Privacy Policy

Last updated: September 3, 2026

This policy describes what data LocalSelections, operated by City Reviewers LLC (“we,” “us”), collects when you use localselections.com (the “Service”), why, and who we share it with. It reflects what the Service actually does today, not a generic template.

1. Data we collect

Account data

If you create an account, we collect your email address and password (your password is stored and managed by our authentication provider, Supabase, using industry-standard hashing — we never see or store it in plain text). You may optionally set a display name, shown to other participants when you join a group session.

Location data

When you use a location-based feature (e.g. spinning for a restaurant category, using the weekly planner, or requesting a “Surprise me” pick), your browser asks your permission to share your device’s geolocation, or you can type in a location manually. That coordinate is sent to our server for that single request only, used to query the third-party location/events/media APIs described in Section 3 below, and is not stored as raw coordinates in our database. What is stored is the resolved, human-readable address of the specific restaurant or event a decision session actually landed on (e.g. “245 W 46th St, New York, NY”) — this lets us show your past picks and build anonymized, aggregated local trend content (see “Trend content” below); it does not let us reconstruct your precise device location at the time you played.

Decision & outcome history

We record each decision session you play (which game, the options in play, and the result — including the resolved address described above when applicable) and, if you provide it, whether you liked or disliked the outcome. If you’re logged in, this history is tied to your account; if you play without an account, it’s tied to a random identifier stored in your browser’s local storage, not to you personally. This history is what powers your personal recap, lets group participants see shared results, and (for logged-in users) lets us lightly personalize future recommendations based on what you’ve previously liked or disliked.

Billing data

If you subscribe to LocalSelections Pro, our payment processor, Stripe, collects your payment card details directly — we never see or store your full card number. We store your Stripe customer ID, subscription ID, subscription status, price, and current billing period, so we can determine whether your account has an active subscription.

Vendor data

If you claim a business listing as a vendor, we collect the business name and a contact email you provide, and (if you purchase boosted placement) related billing data through Stripe as above.

API keys

If you generate an API key to use our public API, we store only a one-way cryptographic hash of the key, never the raw key itself — we cannot recover a lost key, only issue a new one.

2. Trend content (anonymized)

Our public Trends page shows aggregated patterns (e.g. “Sushi is trending in New York, NY”) built from decision history across many users. A given city/category combination is only shown once enough distinct contributors have picked it, so trend content is never traceable back to an individual person or session.

3. Who we share data with

We don’t sell your personal data. We share data with the following third parties, each strictly to operate the Service:

  • Supabase — hosts our database and handles authentication. Stores everything described in Section 1.
  • Vercel — hosts the application itself.
  • Stripe — processes payments and stores your payment method and full billing history; governed by Stripe’s own privacy policy.
  • Google Places API — receives your location (coordinates or manually entered address) and search category for each restaurant lookup, and returns nearby real restaurant results.
  • The Movie Database (TMDB) — receives category/context requests and returns movie and TV recommendations. No location data is sent to TMDB.
  • Ticketmaster — receives your location and event-category context and returns nearby real event results.
  • Google Gemini (free tier) — for some AI-generated “why this one” comparison text, we send the candidate names and attributes (rating, distance, etc. — not your account email or raw location) being compared to Google’s Gemini API on its free tier. Because this specific path uses Gemini’s free tier, the data sent in that request may be used by Google to improve its models, per Google’s free-tier terms. This is separate from, and does not apply to, the Anthropic Claude path described next.
  • Anthropic Claude — for the same AI comparison feature, when configured to use Claude instead of Gemini, we send the same candidate attributes to Anthropic’s commercial API. Anthropic’s standard commercial API terms do not use API customer data to train its models.

We may also disclose data if required by law, or to protect the rights, property, or safety of LocalSelections, our users, or others.

4. Data retention

We retain account and decision-history data for as long as your account is active. If you want your account and associated data deleted, email us (see Section 7) and we will delete it, other than records we’re required to keep for billing, tax, or legal purposes.

5. Your choices

You can use the core solo decision games without an account or location sharing. You can deny or revoke browser location permission at any time and enter a location manually instead. You can request access to, correction of, or deletion of your personal data by emailing us.

6. Changes to this policy

We may update this policy as the Service changes. We’ll update the “Last updated” date above when we do. See also our Terms of Service.

7. Contact

Questions about this policy, or a request about your data? Email support@localselections.com.