DiningStar — Privacy Policy
Last updated: 27 August 2026 · Effective: 27 August 2026
This Privacy Policy explains how Mellivo OÜ (Registry Code 17522398, Sepapaja 6, 15551 Tallinn, Estonia — "we", "us") collects, uses, shares and protects personal data in the DiningStar mobile application (the "App").
DiningStar is a restaurant discovery guide for İstanbul. It shows a curated list of restaurants, opens each restaurant's own digital menu inside the App, and can sort restaurants by how close they are to you. By using the App, you agree to this Policy.
The short version: You can use DiningStar without an account, and browsing, favourites and location stay on your device. An account is required only if you want to contribute — submitting a QR menu photo or reporting a problem. Those contributions are sent to our servers in the European Union, reviewed automatically, and deleted on a fixed schedule.
1. Data We Process
Account details (optional). Browsing, favourites, search, the map and menus all work without an account. If you create one — from the Profile tab, or when you first try to contribute — we process your display name, your e-mail address, and a record of the consents you accepted and their version. Accounts are managed by Amazon Cognito in the AWS Stockholm region (eu-north-1). Your password is set and verified by Cognito; it is never sent to us in readable form and we never see it. Your e-mail address is used to verify the account and to contact you about a submission or a rule violation — never for marketing.
Camera and QR menu photos (optional, account required). If you use the "QR Ekle" tab, the App asks for camera permission. It reads the QR code on your device, and uploads the photo you take together with the web address decoded from the QR code and, optionally, the restaurant name you type. The photo is stored in Amazon S3 (eu-north-1) and is linked to your account identifier so that we can apply submission limits and respond to misuse. Please photograph the QR code itself — do not include people, faces, receipts, or anything else you would not want reviewed.
Problem reports (optional, account required). If you use the report icon on a restaurant, we process the restaurant concerned, the reason you select, any free-text detail you write, and your account identifier.
Moderation records. For each contribution we store its status (pending, under review, accepted, already listed, rejected, flagged), the review outcome and a short reason, and — where a submission breaches the rules — a flag on your account and a counter of violations.
Precise device location (optional). If you open the Map tab and grant permission, the App reads your device's precise GPS location while the App is in the foreground only. It is used for a single purpose: to sort and show restaurants by distance from where you are. The coordinates are held in memory for that screen, are never written to our servers, never stored on disk, never attached to your account, and never shared. Denying the permission does not disable the App — the Map tab simply shows the restaurant list without distances.
Favourites and preferences. The restaurants you star and the cuisine categories you select are stored on your device. If you create an account later, favourites you saved as a guest are carried over into that account on the same device. Favourites are not currently uploaded to our servers.
Restaurant data. The restaurant list, menu links, districts and coordinates shipped with the App are public business information; they are not personal data about you.
Advertising and analytics identifiers. The App shows ads (see section 6) and uses crash reporting and product analytics. For these, Google assigns identifiers to your device — an advertising ID and a Firebase installation ID. We do not link them to your name or e-mail.
What we do NOT collect. We do not sell your personal data. We do not build our own profiles about you, and we do not ask for special categories of personal data. We do not read your photo library — the camera is opened only when you choose to submit a QR code, and only the picture you take in that moment is uploaded. We do not track you across other companies' apps or websites.
2. Third-Party Menus Opened Inside the App
DiningStar's core feature is opening each restaurant's own digital or QR menu inside the App, in an embedded browser view. When you tap "Open menu", your device connects directly to that restaurant's website or QR-menu provider — for example a restaurant's own domain, or providers such as Menulux, Adisyo, FineDine, qrdos, QRetti, pardonapp, foodieqr or a PDF hosted by the restaurant.
Those third parties receive the same technical information any website receives when you visit it: your IP address, approximate region derived from it, device and browser characteristics, and any cookies their site sets. Their own privacy policies apply to that visit, not this one. We do not control them, we do not receive what they collect, and we do not pass them any information about you.
Menus published as PDF files are rendered inside the App by a local PDF viewer. If you tap "Save", the file is downloaded to your device's cache and handed to the system share sheet so you can keep it or open it elsewhere; it is not uploaded anywhere.
Location permission is explicitly disabled for these embedded menu pages, and navigation is restricted to http/https addresses.
3. Maps
The Map tab draws map tiles using the map service provided by your platform — Apple Maps on iOS, Google Maps on Android. Those providers process the map requests your device makes under their own privacy policies (Apple, Google). We do not send your location to them ourselves; the platform map component does so in order to draw the map you asked for.
Restaurant coordinates shown as pins were prepared in advance using OpenStreetMap's Nominatim service during data preparation, not from your device and not at run time.
4. How We Use Data
Data that stays on your device is used only to make the App work for you: to show your favourites, to remember the cuisines you picked, and to order restaurants by distance when you ask for that.
Data you send us is used for a narrow set of purposes: to create and secure your account; to review a QR menu photo and, if it is genuine, add that restaurant to the public catalogue; to investigate a problem you report and correct the catalogue; to show you the status of your own contributions; to enforce the limit of two open submissions per type; and to detect and stop misuse of the contribution feature.
We do not use your data for marketing or advertising profiling, and we do not use it to train artificial intelligence models. We do use automated processing to review contributions — this is described in section 9, together with how to ask for a human review.
5. Legal Bases (GDPR)
Where the GDPR applies, our legal bases are:
- Consent — precise location (granted through the system permission, withdrawable at any time in device settings), camera access for QR submissions, and personalised advertising (asked separately, refusable, and changeable at any time).
- Performance of a contract (Art. 6(1)(b)) — creating and running your account, accepting your contributions, and showing you their status, once you have asked us to do so.
- Legitimate interests (Art. 6(1)(f)) — reviewing contributions before publishing them, enforcing submission limits, preventing abuse of the feature, showing non-personalised ads to fund a free app, and receiving crash reports so faults get fixed. Our interest is keeping a public catalogue accurate and the review queue usable; we balance it by limiting what we collect, reviewing automatically rather than reading more than we need, deleting photos on a fixed schedule, and offering human review of any decision.
If you never create an account, none of this data reaches us and the corresponding obligations do not arise.
6. Advertising
DiningStar is free and is funded by advertising. Ads are served by Google AdMob (Google Ireland Limited). You will see a banner at the bottom of the main screens, and an occasional full-screen ad when you open a restaurant's menu — at most one for every few menus you open, and never in the middle of something you are doing.
What Google receives. To serve and measure ads, Google receives your device's advertising identifier, IP address, approximate location derived from it, device and app information, and ad interactions. We do not send Google your e-mail address, your name, your favourites, your submissions, or your precise GPS location.
Your choice. On first launch — and always in the European Economic Area, the United Kingdom and Switzerland — you are asked whether you consent to personalised ads. If you do not consent, you still get the App in full; the ads are simply not personalised. You can change this at any time from Profile → advertising preferences, and you can reset or limit your advertising ID in your device settings (iOS: Settings → Privacy & Security → Tracking; Android: Settings → Google → Ads).
Google acts as an independent controller for the advertising data it collects; its practices are described at policies.google.com. We do not receive the personal data Google collects for advertising — only aggregate performance figures.
We do not show ads to users we know to be children, and we do not request ads rated above a general/teen audience.
7. Crash Reports and Product Analytics
We use Firebase Crashlytics to learn when the App crashes, and Google Analytics for Firebase to count how features are used — for example how often a menu fails to open, which is how we find broken restaurant links.
These record an anonymous installation identifier, device model, operating system version, app version, the screen you were on, and the error itself. They do not carry your e-mail address, your name, your search text, your favourites, or your location. We use them to fix faults and decide what to improve — not to profile you and not for advertising.
8. Sharing and International Transfers
If you never create an account, we still receive nothing: browsing, favourites and location stay on your device.
If you contribute, the data described in section 1 is processed by Amazon Web Services EMEA SARL as our processor, in the AWS Europe (Stockholm) region, eu-north-1. Automated review uses Amazon Bedrock with a regional inference profile restricted to European Union regions, so submissions are not routed outside the EU/EEA for review. We do not sell your data and we do not share it with advertisers or data brokers.
Advertising, crash reporting and analytics data goes to Google (Google Ireland Limited, with processing in the EU and the United States under the EU–US Data Privacy Framework and standard contractual clauses). See sections 6 and 7.
We disclose data outside AWS only where we are legally required to, or where it is strictly necessary to establish, exercise or defend legal claims — for example in response to a valid order from a competent authority.
Opening a restaurant's menu still connects you directly to that third party, wherever it is hosted; see section 2.
9. Automated Review of Contributions
QR menu photos and problem reports are reviewed automatically, without a person looking at them first. A large language model with image understanding (Anthropic Claude, run through Amazon Bedrock inside the EU) is shown the photo you submitted and the content of the web page the QR code points to, and decides whether the submission really is a restaurant's digital menu.
The possible outcomes are: added to the catalogue, already listed, not accepted (for example the link could not be opened, or the page is not a menu), or flagged as misuse. The outcome and a short reason are shown to you in the Profile tab.
This automated processing does not produce legal effects concerning you. If a decision about your submission or your account seems wrong to you, write to studio@mellivoai.com: a person will review it, you can explain your position, and we will correct the outcome where it was wrong.
We do not use your submissions to train AI models.
10. Contribution Rules, Flagging and Suspension
When you create an account you accept a short set of rules for contributions: submit only genuine restaurant QR menus, do not submit anything unlawful, obscene or misleading, and do not try to game the review.
To keep the queue usable and limit abuse, at most 2 QR submissions and 2 reports can be awaiting review at any one time. This limit is enforced on our servers, not just in the App.
If a submission breaches the rules, your account can be flagged and the ability to submit can be switched off. Repeated or deliberate abuse can lead to your account being closed. You will see a flagged status in the Profile tab, and you can contest it at studio@mellivoai.com.
We keep a record of flags and violation counts for as long as the account exists, because it is what makes the limit meaningful.
11. Retention and Deletion
On your device: favourites and preferences remain until you remove them. On our side: we keep contributions only as long as they serve moderation and abuse-prevention:
- QR menu photos — deleted 180 days after review at the latest, by an automatic storage rule.
- Problem reports — deleted 365 days after review at the latest.
- Submission records (status, outcome, reason) — kept while your account exists, so that you can see your own history in the Profile tab and so that limits and flags remain meaningful.
- Account record — kept until you delete the account.
Restaurant information accepted from a submission becomes part of the public restaurant catalogue and is not personal data about you; it is not deleted when your account is.
You are in control:
- Delete your account inside the App — Profile → "Hesabımı kalıcı olarak sil" (Delete my account). This deletes your account from Amazon Cognito, ends your sessions, and removes local data from the device. Any submission photos still stored are removed on the schedule above.
- Sign out — Profile → "Çıkış yap". This ends the session but keeps the account on the device.
- Uninstall the App — this removes all App data from your device.
- Revoke location — iOS Settings → DiningStar → Location, or Android Settings → Apps → DiningStar → Permissions.
You can also submit a request through our Account & Data Deletion page. Use that route if you want us to remove contributions you have already sent us, or if you no longer have the App installed.
12. Your Rights (GDPR / KVKK and similar)
Depending on where you live you may have rights to access, correct, delete, restrict or object to the processing of your personal data, and to data portability. Much of this you can do yourself in the App: view and edit your profile, view and change your favourites, see your own submission history, and delete your account entirely from the Profile tab. Favourites and preferences never leave your device. For the data we do hold on our side — your account record, the QR menu photos and problem reports you have sent us, and their moderation records — write to studio@mellivoai.com or use our Account & Data Deletion page.
If you believe we have processed your data improperly you may contact us at studio@mellivoai.com, and you have the right to lodge a complaint with your local supervisory authority — in Estonia the Data Protection Inspectorate (Andmekaitse Inspektsioon), in Türkiye the Personal Data Protection Authority (KVKK).
13. Children's Privacy
DiningStar is a general-audience restaurant guide and is not directed to children. We do not knowingly collect personal data from children. Some restaurants listed serve alcohol, and their menus may include alcoholic drinks.
14. Security
On your device, data stays in the App's private storage area, which the operating system isolates from other apps. Data kept only on a device can be lost if the device is lost, reset, or the App is uninstalled. In transit, everything travels over HTTPS/TLS. On our side, accounts are managed by Amazon Cognito, which salts and hashes your password rather than storing it in readable form — we never see it. The contributions you send us are stored in Amazon S3 and DynamoDB in the AWS Stockholm region (eu-north-1), reachable only by the services that need them, and are deleted on the schedule in section 11. No system is perfectly secure, so we keep what we store to the minimum needed for moderation and abuse prevention.
15. Accuracy of Restaurant Information
Restaurant details, menus and prices belong to the restaurants themselves and change without notice. DiningStar links to each restaurant's own menu rather than copying it, so that you see what the restaurant publishes. We do not guarantee that a menu, price or opening status is current.
16. Changes to This Policy
If we change how DiningStar handles data — for example if favourites gain optional cloud sync, or if we begin processing a new category of data — we will update this page, change the "Last updated" date, and, where the change requires it, ask for your consent in the App before it takes effect for you.
17. Contact
Mellivo OÜ · Registry Code 17522398
Sepapaja 6, 15551 Tallinn, Estonia
E-mail: studio@mellivoai.com

