Privacy Policy
Bon Manger (“the app”) is a personal tool for saving, organising, and sharing restaurants and dishes. This policy explains what we collect, why, how it’s handled, and your choices. It is written to align with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. What we collect
Account information. When you sign in with Apple, Google, or email, we receive an account identifier and, usually, your email address. If you use Apple’s “Hide My Email”, we receive only Apple’s private relay address. You may optionally provide a display name.
Content you create. The places, dishes, notes, tags, lists, and want-to-go / been-there states you save. Your personal notes on a place are private to you and are never shared. Notes you add to a specific dish travel with that dish, so they are visible to anyone you share or co-own the list with (see Section 4). This is the core of the service and is linked to your account.
Images. Images you add from your device, and — where available — images we retrieve and store our own copy of from a link you share or paste (including images from third-party social posts or web pages). See Section 6.
Links you capture. When you paste or share a link (e.g. Instagram, TikTok, Google Maps, a web page), we send it to a server-side function to pre-fill the place’s name, address, and location. For map links we use Google Places. For social posts, we retrieve the post (including its caption and any images) through a scraping provider, and send the posting account’s name and the caption to an AI provider to identify the venue. The caption is used only to identify the venue when you save it and is not stored.
Usage analytics (no personal content). We record product events (e.g. app opened, a place saved, a filter applied) to understand usage. These events never include your name, email, the text you typed, place or dish names, notes, or search queries — only hashed identifiers, enumerated values, and coarse counts.
Approximate location (analytics). We use your IP address to derive an approximate location — country, region, and city — so we can understand where our users are (we’re launching in Melbourne first). This is coarse and city-level only; we do not store the IP address itself and we do not collect precise/GPS location for analytics. (The map’s centre-on-me feature is separate — see below.)
Device/technical. Standard service logs from our providers.
We do not collect contacts, precise or background location, or advertising identifiers (the approximate, city-level analytics location above is IP-derived, not GPS). The map centres on your precise location only when you grant permission, and that location is used on-device for the map view — it is not sent to our analytics or stored.
2. How we use your information
- To provide the app: store and sync your library, lists, and images.
- To enable sharing you initiate: co-owned lists and read-only web links.
- To operate accounts and sign-in, and (when offered) subscriptions.
- To understand and improve the product via privacy-preserving analytics.
- To send limited service messages (e.g. a pre-charge trial reminder), if applicable.
We do not sell your personal information, and we do not show ads or use your data for third-party advertising.
3. Who processes your data (sub-processors)
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, image storage | Australia |
| PostHog | Product analytics (no PII) | United States |
| Google (Places) | Resolving shared/pasted links to a place | United States |
| Apify | Retrieving (scraping) shared social posts to resolve a place | United States |
| Anthropic (Claude) | AI identification of a venue from a shared post’s caption | United States |
| Apple | Sign in with Apple; In-App Purchases (if premium) | United States |
| Vercel | Hosting the read-only web share pages | United States / global |
| Expo | App delivery, over-the-air updates | United States |
| Resend | Sending account/sign-in emails | United States |
Some providers are overseas; where data is handled outside Australia we take reasonable steps to ensure it is protected consistently with the APPs.
4. Sharing and disclosure
- Co-owned lists. If you co-own a list, its members can see and edit that list’s places and dishes, including any notes you add to a dish. Your personal notes on a place stay private to you and are not shared.
- Read-only share links. If you create a share link for a list, anyone with the link can view that list (its places, dishes, dish notes, and images) on the web with no account. Your personal notes on a place are never included. The link is unguessable; you can revoke it at any time in the app.
- We disclose information if required by law, or to protect rights, safety, or the integrity of the service.
- We never sell personal information.
5. Your choices and rights
- Access and correction. View and edit your content in the app at any time.
- Deletion. You can permanently delete your account and associated data from Settings → Delete account. This removes your account, saved places, dishes, notes, tags, and the lists you created (including shared lists, which are removed for their members). This cannot be undone. Backups are purged on our providers’ standard cycles.
- Analytics. Analytics are optional: we ask for your consent on first launch, and you can turn them off (or back on) at any time in Settings → Privacy → Anonymous analytics. Because analytics carry no personal content, they cannot be tied back to you by name.
- Under the Privacy Act you may request access to, or correction of, your personal information, and may complain about how we handle it (Section 11).
6. Third-party content, images, and takedown
Some images and details originate from third parties (e.g. a restaurant’s or creator’s social post). When you save such a link, we may store our own copy of the preview image so it persists for you and on surfaces you share. You are responsible for ensuring you have the right to save and share content you add. If you are a rights-holder and believe content has been stored or displayed without authorisation, contact us at hello@bonmanger.app and we will review and remove it promptly.
7. Security
We use reputable providers with industry-standard protections, database-level access controls that restrict each record to its owner (and a list’s members), and we keep secrets off the client. No method of storage or transmission is perfectly secure.
8. Retention
We keep your information while your account is active. When you delete your account, your data is removed as described in Section 5. Aggregate, non-identifying analytics may be retained.
9. Children
Bon Manger is not directed at children. Don’t use it if you are under the age required to consent to processing in your jurisdiction (16 in Australia for these purposes unless a parent/guardian consents).
10. Changes
We may update this policy; we’ll change the effective date and, for material changes, notify you in the app.
11. Contact and complaints
Questions or privacy requests: hello@bonmanger.app. If you’re in Australia and aren’t satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
Effective 3 June 2026.