Information you provide
A nomination may include an item name, category, notes, email address, and optional brand, place, URL, or descriptive tags. Email addresses are used for moderation and follow-up and are not intended for public display.
Private Food Passport on this device
The optional Food Passport stores entries and an auto-saved unfinished draft in persistent browser storage on this device. An entry may include a food name and type, category, Passport states, sensory reactions, date, general place, preparation details, and a private note. This data is not uploaded by default and never becomes a public rating, review, vote, score, or catalog record.
You can export the device Passport as JSON and explicitly delete an entry or unreadable local Passport data. Anyone with access to the same browser profile—and any same-origin script running on FoodRateKing—may be able to read it. Clearing site data in the browser can remove it. Transfer receipts remember whether you explicitly made a one-time private account copy; deleting the device entry removes a readable related receipt, while a separately created account copy remains until you delete or correct it through the account service.
Private accounts
Firebase Authentication processes account email addresses, passwords, Google identity data, sign-in tokens, and recovery actions. FoodRateKing stores the verified Firebase user identifier, your preferred name, optional age range, optional country or broad region, policy acceptance, account status, and owned taste data in D1. The optional profile details are used only for your private account and future consented product personalization; they do not create a public profile or change public rankings. FoodRateKing does not request an exact birthday or address and does not store passwords, Google access tokens, refresh tokens, ID tokens, or provider avatars in D1.
Optional community aggregate sharing
Community sharing is off unless you separately accept the exact sharing notice. If enabled, you can individually mark an eligible firsthand account rating as shared and disclose any maker, seller, employment, free-item, paid, affiliate, competitor, or other relationship. FoodRateKing keeps the consent, selected rating, disclosure, share history, and integrity history linked to your private account while it exists. Earlier ratings, guest or device-transfer ratings, and pairwise picks are not eligible.
Public aggregate output does not expose your name, account identifier, individual rating, exact sample count, or contribution token. Withdrawing consent, stopping a share, correcting a shared rating, or deleting the account makes affected aggregate output unavailable until it is rebuilt; propagation is not guaranteed to be instantaneous. Account-linked sharing records are deleted with the account. A validated release may retain a non-identifying contribution token, score, and share day as immutable release evidence, but it is not linked to your account and cannot keep a stale result active. Restricted private release files must be deleted after validated database loading.
Optional analytics
FoodRateKing uses Google Analytics 4 to understand page visits, navigation, engagement, and broad device or location information. After consent, the site also sends a fixed, versioned set of name-only activation events—such as a completed rating, comparison answer, account setup, or Passport entry—to Google Analytics and to a first-party endpoint. The first-party payload contains only the contract version and event name; D1 stores only daily event totals and first/last receipt times, not raw events, account or session identifiers, food history, answers, notes, OAuth data, precise location, URLs, or referrers. These totals count actions, not unique people or verified retention.
Analytics is denied by default and no analytics request is made until you choose “Accept analytics.” You can reject it or reopen Analytics settings in the site footer at any time. Revocation blocks future analytics requests and clears first-party Google Analytics cookies where the browser permits. Advertising storage, ad user data, ad personalization, and Google signals remain denied.
Automatic service data
Hosting and abuse-prevention systems may process an IP address, request headers, timestamp, device information, and security signals. For analytics abuse control, the connecting address is transformed with a secret-keyed one-way function and retained only in the shared short-lived rate-limit store; raw addresses and user-agent strings are not written to the analytics counters.
How information is used
- Moderate, deduplicate, and evaluate nominations.
- Provide and protect private account access.
- Remember private ratings and comparison history.
- Measure aggregate activation paths after analytics consent.
- Protect the service against spam and abuse.
- Respond to corrections and privacy requests.
Publication
Nominations and accounts are private by default and never publish automatically. Account creation alone does not create a public profile, rating, vote, review, score, or contributor role. Only a rating you separately mark as shared may later enter an identity-free aggregate result after the stated cohort, integrity, validation, and release gates pass. Editorial publication remains a separate evidence and approval process.
Retention and requests
Account holders can use the private account page to delete their account after a recent sign-in. Owned private account, profile, and taste records are removed from D1 first. A one-way deletion tombstone remains for 30 days to prevent an interrupted deletion from reactivating; expired tombstones are eligible for cleanup. If Firebase does not confirm deletion, the minimum Firebase identifier is held in a private reconciliation queue only until deletion is confirmed. Shared rate-limit records older than 24 hours are removed during normal authenticated or analytics traffic. Request nomination access, correction, or deletion through the contact page; identity verification may be required. Nomination and moderation retention remains a separate prelaunch operating decision.
Analytics and advertising
Firebase Analytics is not enabled. No advertising tracker or paid analytics system is intentionally included in this build.