mapelly

Privacy policy

Last updated October 2, 2026

Introduction

This Privacy Policy explains which personal data the App processes, why, for how long, and what rights you have. It applies to the mobile application and its web version. Capitalized words have the meaning given in the Terms of use.

The data controller is: Leman Byte [Street and number], [Postal code] [City], Serbia Contact email: contact@lemanbyte.com

In short

  • You can use the map without an account. Your precise position stays on your device.
  • If you sign in with Google or Apple, the App receives your name, email address and a unique identifier of your account, as well as your profile photo with Google.
  • Your reports are shown publicly without your name. They may reveal health information, such as having been ill after a meal.
  • The App has no advertising and no analytics or tracking tools, and the Owner does not sell your personal data.
  • You can delete your account at any time, directly in the App.

Data processed when you use the App

Location

If you allow it, your device’s location is used on your device to center the map on you and show the places around you. Your precise position is not sent to the Owner’s servers. You can withdraw this permission at any time in your device settings.

Map and search

To show restaurants, the App sends the Owner’s servers the area of the map you are viewing and what you type in the search bar.

Data stored on your device

Your appearance setting and, once you sign in, your session and a copy of your saved places are stored on your device. Signing out removes the session and the saved places from the device.

Technical data

Like any online service, the Owner’s servers and those of its service providers receive technical data when the App contacts them, such as your IP address, the type of device or browser and the time of the request. This data is used to deliver the Service, to secure it and to prevent abuse (for example by limiting the number of requests) and is kept for a limited period.

Data processed when you have an account

Account

When you sign in with Google, the App receives from Google a unique identifier of your Google account, your name, your email address (when Google has verified it) and a link to your profile photo. When you sign in with Apple, the App receives from Apple a unique identifier of your Apple account, your name (Apple shares it only the first time you sign in) and your email address, or an Apple relay address that forwards to it if you choose to hide your email. The Owner also records when the account was created and when you last signed in. The App never receives your Google or Apple password, and your email address is never shown to other Users.

Saved places and “Ate here, no issues”

The restaurants you save, and the restaurants where you confirmed a visit with no issues, with the date of the confirmation. Other Users only see how many visitors confirmed a visit with no issues, never who.

Reports

For each report: the restaurant, category, severity, date of visit, optional text and the date it was sent. Reports are linked to your account so that you can see, edit or withdraw them; this link is never shown publicly. The category, severity, date of visit and text are shown publicly on the restaurant’s page, without your name.

Health information

A report can reveal information about your health, for example that you were ill after a meal or had an allergic reaction. Many laws give such data extra protection. The Owner only processes it because you choose to send it, to publish your report and calculate the restaurant’s level. Please do not include more health details than needed, nor any information about other people.

Public reviews

The Owner’s team reads public online reviews by hand to write reports about food-safety incidents. Nothing is copied from them: the Owner does not store or publish their text, rating or photos, nor the names or profiles of the people who wrote them. A report written from a review only states, in the Owner’s own words, that a customer reported an incident, with the month the review was posted.

Why the data is processed

  • Providing the Service (showing restaurants, keeping your account, saved places and confirmations, publishing your reports and calculating levels): performance of the agreement with you (the Terms of use).
  • Health information in your reports: your explicit consent, given by tapping “Agree and send” when you send a report. You can withdraw it at any time by withdrawing the report in Settings → My reports, which deletes it. You can also delete your account, which deletes all your reports, or write to the Owner.
  • Location: your consent, given through your device’s permission.
  • Securing the App, preventing abuse and moderating content: the Owner’s legitimate interest in keeping the App reliable and its information fair.
  • Reading public reviews to write reports: the Owner’s legitimate interest in informing the public about food safety. These reports do not identify the people who wrote the reviews.
  • Health information in public reviews, for example that a reviewer was ill after a meal: the reviewer made it public themselves by publishing the review.
  • Complying with the law and answering requests from authorities: legal obligations.

Who receives the data

The Owner does not sell your personal data and does not share it for advertising. It works with the following service providers:

  • hosting providers, which run the App’s servers and database;
  • Infomaniak (Switzerland), an artificial intelligence provider: the text of reports, without your name or account, is sent to it to check that they follow the rules before they are published and to write restaurant summaries. It also writes the sentence of the reports the Owner’s team creates, from the team’s choices only: it never receives the text of public reviews;
  • Google, when you sign in with Google (Google’s privacy policy applies to your Google account), and for the App’s fonts, which are downloaded from Google Fonts;
  • Apple, when you sign in with Apple (Apple’s privacy policy applies to your Apple account);
  • OpenFreeMap, whose servers deliver the map, built from OpenStreetMap data, and Nominatim, which the Owner’s team uses to place restaurants on the map from their address.

The Owner may also disclose data to public authorities when the law requires it.

International transfers

The Owner is based in Serbia, and its service providers are located in several countries, including Switzerland and the United States. Your data may therefore be processed outside your country. When the law requires it, the Owner relies on appropriate safeguards, such as adequacy decisions or standard contractual clauses.

How long the data is kept

  • Account, saved places and “Ate here, no issues” confirmations: until you remove them or delete your account.
  • Reports: as long as the App is operated, because restaurant levels rely on their history, unless you withdraw them or delete your account, which deletes them.
  • Session: a sign-in stays valid for up to 90 days, after which you need to sign in again.
  • Data stored on your device: until you clear the App’s data or uninstall it. Signing out removes your session and saved places from the device.
  • Technical data: for a limited period, for security purposes.

Deleting your account and data

You can delete your account at any time, directly in the App: Settings → Delete my account.

Deleting your account permanently deletes:

  • your profile: name, email address, profile photo link and Google or Apple account identifier;
  • your saved places;
  • your “Ate here, no issues” confirmations;
  • all your reports. The restaurant levels no longer count them, and the restaurant summaries that mentioned them are rewritten within a day.

If you signed in with Google, the App’s access to your Google account is also removed.

Deletion cannot be undone.

Removing the App’s access in your Google or Apple account settings does not delete the data held by the Owner: delete your account in the App as described above.

If you can no longer sign in, write to contact@lemanbyte.com and the Owner will delete your account.

Your rights

Depending on the law that applies to you, in particular the EU and UK General Data Protection Regulation, the Swiss Federal Act on Data Protection, the Serbian Law on Personal Data Protection and the privacy laws of US states, you have the right to:

  • access the personal data the Owner holds about you and receive a copy of it;
  • have it corrected if it is inaccurate;
  • have it deleted;
  • restrict or object to its processing, including processing based on legitimate interest;
  • receive it in a structured, machine-readable format (portability);
  • withdraw your consent at any time, without affecting the processing carried out before;
  • lodge a complaint with the data protection authority of your country.

To exercise these rights, write to contact@lemanbyte.com. The Owner will answer within one month and may ask you to confirm your identity, for example by writing from the email address linked to your account.

Children

The App is not intended for children under 13, and the Owner does not knowingly collect their personal data. If you believe that a child under 13 has created an account, write to contact@lemanbyte.com and the account will be deleted.

Security

The Owner takes reasonable technical and organizational measures to protect your data, such as encrypted connections and restricted access to its servers. However, no method of transmission or storage is completely secure.

Changes to this Privacy Policy

The Owner may update this Privacy Policy. The date of the latest update is shown at the top of this page. If the changes are significant, the Owner will inform Users in the App or by email.

Contact

For any question about this Privacy Policy or your personal data, write to contact@lemanbyte.com.

Read the Terms of use