WildHeavy Privacy Policy
1. Introduction
Present Advisory LLC ("Company," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website wildheavy.com and use the WildHeavy mobile application (the "Service").
We are based in Chicago, Illinois. By accessing or using our Service, you agree to the terms of this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.
2. Information We Collect
We collect information that you provide directly to us, as well as data we learn from your use of the Service.
2.1 Personal Data
When you register for an account, we may collect personally identifiable information, such as:
Contact Data: Your email address. (We do not currently require your legal name).
Account Credentials: Username and password.
Profile Data: Your dining preferences, dietary restrictions (if you choose to save them), and profile photo.
Location Data:
- Private Location: You may choose to input a specific location (verified via Google Places API) to enable "Near Me" discovery features. This data is private and used only for localizing recommendations.
- Public Profile Location: You may choose to display a location on your public profile (e.g., "Chicago"). This is free-text and fully optional.
Usage Preferences: How you intend to use the Service (e.g., as a content creator or explorer).
Referral Data: If you use or share a referral code, we track this for verification purposes.
2.2 Derivative Data & Usage
Our servers automatically collect information when you access the Service, such as:
- Device Information: Your mobile device ID, model, manufacturer, and operating system version.
- Usage Habits: Which restaurants you view, how you rank dishes, and your interactions with our AI features.
- Content Interactions: Which rankings and spec cards you view, save, and interact with.
- Spec Card Data: Your restaurant visit logs including dishes ordered, ratings, occasion, party size, and visit dates.
- Log Data: IP address, browser type, and timestamps of access.
- Onboarding Analytics: Progress through our setup flow to improve user experience.
- AI Interaction Logs: When you use AI-powered features, we log usage for quality assurance and cost management.
- Security Logs: Authentication attempts, rate limit events, and potential security incidents.
- Posts & Coordination Data: When you create dining coordination posts, we collect the restaurant name, event date, post type, and any visibility preferences you set. Other users' "interested" responses to your posts are visible to you as the post creator.
2.3 Mobile Permissions
We may request access to certain features on your mobile device, including:
- Camera & Photo Gallery: To allow you to upload a Profile Photo. (Note: Dish and menu photo uploads are not currently enabled for user submission).
- Push Notifications: To send you alerts about account activity or service updates.
2.4 Third-Party Data & Authentication
Google Maps Platform: We use Google Places API for restaurant and city search, and Google Maps Directions API for travel time estimates between route stops. This includes restaurant names, addresses, hours, cover photos, and navigation data.
Restaurant Menu Data: We utilize Firecrawl to index publicly available restaurant websites and menus to validate dish names and improve data accuracy.
Authentication Providers: We currently support email and password authentication. If we enable third-party authentication options in the future (such as Google, Apple, or Phone Number authentication), we would receive your basic profile information from those providers.
2.5 Verification Data
If you apply for verified status (Industry Professional or Tastemaker badges), we collect:
- Evidence of your employment or professional status
- Proof documentation (e.g., business cards, LinkedIn profiles, referral information)
- Any supporting text or URLs you provide
2.6 Cookies and Local Storage
WildHeavy is a "privacy-first" platform. We do not use third-party advertising cookies or tracking pixels. We use storage strictly for functionality:
- Cookies (Web Only): We use a single functional cookie to remember your sidebar preference (expanded/collapsed). This expires after 7 days.
- Local Storage (App & Web): Includes authentication tokens (Supabase), theme preference, onboarding state, and temporary performance cache (feed, rankings, routes).
Managing Data:
- Web: You can clear cookies/storage in your browser settings.
- iOS App: Uninstalling and reinstalling the app will clear all locally stored data.
- Log Out: Logging out clears your authentication token immediately.
3. How We Use Your Information
We use the information we collect to:
- Provide the Service: Create your account, facilitate rankings, and display restaurant data.
- Improve Our Algorithms: We use aggregated, anonymized ranking data to calculate "Dish Scores" and "Reservation Difficulty" metrics.
- Train AI Models: We may use your anonymized reviews and text inputs to train our AI (Large Language Models) to provide better dining recommendations.
- Provide Verified Status: Verify employment or professional credentials for Industry Professional or Tastemaker badges.
- Communication: Send you administrative emails (password resets) and, if you opt-in, marketing emails.
- Security: Detect and prevent fraudulent activity, spam, and "review bombing." We log authentication attempts to detect and prevent unauthorized access.
4. Disclosure of Your Information
We may share information we have collected about you in certain situations:
4.1 By Law or to Protect Rights
We may disclose your information if we believe it is necessary to respond to legal process, to investigate or remedy potential violations of our policies, or to protect the rights, property, and safety of others.
4.2 Third-Party Service Providers
We may share your information with third parties that perform services for us, such as:
- Cloud Infrastructure: Supabase (database, authentication, file storage).
- AI Services: Anthropic's Claude AI models for recommendation features, content summarization, and data normalization.
- Data Processing: Firecrawl (menu indexing) and Google Maps Platform (location search and directions).
- Email Delivery: Resend for transactional emails (password resets, notifications) and service communications.
4.3 Business Transfers
If Present Advisory LLC undergoes a merger, acquisition, or asset sale, your user data may be transferred as part of that transaction.
4.4 Aggregated & Anonymized Data
We may share anonymized data (which cannot identify you) with third parties for marketing, advertising, research, or similar purposes. For example, we might publish a report on "The Most Popular Italian Dishes in Chicago" using your data in aggregate.
5. Content Moderation & Data Processing
To maintain data quality and community safety, we collect and process certain information related to content moderation:
5.1 Human Review Data
When our team reviews content for policy compliance or data accuracy, we log the reviewer's identity, the action taken, the original content, and the modified content (if applicable). This data is stored securely and used only for accountability and quality assurance purposes.
5.2 Automated Processing ("Janitor" System)
We use AI-assisted tools to normalize and standardize User Content, such as:
- Correcting dish name spelling and capitalization
- Matching dishes to official restaurant menu items
- Identifying and merging duplicate entries
- Flagging content that may require human review
This processing is performed to improve search accuracy and data consistency across the platform. The AI system may access scraped restaurant menu data to validate dish names.
5.3 Audit Trail & Retention
We maintain detailed logs of all moderation actions, including:
- The type of action (edit, delete, flag, approve)
- The identity of the reviewer (for human actions)
- Timestamp of the action
- The original and modified content values
- Reason for the action (if applicable)
These logs are retained for a minimum of 2 years to support dispute resolution and ensure accountability.
5.4 Your Rights Regarding Moderated Content
You may request information about moderation actions taken on your content by contacting support@wildheavy.com. We will provide details about what was changed, when, and why, subject to any legal or security limitations.
6. Third-Party Websites
The Service may contain links to third-party websites (e.g., OpenTable, Resy, Google Maps). We are not responsible for the privacy practices or content of third-party sites. Information you provide to those third parties is not covered by this Privacy Policy.
We load fonts from Google Fonts, which involves your browser making requests to Google's servers.
7. Security of Your Information
We use administrative, technical, and physical security measures to help protect your personal information. We log authentication attempts, rate limit events, and potential security incidents to detect and prevent unauthorized access and abuse. However, please be aware that no security measures are perfect or impenetrable, and no method of data transmission can be guaranteed against any interception or other type of misuse.
8. Policy for Children
We do not knowingly solicit information from or market to children under the age of 13. If we become aware that we have collected data from a child under age 13 without verification of parental consent, we will delete that information as quickly as possible.
9. Controls for Do-Not-Track Features
Most web browsers and some mobile operating systems include a Do-Not-Track ("DNT") feature. No uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals.
10. Your Privacy Rights
Depending on your location, you may have certain rights regarding your personal data:
Access & Correction
You may review and change your personal information by logging into your account settings.
Notification Preferences
You can manage your notification preferences in your account settings, including controls for follows, saves, and other activity alerts.
Deletion
You may request that we delete your account and personal data by contacting us or using the in-app deletion tools. Account deletion involves the following process:
- Permanently disabling your authentication credentials
- Replacing your email with an anonymized placeholder
- Removing all personal profile information
- Deleting private location data and social connections
- Attributing any content you created to "Deleted User" so it can no longer be linked to your identity
What Gets Removed:
- Your profile information (bio, avatar, location data)
- Your social connections (follows, saves, likes)
- Your notification history and preferences
- Your private location data
What Gets Anonymized:
- Your authentication credentials are permanently disabled and your email is replaced with an anonymized placeholder (the original email is not recoverable)
- Your public rankings and spec cards are anonymized (attributed to "Deleted User")
- Your contributions continue to count in aggregate scoring calculations
- Your badge status (if applicable) is retained for algorithm accuracy but not publicly displayed
11. Regional Privacy Rights
11.1 California Residents (CCPA/CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act:
- Right to Know: You may request details about the categories of personal information we collect and how it is used.
- Right to Delete: You may request the deletion of your personal data (subject to our retention of anonymized ranking data as disclosed above).
- Right to Opt-Out of Sale: WildHeavy does not sell your personal information to third parties.
- Non-Discrimination: We will not discriminate against you for exercising these rights.
To exercise these rights, contact support@wildheavy.com.
11.2 European Users (GDPR)
If you access the Service from the European Economic Area or United Kingdom:
- Legal Basis: We process data based on Contract (to provide the Service), Legitimate Interest (fraud prevention, ranking integrity), and Consent (where applicable).
- Data Transfer: Your data is processed and stored in the United States. By using the Service, you consent to this transfer. We rely on standard contractual clauses where required.
- Your Rights: You have the right to access, rectify, erase, restrict processing, data portability, and object to processing of your personal data.
- Data Protection Authority: You have the right to lodge a complaint with your local supervisory authority.
To exercise these rights, contact support@wildheavy.com.
12. Contact Us
If you have questions or comments about this Privacy Policy, please contact us at:
Present Advisory LLC
Chicago, Illinois
Email: support@wildheavy.com
Security Issues: security@wildheavy.com