The plain-language version

Privacy policy

Effective August 31, 2026

Tasti is a social tasting journal. This policy explains the information Tasti may handle when you use the app and this website, why it is used, and the choices available to you.

This website is intentionally simple. The website itself does not use Tasti analytics, advertising pixels, accounts, or cookies set by Tasti. The waitlist opens a form provided by Tally.

Information you provide

When you use the Tasti app, you may provide your name, email address, account and profile information, photos or videos, tasting and recipe content, notes, ratings or reactions, food and pairing selections, dates, comments, saves, and social connections. You may also add a user-entered Place, City, and Region to a tasting. Tasti stores those fields with the linked tasting: a named venue can identify a precise place, while City and Region are coarse location. The current app does not request GPS location, use Core Location, or collect coordinates; it stores only the location text you choose to enter. Content you choose to share may be visible to other people according to the audience and privacy settings available in the app.

Information used to operate Tasti

Tasti may process identifiers from an authentication provider, product interactions and other usage records, limited performance measurements, basic device or request information, and records needed to keep the service secure and reliable. To deliver notifications, Tasti stores an APNs device token linked to your account. Tasti also stores the people you follow and related relationships in its in-app social graph to provide social features and personalize recommendations. This Contacts disclosure refers to that Tasti social graph; the app does not upload your iPhone address book. The app may access photos or videos only when you choose to select, import, or upload them.

How information is used

iOS app product analytics

The iOS app may use privacy-conscious product analytics to understand which app pages and features are used and to improve reliability and product flows. This is separate from the website: the website itself does not send Tasti analytics. The app may record page or feature use, active screen duration, recipe-search metadata (such as character count, result count, outcome, surface, and duration), and actions such as opening or saving a recipe, starting a recipe log, and successfully publishing a tasting.

PostHog processes these product-analytics events for Tasti. They are content-free, pseudonymous user-level telemetry, not anonymous or aggregate data. Normalized recipe searches and raw recipe-search text are not sent to PostHog. User-created content—including notes, tags or descriptors, photos, rating values, and friend identity—is not sent in these product-analytics events. Recipe and dish identifiers used in events are opaque catalog identifiers. When enabled for a signed-in profile, app analytics are linked to an opaque Tasti profile or account identifier so we can understand activity across sessions. Fixture or no-auth use, such as app testing without an account, is a no-op; Tasti does not create anonymous or install-level analytics captures.

The app does not use IDFA, cross-app tracking, advertising profiles, or third-party advertising for these analytics, and Tasti does not sell personal information.

Recipe searches and personalization

When recipe personalization is enabled, Tasti stores normalized recipe searches in its first-party Supabase database. These are deliberate searches you submit by pressing Search or selecting a displayed recipe result—not each character you type, searches for people, cancelled searches, or stale results. Tasti uses this history to understand what recipes people are looking for and to personalize recipe recommendations. A private operator report may show thresholded demand; in private beta a named concept may appear after one distinct searcher to the one authorized operator, while public mode requires at least twenty distinct searchers. The report does not automatically import, generate, or rewrite recipes.

Normalized recipe searches stay first-party: they are not sent to PostHog and are not used for generative-model training. Product analytics may separately include search metadata such as query character count, result count, duration, surface, and outcome, but never the search terms or recipe names.

Service providers

Tasti relies on service providers for functions such as authentication, hosting, database storage, and photo storage. They process information on Tasti’s behalf under their own security and privacy commitments. Tasti does not sell personal information or use tasting content for third-party advertising.

If you join the waitlist, Tally processes the information you submit through its form so Tasti can manage waitlist inquiries and updates.

Retention and deletion

Normalized recipe searches remain in the active first-party database until you clear your recipe search history, turn off recipe personalization, or request account deletion. Each of those actions deletes the active search sessions and derived personalization data without removing saves, ratings, tastings, or posts. The current account-deletion request also marks the profile as deletion requested and queues erasure of its linked PostHog analytics; it does not by itself prove that every authentication, content, or storage record has been erased.

Service-provider backups may retain copies after active data is deleted, and a later backup restore may reintroduce a copy until the deletion is reapplied. Tasti cannot promise immediate deletion from backups. Production backup and point-in-time-recovery periods, and the PostHog event-retention period, must be verified from the active provider configuration; this policy does not invent a fixed period that the current repository cannot enforce.

Your choices

Before either optional collection starts, the app shows a privacy notice. Continue enables product analytics and recipe personalization; Privacy Settings lets you review the two independent choices first. You can later turn off product analytics, turn off recipe personalization, or clear your recipe search history from Privacy Settings. Turning off product analytics stops new product-analytics submissions after the change is confirmed and cancels queued unsent events, but does not itself delete events already delivered to PostHog. You can also choose what to post, who to connect with, and whether to grant photo or video access.

You may request help accessing, correcting, exporting, or deleting information—including a broader account or product-analytics privacy request—by emailing otie.net@gmail.com. Rights vary by location.

Children

Tasti is not directed to children under 13, and Tasti does not knowingly collect their personal information.

Changes

This policy may change as Tasti develops. Material updates will be reflected by a new effective date and, when appropriate, an in-app notice.

Contact

For privacy questions or requests, email otie.net@gmail.com.