Last updated: August 20, 2026
MunchMatch ("we," "our," "the app") helps you discover restaurants in the Greater Toronto Area by showing you a swipeable deck of nearby places, and to swipe together with friends. This policy explains what information the app uses, why, and where it goes.
When you first open MunchMatch, the app establishes an anonymous, device-level session with our backend (via Firebase Authentication) so it can find restaurants for you — this is what lets Discover, Home, and your Matches list work with no sign-up step. This anonymous session carries no personal information at all: no email, no name, nothing you typed. It exists purely so our servers can apply reasonable rate limits to the restaurant-search API and isn't linked to anything about you personally. If you never create a real account, an anonymous session that goes unused for an extended period is automatically deleted.
Adding friends and starting a Group Match require a free account, created with one of:
Creating an account this way upgrades the same anonymous session described above into a real one, rather than starting over — anything you've already done in the app (your Matches, preferences, streak) stays exactly as it was.
We store your email address, your name if a sign-in provider shared it with us, and which method you used to sign in. This data is stored on Google Cloud infrastructure via Firebase (Google's app-development platform), governed by Google's Privacy Policy. Access to it is restricted so that only you can read or modify your own account record.
We use this information to operate your account, to understand our user base at a high level (for example, how many people use each sign-in method), and for nothing else. We don't sell it, share it with advertisers, or use it for marketing.
If you allow location access, MunchMatch uses your device's approximate location (via Apple's Core Location framework) to find restaurants near you, or to sort your saved picks by distance. You can also search by city instead of using your location. Location is requested only "while using the app", and we never request background location access.
Your location coordinates are sent to our restaurant-search service, which forwards them to the Google Places API solely to retrieve nearby restaurant results. We do not store your location history. Google's handling of this data is governed by Google's Privacy Policy.
When you host a Group Match (see below), your location at the moment you start the session is used once to build that session's shared list of restaurants — the same one-time use as a solo search, just shared with the friends you invite.
If you choose to set a profile picture, MunchMatch lets you pick a photo using Apple's built-in photo picker. The app never sees or has access to your full photo library, only the specific image you select. That image is stored locally in the app's private storage on your device and is not uploaded anywhere.
Instead of a photo, you can choose an emoji or one of a fixed set of illustrated mascot icons we provide. Unlike a photo, a chosen emoji or mascot icon is stored on our servers and shown to your confirmed friends, so they see something personal instead of a blank icon.
Which restaurants you like, pass on, or save to your Matches list on your own, along with any filters or dietary preferences you set, are stored locally on your device only. This data is not transmitted to us and is deleted if you uninstall the app.
If you add friends, we keep a small friend-visible summary derived from that local data — your display name, tagline, chosen emoji or mascot avatar, dietary tags, your most-liked cuisines, badge/milestone progress, how long you've been a member, and your 10 most recently liked restaurants. Only your confirmed friends can see this summary; it updates automatically as you use the app and is removed if you delete your account or unfriend someone (they stop seeing updates, though Firestore's offline caching means a small delay is possible before a friend's device reflects a removal).
Adding a friend requires their friend code or an in-app invite; both people must accept before you become friends. We store the friendship itself (which accounts are connected) and any pending friend requests (who sent it, to whom) so the request can be shown and accepted or declined. Removing a friend or deleting your account removes this data.
Group Match lets you and your friends swipe together on the same list of restaurants. When a session is created, we store that session's restaurant list, who's invited, and each participant's likes/passes and completion status, so everyone in the session can see who's finished and be shown a restaurant everyone liked. This data is visible only to people in that specific session, and is not used for anything beyond running that session.
If you allow notifications, we store a device push token (provided by Apple's push notification service) tied to your account, used solely to notify you when someone sends you a friend request or invites you to a Group Match. We don't use this for marketing or any other kind of message, and you can turn notifications off at any time in iOS Settings or in the app's Settings screen — doing so removes the stored token.
Each time you view, like, pass on, or open the menu or video links for a restaurant card, we record that as an anonymous, aggregate count against that restaurant's listing — for example, "142 likes, 89 passes, 23 menu views this week." We also record roughly how long a card stays on screen before you swipe, averaged across everyone. These counts are tied to the restaurant (via its Google Places listing), never to your account, name, or device — there is no record anywhere linking a specific like or pass back to a specific person. This aggregate data may be shown to the restaurant's owner (see "Business accounts" below) and used to compute how a restaurant compares to similar restaurants nearby.
We're building a separate business portal so a restaurant owner or operator can claim their restaurant, view its aggregate performance analytics described above, and optionally upload a custom photo, add a promotion message, or pay to have their restaurant shown more often to relevant nearby users ("boosted," always labeled "Promoted" in the app). This is not yet available to the public. We'll update this section with full details before it launches; a business account will always be entirely separate from any consumer MunchMatch account and will never be able to see anything about individual app users, only aggregate numbers for restaurants it has claimed.
MunchMatch links out to a number of external services when you tap through from a restaurant card: directions (Apple Maps, Google Maps), food delivery (Uber Eats, SkipTheDishes, DoorDash), menus (the restaurant's own website), and short-form video (TikTok, Instagram, YouTube). These are independent services with their own privacy policies; MunchMatch does not share your personal data with them beyond what your device normally sends when you open a link (such as your IP address).
You can disable location access at any time in iOS Settings → Privacy & Security → Location Services, and disable notifications in iOS Settings or the app's Settings screen. You can clear your saved matches and preferences by deleting the app. You can permanently delete your account at any time from Profile → Settings → Delete Account inside the app — this immediately and permanently removes your email, name, and sign-in record, your friend-visible summary, your friendships and pending friend requests, and your notification token, and can't be undone. You're also removed from any Group Match session you're actively in (or, if you're hosting, that session is cancelled); a record of your participation in past, already-completed sessions may remain, visible only to the other people who were in that specific session, and is no longer linked to an active account.
If this policy changes, we'll update the date at the top of this page and, for material changes, note it inside the app.
Questions about this policy can be sent to support.munchmatch@gmail.com.