Privacy Policy
What we collect, why we are allowed to, how long we keep it, and what you can make us do about it.
1Who we are
The controller
MoodBite is a service provided by Xium Labs Ltd, a company registered in England and Wales under company number 16702035, with its registered office at 124 City Road, London, EC1V 2NX.
Xium Labs Ltd is the controller of the personal data described in this policy. MoodBite is the name of the service, not a separate legal entity. Where this policy says "we" or "us", it means Xium Labs Ltd.
Contacting us about your data
Write to us at [email protected], or by post at the registered office above. Requests about your rights under section 10 should be sent to the same address and will be recognised however they are worded.
You do not need to use a particular form of words, quote this policy, or state which law you are relying on. If your message can reasonably be read as a request about your personal data, we will treat it as one.
Registration and oversight
Xium Labs Ltd is registered with the Information Commissioner's Office, the United Kingdom's supervisory authority for data protection.
2What we collect
Grouped by where it comes from. We collect nothing in these groups that the service does not use.
What you give us
When you create an account we collect your email address and, if you provide one, your name. If you sign in using an external identity provider, we receive your email address and display name from that provider, and no password.
The mobile app lets you describe what you want in three ways, and the last two are worth spelling out. A photograph is sent away to be read and is not kept. Speech is turned into text before it reaches us, so we receive the words and never a recording. Whichever way you start, what ends up in your history is the text, and it is deleted with the rest of your history.
- Account details: email address, display name, and profile settings.
- Preferences: the moods you select, cuisines you favour, budget range, and any dietary requirements you choose to record.
- Content you create: searches, favourites, reviews, notes, and messages you send us.
- Photographs of food, if you use photo search. You choose an existing picture or take a new one with the camera. The picture is sent to our machine learning provider to work out what the dish is, and is not retained: it is not written to our database, not placed in storage and not kept in our logs. Once the description comes back, the image is gone. We never ask for your photo library as a whole, only the one picture you choose or take.
- Spoken descriptions, if you use the microphone. See section 2.3 for what happens to the audio, which is that we do not get it.
- Reservation details: the restaurant, date, time, party size, and any request you add.
- Business accounts: the restaurant you claim, the evidence you submit to verify that claim, and the settings you configure.
What your device tells us
Some information reaches us simply because you connected to the service. We use it to keep the service running, secure and usable, not to build a profile of you.
- Network and device information: IP address, browser and device type, and language.
- Location: only where you have granted permission in your device or browser, and only to find places near you. You can withdraw that permission at any time in your device settings, and you can enter a location manually instead.
- Find people nearby: this is off unless you switch it on. When you do, we round your position to a grid roughly two kilometres across and keep only that area, not where you actually are. The stored area does not change while you move around inside it. Other people are never shown a distance or a point on a map, only a wide band such as "within 5 km", and only if you follow each other or you have chosen to be findable by anyone. We keep the area for thirty days after your last visit and then delete it automatically. Switching the setting off deletes it immediately.
- Service records: pages requested, errors encountered, and security events such as failed sign-ins and rate limits.
Worth knowing
What we do not collect
We do not use advertising networks, tracking pixels, cross-site trackers, third-party analytics services or advertising identifiers. There are none in the service.
We do not collect or store your card number, expiry date or security code. Card details are entered directly with a regulated payment provider and never reach our systems.
We do not buy personal data about you from data brokers, and we do not enrich your profile with information bought from anyone else.
We do not receive audio. Where you speak to the app instead of typing, your device or its operating system performs the transcription and only the resulting text is sent to us. The app asks for that transcription to happen on the device itself wherever the device supports the language; where it does not, the platform performs it under the platform's own terms. Either way no recording is made by us, sent to us or stored by us, and there is nothing in the service that could listen when you have not asked it to.
Read this
Information that can be sensitive
Some information you choose to give us can, by its nature, reveal something protected. A dietary requirement can indicate a health condition such as coeliac disease or a severe allergy, or a religious belief such as halal or kosher observance.
Where you enter that into your profile, we treat it as special category data under UK and EU data protection law. We ask for it only where you volunteer it, we rely on your explicit consent to use it, and we use it for one purpose: to filter and rank the places we show you. It is not used to profile you, it is not shared, and it is not used for any decision that produces a legal or similarly significant effect. You can remove it at any time from your profile, and doing so removes it from our systems as described in section 8.
The box where you describe how you feel works differently, and the difference matters. We ask you for an appetite, not for anything about your health, your beliefs or your private life. We do not want that information, we do not ask for it, and nothing in the service is built to act on it. Please do not put it there.
If you write something of that kind into that box anyway, we do not read it as you asking us to process special category data, and we do not rely on your explicit consent to hold it. It is handled only as part of the text you asked us to interpret, under the same basis as the rest of that text, and it is deleted with the rest of your history. If you would rather a particular entry were gone sooner, delete it from your history or write to [email protected].
The identifier in the mobile app
You can use the MoodBite app to search a couple of times before you create an account. To count those searches we need something to count them against, and it cannot be the guest account itself: a guest account can be replaced by clearing the app’s data, so a limit tied to it would not be a limit at all.
So the app generates a random identifier and stores it on your phone, in the iOS Keychain or the Android Keystore. It is a random string. It is not your advertising identifier, it does not describe your handset, and it is not combined with anything else about you. We use it for one thing: counting to two.
We keep it for 90 days from your last search and then delete it. If you create an account this stops, because your searches are then counted against the account and nothing further is written against the identifier. If you delete your account, the app clears the identifier and we delete our records of it at the same time, which restores the free searches.
Because the identifier lives on your phone and we hold no copy tied to your name, we cannot look it up for you. If you want to make a request about it under section 10, the app can show it to you and you should include it in your message.
3Why we are allowed to use it
Under UK and EU law every use of personal data needs a lawful basis. These are ours, purpose by purpose.
To provide the service you asked for
Creating and maintaining your account, returning recommendations, managing your favourites, submitting reservations and operating business accounts are all necessary to perform our contract with you. The lawful basis is Article 6(1)(b) of the UK GDPR and the EU GDPR.
To keep the service secure and working
We use service records to prevent fraud and abuse, to enforce rate limits, to investigate incidents and to diagnose faults. The lawful basis is Article 6(1)(f), legitimate interests, being our interest and yours in a service that stays available and is not overrun.
The same basis covers the identifier described in section 2.5, which counts the free searches offered before you create an account. Without it that allowance could not be enforced at all, and the cost of offering it would be unbounded.
We have weighed that interest against your rights. The data involved is technical rather than intimate, it is kept for a limited period under section 8, and it is not used to make decisions about you as an individual. You may object at any time under section 10, and for the app identifier in section 2.5, creating an account ends the processing.
Where we ask you first
We rely on your consent, Article 6(1)(a) and Article 9(2)(a) where the information is special category, for device location, dietary and other sensitive preferences, marketing messages, push notifications, and non-essential storage on your device.
You can withdraw any of these at any time, and withdrawing is as easy as giving. Withdrawal does not affect the lawfulness of anything done beforehand.
Where the law requires it
We retain records of transactions to meet accounting and tax obligations, and we may disclose information where we are legally required to. The lawful basis is Article 6(1)(c), compliance with a legal obligation.
4Automated processing and artificial intelligence
You are interacting with an automated system
MoodBite uses automated systems, including machine learning, to interpret what you describe and to rank the places we suggest. When you enter a mood or a description of what you want, that text is processed automatically to produce suggestions.
We tell you this because you are entitled to know when you are dealing with an automated system rather than a person.
Worth knowing
What the automated processing does and does not decide
The automated processing orders and filters suggestions. It does not decide whether you may hold an account, what you are charged, whether a reservation is accepted, or anything else producing a legal effect or similarly significant effect on you. Article 22 of the UK and EU GDPR, which governs decisions of that kind made solely by automated means, is therefore not engaged.
Reservation decisions are made by the restaurant, not by us and not automatically.
In broad terms, the logic works by matching what you describe against the characteristics of nearby places and the themes present in public reviews of them, then ordering the results by how closely they fit. It is a ranking of options, not a judgement about you.
Nothing in that order is bought. No payment by a restaurant moves it up or down the results. Advertisements appear beside results, are always marked as advertisements, and are selected separately from them.
Read this
Recommendations are suggestions, not advice
Automated suggestions can be wrong, incomplete or out of date. They are not dietary, medical, nutritional or allergen advice, and they must not be relied on as a safety measure.
If you have a food allergy, intolerance or medical dietary requirement, you must confirm directly with the restaurant before ordering or eating. Information about a venue may be inaccurate, may have changed, or may not reflect how a dish is prepared on the day. This warning is repeated in our Terms of Service because it matters more than anything else in either document.
5Who else sees your data
Worth knowing
We do not sell your personal information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in California and other United States privacy laws. We have never done so.
This is a statement about how the service is built, not only about our intentions. There is no advertising technology, no tracking pixel and no data broker relationship in MoodBite.
Service providers acting on our instructions
We use a limited number of suppliers to operate the service. Each acts as our processor, is bound by a written contract meeting Article 28 of the UK and EU GDPR, may use the data only to perform the service for us, and may not use it for its own purposes.
We describe them by category rather than by name. Publishing a component-by-component map of the systems that hold customer data hands an attacker a target list, and we consider that a poor trade for our users. If you want to know the identity of a specific supplier, ask us at [email protected] and we will tell you.
Mapping and place information is deliberately absent from the list below. That supplier does not act on our instructions and is not our processor, so it is described separately in section 5.6.
- Cloud hosting and content delivery, which run the service and defend it against attack.
- Database and authentication infrastructure, which stores your account and content.
- Payment processing, which handles card details we never see.
- Transactional email delivery, for messages such as confirmations and password resets.
- Push notification delivery, where you have enabled notifications.
- Machine learning processing, to interpret what you describe, read a dish from a photograph you choose to send, and rank suggestions.
Restaurants you book with
When you request a reservation we pass the restaurant the details it needs to honour it: your name, the date and time, the size of your party, and any request you added. Once received, the restaurant handles that information as its own controller, under its own privacy policy.
We do not give restaurants your browsing history, your other bookings, your saved preferences or your contact details beyond what a booking requires.
Read this
Mapping and place information
To show you restaurants near you, we send your location and your search terms to Google Maps Platform. This is the one supplier in this section that is not our processor.
Google operates Maps Platform under controller-to-controller terms, published at business.safety.google/controllerterms. That means it is an independent controller of the data it receives, not a supplier acting only on our instructions, and it may use that data for its own purposes under its own privacy policy. We cannot restrict that use on your behalf, and no contract we hold with it does so.
This is why granting location is optional and always has been. You can type a place name instead and never send us, or Google, a position at all. Where you do grant it, we hold a coarse area rather than a point, as described in section 2.
Legal disclosure
We may disclose personal data where we are required to by law, court order or a binding request from a competent authority, or where disclosure is necessary to establish, exercise or defend legal claims, or to protect the safety of any person.
We review such requests and refuse or narrow those which are overbroad, defective, or not supported by the law relied on. Where we are lawfully able to notify you of a request for your data, we will.
If the business changes hands
If Xium Labs Ltd is involved in a merger, acquisition, restructuring or sale of assets, personal data may transfer to the acquiring party. Any recipient remains bound by this policy in respect of data received under it until it lawfully provides you with a replacement notice. We will tell you before your data becomes subject to a materially different policy.
6Sending data outside the UK and EEA
When transfers happen
We are established in the United Kingdom. Some of the suppliers described in section 5.2, and the mapping provider described in section 5.6, operate infrastructure outside the United Kingdom and the European Economic Area, including in the United States. Where that happens, your personal data is transferred internationally.
How those transfers are protected
We transfer personal data outside the UK or EEA only where one of the following applies: the destination is covered by an adequacy decision or adequacy regulations; the transfer is governed by the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where UK data is involved; or another lawful transfer mechanism applies.
Where we rely on contractual safeguards, we assess whether the law and practice of the destination country would undermine them, and apply additional technical and organisational measures where needed.
You may ask us at [email protected] for information about the safeguards applying to a particular transfer.
7How we protect it
Security measures
We apply technical and organisational measures appropriate to the risk, as required by Article 32. These include encryption of data in transit, access control enforced at the data layer so that a fault in the application cannot expose one user's records to another, restricted administrative access with a second factor, and logging of privileged actions.
We describe our measures in general terms deliberately. A detailed public description of a system's defences is useful mainly to someone trying to defeat them.
If something goes wrong
No system is immune. If a personal data breach occurs and it is likely to result in a risk to your rights and freedoms, we will notify the Information Commissioner's Office without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by Article 33.
Where a breach is likely to result in a high risk to you, we will tell you directly and without undue delay, describing what happened, what it means for you, and what we are doing about it.
8How long we keep it
The principle
We keep personal data only for as long as it is needed for the purpose it was collected for, or for as long as the law requires us to. When neither applies, it is deleted or irreversibly anonymised.
The periods we apply
These are the periods we work to. Where a legal claim or an investigation is live, the relevant records are preserved until it concludes, and then deleted under the same rules.
- Account and profile data: for as long as your account is open, and deleted within 30 days of you closing it.
- Reservation records: six years, matching the limitation period for contract claims in England and Wales and the period for which business records must be kept.
- Payment and billing records: six years, as required for tax and accounting.
- Content you created, such as reviews: removed from public display when you delete it, and cleared from our systems within 30 days.
- Security and access logs: up to 12 months, then deleted.
- One-time codes and rate-limiting records: minutes to hours. These are transient by design.
- Cached place information: refreshed and overwritten continuously, and holding no account identifiers.
- Cookie consent records: six months, then we ask again.
Deleting your account
You can delete your account from your account settings. Deletion removes your profile, preferences, saved places and content. It is not a flag that hides you from view while your records remain.
Records we are legally required to keep, principally transaction records for tax purposes, are retained for the periods in 8.2 and are not used for any other purpose in the meantime.
9Cookies and storage on your device
What we store and how to control it
We store a small number of items on your device. Some are required to sign you in and keep the service secure. The rest remember preferences such as your selected mood and how you set your location.
Our Cookie Policy lists every item individually, with its purpose and lifetime. You can change your choices at any time using Cookie settings in the footer of any page, and refusing a category removes what is already stored for it.
In the UK and the EEA we ask before storing anything that is not strictly necessary. Elsewhere, you can refuse at any time and we honour automated opt-out signals such as Global Privacy Control wherever they are sent.
10Your rights
These rights are free to exercise. We will not treat you differently for using them.
Rights under UK and EU law
If you are in the United Kingdom or the European Economic Area you have the following rights in respect of your personal data.
- Access: a copy of the personal data we hold about you, and information about how we use it.
- Rectification: correction of data that is inaccurate or incomplete.
- Erasure: deletion of your data where one of the grounds in Article 17 applies.
- Restriction: to have us stop using data while a dispute about it is resolved.
- Portability: to receive data you gave us in a structured, commonly used, machine-readable format, and to have it sent to another controller where technically feasible.
- Objection: to object to processing based on legitimate interests, and an absolute right to object to direct marketing.
- Withdrawal of consent: at any time, without affecting what was done before.
Applies to United Kingdom, EU and EEA
Rights under United States state law
Depending on your state of residence, you may have rights under laws including the California Consumer Privacy Act as amended, and comparable laws in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and other states.
We extend the following to residents of any US state that provides them, without requiring you to establish that a particular threshold applies to us.
- To know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of recipients.
- To delete personal information we hold about you, subject to the exceptions the relevant statute provides.
- To correct inaccurate personal information.
- To obtain a portable copy of your personal information.
- To opt out of sale, sharing and targeted advertising. We do none of these, so there is nothing to opt out of, but the right stands and the mechanism is available.
- To limit the use of sensitive personal information. We use it only to filter your results, which is within the permitted purposes, and you can remove it at any time.
- To appeal a refusal. If we decline a request, our response explains why and how to appeal, and we respond to appeals within the statutory period.
- Not to be discriminated against for exercising any of these rights.
Applies to United States
Health-related information
Some United States laws, including the Washington My Health My Data Act and Nevada Senate Bill 370, treat information that can indicate a health condition as consumer health data. Dietary requirements and recorded moods may fall within those definitions.
We collect that information only where you volunteer it, use it only to filter and rank the places we show you, never sell it, and never share it for advertising. You may withdraw your consent and have it deleted at any time by removing it from your profile or by writing to [email protected].
Applies to United States
How to exercise your rights
Send your request to [email protected] from the email address on your account, or from any address if you tell us enough to find your records.
We respond within one month for requests under UK and EU law, extendable by two further months for complex requests, in which case we will tell you within the first month and explain why. For requests under United States state law we respond within 45 days, extendable once where the law permits.
We may ask you to confirm your identity before acting, because handing your data to someone impersonating you would be a worse failure than a delay. We ask for the minimum needed to be satisfied, and we do not use what you send for anything else.
You may use an authorised agent where the applicable law allows it. We will ask for evidence of their authority.
Complaining about us
If you are unhappy with how we have handled your data, please tell us first at [email protected] so we have the chance to put it right.
You can also complain to a supervisory authority. In the United Kingdom that is the Information Commissioner's Office. In the EEA it is the supervisory authority in the country where you live, where you work, or where the issue arose. You are not required to raise it with us before going to a regulator.
11Children
Read this
Minimum age
MoodBite is not intended for children. You must be at least 16 years old to create an account or use the service.
We do not knowingly collect personal data from anyone under 16. If we learn that we hold personal data belonging to a child under 16, we delete it promptly. If you believe a child has provided us with personal data, contact [email protected] and we will act on it.
12Changes to this policy
How we change it
This policy carries a version number and the date it takes effect, both shown at the top of the page. When we change it we update both.
Where a change materially affects how we use your personal data or what your choices are, we will tell you directly before it takes effect, by email to the address on your account or by a prominent notice in the service. Where a change requires your consent, we will ask for it rather than assume it from your continued use.
