Legal
Privacy Policy
Jiak Simi is currently in pre-release testing — through Apple TestFlight on iPhone and iPad, and through a closed test on Google Play on Android. This policy describes the app as it works today; we will update it as the app develops, and the “Last updated” date above will change when we do.
1. Who we are
Jiak Simi (“Jiak Simi”, “we”, “us”, “our”) is a food-recommendation mobile application for Singapore, operated by Tan Zhi Ying Kimberley, an individual sole proprietor based in Singapore (the “Operator”). This Policy explains what personal data we collect via the Jiak Simi app (the “App”) and the website jiaksimi.ai (the “Site”), why, who we share it with, how long we keep it, and your rights. It is written to comply with Singapore’s Personal Data Protection Act 2012 (PDPA). By creating an account or using the App, you acknowledge you have read and understood this Policy.
2. The personal data we collect
We only collect what the App needs to give you food recommendations.
2.1 Data you give us
| What | Example | Why |
|---|---|---|
| Account details | Your email address | Create/secure your account; contact you about the service |
| Dietary preference | Omnivore, vegetarian, vegan, halal, halal-vegetarian; optional “no beef”; any allergies you tell us | Personalise food discovery. Dietary information may be inferred, incomplete, or wrong and is not certification or safety advice. We use allergy information only to show a prompt to check with the restaurant — never to mark a place “safe.” |
| Saved locations | Your Home and/or Work location | Recommend places near home/work |
| Taste quiz answers | Your onboarding-quiz picks | Build your starting “Palate Compass” |
| Saved places & ratings | Jiak List entries, want-to-try/eaten status, Shiok Score (0–100) | Track your list; refine your taste profile |
| Lists you choose to share | A Jiak List you publish to a link | Generate a shareable link |
| Feedback you send us | Free-text feedback via the in-app form | Improve the App. If you choose “send anonymously,” we store it with no link to your account. |
| Reports you make about a shared list | The reason you choose, and the reported list’s title and the display name its sharer typed | Review and remove content that breaks our Terms. A report is never anonymous — it is linked to your account so we can come back to you about it. |
| List cover photos | A photo you choose from your library as the cover of one of your lists | Shown only to you as that list’s cover. Hidden location metadata (GPS/EXIF) is stripped on upload; covers are private — they are not shown to people you share the list with — and are deleted with your account. |
| Links & captions you paste to import places | A YouTube/TikTok link and the caption text you paste with it | Spot restaurant names in the text so we can add those places to a list for you. See “Importing places from links” in Section 4. |
How you sign in. You create your account with your email address and a one-time code we email you — there is no password.
Trying the App before you sign up. You can start using the App — take (or skip) the taste quiz, see picks, and save places — before creating an account. During that time your activity is held against a temporary anonymous account that has no email, name, or other identifier attached to it. If you create an account, it becomes your account and your activity carries over. If you never sign up, the data stays unlinked to any identity.
2.2 Data we generate as you use the App
| What | Why |
|---|---|
| Your taste profile (“Palate Compass”) | Six taste scores + finer “palate notes,” from your quiz and the places you rate — the core of how we match you. |
| Taste profile history | Snapshots of how your taste changes over time (e.g. “your palate has been busy”). |
| Recommendation & visit activity | Which recommendations we showed you and what you did (opened, ignored, dismissed, added, “spun again,” logged a repeat visit). Used to improve recommendation quality — see the automated-personalisation note below. |
| Per-place taste adjustments | If you correct a place’s taste tags, we store your correction to sharpen your recommendations. |
Automated personalisation (transparency). Recommendations are personalised automatically from your activity — including a learned preference for the kinds of places you rate highly. This affects only what we suggest; it makes no decision with legal or similarly significant effect on you.
2.3 Data collected automatically
| What | Why |
|---|---|
| Device location (only if you allow it) | If you grant permission, to show places near you. Optional — the App works from your saved Home/Work without it. |
| Basic technical & first-party usage data | To run the App reliably and securely, and to understand which features are used (e.g. app version, device type, error logs, in-app session activity). |
We use our own systems (Supabase), Apple’s/Google’s built-in store reporting, and a crash-reporting service (Sentry) to keep the App running and fix errors. On a crash, Sentry receives technical diagnostics only — the error and stack trace, app version, device/OS type, and a short “breadcrumb” trail — configured not to collect your IP or other personal identifiers, and we never send it your account details or taste profile. We do not use any third-party behavioural or advertising analytics.
Bot protection. When you sign in or create an account, we run a silent bot check (Cloudflare Turnstile) to stop automated sign-ups. To do this, Cloudflare receives your IP address and browser/device signals. It does not receive your account, email address, taste profile or location — the check runs before you are signed in, so there is no identity to send. See Section 4.
Push notifications. If you allow notifications, we store a device push token and your notification preferences to send you service and activity notifications (for example, when someone saves a list you shared, milestone updates, and — if you enable it — a reminder when you’re near a place on your list). Delivery is handled by Apple Push Notification service / Google Firebase Cloud Messaging via Expo. You can turn notifications off at any time in the App or your device settings. We do not send marketing push notifications.
2.4 What we do not collect
We do not store payment card details. We do not knowingly collect data from anyone under 13.
3. Why we use your data (our purposes)
- Provide the core service — build your taste profile and recommend restaurants filtered by diet, distance, and price.
- Personalise and improve recommendations — learn from what works so matches get better.
- Operate your account — sign you in and save your lists across devices.
- Maintain, secure, and improve the App — fix bugs, prevent abuse and fraud, and understand feature use.
- Communicate with you — reply to support and send service messages (important changes, security notices). We do not send marketing or promotional emails.
- Comply with the law.
We collect, use, and disclose personal data with your consent, where this is necessary to provide the App you request, or where Singapore law otherwise permits. For limited security, fraud-prevention, and service-improvement work, we may rely on a permitted exception after assessing and mitigating the effect on individuals.
4. Who we share your data with
We do not sell your personal data. We share only with providers we need, only as far as necessary:
| Provider | Role | Data involved |
|---|---|---|
| Supabase (database & auth hosting; Singapore region) | Stores your account, taste profile, lists, and activity | The account and taste data in Section 2 |
| Google Maps Platform / Places | Restaurant info, addresses, photos, maps; find places near you | Your location / saved-location coordinates and search terms |
| OpenRouter (AI model routing; United States) | Routes our requests to a third-party AI model that generates restaurant taste tags. We may change model providers over time (currently a Qwen model). | Restaurant details and public review text, plus any link/caption text you paste to import places. We do not send your identity, email, or taste profile to the AI. |
| Sentry (crash reporting; United States) | Diagnostic report on a crash/error | Technical diagnostics only (error + stack trace, app version, device/OS, breadcrumbs); configured to exclude your IP and personal identifiers; no account details or taste profile |
| Cloudflare Turnstile (bot protection; United States) | Silently checks that sign-in and sign-up requests come from a person, not an automated script | Your IP address, browser/device signals (TLS fingerprint, User-Agent) and our site key. No account, email, taste profile or location — the check runs before you are signed in. See Cloudflare’s Turnstile Privacy Addendum. |
| Expo + Apple APNs / Google FCM | Deliver push notifications to your device | Your push token and the notification content |
| Resend (transactional email; United States) | Sends your account emails (sign-up confirmation, one-time sign-in codes) | Your email address and the message |
Google Maps. The App includes Google Maps features and content. When those features are used, Google may collect and process data under its own terms — see the Google Maps/Google Earth Additional Terms of Service (https://maps.google.com/help/terms_maps/) and the Google Privacy Policy (https://policies.google.com/privacy). Restaurant photos shown in the App are served by Google and credited to the person who took them.
Importing places from links. If you paste a link (for example a YouTube or TikTok food video) to import places, the link and any caption text you paste are sent to our AI provider (OpenRouter, above) to spot restaurant names. For YouTube links we also request the video’s public title and description from YouTube (a Google service). We never access your social-media accounts, and we don’t store the video — only the source link, kept with the list it created.
We may also disclose personal data if required by law, to enforce our Terms, or to protect the rights, safety, or property of our users or the Operator.
5. Sending data outside Singapore
Your core account and taste data is stored in Singapore (Supabase, Singapore region). Some processing necessarily happens outside Singapore: Google Maps processes location/place lookups on Google’s global infrastructure; our AI taste-tagging is routed via OpenRouter (US) to model providers that may sit in other countries; and Sentry stores crash diagnostics in the United States. Resend, which sends your account emails, also processes them in the United States. Cloudflare processes the sign-in bot check on its global network. The data sent for AI tagging is restaurant information and public review text (plus any link/caption text you choose to paste for link imports) — not your identity or taste profile; the data sent to Sentry is technical diagnostics excluding personal identifiers. The data sent for the bot check is your IP address and device/browser signals — not your identity, account or taste profile — and Cloudflare states it is used solely to detect bots, not to profile or target individuals. Where data is processed overseas, the PDPA’s Transfer Limitation Obligation requires comparable protection; we use reputable providers contractually bound to protect your data (data-processing agreements / standard contractual clauses).
6. How long we keep your data
- While your account is active — we keep your account, taste profile, lists, and activity so the service works.
- When you delete your account — deletion is immediate and permanent. Your data is removed from our active systems straight away and cannot be recovered. Residual copies in encrypted backups are overwritten on our normal cycle and gone within 30 days. This includes any list cover photos you uploaded. (See Section 8.)
- Limited exceptions — we may keep a minimal amount briefly where the law requires, or in de-identified form that no longer identifies you. In practice this means our running-cost records: we log what each AI tagging call and each restaurant-photo lookup costs us, so we can keep the App affordable. When you delete your account, your identity is removed from those records and only the cost, the timestamp and which restaurant was involved remain. They say nothing about you, your taste profile or where you have eaten, and they cannot be traced back to you.
7. How we protect your data
We take reasonable security measures — encrypted connections, database access controls, and established infrastructure providers (Supabase, Apple, Google, Sentry, Expo). No method is completely secure, but we work to protect your data and to respond promptly to incidents as required by the PDPA’s data-breach-notification rules.
8. Your rights and choices
Under the PDPA you may:
- Access the data we hold about you and how it’s been used/disclosed in the past year.
- Correct inaccurate data (much is editable in-app: diet, locations, lists, taste adjustments).
- Withdraw consent and delete your account at any time in Settings → Privacy & Data → Delete my Account (type DELETE to confirm); deletion is immediate and permanent.
- Control location — grant/revoke device location permission any time; the App still works without it.
- Control notifications — turn push notifications on/off in the App or device settings.
Withdrawing consent. You may withdraw consent at any time by writing to us (Section 11). We may need reasonable time to process this and will tell you the likely consequences — in some cases we may no longer be able to provide the App or certain features. Withdrawal doesn’t affect processing the law permits or requires us to continue.
Access/correction requests. Edit most data in-app; for anything else, write to us (Section 11). A reasonable fee may apply to an access request (we’ll tell you first). We respond as soon as we reasonably can, and within the 30 days the PDPA requires; if we need longer, we’ll say when.
9. Children
The App is not intended for children under 13, and we do not knowingly collect their data. If you believe a child under 13 has given us data, contact us and we’ll delete it.
10. Changes to this Policy
We may update this Policy. For a significant change we’ll notify you in the App or by email before it takes effect. The “Last updated” date shows the current version; continued use after a change means you accept it.
11. Contact us
The Jiak Simi Data Protection Contact — Email: hello@jiaksimi.ai
If you’re not satisfied with our response, you may contact Singapore’s Personal Data Protection Commission (PDPC) at www.pdpc.gov.sg.
Read together with the Jiak Simi Terms of Use.