krogat is a friends-first restaurant log. This page says what we store about you, why, and how to get it out again. It is written to be read, not skimmed past. If anything here is unclear, ask.
Who is responsible
The data controller is the operator of krogat. krogat is currently a private beta run by an individual, not a company. Supervisory authority: Integritetsskyddsmyndigheten (IMY), Sweden.
What we store
Account: your email address (for sign-in links), and if you sign in with Google or Apple, the name and avatar they pass to us. Profile: username, display name, avatar, Instagram handle, a short bio and your home city.
Ratings: every visit you log — restaurant, score, whether you would go back, date, meal type, dishes, a note, a price bucket, photos you attach, the friends you tag, and whether the rating is visible to friends or only to you.
Graph: who you follow and who follows you, circle memberships, invite links you create, and the tastemaker accounts you tick during onboarding.
Imported Instagram following lists: if you use "Bring your Instagram", we keep only the list of handles you follow, to match you with friends who join later. We never see your Instagram password, never read your messages, and never store the export file or screen recording — those are read once and discarded.
Lists: your Want-to-try list and any custom lists, including whether you made a list public.
Notifications and push subscriptions: in-app notifications, and if you turn on push, the browser endpoint needed to deliver them.
Analytics: product events such as "rating saved" or "map viewed", with your user id and no third-party trackers. Error reports go to Sentry with a stack trace and your user id, never your ratings.
What we deliberately do not store
Your location. We use your position in the moment to suggest nearby restaurants; it is never saved and there is no location trail. The only place-level data we keep is the restaurant you chose to rate and the city you picked.
Receipts. If you scan a receipt, the image is read once by an AI model to pre-fill your rating (date, dishes, total) and then dropped. We keep the extracted text, not the picture.
Google reviews or Google photos of restaurants. Restaurant facts (name, address, price level, rating count) are cached from Google for at most 30 days and refreshed.
Why we process it (legal basis)
Running the service you signed up for (contract, GDPR art. 6.1 b): account, ratings, graph, lists, notifications.
Your consent (art. 6.1 a): importing your Instagram following list, push notifications, the weekly email digest, and companion tagging emails. Each can be withdrawn in Settings.
Our legitimate interest (art. 6.1 f): keeping scores honest (anti-gaming checks on new accounts), fixing bugs, and understanding how the product is used in aggregate.
Who sees what
Other signed-in members see your profile, and your ratings that are set to "friends" (or, if you switched on "approve followers", only your approved followers see them). Restaurant pages show scores aggregated across members. Public restaurant and profile pages, and the share cards you generate, show only aggregate scores or what you chose to share.
Ratings marked "only me" count in your own history and never in anyone else’s score. Imported handle lists are never shown to anyone, including the people on them.
AI reads
On a restaurant page we show short AI-written summaries of members’ photos and notes, and of what named critics have published. To do that, members’ photos and notes for that restaurant are sent to Anthropic’s API. They are used for that read only, are not used to train models, and your name is never attached. These reads are context next to the scores and never change a score.
Processors we use
Supabase (database, auth, file storage; EU region) · Netlify (hosting; EU/US edge) · Google Maps Platform (restaurant search and map tiles) · Anthropic (AI reads, receipt scan, screen-capture import) · Resend (transactional email) · Sentry (error reporting) · Tripadvisor and Foursquare (restaurant data fetched about restaurants, never about you).
Some of these are outside the EU; transfers rest on the EU–US Data Privacy Framework or standard contractual clauses.
How long
For as long as you have an account. Delete your account in Settings and everything above is removed immediately, including photos and imported handle lists; backups roll off within 30 days. Aggregate scores are recomputed without you.
Your rights
Export everything we hold about you as JSON from Settings, any time. Delete your account from Settings, any time. You can also ask us to correct data, restrict processing, or object, and you can complain to IMY. Write to the address at the top.
Cookies
Two: a session cookie that keeps you signed in, and one that remembers your language. No advertising or third-party cookies.
Children
krogat is for people aged 16 and over.
Changes
If this policy changes in a way that matters, you will see a notice in the app before it takes effect.