Privacy Policy
1. Who we are
Cora is operated by Lumospark LLC, a limited liability company registered in Wyoming, USA (“Lumospark”, “we”, “us”). Lumospark is the data controller for the personal data described here.
Contact and data requests: hello@coramap.com
Cora is a taste-personalised venue-discovery service for restaurants, bars, and cafes in London and Copenhagen, available on iOS.
2. What we collect
You give us:
- Account information — email address and name, via Sign in with Apple, Google, or email.
- Taste profile — cuisine, vibe, and dietary preferences from onboarding.
- Reviews — ratings, occasion tags, noise levels, standout/avoid dishes, and optional free-text notes. Reviews are visible to others (see §5).
- Saved places and lists — venues you bookmark and the lists you organise them into.
- Profile photo (avatar) — if you choose to set one. Location metadata (EXIF/GPS) is stripped before upload.
- Venue and menu photos — photos you choose to contribute for a venue, and photos of a menu you scan. Venue photos are reviewed before they appear publicly, and are shown alongside your account. Menu photos are read to extract the menu items.
- Search queries — the free-text you type to find places.
We collect automatically:
- Precise location — when you grant permission. “While Using the App” for nearby results, and “Always” only if you book a table and let us notice when you have been (see §3).
- Device identifier — an app-generated install ID (a random value stored on your device, reset on reinstall) used to give signed-out searches a fair rate-limit allowance. It is not your Apple advertising ID and is not used for advertising.
- Push notification token — only if you turn notifications on. Apple issues a token identifying your device, which we store against your account so we can send you a notification when someone follows you or shares a list with you. It is not your Apple advertising ID, is never used for advertising, and is deleted when you turn notifications off, sign out, or delete your account.
- IP address — processed to rate-limit our services against abuse.
- Usage and interaction data — searches performed, results shown, taps, and feedback, recorded on our servers to improve recommendations.
3. Location
With your permission, Cora uses your device’s precise (GPS-level) location while you are using the app, to show nearby venues and sort results by distance. When you run a search, your coordinates are sent to our backend to produce location-relevant results and are stored with the search record.
Background location — only if you book. If you tap through to book a table, Cora asks separately for “Always” location permission and sets a geofence around that one venue, so it can notice when you have been and offer to ask how it was. This is the only background use of your location: we do not follow you the rest of the time, and we do not detect visits to venues you have not booked. You can decline it, or revoke it later in iOS Settings, and every other part of the app keeps working.
You can decline or revoke location permission at any time in iOS Settings; Cora still works with manual city selection.
4. How we use your data and why
- Personalise your venue recommendations from your taste profile and activity — to perform our service to you.
- Find “taste twins” (users with similar tastes, whose reviews inform your ranking) — our legitimate interest in relevant results.
- Show nearby venues and sort by distance — to perform our service, with your location permission.
- Improve our recommendation algorithm and product — our legitimate interest.
- Detect and prevent abuse (rate-limiting) — our legitimate interest in security.
We do not sell your personal data, and we do not use it for third-party advertising.
5. What other people can see
Cora has social features. Please be aware:
- Your profile is visible to others — your display name, @username (if set), and avatar, and you are discoverable in people-search.
- Your reviews are visible to others and are used to inform other users’ “taste twin” recommendations.
- Following is visible — you can follow other users and send friend requests; who you follow can be seen by others using Cora.
- Lists are private by default — a new list is visible only to you unless you choose to share it.
- You are in control — you can report any review from the menu on it, and block the person who wrote it. Blocking hides their content from you and yours from them, and you can undo it from your profile. We review reports within 24 hours.
6. Who we share data with
We use the following service providers, who process data on our behalf under contract:
- Supabase — database, authentication, and file storage (including avatars). EU-hosted (Frankfurt).
- OpenAI — converts your search query text into a numerical embedding to match it to venues. Receives your query text.
- Anthropic (Claude) — interprets search queries, generates result explanations, and runs a safety check. Receives your query text and venue/editorial context.
- Google Places — venue autocomplete, ratings, hours, and details. Receives venue/location terms from your query.
- DeepL — translates review text between English and Danish when you use translation. Receives the text being translated.
- Vercel — hosting.
- Apple — authentication, and delivery of push notifications. If you turn notifications on, Apple's Push Notification service receives your device's push token and the notification itself, which names the person who followed you or shared a list with you.
- Google — authentication only.
- Open-Meteo — weather context, using city-level coordinates only (no personal data).
7. International transfers
Our database is EU-hosted. Some providers above (OpenAI, Anthropic, Google, Vercel) are US-based, so some data is transferred to the United States. Where data is transferred outside the UK/EU, we rely on appropriate safeguards such as Standard Contractual Clauses.
8. Analytics and cookies
This app does not run third-party product-analytics SDKs or session recording on your device. We record usage and interaction data (§2) on our own servers to improve the service. Our marketing website uses only essential and functional cookies.
9. Storage, security, and retention
Data is stored in Supabase (PostgreSQL) in the EU with row-level security. Authentication uses OAuth 2.0 with PKCE. Avatars are stored with access controls and EXIF/GPS metadata is stripped on upload. All connections use HTTPS/TLS.
Retention:
- Account data (profile, taste profile, reviews, saves, lists) — kept until you delete your account.
- Push notification token — kept only while notifications are on. Deleted when you sign out, when you delete your account, and automatically when Apple reports the token is no longer valid.
- IP address / rate-limit records — up to 90 days, then purged.
- Search and interaction logs — up to 24 months.
10. Your rights
Depending on where you live (UK/EU GDPR and others), you may have the right to access, correct, export, delete, or object to the processing of your personal data, to withdraw consent, and to complain to a supervisory authority (in the UK, the ICO; in Denmark, Datatilsynet).
- Delete your account — in the app under Profile → Account. This permanently deletes your data, including reviews, saved places, taste profile, and avatar.
- Access or export your data — email hello@coramap.com.
- Location — deny or revoke location permission at any time; the app works with manual city selection.
11. Children
Cora is not directed at children under 13, and we do not knowingly collect data from them.
12. Changes
We may update this policy. Material changes will be communicated in the app, and the “last updated” date will change.
13. Contact
Lumospark LLC — hello@coramap.com