Your coordinates are used on your device to move the map camera and nothing else. They are never stored and never sent to us — there is no column in our database that holds your location. You can refuse the permission and the map still works; it just starts over central Manchester. Lawful basis: Consent, given through the iOS permission prompt.
Photos and camera
Only the images you choose when you add a photo to a review. We do not read your photo library otherwise. Lawful basis: Consent, given through the iOS permission prompt.
Diagnostics
Crash and error reports through Sentry: the error, where in the app it happened, your device model and OS version, the app version, and your Savourd account id so we can tell one person’s bad session from a fleet-wide fault. In the iOS app, and on the public pages of this website, we have turned off IP address and user agent collection — an IP does not help debug a crash. On the signed-in web app it is left on, and a small sample of those sessions is recorded for replay. Lawful basis: Our legitimate interest in an app that works and gets fixed when it doesn’t.
Product analytics
Through PostHog: which screens you open and which actions you take, tied to your Savourd account id and your handle. Never your email address. Lawful basis: Our legitimate interest in understanding which parts of Savourd are used.

What we deliberately keep out of analytics

This is a design decision in the code, not a preference we might quietly drop:

  • Your review text, your notes and the dish names you write are never sent to our analytics. The events record only whether a review had notes, and how many dishes it named — enough to answer “do people write notes?” without shipping what they wrote.
  • What you type into search is never sent either — only how many characters it was. People search for venue names, for their friends, and occasionally for things they would not want recorded.
  • Your email address never reaches analytics. The function that identifies you has no parameter an email address could travel in.
  • Session replay is off in the iOS app, and on the public pages of this website. We do not record your screen in either. (The signed-in web app does record a sample of sessions for error diagnosis — see Diagnostics above.)

Who can see what

  • Your reviews are public inside Savourd. Other signed-in Savourd users can see your handle, your reviews and where you ranked each place, the notes and dish names you wrote, your photos, your bests and your lists. Notes and dishes are quoted on venue pages, on the map and in other people’s recommendations, attributed to your handle. There is currently no setting that makes an individual review private — write accordingly.
  • Savourd is not open to the web. None of it is visible to people who are not signed in, and search engines cannot reach it.
  • Blocking works in both directions. If you block someone, your reviews stop being served to them and theirs stop being shown to you. This is enforced by the database, not just the app.
  • Your dietary needs are hidden by default and shown on your profile only if you turn that on yourself.
  • We can see your data. Archie has administrative access to the database, used for support, moderation and debugging. Reports you send are read by hand.

Your photos

Review photos live in a private storage bucket. They are not served from a public URL: every time a screen needs to show one, the app exchanges the file path for a signed link that expires after an hour. A link that leaks stops working the same day.

Who processes your data

We do not sell your data and we do not share it with anyone for their own purposes. These are the companies that process it on our instructions:

Supabase
Database, authentication and private photo storage. Our project runs in AWS eu-west-2 (London, United Kingdom), so your account and everything you write stays in the UK.
Vercel
Hosting for this website and our API. United States.
Google Places API
Venue names, addresses, opening information and photos. When you search for a place, your search text is sent to Google so it can answer — your identity is not. The request is made by our server on our API key, not by your phone. United States.
Mapbox
Map tiles. Opening the map sends Mapbox the tiles your device asks for and your IP address — what any request for a tile needs in order to be answered, and nothing beyond it. The Mapbox SDK’s own usage telemetry is turned off in the app. United States.
Sentry
Crash and error reporting, on Sentry’s EU region (Germany).
PostHog
Product analytics, on PostHog’s EU Cloud.
Expo / EAS
App updates. The app asks Expo’s servers whether a newer version of its code is available, which means Expo sees your IP address and your device’s build fingerprint. United States.
Apple and Google
Sign in with Apple and Google sign-in, if you use them. They tell us who you are; they also know you signed into Savourd.

International transfers

Your account, your reviews and your photos are stored in the United Kingdom. Diagnostics and analytics are processed in the European Economic Area, which the UK recognises as providing adequate protection.

Vercel, Google, Mapbox, Expo and Apple process data in the United States. Those transfers rely on the European Commission’s Standard Contractual Clauses together with the UK International Data Transfer Addendum, or on the UK Extension to the EU–US Data Privacy Framework where the company is certified under it.

Keeping it, and deleting it

  • We keep your account and what you have written for as long as your account exists.
  • You can delete your account from inside the app: Me → Account → Delete account. That permanently deletes your account, your reviews and their photos, your lists and positions, your bests, your want-to-try list, your follows in both directions, your blocks, your reports and your match scores. It is not a deactivation and it cannot be undone.
  • Deleted data can persist in our database provider’s encrypted backups until those roll off, which on our Supabase plan is up to 7 days. Backups are not queried by the app; they exist to restore the service after a failure.
  • Diagnostic events in Sentry expire on Sentry’s retention schedule, 90 days for error events. Analytics events in PostHog expire under our PostHog plan’s retention settings.
  • If you would rather we deleted your account for you, email hello@savourd.co.uk and we will do it within 30 days.

Your rights

Under the UK GDPR you have the right to ask us for a copy of your data, to have anything inaccurate corrected, to have your data deleted, to receive it in a portable format, to restrict how we use it, and to object to processing we carry out on the basis of our legitimate interests — which includes the analytics and diagnostics described above. Where we rely on your consent, you can withdraw it at any time.

Email hello@savourd.co.uk to use any of them. We will respond within one month. There is no charge.

If you are not happy with how we have handled your data you can complain to the Information Commissioner’s Office at ico.org.uk, or on 0303 123 1113. We would rather you told us first, but you do not have to.

No advertising, no tracking across apps

Savourd carries no advertising. We do not sell or rent your data. We do not track you across other companies’ apps or websites, and we do not share anything with data brokers. That is why the app never shows you iOS’s “allow tracking” prompt: there is nothing for it to ask about.

Cookies and storage on this website

The four public pages of savourd.co.uk — this one, the home page, the terms and the support page — set no cookies, store nothing in your browser, and send nothing to anyone while you read them. No analytics, no session recording, no visit counter, no third-party requests at all.

That is enforced in the code rather than left to configuration. Our analytics is not switched off on these pages; it is never started on them, and our error reporter is built without the session-recording and visit-tracking parts rather than with them turned down. A check runs against the live site and fails if any of that stops being true, so this paragraph cannot quietly go out of date.

The one exception: if a page itself breaks, an error report is sent so we can fix it. That happens only when something actually goes wrong, and we have turned off the setting that would attach your IP address to it.

If you sign into the Savourd web app, Supabase sets cookies that keep you signed in. Those are strictly necessary — turning them off signs you out. The signed-in web app is also instrumented in the ordinary way described elsewhere in this policy; these four public pages are not.

Changes to this policy

If we change how we handle your data we will update this page and move the date at the top. If the change is significant we will tell you in the app before it takes effect.

Contact

Archie Comparelli, trading as Savourd, Manchester, United Kingdom. Email hello@savourd.co.uk.