Privacy Policy
Last updated: August 3, 2026
Sericaia ("Sericaia," "we," "us") is a restaurant diary and social discovery service, available on the web and as an iOS app. This policy explains what information we collect, how we use it, and the choices you have — including how to permanently delete your account and everything tied to it.
Information we collect
We collect the following categories of information, all provided directly by you or generated through your use of Sericaia:
- Account information: your name, username, email address, and password (stored only as a salted cryptographic hash — we never store or can recover your actual password). If you sign in with Google, we receive your name, email address, and profile photo from Google instead of a password.
- Content you create: visit logs, ratings, written reviews, photos you upload, lists and their descriptions, comments, likes, your profile bio, and your follow relationships with other users.
- Location information (mobile app only):if you grant permission, your device's precise location is sent to our server to compute restaurants popular near you. It is used only to answer that single request and is never stored or logged — we do not retain a history of your location.
- Device and security information: a device identifier generated by the mobile app (used to manage your login session and let you sign out of individual devices), and your IP address (used transiently for rate limiting and abuse prevention — not retained beyond that purpose).
- Product analytics and diagnostics:which screens you open and which actions you take (for example “a visit was logged”, or “a search returned no results”), plus crash and error reports. This is tied to a pseudonymous identifier derived from your account — not to your name, email, or username. We never collect the text you write (reviews, notes, comments, list descriptions, reports), the words you search for, your photos, or your location. Anything you mark private is recorded only as an action having happened, never with the restaurant, dish, list or rating involved. You can turn this off at any time in Settings → Privacy, which stops all collection — on your device and on our servers — and deletes the usage data already associated with your account.
We do not use advertising SDKs, we do not track you across other apps or websites, and we do not sell or share your information with data brokers.
Email we send you
We only send email about your own account — never marketing, and never on anyone else's behalf. There are three:
- Confirming your address when you create an account. Your account works whether or not you confirm; confirming is what lets us help you recover it later.
- A password reset link, when you ask for one. The link works once and expires after 30 minutes. We store only a one-way hash of it, so the link in your inbox cannot be reconstructed from our records.
- A notice that your password was changed, so you find out if somebody else changes it. It contains no link.
If you ask to reset a password for an address that has no account, we say exactly the same thing as if it did, and send nothing. That is deliberate: it stops anyone using the form to discover whether a given person has a Sericaia account.
How we use your information
- To operate the core features of Sericaia — your diary, feed, lists, and social graph.
- To authenticate you and keep your account secure (fraud/abuse prevention, rate limiting).
- To show you restaurants popular with people you follow or near your current location.
- To communicate with you about your account when necessary (e.g. a security notice).
- To understand which parts of Sericaia are used and where they fail, so we can fix and improve them — never to profile you or to target advertising.
How we share your information
We do not sell your information, and we do not share it with advertisers. We do share limited information with:
- Other users of Sericaia,according to your own privacy settings — a visit or list you mark private is only ever visible to you; anything else is visible to other users per Sericaia's normal social features (following, public reviews, etc.).
- Google,only if you choose to sign in with Google, and only to authenticate you. Restaurant details and photos shown in Sericaia are sourced from Google's Places API, but using that feature does not send your personal information to Google.
- Infrastructure providers who host our servers, database, and uploaded photos on our behalf, strictly to operate the service — never for their own independent use.
- Our email provider(Resend), which delivers the account emails described above. It processes your email address, and the contents of those messages, solely to deliver them on our behalf and under contract — never to market to you, and never for its own purposes. Email is processed in the EU.
- Our analytics and error-reporting providers (PostHog, for product analytics; Sentry, for crash and error reports), which process the pseudonymous usage and diagnostic data described above on our behalf and under contract. Data is processed in the EU and is never used for advertising.
Your choices and rights
- You can mark any visit or list private at any time, restricting it to yourself only.
- You can turn product analytics off at any time in Settings → Privacy. Doing so stops all further collection — both in the app and on our servers — and deletes the analytics profile already held about you. Turning it back on later resumes collection from that point; it does not restore what was deleted.
- You can edit or delete individual visits, reviews, photos, comments, and lists.
- You can permanently delete your account at any time from Settings (web) or your Profile (mobile app), after confirming your password. This immediately and permanently deletes your account and everything tied to it — there is no grace period or recovery afterward.
Data retention
We retain your information for as long as your account is active. When you delete your account, your data is deleted immediately, not after a delay — see "Your choices and rights" above.
Children's privacy
Sericaia is not directed at children, and we do not knowingly collect information from anyone under 13. If you believe a child has provided us with personal information, contact us using the details below and we will delete it.
Security
Passwords are never stored in plain text. Sessions use short-lived, rotating credentials, and all traffic to Sericaia is encrypted in transit. No method of transmission or storage is 100% secure, but we work to protect your information using practices appropriate to the sensitivity of the data involved.
Changes to this policy
We may update this policy from time to time. If we make material changes, we'll update the "Last updated" date above.
Contact us
Questions about this policy or your data? Contact us at franciscosousa391@gmail.com.