Privacy Policy
How AspireCore LLC collects, uses, and protects your data in Servd.
Overview
AspireCore LLC ("we", "us", "our") operates Servd (the "Service"). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the rights you have over it.
We aim to collect the minimum data required to make the Service work, keep it on systems we control where reasonable, and never sell it to third parties for advertising.
Information You Provide
When you create an account or use the Service, you may provide:
- Account info: email, display name, handle, profile photo, bio, and your date of birth (used to confirm you are 18 or older).
- Home city + cities you frequent (Taste Travels).
- Plate posts: photos, dish names, captions, restaurant tags, flavor reactions, comments.
- Dish ratings + reviews you write.
- Memory queries (natural-language searches like "the lamb taco I had in Mexico City").
- Friend requests + accepted friendships.
- TONIGHT session participation (group restaurant decisions).
- Live broadcasts you start and replays you publish: the video and audio you stream, plus comments and reactions during the broadcast.
- Booking confirmations you log via the post-booking sheet.
Information Collected Automatically
When you use the Service, we automatically collect:
- Device info: device model, OS version, app version, language.
- Approximate location, when you grant the OS permission, used to surface restaurants near you. We do not track your precise location in the background.
- Approximate location you choose to share with a TONIGHT group: sharing is off unless you switch it on, and you switch it on per session. When you do, the app rounds your location to roughly a kilometre before it leaves your device and never stores it more precisely than that. It is used only to centre the group's restaurant suggestions fairly between everyone instead of around whoever started the session, it is visible only to people in that session, and it is erased when the session ends.
- A push-notification token for each device where you allow notifications — an identifier issued by the device's operating system that lets a notification reach that install. It is stored with your account, replaced when the device issues a new one, removed when you sign out of that device, and deleted with your account.
- Usage telemetry and diagnostics: feature interactions, error and crash reports, performance metrics. These events are recorded against your account so we can reproduce a problem you hit and tell whether a feature works. They are kept for up to 90 days and then deleted automatically. If you delete your account, the link between these events and you is severed at once and only de-identified records remain. Telemetry is never used for advertising and is never sold.
- Purchase receipts and subscription status from the app store when you buy a subscription. We never receive your card or bank details.
- IP address, used by our cloud infrastructure for security and rate limiting.
How We Use Your Information
We use your information to:
- Provide, operate, and improve core features (your feed, dish ranking, restaurant briefs, friend graph, group decisions, bookings, live broadcasts).
- Personalize content based on your taste profile and history.
- Process your subscription purchases and manage access to paid features.
- Send transactional notifications (friend accepted you, your TONIGHT group made a pick, your booking was confirmed).
- Detect, prevent, and respond to fraud, abuse, security incidents, and violations of our Terms.
- Comply with legal obligations and respond to lawful requests.
Service Providers We Use
To provide the Service, we share data with a small set of service providers. Each receives only the minimum data needed for its function, and providers processing personal information on our behalf are bound by data-processing agreements:
- Cloud database and application hosting — stores your account, plate posts, friendships, and most app data, and runs our server-side functions.
- AI model provider — generates dish recommendations and restaurant briefs, interprets your natural-language searches, and reads the photos you submit to features like Taste DNA, the plate scanner, and the check scanner that reads a restaurant bill so a group can split it. That last one means a photo of a paper check — which can show the venue, the items ordered, and the totals — is transmitted for reading like any other photo you submit. Photos you submit to these features ARE transmitted to the provider for processing and are discarded by us after the response — only the resulting structured palate axes, dish reads, descriptors, and (for a check) the line items you then edit and split are saved. We do not send your name, email, or other account identifiers with these requests.
- Venue-data and availability providers — supply restaurant information, menus, and reservation availability drawn from venues' own published materials and public listings. When you check availability we send venue identifiers and your party size and time; we never send your account details to these providers or to any venue platform.
- Google (Google Maps Platform) — restaurant data, photos, and reviews. Google's handling of data is described in the Google Privacy Policy at https://policies.google.com/privacy.
- Apple / Google (sign-in providers) — only if you choose to sign in via these.
- Apple App Store / Google Play (purchases) — process payment for any subscription you buy. We receive purchase receipts and subscription status, validated for us by a subscription-management provider; your payment details stay with Apple or Google.
- Push-notification delivery — a push-delivery service that receives your device's notification token and the contents of the notification, and hands them to Apple's and Google's device-push networks for delivery. Used only for the transactional pushes you opt into.
- Error and crash reporting — receives technical diagnostics (device model, OS version, what the app was doing when it failed) so we can find and fix defects. Not used for advertising.
- Live-video infrastructure — real-time streaming and video-delivery providers that carry the audio and video of live broadcasts and replays between you and your viewers.
How We Share Your Information
We share your information only as described in this policy. Specifically:
- With other users when you opt in: e.g., your handle + display name + avatar are visible to anyone who can see your plate posts (per your visibility settings); your taste DNA may be used (in aggregate, not exposed) to help your TONIGHT group decisions.
- With service providers (above) under written data-processing agreements.
- In response to valid legal requests (subpoena, court order, government investigation).
- In connection with a business transaction (merger, acquisition, asset sale) — we will notify you and you will have an opportunity to delete your account before any transfer.
- We do NOT sell your personal information for advertising. We do NOT share your taste DNA, plate posts, or memory queries with advertisers.
Your Choices and Controls
You have the following controls:
- Edit profile: change name, handle, bio, home city, cities, photos at any time.
- Plate visibility: choose "public" or "Circle-only" per post.
- Friend control: send, accept, decline, or remove friendships at any time.
- TONIGHT participation: decline an invite at any time; the initiator can cancel a session.
- Subscriptions: manage or cancel an auto-renewing subscription at any time in your device's app-store subscription settings.
- Notifications: control via the OS permissions or in-app settings.
- Location: revoke OS location permission at any time; you can still use most features but restaurant lists default to a fallback location.
- Account deletion: delete your account and associated data via the in-app data deletion flow (see the "Data Deletion" page).
Your Privacy Rights
Depending on where you live, you may have additional rights under laws like the California Consumer Privacy Act (CCPA), the EU General Data Protection Regulation (GDPR), the UK Data Protection Act, or Canadian PIPEDA, including:
Where the GDPR applies, our legal bases for processing are: performance of our contract with you (running the Service you signed up for); your consent, which you may withdraw at any time (for example, location permission and photo features); our legitimate interests (keeping the Service secure, preventing abuse, improving features); and compliance with legal obligations.
- Right to access — request a copy of the personal information we hold about you.
- Right to correction — request that we fix inaccurate information.
- Right to deletion — request that we delete your data (see Data Deletion).
- Right to portability — request your data in a machine-readable format.
- Right to restrict or object to certain processing.
- Right to withdraw consent for processing that relies on consent.
- Right to lodge a complaint with your local data-protection authority.
Data Retention
We retain your account data for as long as your account is active. Content you have published (plate posts, replays of your live broadcasts) stays on your profile until you delete it or delete your account. When you delete your account, we delete your personal information from our active systems within 30 days, except where retention is required by law (e.g., financial records) or where data has already been de-identified or aggregated for analytics.
Backups containing your data may persist for up to 90 days after deletion; they are not used for any active processing and roll off according to our backup rotation.
Security
We use industry-standard practices to protect your data — encrypted connections (TLS 1.2+), encryption at rest where supported by our cloud providers, scoped access controls, and per-user access rules enforced at the data layer. No system is perfectly secure; please use a strong, unique password and notify us immediately at the contact below if you suspect unauthorized access to your account.
Children's Privacy
Servd is for adults 18 and over. We ask for your date of birth when you create an account and enforce the 18+ requirement at account creation. The Service is not directed to children under 13, and we do not knowingly collect personal information from anyone under 18. If you believe someone under 18 — or any child under 13 — has provided us with personal information, contact us and we will delete it.
International Transfers
We are based in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or any country where our service providers operate. By using the Service, you consent to this transfer.
Our Websites
Our public web pages (for example theservd.com and aspirecorellc.com) use Google Tag Manager to measure page visits. Those analytics run on the websites only — they are separate from the app and are not linked to your Servd account. You can limit them with standard browser controls such as content blockers and cookie settings.
Do Not Track
Some browsers can send a "Do Not Track" signal. There is no common industry standard for what a site must do when it receives one, and our websites do not currently respond to it. We say so plainly because California law requires us to disclose how we treat that signal rather than leave you guessing.
What that signal usually aims at is not something we do in the first place: we do not follow you across other companies' websites or apps to build an advertising profile, and we do not sell your personal information for advertising (see "How We Share Your Information"). The website analytics described above can be blocked with ordinary browser controls.
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be surfaced in the app and the "Last updated" date above will change. We encourage you to review this page periodically.
Contact Us
For privacy questions, requests to exercise rights, or to report a privacy concern, contact us at privacy@aspirecorellc.com.
AspireCore LLC