A straightforward privacy note

Your information.
Clear expectations.

This note covers the public website, Request Access, and the current closed-beta prototype. Requesting access and creating an app account are separate steps.

Requesting access

When you submit Request Access and receive confirmation, your answers are stored privately for founder review. Applying does not create a Sivora account or automatically grant access.

The form asks for your name, email, connection to Columbus, city or neighborhood, food-discovery habits and channels, an explanation if you choose an Other channel, and why you want to try Sivora. Please do not include your street address or sensitive personal information. Use the email you intend to use with Google.

We use these answers to evaluate and manage beta access, contact applicants about access where applicable, and administer the closed beta. Request information is kept privately with Supabase for founder review, separately from Sivora accounts and profiles. A founder email alert uses Resend to send only your name, email and submission time after the request is stored. A confirmation acknowledges a stored request; it does not promise an email response.

Signing in and account information

The closed-beta app uses Cloudflare Access as an outer access gate and Supabase Auth with Google to establish your identity. These services process sign-in information such as your email, account identifiers, name and profile picture. Sivora does not operate its own password system. An app account has a profile, preferences and access-status records; these are initialized when an authentication account is created.

New account creation is currently disabled while first-time beta onboarding is being prepared. An access request does not create these records or give you a privileged role. Google and Supabase provide services; their use does not imply endorsement of Sivora.

Your places, saves and contributions

Supabase stores your Want to Try and Tried restaurant state, first-added Moment and Source references, recommendation text copied from that Moment, and separate Moment bookmarks. My Food currently preserves that recommendation snapshot; it does not provide a general note editor.

We also store your display name and account preferences so your experience can continue when you return. Private saves are not available to other ordinary users. Authorized operators may access records for support and beta administration.

Approved, active beta users can submit text Grapevines. External source links and submission images require Contributor access. We store drafts, submitted text or source links, revisions, and review status. Approved material and its public attribution may appear in Sivora.

Activity records and analytics

The app records adding or removing Moment bookmarks and changes to Want to Try and Tried, alongside submission and account-administration history. These records can include your account identifier, relevant restaurant, Moment or Source identifiers, the screen where an action began, and timestamps. They are stored in Supabase to support product state, attribution, internal understanding of usage, and administration. They are account-linked records, not anonymous analytics.

Optional interview analytics are off by default. If you allow them in Account or Contributor onboarding, the app records session starts, Explore and Map navigation, restaurant, Moment and Source opens, feedback-link use, and defined client-error categories during signed-in use. These records include your account identifier, a random session identifier, event order, relevant product identifiers, and timestamps. They are stored privately in Supabase so the founder can understand the beta experience. They are not anonymous or aggregated-only data.

Turn optional analytics off in Account to stop new collection. This does not switch off the service and action history described above. The collector does not record notes, search text, URL queries, error messages or stacks, or screen recordings, and uses no third-party product-analytics SDK. Opening the feedback link records that opening, not whether you sent an email. Failed sign-ins before an account session are handled through service diagnostics, not this optional collector.

Browser storage

Unsaved answers are held in the current page's memory. Leaving or refreshing clears them. When sending fails, your answers stay on the page so you can retry. Browser autofill is controlled by your browser.

The app uses localStorage for the Supabase sign-in session and browser-specific external-media preferences. Session storage holds temporary information such as Explore ordering and a pending Want to Try action while you sign in. Cloudflare Access uses an authorization cookie for the beta gate. Clearing browser storage can sign you out or reset local choices; it does not delete saved records on the server.

The optional analytics session identifier stays in page memory. It changes on reload, sign-out, account change, or a later opt-in after withdrawal; it is not stored as a tracking cookie or fingerprint.

Feedback and messages

The feedback form sends your name, email and message through Supabase and Resend to the founder-controlled inbox. Your email is used as the reply address. The message is not stored in the app database; email services process and retain it. Sending confirmation means the email service accepted it, not that inbox delivery was confirmed. A private counter limits sending attempts without storing your message or identifying you.

If you email feedback, a privacy request, or a content concern, we receive the sender information and message you choose to send. We use these to review the issue, respond where appropriate, and improve or administer the prototype. Email is forwarded to a founder-controlled inbox; no automatic marketing campaign is connected to Request Access.

Hosting, technical data and service providers

This website's application code does not add advertising trackers, analytics, account cookies, or local storage for form answers. Images are served with the site, and fonts come from your device. Prototype screenshots do not load social embeds or live maps.

Cloudflare hosts the website and routes email sent to our contact address to the founder's inbox. Email providers process messages you choose to send; include only the details needed for your request.

Cloudflare and Supabase receive technical information when serving the site, authenticating accounts, receiving applications, or handling app requests. This can include IP addresses, browser/user-agent information, timestamps and request metadata. The app uses request identifiers and protected address-derived identifiers for abuse controls, and records selected failures and security decisions in infrastructure logs. These operational records are separate from optional product analytics.

Authorized editors can use an AI-assisted drafting tool that sends selected source, restaurant and contribution text to OpenRouter and Google's model-serving service to suggest editorial copy. This includes submitted recommendations when part of the selected context. It is a separate editorial action, not something triggered by Request Access, reading a Moment, or saving a restaurant. People review publication; the tool does not publish on its own.

External links, embedded media and maps

Screenshots may identify creators, publications, and source material shown in the prototype. Other websites have their own privacy practices. To flag a concern, use our report and takedown pathway.

An Original source link opens the third-party website in another tab. Embedded media instead loads that provider's content inside Sivora. Available embeds include TikTok, Instagram and Reddit. By default, the app asks before loading official embeds and blocks remote preview images.

You can load an embed once, always allow a provider, or block it in External media settings. Always allowing a provider permits eligible media to load automatically on later relevant screens. Preview-image permission is separate: remote TikTok thumbnails can load after you allow that provider's previews. Other remote preview providers are currently disabled.

These provider choices stay in this browser, rather than syncing across devices. Reset or block the provider in External media settings to change a previous allowance. An account-level block also prevents these social embeds and previews; choosing Ask at account level does not erase an allowance already saved in this browser.

Loading an embed or remote image connects your browser directly to the provider. It may receive your IP address, browser and request information and may use its own cookies or storage, subject to your browser settings and its privacy policy. Blocking embeds does not prevent you from opening an external source link.

Separately, the Map loads tiles from OpenStreetMap, and opening Account may load your Google profile picture. These requests are not controlled by the social-media preferences. The public website uses static product screenshots and does not load those maps or embeds.

Retention and deletion

Unapproved access requests may be retained for up to 90 days. The founder reviews and deletes requests manually; automatic deletion is not currently implemented. A later application can create a new request. Application answers are not automatically copied into account profiles.

That 90-day rule does not apply to account, saved-state, contribution, or operational records. We retain these for the product, support and security purposes described here; a fixed retention period for each category has not yet been established.

Raw optional interview navigation and error records are retained for no more than 30 days. The founder reviews and deletes them manually; scheduled expiration is not currently implemented. You can request earlier deletion through the contact below, and attributable raw telemetry is removed when the Auth account is deleted. This 30-day rule does not delete saved restaurants, notes, bookmarks, preferences, or separate account, product and security history.

Request Access deletion is handled by the founder, not an applicant self-service tool. Self-service account deletion and export are also currently disabled, even if an account control is visible in the app. Contact us to request review, access or deletion of your beta data. We may need to verify which account or application belongs to you.

Age eligibility

Request Access and the closed beta are intended for people aged 13 and older. Please do not submit information about children under 13. Contact us if you believe such information has been submitted.

Privacy questions and deletion requests

Contact contact@sivora.city for privacy questions or to request access to or deletion of your Request Access information or beta-account data. Include the email used to apply or sign in so the founder can identify the relevant records. Do not send passwords or identity documents.