Morel (“the Service”) is operated by Ardent Research, Inc. (“we”, “us”, or “our”). This Privacy Policy explains what information we collect, how we use and share it, and the choices you have.
1. Information We Collect
Account Information
When you create an account, we collect your email address, display name, and profile photo (if you sign in with Google). This is used to identify you on the platform and display your profile.
Phone Number (optional)
If you choose to add your phone number — an optional step used to confirm it's really you and to help friends find you — we collect it and send it to our SMS provider, Twilio, to deliver a one-time verification code. Adding a phone number is never required to use the app, and you can skip it or remove it at any time.
Contacts (optional)
If you choose to use the “Find Friends” feature and grant the app access to your contacts, we read your address book on your device and send only the phone numbers — never names or any other contact details — to our server. Each number is hashed and compared against the phone numbers of existing Morel users who verified a phone number.
We keep those hashed numbers so that when someone from your contacts joins Morel, we can tell you. We keep them only for that purpose and to show you people you know on the app. They are stored with our database provider and included in our backups, as described in Section 3, and we share them with no one else. We do not keep names or any other contact details, and we do not keep the numbers themselves in readable form — although a hashed phone number is not anonymous, so we treat them as personal information. Hashed numbers stay until you delete them — you can do that anytime from Settings → Notifications, and deleting your account deletes them too.
Granting contacts access is never required to use the app, and you can revoke it at any time in your device's Settings.
Check-in Data
When you check in to a restaurant, we collect your device's precise location (latitude and longitude, from GPS) to verify you are near the restaurant. We also collect photos you upload, dish ratings, and review notes.
Background Location (only with the always-on location permission)
If you grant the app the always-on location permission — “Always Allow” on iPhone, “Allow all the time” on Android — we receive location data while the app is not open, so we can remind you to check in. We receive none of it unless you grant that permission, and you can change it at any time in your device's settings.
On iPhone, your device sends us two kinds of data, and works out on its own when you arrived somewhere:
- Visit events (via Apple’s CLVisit framework). When iOS detects you have arrived at or departed from a place, your device sends us the visit’s centroid coordinates plus arrival and departure timestamps. We use this to detect when you may have visited a restaurant so we can send a relevant check-in reminder.
- Movement samples (via Apple’s Significant Location Changes framework). Coordinates with timestamps are sent from your device approximately every 500 meters of movement. We use these samples to derive candidate visits in cases where the CLVisit event arrived too late or did not fire at all.
On Android this works differently, and Google is involved. Instead of your device deciding on its own, we ask Google Play services to watch for you arriving at or leaving the restaurants we are interested in, and to tell us whether you are still, walking, or driving. That means Google Play services receives your location and the list of restaurants being watched, and it is Google rather than your own phone that works out that you arrived. What reaches us is the same either way: the place, the times, and how you were moving. See Section 3.
All of this background location data, on either platform, is stored for 90 days and then automatically deleted. It is stored alongside your account so visit reminders can reference your prior check-in history and so you can request a copy of (or deletion of) your data at any time — see Sections 6 and 7 below. Separately, when we detect a possible restaurant visit we send that result — the restaurant, roughly how close you were, and how long you stayed — to PostHog, our product-analytics provider (see section 3), where it is kept separately under the analytics retention in section 6 rather than on the 90-day schedule above. The underlying coordinates are not sent to PostHog.
To stop background location collection, change the Morel app’s location permission to something other than always-on. On iPhone that is Settings → Privacy & Security → Location Services → Morel, set to “While Using the App” or “Never.” On Android it is Settings → Apps → Morel → Permissions → Location, set to “Allow only while using the app” or “Don’t allow.” Visit reminders will stop firing. Setting it to “while using the app” leaves everything else working; turning location off entirely also stops check-in verification and walking directions, which need your location at the moment you use them.
Motion and physical activity (a separate permission)
If you grant the app the motion permission — “Motion & Fitness” on iPhone, “Physical activity” on Android — we receive a short summary of how you were moving alongside each visit event above. On iPhone your phone does all of the interpreting on-device, using Apple’s Motion & Fitness API. On Android this works differently: Google Play services does that interpreting, so Google is involved rather than only your device. See Section 3. What reaches us is the same either way:
- An activity label for the couple of minutes around the visit: one of stationary, walking, running, cycling, automotive, mixed, or unknown.
- For arrivals only, a second label covering the stretch since you arrived, plus three numbers that describe it: the share of readings that were stationary, how many seconds the stretch covered, and how many readings it contained.
We use this for two things: telling the difference between stopping at a restaurant and walking or driving past one, so we don’t send you a check-in reminder for a place you never entered, and measuring how often that judgement is right so we can improve it.
We do not receive step counts, workouts, distance, pace, floors climbed, raw accelerometer or gyroscope data, the individual readings behind the numbers above, or anything from Apple Health. We never use this data for advertising, profiling, or fitness tracking, and we never sell it.
We store the first label, together with the reminder decision it led to (for example, “skipped, looked like walking past”). Both are kept on the visit record they belong to and deleted on the same 90-day schedule as the location data above. That same label is also sent to PostHog, our product-analytics provider (see section 3), where it is kept separately under the analytics retention in section 6 rather than on the 90-day schedule above. The arrival-window label and its three numbers are used to make that decision and then discarded. They are never written to our database.
To stop motion collection, turn off Morel in Settings → Privacy & Security → Motion & Fitness on iPhone, or Settings → Apps → Morel → Permissions → Physical activity on Android. Visit reminders keep working, but they will be less accurate and you may get more reminders for places you only walked past.
Photo auto-find
When you check in, Morel can suggest photos you already took at that restaurant so you can add them in one tap. The matching runs on your device and we never receive or see your photo library: on iPhone it uses each photo’s time and location; on Android it also uses Google ML Kit to judge on-device which photos look like food, and that component reports usage and diagnostic information back to Google, though never the images. See Section 3. Only the photos you choose to add to a check-in are uploaded to us. We strip embedded location data from photos before upload; on the rare browser where that step cannot run, the photo is uploaded as it is and we record the failure so we can fix it.
Importing from another app (optional)
If you choose to bring your lists over from another restaurant app, you sign in to that app from within Morel. The sign-in details you enter are used only to reach your own account on that service and fetch your lists. Depending on your device, they either go straight from your device to that service or pass through our servers on the way. We never store your password, and we never use those details for anything other than the import you asked for. We store the lists, ratings, and photos that come back so they appear on your Morel profile. Importing is entirely optional and is never required to use the app.
Usage Data
We use PostHog and Vercel Analytics to collect usage data including pages visited, features used, and performance metrics. To understand and debug how features are used, PostHog also captures session replays — playbacks of your in-app interactions, such as taps and navigation. What you type into a form field is masked as you type it and is not recorded, but text you have already posted and that is shown back to you on screen, such as check-in notes, comments, and your bio, is visible in the replay. This helps us improve the Service. We honor your browser's “Do Not Track” signal for PostHog analytics and session replay, and we exclude our own admin accounts from PostHog. Neither exclusion applies to the usage events we record in our own database, or to Vercel's page-performance measurements.
Device Information
We collect standard technical information including browser type, IP address, and device type for security (rate limiting, bot detection) and analytics purposes. When you search or start a check-in, our bot-detection provider also runs a script that observes how the page is being used, such as timing and interaction patterns, to tell real people from automated traffic. See Section 3.
How you found us
We record how you arrived at Morel, so we know which of our own campaigns and invite links are working. That includes the referral or campaign code in a link you followed, and, when you install the app from an app store, the install-attribution information the store gives us: on iOS whether the install came from one of our App Store ads, and on Android the install referrer Google Play recorded, which can include a Google Ads click identifier. We do not use any of this to target ads at you.
2. How We Use Your Information
- To provide and improve the Service
- To display your check-ins and profile to other users
- To verify check-in authenticity via geolocation
- To detect when you may have visited a restaurant and send you a check-in reminder
- To prevent abuse and enforce our Terms of Service
- To send essential account-related communications
- To compute restaurant rankings and recommendations
- To measure which of our own campaigns and invite links brought people to Morel, never to target ads at you
3. How We Share Your Information
We do not sell or license your data, we do not share it with data brokers, and we do not share it for cross-context behavioral advertising or to target ads at you. The only advertising-related exception is measuring our own app-store ad campaigns. On iOS, the app sends Apple a one-time attribution token, described below. On Android, we read the install referrer that Google Play records when you install the app, which can include a Google Ads click identifier, so we can tell which campaign your install came from; that referrer is read on your device and sent only to our own servers, never to an advertising network.
We share data only with the service providers listed below, and only to the extent needed to operate the Service, with one exception you control: if you choose to bring your lists over from another app, the sign-in details you enter for that app go to that app, as described in Section 1.
Most of these providers are bound by an agreement with us that requires them to protect your data and use it only for the purposes we specify. Two groups are not. Google and Apple sign-in, Apple's ad measurement, and Meta act as independent companies under their own terms and privacy policies rather than on our instructions. And our place-lookup provider, the OpenStreetMap Foundation, runs a free public service that we use without an account or an agreement, so what it does with the coordinates and place names we send is governed by its own privacy policy.
Signing in
- Google and Apple (sign-in, only if you choose it) — handle your sign-in and return your email address and your name to us, and in Google's case your profile photo as well. Your name becomes your starting display name and username, and you can change both. If you use Apple's “Hide My Email”, we only ever receive the relay address Apple gives us. Their use of your data is governed by their own privacy policies.
Hosting, storage, and backups
- Supabase (database, authentication, file storage) — receives your account details, check-ins, photos, ratings, notes, collections, and follows. If you use Find Friends, hashed versions of your contacts' phone numbers are stored so we can tell you when someone you know joins. Hosted in the United States.
- Vercel (hosting, product analytics, and bot detection) — receives request metadata including IP address, user agent, and referrer for every page load and API call, plus page performance measurements. Vercel's bot-detection service also runs a script in your browser that looks at how the page is being used to tell real people from automated traffic; that service is operated for Vercel by Kasada.
- Cloudflare (backup storage) — receives a copy of our database and of the photos in our file storage, so we can restore the Service if something goes wrong. It is a backup only: nothing is served to anyone from it. See Section 6 for how long backup copies persist, including after you delete something.
- Upstash (rate limiting and short-lived caching) — receives your user ID, a salted one-way hash of your IP address, and, on our visit-tracking endpoints, part of your device token, to enforce per-user, per-IP, and per-device request limits. It also briefly caches your account status (whether your account is banned, suspended, or scheduled for deletion) and which legal documents you still need to accept. Two other things are cached for longer, and neither is stored against your account: when we work out which city you are in, the coordinates are rounded to roughly a 110-metre square and that square is kept for up to three days; and when you search, a numeric representation of your search wording is kept for up to 30 days so the same search does not have to be recomputed. None of this is used for any other purpose.
Analytics and error monitoring
- PostHog (product analytics and session replay) — receives a pseudonymous user identifier, IP address, device metadata, event data about your in-app actions, and session replays (playbacks of your in-app interactions). What you type into a form field is masked as you type it, but text you have already posted and that is shown back to you on screen, such as check-in notes, comments, and your bio, is visible in the replay. This event data includes which restaurant you checked in at or were detected near, how close you were, and how long you stayed, as well as the search terms you type.
- Sentry (error monitoring) — receives error stack traces, browser/device metadata, the address of the page or API request that failed, a pseudonymous user identifier, and a short trail of what led up to the error (recent screens you visited, taps, network requests the app made, and diagnostic log messages). It does not receive your session cookie or the contents of what you submitted. It also receives timing measurements for a sample of requests that succeed, so we can find slow parts of the app.
Maps and location
- Mapbox (maps and directions) — receives your device's location when you ask for directions, and the area of the map you are looking at as you pan and zoom. Because map tiles load directly from Mapbox, it also receives your IP address and a randomly generated identifier that Mapbox stores on your device. That identifier is not tied to your account, persists after you close the app, and is replaced with a new one roughly once a day.
- OpenStreetMap Foundation (place lookup) — receives your device's coordinates, or a place name you type, in order to work out which city you are in.
- Google (place search) — receives the venue and city names you type and your device's coordinates, in order to return matching restaurants. Restaurant photos supplied by Google also load directly from Google, which means Google receives your IP address when such a photo appears on a page you view.
On Android specifically
The Android app relies on Google Play services for things the iPhone app does with Apple's own frameworks, so on Android these go to Google:
- Google Play services (location and activity recognition) — if you turn on visit reminders, Google Play services receives your location and the set of restaurants we are watching for, and works out whether you are still, walking, or driving. On iPhone that interpreting happens on your own device; on Android, Google does it.
- Google ML Kit (photo auto-find) — decides on-device which of your photos look like food, so the images themselves are not sent anywhere. The component does report usage and diagnostic information to Google.
- Your speech engine (spoken walking directions) — if you use spoken directions, the instruction text, including street and destination names, goes to whichever text-to-speech app your phone uses, which on most Android phones is Google's.
AI and content moderation
- OpenAI and Anthropic (AI generation and automated content moderation) — for AI verdicts and dish recommendations, these providers receive restaurant names, menu descriptions, and snippets of publicly visible reviews. Separately, the text you write is sent to OpenAI's moderation service to automatically flag content that may violate our policies. That check covers review notes, comments, bios, questions, display names, and dish names you propose, and it runs on check-in notes even when you mark the check-in private. If you use the in-app dining assistant, the messages you send it, and the earlier messages in that conversation, are sent to Anthropic to generate a reply.
- Google (AI generation, Gemini and Vertex AI) — receives restaurant and dish names, snippets of publicly visible reviews, and the wording of dish names you enter, to generate recommendations and to match dishes to one another. It also receives photos you upload, when we suggest which dish a photo shows; the review notes you write, when we summarise what people say about a restaurant; the cover image or a first video frame of an Instagram or TikTok post you share with us, to read the venue name off it; and your search terms, to interpret what you are looking for. This is separate from signing in with Google, and it applies whether or not you use Google to sign in.
- OpenRouter (AI routing) — receives restaurant names, addresses, and menu listings, and passes them on our behalf to the model that serves the request, currently DeepSeek, and to Exa for a web lookup about the restaurant. OpenRouter chooses which company hosts that model, and it may be outside the United States. No text you have written is included.
- Sightengine (automated photo moderation) — receives a link to each photo you upload or import, and downloads it to automatically flag images that may violate our policies. That link is a public web address containing your account identifier, and for check-in and menu photos the restaurant name, so Sightengine can tell which photos belong to the same person. This covers check-in photos, profile pictures, crew images, menu photos, and photos brought over from another app, and it runs on check-in photos even when you mark the check-in private.
Messages and notifications
- Twilio (SMS verification, only if you add a phone number) — receives your phone number to send a one-time verification code.
- Resend (email delivery) — receives your email address and the contents of emails we send you, and, when you contact us, the message you wrote.
- Apple Push Notification Service (APNS) and Firebase Cloud Messaging (FCM) — receive a push token and the notification payload when we deliver a notification to your device. That payload can name another person or a restaurant — for example, who followed you.
- Meta (Instagram) — if you connect your Instagram account, we store the link between it and your Morel account and save your verified @username to your profile, hidden from your public profile unless you choose to show it. When you message us on Instagram or share a post with us, Meta receives our replies to you, which can name the restaurants we saved for you, and Meta stores those messages. Separately, whenever you import a post or video link in the app, our servers ask Meta's public API to look up the restaurant account mentioned in it; that request names the restaurant's Instagram handle, never you.
Support, feedback, and operations
- Slack (internal alerts) — receives operational alerts that can include your display name and username, content you posted that was automatically flagged for review, photos you uploaded that were flagged, a report you submit about someone else's content, the email address of a newly created account, and, if you submit the restaurant “get in touch” form, the name, email address or phone number, and message you entered there.
- Linear and GitHub (bug and feedback tracking) — receive the feedback you submit, an identifier for your account, and a temporary link to any screenshot or recording you attached. We do not attach your email address or name to these reports, though anything you type into the feedback box, or that is visible in a screenshot you attach, is passed along as you sent it. Separately, an internal report we generate to check that visit reminders are working can list the usernames of a small number of accounts. When we ask an AI assistant to help investigate a bug report, the report's contents, including anything you wrote in it, are sent to Anthropic.
- GitHub and Blacksmith (build and maintenance systems) — run the automated jobs that build, test, back up, and monitor the Service. Some of those jobs handle your data while they run: the weekly database backup is produced on a GitHub machine before it is stored, and our monitoring and configuration jobs run on machines operated by Blacksmith. These systems process data in order to run the Service; they are not given it for any purpose of their own.
- Apple (advertising measurement) — on iOS the app asks the system for a one-time, device-minted token and our server sends it to Apple, which tells us whether the install came from one of our App Store ads and, if so, which campaign. This happens for every iOS install, not only ad-driven ones. We send Apple nothing else: no name, email, account identifier, or your IP address. We do not receive an advertising identifier, we do not track you across other apps or websites, and we do not use this for advertising to you.
We may also disclose information (a) to comply with a legal obligation, subpoena, or court order; (b) to enforce our Terms or protect the rights, property, or safety of Morel, our users, or others; or (c) in connection with a merger, acquisition, or sale of assets, in which case we will notify you.
4. What Is Public to Other Users
The following is visible to other users of the Service by default: your display name, profile photo, bio, restaurants you've checked in at, dish photos and ratings, review notes, follower and following lists, collections you've shared, and your Instagram handle if you add one.
You control visibility in these ways:
- Private check-ins. You can mark an individual check-in as private when you post it, which hides it from the public feed and your public profile. Private check-ins are still used to compute your personal history and stats.
- Collection sharing. Collections (“Want to Go”, custom lists) are private by default. They are only visible to others if you generate a share link.
- Account deletion. You can delete your account at any time from Account Settings. See “Your Rights” below.
Search engines may index public profile and check-in pages. Once content has been public, copies may persist in search indexes and archives outside our control.
5. Legal Basis for Processing (EEA / UK Users)
If you are in the European Economic Area or United Kingdom, we process your personal data on the following legal bases under the GDPR:
- Contract (Art. 6(1)(b)) — to create your account, display your check-ins, and provide the core features you request.
- Legitimate interests (Art. 6(1)(f)) — for security (rate limiting, bot detection), fraud prevention, product analytics, and improving the Service.
- Consent (Art. 6(1)(a)) — for push notifications and, where required, non-essential analytics cookies. You can withdraw consent at any time.
- Legal obligation (Art. 6(1)(c)) — to comply with applicable law.
6. Data Retention
- Account data — retained while your account is active.
- Unfinished check-ins — a check-in you start and never finish stays in your account, along with any photos you added and the location recorded when you started it. You can finish it for 72 hours; after that it can no longer be completed. We delete some unfinished check-ins automatically once we have reminded you about them; others stay until you delete them yourself.
- Check-ins, photos, and ratings — retained for the life of your account unless you delete them.
- Server and access logs — retained for up to 90 days for security and debugging purposes.
- Analytics events — events about how you use the app are kept in two places: with PostHog, under its default retention policy, and in our own database, where we currently keep them for the life of your account. Deleting your account deletes our copy.
- Deleted accounts — personal data is removed from the live Service within 30 days of deletion, except where retention is required by law or to resolve disputes. Backup copies are covered separately below.
- Backups — we keep backup copies of our database and of our photo storage so the Service can be restored after a failure. Content you delete — including the photos of a deleted account — can persist in those backup copies after it is gone from the live Service. Our database provider keeps its own backups of the database on a short rolling window. Separately, we keep a weekly copy of the database, and copies of our photo storage, with our backup-storage provider; neither of those currently expires on a fixed schedule. We are working to put one in place, and we will state the retention period here once it is. Backups are used only to restore the Service or to recover content that was lost by accident, such as putting back a photo that went missing because of a fault on our side. We do not use them to build profiles, to answer questions about you, or to bring back anything you deliberately deleted. Because restoring returns part of the Service to an earlier point in time, content deleted after that point can reappear; if that happens, we will re-apply any deletion requests we received in the meantime.
7. Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Export your data in a portable format
- Ask us to stop using your data for product analytics (contact us). Enabling your browser's “Do Not Track” setting stops PostHog analytics and session replay on the web; it does not apply in the iOS or Android app, and it does not stop the usage events we record in our own database.
- Object to or restrict certain processing (EEA / UK)
- Lodge a complaint with a supervisory authority (EEA / UK)
California residents (CCPA / CPRA): You have the right to know what personal information we collect, request deletion, correct inaccurate information, and limit use of sensitive personal information. We do not sell or share your personal information for cross-context behavioral advertising, and we do not offer financial incentives in exchange for personal information. You will not be discriminated against for exercising these rights. The business responsible for your personal information is Ardent Research, Inc.
To exercise any of these rights, email us at the address below or use the “Delete Account” option in Account Settings.
8. Cookies and Local Storage
We use cookies for authentication (session management via Supabase). PostHog sets cookies and uses local storage to measure product usage and capture session replays; on the web you can opt out of those by enabling your browser's “Do Not Track” setting, which we honor. Our maps provider, Mapbox, stores a randomly generated identifier on your device, described in Section 3. We also use browser local storage to save your city preference and collection data for offline access. We do not use advertising cookies.
9. Security
We implement reasonable security measures including row-level security on our database, rate limiting, bot detection, and encrypted connections (HTTPS). However, no method of transmission over the Internet is 100% secure.
10. Children's Privacy
The Service is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at support@eatmorels.com and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the “Last updated” date at the top of this page.
12. International Data Transfers
Morel is operated by Ardent Research, Inc. from the United States, and most of our service providers are located in the United States. Some are not: our place-lookup provider is based in the United Kingdom, our automated photo-moderation provider is based in France, and our backup-storage provider operates data centres worldwide. In addition, Google processes the photos and review notes described in Section 3 on a multi-region endpoint, so that processing can take place in Google data centres outside the United States. Our AI routing provider may pass a request to a model host outside the United States; those requests contain restaurant and menu information, not text you have written. If you access the Service from outside the United States, your data will be transferred to and processed in the United States and in the other countries described above. Where required, transfers out of the EEA or UK rely on Standard Contractual Clauses or equivalent safeguards.