PRIVACY POLICY

Toochooz

Last Updated: August 19, 2026

 

 

PREAMBLE AND SCOPE

This Privacy Policy ("Policy") governs the collection, use, storage, transfer, and disclosure of information by Toochooz LLC, an Ohio limited liability company ("Toochooz," "Company," "we," "us," or "our"), in connection with the digital properties operated under the Toochooz brand.

 

This Policy applies to all of the following:

        The Toochooz iOS application, available through the Apple App Store.

        The Toochooz Android application, available through the Google Play Store.

        The Toochooz website, which consists of the restaurant-submission portal described below, a static informational "About" page describing the Company and the App, and the pages on which this Policy and the Toochooz Terms of Service are posted. The "About" page is static text and does not collect information from visitors.

        The Toochooz restaurant-submission portal, through which members of the public may submit restaurant listings, images, hours of operation, and related data, or submit listing removal requests, for moderation and potential inclusion in the Toochooz database.

 

The iOS and Android applications are referred to collectively as the "App." The website and restaurant-submission portal are referred to collectively as the "Website" or "Submission Portal." This Policy is published at a single URL and applies to each property. Where provisions are specific to one property only, they are clearly identified as such. By accessing or using any Toochooz property, you acknowledge that you have read, understood, and agree to be bound by this Policy in its entirety.

 

SECTION 1: DEFINITIONS

For the purposes of this Policy, the following definitions apply:

        "Personal Data" means any information that identifies or could reasonably identify a natural person, including but not limited to phone numbers, location data, device identifiers, and IP addresses.

        "User" means any individual who accesses or uses the App, the Website, or both.

        "App User" means any individual who has registered for and uses the Toochooz mobile application on iOS or Android.

        "Submitter" means any individual who accesses the Submission Portal to submit or request removal of restaurant data.

        "Username" means the permanent display name selected by an App User at the time of registration, limited to sixteen (16) characters.

        "Content" means any data, text, images, restaurant information, recipes, or other materials submitted by Users.

        "Database" means the Toochooz proprietary database of restaurant and recipe data, including all associated metadata.

        "Paired Session" means a linked connection between two registered App Users who have mutually elected to connect their accounts for the purpose of jointly swiping on restaurant or recipe cards.

        "Swipe Session Data" means affirmative or negative swipe inputs recorded during an active session. Swipe Session Data resets daily at 5:00 AM local time, as described in Section 2.8.

        "Match" means a card on which both paired Users have registered an affirmative swipe while that swipe remains eligible. Swipe eligibility runs until the applicable User's next daily 5:00 AM reset, and an active Match lasts approximately thirty (30) minutes, as described in Section 2.8.

        "Firebase" means the cloud infrastructure platform provided by Google LLC, used to host, store, and serve the Toochooz Database and user data.

        "Google Cloud Vision" means the automated image and text analysis service provided by Google LLC, used to screen submitted Content for prohibited material.

        "Pseudonymized" means that data is stored under an identifier that is not your name or phone number, but that could, with additional information held by Toochooz or a service provider, be linked back to an individual account. Pseudonymized data is not fully anonymous.

 

SECTION 2: THE TOOCHOOZ MOBILE APPLICATION — DATA PRACTICES

2.1 Overview

The Toochooz App is a free, swipe-based platform designed to facilitate joint decision-making between two users regarding restaurant selection and recipe discovery. The App is published and operated by Toochooz LLC, an Ohio limited liability company. The App is available on both iOS and Android, and the data practices described in this Section apply to both versions unless otherwise stated.

2.2 Account Registration — Phone Number and Mandatory Agreement

To access the core features of the App, users are required to register an account via phone number verification. Your phone number serves as your primary account identifier and authentication credential. It is stored securely in our Firebase backend. We do not collect your legal name, email address, or other personally identifying information at the point of registration beyond the phone number used for verification and the Username you select.

 

Before Toochooz sends a phone-number verification code, each prospective user must affirmatively select the checkbox agreeing to the Toochooz Terms of Service and this Privacy Policy. The App will not permit the user to request a verification code until the checkbox is selected.

 

After authentication is completed, Toochooz records the accepted Terms version, accepted Privacy Policy version, and acceptance timestamp with the user's account.

2.3 Username — Selection, Permanence, and Visibility

At the time of registration, you are required to select a Username of up to sixteen (16) characters. Your Username is permanent and cannot be changed after registration. Your Username appears at the top of your profile tab within the App. It is also visible to:

        Any user to whom you send a pairing request.

        Any user whose pairing request you receive and review.

        Any user currently paired with your account. While paired, your Username appears at the top of the Swipe Tab on your partner's device in a header reading "Swipe with" followed by your Username, and is also viewable via the Unpair Accounts screen.

 

Your Username is not publicly searchable and is not visible to the general user population. Because the Username is permanent, you are solely responsible for selecting a Username that is appropriate and compliant with the Terms of Service at the time of registration.

2.4 Pairing — Data Shared Between Users

The App's pairing feature allows two users to connect their accounts by phone number. You acknowledge and agree that:

        When you send a pairing request, the recipient sees your Username and phone number.

        When you receive a pairing request, you see the requesting user's Username and phone number.

        While paired, each user's Username is displayed to the other at the top of the Swipe Tab in a header reading "Swipe with" followed by the partner's Username. Each user can also view the other's Username and phone number via the Unpair Accounts screen.

        Pairing is entirely user-initiated. Toochooz does not suggest, match, or facilitate pairings through any backend process. All pairings are established solely through mutual user action.

        While paired, each user can view the active, approved recipes uploaded by the other user that are associated with the current pairing, via the Manage Recipes feature.

 

Toochooz does not sell pairing relationship data and does not share it with third parties for their independent commercial use.

Blocking Data

When a user blocks another user, Toochooz stores the blocked user's account identifier, Username, phone number, and blocking timestamp in a private blocked-users record associated with the blocking user.

 

This information is used to display the Blocked Users list, prevent pairing in either direction, reject pending pairing requests, and dissolve an existing pairing. The blocked-users list is visible through the App only to the blocking user.

 

A block remains active until the blocking user unblocks the account or deletes their own account. Blocking does not delete recipes. If the same two users later unblock and pair again, recipes associated with their prior pairing may become available again.

 

A blocked user is not directly notified of the block. A pairing attempt may display a standard request-submitted confirmation even though no request is created or delivered to the blocking user.

2.5 Pairing Dissolution — How the App Communicates Status Changes

When a pairing is dissolved — whether because one user initiates an unpair action or because one user deletes their account — the former paired partner does not receive a direct notification or message. Instead, the App's user interface updates automatically to reflect the unpaired state upon the next application state refresh on the former partner's device. Specifically:

        The swipe tab will display a prompt indicating that the user should pair their account.

        The recipe upload function on the profile tab will be disabled, with an in-app message indicating that pairing is required to upload recipes.

 

This interface change may take a brief moment to appear if the former partner is actively using the App at the time the dissolution occurs. Toochooz is not responsible for any confusion or inconvenience resulting from this brief delay.

2.6 Location Data

The App includes a toggle allowing users to enable or disable location access at any time. You acknowledge and agree that:

        The restaurant swiping feature requires location access to function. If location access is disabled, the restaurant swiping portion of the App will not operate.

        Restaurants are populated based on your current location and your selected search radius of one (1) to thirty-five (35) miles.

        Toochooz obtains your current geographic location (latitude and longitude) when you use the App so that it can display restaurants near you, including when you are traveling or have moved since your last session.

        Toochooz accesses your geographic location only while the App is open and in use. The App does not request or collect background location and does not update your location while the App is closed or running in the background. When you open or return to the App, it may obtain a fresh location reading to keep nearby restaurant results current.

        Each new location reading replaces the previous one. Toochooz stores only your most recent location value in association with your account.

        Toochooz does not create or retain a location-history record. We do not build a trail, timeline, or profile of the places you have been over time.

        Your location is used solely to display nearby restaurants and to operate the App's location-dependent features. Location data is not used for advertising, ad targeting, or cross-app tracking, and it is not sold or shared with third parties for their own advertising purposes.

        You may disable location permission at any time through the in-app toggle or through your device's operating system settings. If you disable location access, no further location readings will be collected and your stored value will not continue to update.

 

The App sends your current foreground location to a server-controlled restaurant-discovery endpoint that returns only a bounded set of nearby restaurant records. The App does not receive direct collection-wide access to the Toochooz restaurant or brand databases.

 

Restaurant discovery is subject to per-user pagination and rate limits intended to protect the Database from scraping, automated enumeration, abuse, and excessive requests.

2.7 Push Notifications

The App uses Firebase Cloud Messaging to deliver push notifications. Notifications may be sent in connection with:

        Incoming pairing requests and acceptance of a pairing.

        Matches, including notification that you and your paired partner have both swiped affirmatively on the same restaurant or recipe card.

        Recipe deletion requests received from a paired partner.

 

To deliver these notifications, the App registers a device push token with Firebase Cloud Messaging and associates it with your account. Notification access can be toggled on or off within the App's Profile Tab or through your device settings. Toochooz does not use push notifications for advertising or marketing purposes.

 

Your push token is retained according to the following criteria rather than a fixed calendar period: the current token is retained while your account exists and notifications are active; it is replaced whenever the device issues a refreshed token; it is removed when Firebase Cloud Messaging reports that the token is no longer valid; and it is deleted when you delete your account.

2.8 Swipe Sessions, the Daily Reset, and Matches

Swipe activity in the App is organized around a daily cycle, rather than a rolling twenty-four-hour expiration. Specifically:

        Daily reset. Your swipe session resets each day at 5:00 AM in the time zone recorded on your account. At the daily reset, the swipe deck is refreshed and swipe inputs recorded during the prior cycle no longer carry forward into the new cycle. Because the reset follows the time zone stored on each account, two paired users whose accounts record different time zones will reset at different moments.

        Swipe eligibility. An affirmative swipe remains eligible to produce a Match until the applicable user's next daily 5:00 AM reset, unless it is consumed by a Match. This applies to both restaurant swipes and recipe swipes.

        Active matches. Once a Match is created, the Match remains active for approximately thirty (30) minutes, after which it expires and is no longer displayed.

        Match cooldown. Creating a Match also pauses swiping for both paired users in the mode in which the Match occurred, for approximately thirty (30) minutes. The cooldown is per-mode: a restaurant Match pauses restaurant swiping only, and a recipe Match pauses recipe swiping only.

        Switching modes during a cooldown. Swiping in the other mode remains available, but the App does not switch modes for you. To swipe in the other mode you must go to the Profile Tab and toggle between restaurant mode and recipe mode. Both modes may be in overlapping cooldowns at the same time, in which case swiping is paused in both until the respective cooldowns elapse.

        Match display during a cooldown. When a Match is created, the App displays a modal identifying what you matched on, together with a live countdown timer running for the remainder of the cooldown. You may dismiss the modal. If you take no action, the modal continues to display the Match and the countdown.

        Affirmative (right) swipes. An affirmative swipe removes the card from your deck. The card remains eligible to produce a Match until your next daily 5:00 AM reset, unless it is consumed by a match.

        Negative (left) swipes. A negative swipe does not remove the card from your deck. The card is moved to the bottom of the deck, so once you have swiped through the remaining options, cards you previously declined are shown to you again.

        Cards returning to the deck. When a cooldown ends, that mode's deck resets and previously swiped cards, including cards you swiped affirmatively, are reinserted and may appear again. If no Match is made that day, cards are reinserted at the next daily 5:00 AM reset.

        These durations are approximate. Exact timing may vary based on device clock, time zone handling, network conditions, and background processing behavior on your device.

 

Toochooz does not maintain a permanent, user-identifiable swipe history or a long-term behavioral preference profile for individual users. Match records are retained for a limited operational period as described in Section 5, and pseudonymized event counts relating to swipes and matches are retained for analytics purposes as described in Sections 2.10 and 5.

2.9 Recipe Submissions — Data Collected and Retention

Users may submit recipes, which may include a title (maximum fifty (50) characters), a description (maximum one hundred sixty (160) characters), and an image. Recipe content is stored in the Toochooz Database and associated with the submitting user's account. Key data practices regarding recipes include:

        Recipes remain associated with the pairing identifier under which they were submitted. If two users unpair and subsequently re-pair, recipes submitted under that pairing may become available again within the renewed pairing. Recipes are not transferred to or shared with a pairing involving a different partner.

        Recipes are visible to a user's current paired partner via the Manage Recipes feature while the pairing is active.

        Upon account deletion, all recipes ever uploaded by the deleting user across all pairings, past and present, are permanently deleted, including all associated images, descriptions, and metadata.

        All recipe submissions are subject to initial automated screening by Google Cloud Vision prior to publication. Reported recipes are subject to a second, stricter round of automated moderation. Recipes removed through either round of moderation are not recoverable.

        Recipes that are rejected by automated moderation are retained in a rejected-submission log for approximately fourteen (14) days for anti-abuse, quality-assurance, and troubleshooting purposes, and are then deleted.

        Any user may report a recipe directly from the swipe screen using the per-card report button. The report form offers exactly two reasons, and the reporting user must select one of them: “Offensive language” or “Inappropriate imagery.”

Recipe Reporting Data

When a recipe report is submitted, Toochooz stores the recipe identifier, pairing identifier, reporting user identifier, selected reason, processing status, and relevant timestamps.

 

Toochooz also creates a private, temporary hidden-recipe record containing the recipe identifier, hiding timestamp, and the fact that the recipe was reported. The recipe is immediately removed from the reporting user's swipe deck while enhanced moderation is performed.

 

If the recipe fails enhanced moderation, it is deactivated or removed for all users. If it passes enhanced moderation or the review cannot be completed, the temporary hidden-recipe record is deleted and the recipe may reappear for the reporting user upon the next deck refresh.

 

Reporting does not grant the reporting user a permanent deletion or veto right over another user's compliant recipe. The existing recipe-deletion-request feature remains separate and allows a user to ask the recipe owner to delete a recipe.

2.10 Analytics

Toochooz uses two categories of analytics: Firebase Analytics, provided by Google LLC, and a custom analytics pipeline operated on our own backend infrastructure. Both are active in the App.

Firebase Analytics

Firebase Analytics is enabled in the App and collects the following categories of information:

        Screens viewed within the App and the sequence in which they are viewed.

        Interactions and events within the App, such as taps, feature usage, and completion of key flows.

        Session information, including session start and end, session duration, and frequency of use.

        Device and operating system information, including device model, operating system version, platform (iOS or Android), app version, language, and similar technical attributes.

        App-instance identifiers, which are identifiers assigned to your installation of the App.

        Approximate geography, meaning coarse location such as country or region derived by Google from network information. This is separate from, and less precise than, the location data described in Section 2.6.

Custom Backend Analytics

In addition to Firebase Analytics, Toochooz records analytics events on its own backend for business and product purposes. These events include:

        Daily active-user and active-pair metrics.

        Completed onboarding events.

        Accepted pair-request events.

        Restaurant and recipe right-swipe events.

        Restaurant and recipe match-creation events.

        Recipe moderation outcomes, including approval, rejection, removal, retention, and errors.

        Account-deletion totals.

 

Firebase Analytics separately records broader mobile interactions, including pair requests sent and accepted and left/right swipe events.

Identifiers, Pseudonymization, and Honesty About Anonymity

Analytics events are stored under pseudonymized identifiers or in aggregated form. We do not attach your phone number or Username to analytics events. However, we want to be accurate rather than overstate our practices: pseudonymized data is not the same as fully anonymous data. Because an analytics identifier may, with additional information held by Toochooz or by Google, be capable of being associated with an account, we describe this data as "pseudonymized" or "aggregated" rather than "anonymous." Aggregated statistics that report only totals and cannot be resolved to any individual are treated as de-identified.

Advertising Signals Disabled

Toochooz has disabled the advertising-related features of Firebase Analytics. Specifically, advertising storage, ad user data, and advertising personalization are all set to a disabled state. Toochooz does not use analytics data to build advertising audiences, to personalize advertisements, or to track you across other applications or websites. Toochooz does not display third-party advertising in the App.

2.11 Crash Reporting and Diagnostics

Toochooz uses Firebase Crashlytics to collect crash reports, stack traces, handled and unhandled error information, App and operating-system versions, device model and state, App-installation identifiers, and related diagnostic information.

 

Because Firebase Analytics is enabled, Crashlytics reports may include analytics breadcrumbs describing App events leading up to a crash. Toochooz does not intentionally attach phone numbers, Usernames, recipe content, or precise location to Crashlytics reports.

 

Crashlytics information is used for App functionality, debugging, stability monitoring, security, performance improvement, and resolution of technical failures. It is not used for advertising or cross-app tracking.

2.12 Service Providers Used by the App

The App relies on the following third-party services, each operating under its own terms and privacy policy:

        Firebase Authentication (Google LLC) – phone number verification and account authentication.

        Cloud Firestore (Google LLC) – storage of account records, pairing records, recipes, restaurant data, match records, and related application data.

        Firebase Storage (Google LLC) – storage of uploaded images, including recipe images and restaurant images.

        Cloud Functions for Firebase (Google LLC) – server-side processing, including moderation workflows, match handling, scheduled jobs, and account deletion routines.

        Firebase Cloud Messaging (Google LLC) – delivery of push notifications, including pairing and match notifications.

        Firebase Analytics (Google LLC) – usage analytics as described in Section 2.10.

        Google Cloud Vision (Google LLC) – automated content moderation of recipe and restaurant images and text.

        reCAPTCHA (Google LLC) – anti-abuse and bot-detection verification, including on the Submission Portal and in connection with phone-number verification.

        Firebase Crashlytics (Google LLC) – crash reporting, diagnostics, debugging, error investigation, and App-stability monitoring.

        Firebase App Check (Google LLC) – verification of authentic App requests and prevention of scraping, fraud, automated abuse, modified-client activity, and unauthorized backend access.

        Google Play Integrity (Google LLC) – Android package, signing, installation, licensing, and device-integrity attestation used through Firebase App Check.

        Apple App Attest (Apple Inc.) – cryptographic verification that iOS requests originate from a genuine Toochooz installation on an Apple device.

        Apple DeviceCheck (Apple Inc.) – fallback device-integrity verification used where App Attest is unavailable or unsupported.

 

Toochooz generally acts as the controller or business for personal data processed through Firebase and Google Cloud services, while Google generally acts as a processor or service provider under the applicable service and data-processing terms. Google Analytics for Firebase (referred to in this Policy as “Firebase Analytics”) is a separate service governed by its applicable terms. Users may review Google's privacy documentation for additional information about these services.

2.13 Restaurant Non-Affiliation and Brand Communication Policy

Toochooz is not affiliated with, endorsed by, or connected to any restaurant, restaurant brand, or restaurant location displayed in the App. Each restaurant card in the App displays an explicit non-affiliation notice. Restaurant names, logos, and associated imagery are the property of their respective owners. Toochooz does not collect or store any data on behalf of, or share any data with, any restaurant displayed in the App.

 

Restaurant data displayed in the App is composed of two distinct categories. Restaurant names, addresses, geographic coordinates, and hours of operation are publicly available factual information. The Toochooz Database is initially seeded with this category of data and is expanded over time through user submissions made via the Submission Portal. This factual data is not subject to wholesale removal upon brand or restaurant request. Restaurant logos, storefront photographs, and other associated imagery may be subject to copyright or trademark protection and are addressed by the following policy.

 

A restaurant or brand owner contacting support@toochooz.com or another direct channel may request the following actions, which Toochooz will accommodate in good faith:

        Replacement of the brand's existing logo or image with a new logo or image supplied directly by the brand, subject to format and quality requirements.

        Removal of the brand's logo or image entirely, in which case Toochooz will substitute a generic placeholder corresponding to one of the restaurant's assigned cuisine types so users continue to receive a complete restaurant card. Toochooz does not unilaterally substitute placeholder images for brands that have not made such a request. Mass image replacement (whether with a brand-supplied image or a cuisine-type placeholder) across all of a brand's locations is supported upon legitimate request.

        Update or correction of a specific location's address, hours of operation, or open/closed status when accurate information is provided.

        Adjustment of cuisine type(s) assigned to a restaurant in the Database.

        Coordinated removal of specific listings for permanently closed locations, evaluated on a case-by-case basis.

 

Toochooz does not honor brand requests to remove names, addresses, geographic coordinates, or hours of operation from the Database in bulk based solely on the brand's general objection to inclusion in the Toochooz platform. The only category of data that will be wholesale removed at a brand's request is the brand's proprietary imagery, which will be replaced with cuisine-type placeholders.

 

Brand-direct communications are completely separate from the public Listing Removal Request form available on the Submission Portal. The public form is designed for use by any member of the public to flag listings that should no longer appear to App users (for example, restaurants that have closed). Public removal requests, when approved, hide a listing from public visibility in the App but do not remove the listing data from the underlying Database. The public removal request form is governed by Section 3 of this Policy and the Website Terms of Service.

2.14 Account Deletion and Data Removal

Users may delete their account at any time using the account deletion function in the App's Profile Tab. Upon account deletion, the following occurs:

What is deleted

        Your account record, including your phone number, Username, and associated preferences and settings.

        Your authentication record with Firebase Authentication.

        All recipes you have ever uploaded, across all pairings, including all recipe images, descriptions, and metadata.

        Your identifiable analytics-user record, meaning the record that links an analytics identifier to your account.

        Your stored location value and your push notification token.

        Any active pairing, which is immediately dissolved server-side. The former partner's device reflects this change upon the next application state refresh via the UI changes described in Section 2.5.

        Your current swipe session data and any active match records associated with your account.

        Your blocked-users list, any pending temporary hidden-recipe records, your restaurant-discovery sessions, and your restaurant-discovery rate-limit record. Blocks created by other users that reference your account are also removed.

What remains

So that we do not overstate what deletion accomplishes, please note the following:

        Analytics events that were previously generated under a pseudonymous identifier remain in our analytics systems until their applicable retention period expires, as set out in Section 5. These events are not deleted at the moment you delete your account, because they are stored as event records rather than as part of your account record.

        Aggregated statistics — totals, counts, and summary metrics that cannot be resolved to any individual user — remain and are not deleted.

        Records that Toochooz is required to retain for legal, security, fraud-prevention, or audit purposes may be retained for the periods described in Section 5 or as otherwise required by law.

        Crashlytics information is not intentionally linked to your Toochooz account and may remain under Google's applicable diagnostic-data retention practices.

 

Account deletion is permanent and irreversible. Toochooz cannot recover a deleted account, its recipes, or its associated data.

 

SECTION 3: THE TOOCHOOZ RESTAURANT SUBMISSION PORTAL — DATA PRACTICES

3.1 Overview

The Submission Portal is a publicly accessible web interface that allows members of the public to (a) contribute new restaurant listings to the Toochooz restaurant Database, and (b) submit Listing Removal Requests asking that a specific listing no longer be displayed to App users (for example, when a restaurant has permanently closed or relocated). No account registration is required to use either form.

3.2 Mandatory Agreement Before Submission

Both the restaurant submission form and the listing removal request form require the user to affirmatively check a box agreeing to the Toochooz Terms of Service and this Privacy Policy before the form can be submitted. Submissions cannot be processed without this affirmative agreement.

3.3 Information Collected — Restaurant Submissions

When you submit a restaurant listing through the Submission Portal, we may collect the following:

Voluntarily Submitted Restaurant Data:

        Restaurant name.

        Between one (1) and three (3) cuisine types selected from a predefined list.

        Hours of operation for each day of the week, with optional support for a second open/close window per day.

        Geographic coordinates (latitude and longitude) and/or full address (Address Line 1, optional Address Line 2, City, State, ZIP Code). At least one location format is required.

        Timezone of the restaurant's location.

        One uploaded restaurant logo or storefront image (JPG or PNG, maximum 2MB).

Automatically Collected Technical Data:

        IP address of the submitting device, processed for rate limiting, security, spam prevention, and abuse detection. The raw IP address is not persisted. Toochooz stores only a one-way pseudonymized IP-derived identifier, with retention described in Section 5.5.

        Browser, operating-system, device, and user-agent information may be transmitted by your browser in the ordinary course of serving the request, but is not persisted in restaurant submission records.

        reCAPTCHA verification data or similar anti-abuse signals.

        Timestamp of submission.

 

We do not require or solicit your name, email address, or any other personally identifying information in connection with restaurant submissions.

3.4 Information Collected — Listing Removal Requests

When you submit a Listing Removal Request, we may collect the following:

        The reason for the requested removal.

        The restaurant name, address (Address Line 1 and optional Address Line 2), city, two-letter state abbreviation, and ZIP code.

        reCAPTCHA verification data or similar anti-abuse signals.

        Technical data, including the IP address, processed for security and abuse prevention. As with restaurant submissions, the raw IP address is not persisted; only a one-way pseudonymized IP-derived identifier is stored, with retention described in Section 5.5. Browser, operating-system, device, and user-agent information is not persisted in removal request records. A timestamp of submission is recorded.

 

We do not require or solicit your name, email address, or any other personally identifying information in connection with removal requests.

3.5 Image Submissions and Copyright

Toochooz expressly disclaims any responsibility or liability for the copyright status or third-party ownership of any image submitted by a third party through the Submission Portal.

Toochooz cannot reasonably be expected to conduct individualized copyright verification on every submitted image. By submitting an image, you represent that you hold all rights necessary to do so. Copyright infringement notices may be sent to support@toochooz.com.

3.6 Use of Submitted Data

Restaurant submissions are reviewed and moderated by Toochooz. Approved data may be added to the Database and may appear in the App. Submitted images may be resized or modified for consistency. Rejected restaurant submissions are logged for audit and anti-abuse purposes and retained for approximately one hundred eighty (180) days.

 

Listing Removal Requests are reviewed and evaluated by Toochooz. Approved removal requests result in the affected listing being hidden from public visibility in the App; the underlying listing data remains in the Toochooz Database for audit, operational, and reactivation purposes. Toochooz reserves the right to decline any removal request at its sole discretion.

 

No submitter personal information is required or displayed publicly in connection with either type of submission.

3.7 IP Address Bans

Toochooz may permanently ban submitting devices from accessing the Submission Portal in response to submission spam, bulk false restaurant listings, bad-faith removal requests, or repeated violations of the Website Terms of Service. Bans are enforced using the one-way pseudonymized IP-derived identifier described in Section 3.3 rather than a stored raw IP address. An identifier supporting an active permanent abuse ban may be retained while that ban remains active. Banned users may contact support@toochooz.com to discuss the matter, though Toochooz makes no commitment to lift any ban.

3.8 License

Submitters grant Toochooz LLC a non-exclusive, worldwide, royalty-free, fully paid-up, transferable, and sublicensable license to use submitted restaurant data and images in the App and associated products, as more fully described in the Website Terms of Service.

3.9 Cookies and Security Technologies

The Toochooz restaurant-submission website uses Google reCAPTCHA to prevent spam, fraud, and abuse. When reCAPTCHA runs, it may set the necessary _GRECAPTCHA cookie and process technical information such as IP address, browser and device information, and interaction signals for security risk analysis. This cookie is used for security purposes, not advertising.

 

Toochooz does not currently use advertising or marketing cookies. The static "About" page does not set cookies of its own. Google processes reCAPTCHA data on Toochooz's behalf for security, fraud, and abuse prevention in accordance with the applicable Google Cloud service terms and data-processing terms.

 

SECTION 4: HOW WE USE YOUR DATA

4.1 Service Delivery

        To operate, maintain, and improve the App and the Submission Portal.

        To authenticate App Users and manage accounts.

        To populate and refresh the Database with approved submissions.

        To display restaurant and recipe cards to App Users based on location and pairing.

        To facilitate Paired Sessions, the daily swipe reset, and the creation and expiration of Matches between connected App Users.

        To deliver pairing and match push notifications.

4.2 Content Moderation

        To screen recipe submissions and images using Google Cloud Vision.

        To conduct enhanced moderation on reported recipes.

        To manually review restaurant submissions and removal requests.

        To log and analyze rejected submissions for anti-abuse and anti-spam purposes.

4.3 Security and Fraud Prevention

        To detect, investigate, and prevent fraudulent or abusive activity on our platforms.

        To process IP addresses for rate limiting, security, spam prevention, and abuse detection, storing only a one-way pseudonymized identifier as described in Section 5.5.

        To operate reCAPTCHA and similar bot-detection measures.

        To enforce our Terms of Service and Content Standards, including IP bans.

        To verify App authenticity using Firebase App Check, Google Play Integrity, Apple App Attest, and Apple DeviceCheck; restrict direct database enumeration; apply per-user restaurant-discovery rate limits; and prevent scraping, automated access, modified-client abuse, unauthorized backend requests, and billing fraud.

4.4 Analytics and Improvement

        To analyze pseudonymized and aggregated usage patterns via Firebase Analytics and our custom backend analytics, as described in Section 2.10, in order to improve App performance, reliability, and user experience.

        To understand completed onboardings, accepted pairings, right-swipe and match-creation volumes, and recipe moderation outcomes at an aggregate level.

        To diagnose errors, monitor system health, and plan capacity.

        To collect crash reports and diagnostic information through Firebase Crashlytics for debugging, stability monitoring, performance improvement, error investigation, and resolution of technical failures.

 

Analytics data is not used for advertising, ad personalization, or cross-app tracking.

4.5 Business Operations

        To communicate with users about service-related matters and to respond to inquiries and data rights requests.

        To comply with legal obligations and to establish, exercise, or defend legal claims.

        To evaluate and carry out a merger, financing, acquisition, reorganization, or sale of assets, subject to Section 6.

 

SECTION 5: DATA RETENTION

Toochooz retains data only as long as needed for the purposes described in this Policy. The following retention periods apply. Where a period is described as approximate, actual deletion may occur slightly before or after the stated period due to scheduled job timing.

5.1 Account and Content Data

        App User account data (phone number, Username, settings, and most recent location value) is retained for the duration of the account and deleted upon account deletion.

        All recipe data and images uploaded by a user are deleted upon that user's account deletion, regardless of which pairings they were associated with.

        Recipe data persists while the creator's account remains active unless the recipe is deleted. Recipes remain associated with the pairing identifier under which they were submitted. They may become available again if the same two accounts pair again, but they are not transferred to or shared with a pairing involving a different partner. Creators may continue to manage their own submitted recipes as permitted by the App.

5.2 Operational and Session Data

        Swipe session data resets each day at 5:00 AM in the time zone recorded on the account and does not carry forward into the next cycle. Cards removed from a deck by an affirmative swipe are reinserted when the applicable mode's cooldown ends or at the next daily reset. Cards declined by a negative swipe are not removed and continue to cycle within the deck.

        Match records are retained for approximately thirty (30) days for operational, support, and abuse-investigation purposes, and are then deleted.

        Operational job records, including scheduled task logs, cleanup jobs, and deletion job records, are retained for approximately ninety (90) days.

        Pending pairing requests are retained for approximately fourteen (14) days. Records of accepted pairing requests are retained for approximately two (2) days. Records of rejected pairing requests are retained for approximately one (1) day.

        Active pairing fields are retained until the pairing is dissolved or an account is deleted. When a pairing is dissolved, the pairing fields are cleared rather than retained as a pairing history.

        Push notification tokens are retained according to the criteria described in Section 2.7 rather than for a fixed period.

        Blocked-user records are retained until the blocking user unblocks the account or deletes their account.

        Restaurant-discovery sessions contain the user identifier, bounded restaurant-result identifiers, pagination position, and relevant timestamps. They become eligible for automatic deletion approximately fifteen (15) minutes after creation, although actual deletion may occur later through Firestore TTL processing.

        Per-user restaurant-discovery rate-limit counters are overwritten as rate windows change and are deleted when the associated account is deleted.

5.3 Moderation and Submission Data

        Rejected recipes and their associated moderation metadata are retained for approximately fourteen (14) days.

        Temporary hidden-recipe records created after reporting are retained only while enhanced moderation is pending. They are deleted when the review is completed or cannot be completed. Any remaining temporary hidden-recipe records are deleted when the reporting user deletes their account.

        Rejected restaurant submissions are retained for approximately one hundred eighty (180) days for anti-abuse and audit purposes.

        Moderation audit records relating to recipe moderation are retained for up to seven hundred thirty (730) days. These records contain only the recipe identifier, the audit type, the moderation result and reasons, the moderation provider, summarized moderation scores, and processing timestamps and duration. They do not contain any IP-derived identifier, raw IP address, user-agent data, or restaurant submission or removal request metadata.

        Listings hidden from public visibility through approved Listing Removal Requests remain in the Toochooz Database; only their public-facing visibility in the App is affected. Listing Removal Request records, including the reason and submitted location data, are retained for audit, operational, and anti-abuse purposes.

5.4 Analytics Data

        Business analytics events, including the custom backend analytics events described in Section 2.10, are retained for up to seven hundred thirty (730) days.

        Firebase Analytics data is retained in accordance with the retention setting configured in the Firebase console and Google’s applicable retention practices.

        Aggregated statistics and de-identified data that cannot be resolved to any individual user may be retained for longer than the periods listed above, including indefinitely.

        Firebase Crashlytics and Firebase App Check information is retained according to the settings and retention practices maintained by Google and, where applicable, the relevant Apple attestation provider.

5.5 Technical Logs

Toochooz processes a submission device's IP address for rate limiting, security, spam prevention, and abuse detection. The raw IP address is not persisted in the restaurant-submission database. Toochooz instead stores a one-way pseudonymized IP-derived identifier. Rate-limit records are retained for approximately two (2) days; identifiers associated with rejected restaurant submissions may be retained for approximately one hundred eighty (180) days; and identifiers supporting an active permanent abuse ban may be retained while that ban remains active. Approved restaurant listings do not retain this identifier or submitter browser, operating-system, device, or user-agent metadata.

 

The IP-derived identifier exists only in pending and rejected restaurant submission and removal request records, in short-lived rate-limit records, and in permanent-ban records where applicable. It is not carried into approved listings or into the recipe moderation audit records described in Section 5.3.

 

SECTION 6: DATA OWNERSHIP, DISCLOSURE, AND YOUR RIGHTS

6.1 Database Ownership

The Toochooz Database, including the compilation of restaurant data, the arrangement and structuring of that data, and any compilations or derivatives thereof, constitutes proprietary intellectual property of Toochooz LLC. Ownership of the Database as a compiled work does not alter any ownership rights you may have in the individual content you personally created and submitted, which are addressed in the Toochooz Terms of Service.

6.2 No Sale or Sharing for Cross-Context Behavioral Advertising

Toochooz LLC does not sell your personal information, and does not share your personal information for cross-context behavioral advertising.

This commitment applies to your phone number, your location data, your Username, your device identifiers, your recipes, and your usage data. We do not sell or rent these to data brokers, advertisers, or other third parties for their independent commercial use.

 

Toochooz may use aggregated or de-identified data — data that cannot reasonably be used to identify you — for analysis, research, product development, reporting, and describing the service to prospective partners or investors.

6.3 Business Transfers

Toochooz may transfer your data to a successor or acquiring entity in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or substantially all of its assets. Any such recipient will be bound to honor the commitments made in this Policy with respect to data collected before the transfer, unless and until you are provided notice of and the opportunity to review a different policy. A change of ownership of Toochooz LLC does not by itself authorize the sale of your personal information for advertising purposes.

6.4 Other Disclosures

Toochooz may disclose data in the following limited circumstances:

        To service providers who process data on our behalf and under our instructions, as listed in Section 2.12.

        To comply with applicable law, legal process, or a valid governmental request.

        To enforce our Terms of Service, investigate potential violations, or protect the rights, property, or safety of Toochooz, our users, or the public.

        With your direction or consent.

6.5 User Rights Regarding Personal Data

Depending on your jurisdiction, you may have rights to access, correct, or request deletion of your personal data. App Users may exercise their deletion rights directly by deleting their account within the App. For all other requests, contact support@toochooz.com.

 

U.S. State Privacy Law Rights: If you are a resident of a U.S. state with a comprehensive consumer privacy law — including but not limited to California (CCPA/CPRA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), and other states with similar laws now or hereafter enacted — you may have additional rights, which may include:

        The right to know what personal information we have collected about you and how it is used.

        The right to request deletion of your personal information, subject to certain exceptions.

        The right to correct inaccurate personal information.

        The right to opt out of the sale or sharing of your personal information for cross-context behavioral advertising. As stated in Section 6.2, Toochooz does not sell or share personal information for this purpose, so there is nothing to opt out of.

        The right to non-discrimination for exercising your privacy rights.

 

To exercise any of these rights, please contact support@toochooz.com with a description of your request and the U.S. state in which you reside. Toochooz will respond to verifiable requests within the timeframes required by the applicable law. We may need to verify your identity before responding to certain requests, including by confirming details associated with the phone number on your account.

 

Note that the exercise of individual rights does not require Toochooz to delete aggregated or de-identified data, and certain rights may be subject to exceptions under applicable law (such as legal compliance, security, and legitimate business purposes).

 

SECTION 7: DATA SECURITY

Toochooz employs industry-standard technical and organizational measures to protect collected data, including:

        Secure storage within Google Firebase, which employs enterprise-grade security infrastructure.

        Server-side storage of all third-party API credentials. No API credentials are exposed to client-side code or end users.

        Security rules restricting client access to data to the account that owns it and its active paired partner, where applicable.

        Access controls limiting Database access to authorized personnel only.

 

No method of data transmission or storage is completely secure. Toochooz cannot guarantee the absolute security of your data and disclaims liability for unauthorized access resulting from circumstances beyond our reasonable control.

SECTION 8: CHILDREN'S PRIVACY

The App and the Submission Portal are not directed to children under the age of thirteen (13). We do not knowingly collect personal data from children under thirteen. If we become aware that we have inadvertently collected such data, we will promptly delete it. Parents or guardians who believe their child has provided us with personal data may contact us at support@toochooz.com.

SECTION 9: THIRD-PARTY SERVICES

The App and Website integrate with third-party services that operate under their own privacy policies, as listed in Section 2.12. Toochooz is not responsible for the privacy practices, content, or security of any third-party service. We encourage you to review the privacy documentation of Google LLC with respect to Firebase Authentication, Cloud Firestore, Firebase Storage, Cloud Functions, Firebase Cloud Messaging, Firebase Analytics, Firebase Crashlytics, Firebase App Check, Google Play Integrity, Google Cloud Vision, and reCAPTCHA, and of Apple Inc. with respect to Apple App Attest and Apple DeviceCheck, as applicable.

SECTION 10: CHANGES TO THIS POLICY

Toochooz reserves the right to modify this Privacy Policy at any time. Changes will be posted at the URL where this Policy is maintained with an updated "Last Updated" date. Your continued use of the App or the Submission Portal following the posting of any changes constitutes your acceptance of the revised Policy.

SECTION 11: CONTACT INFORMATION

For questions, concerns, or data requests relating to this Privacy Policy, please contact:

 

Toochooz LLC

Email: support@toochooz.com

 

This Privacy Policy was last updated on August 19, 2026 and is effective as of that date. This document supersedes all prior versions.