Korin legal
Privacy Policy
Last updated: 24 August 2026
1. Who we are
Korin is operated by GAO ZIYUE. This policy applies to the Korin iOS app, website, waitlist, and related services. For privacy questions or requests, contact feedback@eatwithkorin.com.
2. Data we collect
- Account and profile: email address, user ID, display name, optional profile image and biography, public-profile visibility choices, and notification preferences.
- Your activity: saved restaurants and foods, restaurant check-ins, ratings, reviews and review images, restaurant combinations, likes, and in-app notifications.
- Food-label analysis: label photos you submit, product name and category, extracted ingredients and nutrition facts, generated assessments, analysis history, and any contribution you choose to send for catalogue review.
- Search and device data: searches sent to the Korin API and, if you enable push notifications, an app-specific APNs device token linked to your account.
- Feedback: restaurant suggestions, feature requests, bug reports, and information you include in them.
- Waitlist: the email address you submit before launch.
- Technical data: short-lived request metadata, approximate network information, errors, and security events recorded by our hosting provider.
If you allow location access, the iOS app uses your current location on the device to calculate relative restaurant distance. When you check in, Korin temporarily sends the current coordinates to its API to verify that you are within 500 metres of the restaurant. The precise location is not stored in your Korin account.
3. How we use data
We use this data to authenticate you, provide and personalise app features, analyse food labels you submit, publish content and activity according to your choices, deliver notifications you enable, operate the waitlist, respond to feedback, prevent abuse, diagnose failures, maintain security, and meet legal obligations.
4. Public content
Your display name, profile image, biography, published ratings, review text and images, public restaurant combinations, and activity types enabled in your privacy settings may be visible to other Korin users. Reviews can remain visible on the relevant restaurant or food even when you hide them from your public activity page. Your email address, favorites, private food-label analyses, device token, notifications, and private account details are not published. Do not include sensitive personal information in public content.
5. Service providers and external links
We use Cloudflare for application hosting, database, file storage, and operational logs; Supabase for authentication; Apple for iOS distribution, TestFlight, and push notifications; and an administrator-configured AI provider, such as OpenAI, Anthropic, or Google, to process the food-label images and extracted label text you choose to analyse. These providers process data on our behalf under their own terms. If you open an external map, restaurant, Lazada, or Shopee link, that third party receives the request and its own privacy policy applies.
6. Retention and deletion
Account data is kept while your account is active. You can permanently delete your account from Settings in the iOS app; this removes the active Supabase account, profile, preferences, device tokens, notifications, likes, favorites, check-ins, feedback, reviews, restaurant combinations, food-label analysis histories and contributions, waitlist entry with the same email, and associated user-uploaded images. You can also remove individual food-label analysis histories and withdraw eligible pending contributions in the app. Cloudflare D1 Time Travel may retain recoverable database history for up to 7 days on a Free plan or 30 days on a Paid plan. Worker operational logs are retained for up to 3 days on a Free plan or 7 days on a Paid plan. Waitlist data is kept until launch communications are complete or you ask us to remove it.
7. Security and international processing
We use HTTPS, access controls, encrypted secret storage, and restricted administrator accounts. No online service is completely risk-free. Our providers may process data in countries other than yours, subject to their safeguards and applicable law.
8. Your choices and rights
You can edit your profile, remove your own editable content where the app permits, withdraw optional location or photo access in iOS Settings, and delete your account in the app. You may contact us to ask for access, correction, deletion, or information about how your data is handled, subject to applicable law.
9. Children and changes
Korin is not intended for anyone who cannot consent to this data processing under the law that applies to them. We may update this policy as the service changes and will revise the date above; material changes will be communicated where required.
简体中文摘要
Korin 由 GAO ZIYUE 运营。我们处理登录邮箱、用户 ID、昵称、可选头像与简介、公开与通知偏好、收藏、打卡、评价与图片、菜品组合、点赞与通知、搜索、食品标签图片及分析记录、反馈以及候补名单邮箱,用于提供功能、维护安全和处理用户请求。启用 Push 后,App 会把与账户关联的 APNs 设备令牌保存到服务端;食品标签分析会把你主动提交的图片和标签内容发送给后台配置的 AI 服务商处理。 获得定位许可后,iOS App 会在打卡时临时把当前位置发送至 Korin API,用于验证你是否在餐厅500米范围内;精确位置不会保存。
你可以在 App「设置」中永久删除账户及相关资料,包括设备令牌、通知、点赞、菜品组合、食品分析记录与投稿及相关图片;也可以单独删除食品分析记录或撤回符合条件的待处理投稿。由于 Cloudflare D1 的恢复机制,已删除数据库记录可能在 Free 方案中最多保留 7 天、Paid 方案中最多保留 30 天;运行日志分别最多保留 3 天或 7 天。 如需访问、更正或删除资料,请联系 feedback@eatwithkorin.com。如中英文内容存在差异,以英文完整条款为准。