CityCrumbs is operated by CityCrumbs, Inc. ("CityCrumbs", "we", "us"), a Delaware corporation. You can reach us at hello@citycrumbs.com, and we will provide a postal address on request.
This policy covers both this website and the CityCrumbs mobile app for iOS and Android.
If you join the waitlist, we collect the phone number you enter and the date you submitted it. We record that you agreed to receive text messages, along with the exact wording you agreed to, so we can demonstrate consent if asked. Stored alongside it are the city the form was set to, the page you arrived from, your browser's user-agent string, and a one-way hash of your IP address — we keep the hash rather than the address itself, and it exists to evidence that consent, not to identify you.
This website does not use cookies, advertising trackers, or analytics. We do not build a profile of your visit.
When you create an account we collect your email address, username, display name, and optionally a profile photo, a short bio, and a home city you type in yourself.
You can sign in with Google or with Apple instead of a password. From Google we receive your basic Google profile information. From Apple we receive an identifier, your email address, and — only on the very first sign-in — your name. If you use Apple's Hide My Email, we only ever see the relay address Apple gives us, never your real one.
We collect the content you create: the places you save, your notes about them, photos and videos you upload, the lists you build, and who you follow.
The app asks permission to use your location, camera, photo library, and microphone. These are used to show nearby places and to let you attach media to a recommendation. You can decline any of them, and you can change your mind later in your device settings — parts of the app will simply not work. When you search for a place, what you type and your approximate coordinates go to our own server, which passes them to Google Maps; we hold the Google key there so it never ships inside the app.
We use PostHog to understand how the app is used. This is product analytics, not advertising.
We use Sentry to find out when the app breaks. It collects crash reports and error details, your device model and operating system version, your IP address, and the account id of whoever hit the problem.
Sentry also records a session replay — a playback of how the app was used in the run-up to a problem. All text, images, and graphics in that recording are masked before they leave your device, so what reaches us is a moving wireframe of taps and screens, not your photos, your notes, or anyone else's. We record these to fix bugs and for nothing else.
Likes, comments, follows, and list updates are stored as notifications on your account so the app can show them to you, and the unread count is mirrored onto the app icon badge. We do not currently send push notifications, and we do not collect a push token for your device. If that changes we will update this policy first.
We do not sell your personal information, and we do not share it with advertisers.
Joining the waitlist means agreeing to receive automated marketing texts at the number you gave us. Message frequency varies. Message and data rates may apply — those are charged by your carrier, not by us.
Reply STOP to any message to stop receiving them. Reply HELP for help. Opting out is immediate and permanent unless you sign up again.
We use Twilio to send these messages, so your number is shared with Twilio for that purpose. Carriers are not liable for delayed or undelivered messages.
Every list you make is marked public or private, and that setting is the whole answer. It is worth reading before you assume anything else.
A public list is public on the open web, not just inside the app. It gets a page on citycrumbs.com — as do your profile and the places in it — showing your username, your photo, your notes, and the media you attached. Those pages are:
A private list is none of those things. It is visible to you, it is not rendered on the web, and it is not indexed. Saving a place to a private list is the quiet option, and it stays quiet.
Making a public list private stops us serving its page, but we cannot make a search engine forget it and we cannot reach a copy someone already took. Treat anything you have published as published.
We share data with companies that run parts of the service for us, and only for that purpose:
We may also disclose information if the law requires it, or to protect our rights or someone's safety.
We run an internal tool that reads publicly posted roundups — a food writer's list of ten restaurants, say — and turns them into a draft list for that writer to claim. To do that we store the public handles and names mentioned in the post, the address of the post, and its caption.
Nothing from that tool is visible to anyone but us until a real person claims it and chooses to publish it, and an unclaimed draft is deleted after 30 days. If you have found yourself in one and would rather not be, email us and it goes immediately.
Waitlist phone numbers are kept for 24 months from the day you join, or until you opt out — whichever comes first. Account data is kept while your account is open. Crash reports and session replays are kept for up to 90 days. Unclaimed drafts from the tool described above are deleted after 30 days. If you delete your account we delete or anonymise your data within 30 days, except where we must keep records to comply with the law. We keep a record that you opted out for as long as we operate, so we don't text you again by mistake.
Some privacy laws — the California Consumer Privacy Act, the Delaware Personal Data Privacy Act, the GDPR — grant rights to know what a company holds about you, to have it corrected or deleted, to take it elsewhere, and not to be treated worse for asking. Whether any of them currently applies to a company our size, we extend those rights to everyone who uses CityCrumbs. Email us and we will honour the request.
We do not sell personal information or share it for cross-context behavioural advertising, so there is nothing to opt out of on that front.
CityCrumbs is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has given us information, email us and we will delete it.
Data is stored with Google Firebase and protected by access rules, encryption in transit, and encryption at rest. No system is perfectly secure, and we cannot guarantee absolute security.
If we change this policy we will update the date at the top, and for significant changes we will tell you in the app or by email.
CityCrumbs, Inc., a Delaware corporation
hello@citycrumbs.com
For privacy requests, put "Privacy" in the subject line. We will provide a postal address on request.