SatuJe legal
Privacy Policy
This policy explains the information SatuJe uses to provide nearby, personalised food suggestions and the choices you have over that information.
Updated 2026-09-25Who is responsible
SatuJe is responsible for the personal information described in this policy. For privacy questions or rights requests, email dev@satuje.app. The legal operator is identified in the footer of this page.
Information SatuJe uses
Continuing without registration creates an anonymous account. SatuJe stores its identifier and session, your language and preferences, taste affinities, recommendation requests and outcomes, provider place identifiers and feedback. If you enable Share usage analytics in Preferences, SatuJe also stores first-party product events. The anonymous account identifier links product interactions and provider-usage events for analytics, personalisation, and service reliability; it is not an advertising identifier. Optional analytics are off by default. Save your choice in Preferences to enable or withdraw consent; withdrawal stops new optional records and does not disable recommendations, History or Makan DNA. Service usage totals without user identifiers continue for capacity and service operation.
Optional contributions can include dish or menu files, restaurant and dish details, a permission confirmation, optional public credit, and a private contact email for restaurant submissions.
Location
SatuJe requests foreground location only when you ask for a nearby choice. It does not register background or continuous tracking. Current coordinates service the nearby search; recommendation sessions retain coordinates rounded to three decimal places rather than a precise movement trail. Google receives the search centre, radius, and relevant food query to return nearby places. You can instead enter a city, neighbourhood, or address without granting device-location permission. This text is sent to Google Maps to find matching areas. Your selected area is saved on your device and its coordinates are used as the search centre. Distances refer to that selected area.
Your choice about AI processing
Before sending requests to OpenAI, SatuJe asks for your explicit permission. OpenAI receives the text you type, including any personal information or dietary needs you include, to interpret your food request. If you use voice input, it also receives your recording and transcript for transcription, food-search relevance checks and interpretation. SatuJe does not add your account identifier or device coordinates to these AI requests. Avoid including information you do not want processed.
You can decline and use Choose for me and the basic quick picks without OpenAI. Review or withdraw AI permission in Preferences → Privacy & data. Withdrawal blocks new AI requests; it cannot recall data already sent. Microphone access and optional analytics are separate choices. We store your latest choice, disclosure version and time against your anonymous account to enforce your permission. This record is deleted when you delete your account.
Voice and reminders
After you allow AI processing and choose voice input, the recording is sent through SatuJe’s authenticated API to OpenAI for transcription and a food-search relevance check. Recordings are limited to 15 seconds. Stopping automatically starts a search when the request is relevant. SatuJe does not save the raw recording in its database or object storage, does not log it, and deletes the temporary device file after success or failure. The accepted transcript then follows the same flow as typed text. Short-lived account counters, keyed IP hashes and recording fingerprints help prevent abuse; these do not contain the audio or transcript.
Optional visit reminders are scheduled locally on your device. SatuJe does not register a push token or subscribe you to marketing notifications.
How information is used
SatuJe uses this information to authenticate the anonymous session, provide and personalise recommendations, remember choices, show history, operate optional contributions, prevent abuse, diagnose failures, measure product usage, handle support and privacy requests, and improve reliability. SatuJe does not sell personal information, show ads, or use information for cross-company advertising tracking.
Service providers
- Supabase provides anonymous authentication, database, and private file storage.
- Google Places and Google Maps provide nearby place results, details, and map destinations. Google Place IDs may be stored; response content is transient and is not persisted as SatuJe’s place database. When you open directions on iOS, you can choose Apple Maps or Google Maps. The selected service receives the destination and handles navigation under its own privacy policy.
- OpenAI processes typed requests into structured food intent and transcribes audio when you choose voice input.
- Vercel hosts the service. Hosting and authentication providers process request and security records, such as IP addresses, user-agent information, request paths, response status and timing, to operate, secure and diagnose the service. These operational records are separate from optional product analytics. Sentry reporting is disabled in this release. SatuJe excludes food-request text, precise coordinates, credentials and contribution files from application error reports.
These providers may use subprocessors and process information in the United Kingdom, Malaysia, Singapore, the United States, or other countries under contractual and organisational safeguards. SatuJe requires providers handling personal information on our behalf to provide the same or an equivalent level of protection described in this policy, including confidentiality, security and limits on use.
Advertising measurement
SatuJe advertises on Facebook and Instagram. To count which ads lead to installs, the SatuJe app includes the Meta SDK, which starts when the app opens. It sends Meta install and app-open events with an app-specific installation identifier and device information such as device model, operating system, app version, language, time zone and IP address.
On iOS, SatuJe does not ask to track you and does not access the device advertising identifier; attribution uses Apple’s SKAdNetwork and Meta’s aggregated measurement. On Android, SatuJe does not access the Advertising ID; Meta may use Google Play install-referrer information. SatuJe does not send Meta your account identifier, food requests, location, preferences, contributions or analytics events. Meta handles this information under its own privacy policy.
Reports and hidden contributors
Reports store the contribution reference, your account identifier, reason, optional details, and moderation outcome. Hiding a contributor stores a private link between accounts so their contributions can be hidden from your recommendations. Contributors are not notified of your block. Reports and blocks remain while the relevant accounts and contribution exist, unless deleted sooner. Your report and block records are removed when you delete your account.
Retention
User-linked preferences, history, and learning signals remain while the anonymous account exists unless deleted sooner. First-party analytics expire after 24 months, with hourly cleanup of expired records, or are deleted with your account. Service usage totals without user identifiers expire after 24 months. Cleanup audit records are kept for 90 days. Incomplete contribution uploads expire after two hours, completed pending submissions after 90 days, and rejected submissions after 30 days.
Raw voice recordings are not retained by SatuJe. We disable storage of OpenAI Responses API application state. OpenAI may nevertheless retain request text and responses in abuse-monitoring logs for up to 30 days, or longer when legally required. This includes transcripts sent for food interpretation. This is not a zero-data-retention service. Hosting and authentication providers may retain limited security, diagnostic and backup records under their service retention schedules and applicable law; deleting your SatuJe account does not immediately erase those independent records.
Your choices and deletion
You can decline optional permissions, edit preferences, avoid voice and contribution features, and delete your account in the app at Preferences → Privacy & data → Your data → Delete my SatuJe data. This removes the anonymous account and linked SatuJe data.
Shared restaurant identifiers, separately reviewed non-user-specific information, and statistics that can no longer be linked to your anonymous account may remain. See Manage your data for the full process and an external request route.
Children and changes
SatuJe is intended for adults and is not directed at children. Contact support if you believe a child supplied personal information. This policy may change as SatuJe develops; the updated date will change and material changes will receive an appropriate notice.
