Last updated: 14 August 2026
⚠️ Still recommended: have this reviewed by a qualified UK solicitor. ICO registration is in progress but not yet complete as of publication — see §1. Complete it at ico.org.uk/registration and update §1 with the registration reference once done.
Picky is operated by Nikita Kyrushko, an individual based in the United Kingdom trading as "Picky" ("Picky", "we", "us"). Nikita Kyrushko is the data controller for personal data processed through the Picky app and get-picky.com (the "Service"). Contact: hello.picky.ai@gmail.com.
As a UK sole trader processing personal data, we are required to register as a data controller with the Information Commissioner's Office (ICO) and pay the data protection fee. Registration is in progress; this section will be updated with our registration reference once complete.
We process personal data in accordance with the UK GDPR and the Data Protection Act 2018.
Account data — email address, password (hashed by our authentication provider; we never see it), display name, and your date of birth (used once to verify you are 13 or over).
Your food profile — the foods you avoid, their severity (hard/soft), safe foods, texture preferences, and your eating situation. This can reveal information about your health (for example ARFID, allergies, or sensory-related restrictions), which is special category data — see section 4.
Menu scans — photos or text of restaurant menus you submit, and the AI-generated verdicts, reasons and ingredient breakdowns produced from them.
Meal outcomes and taste data — restaurants you say you're eating at, how meals went, cuisine information, your AI-generated taste summary and confidence profile, saved places and trips you plan.
Payment data — handled by Apple (App Store) or Google Play. If you subscribed through the get-picky.com website, payments are handled by Stripe. We receive subscription status and transaction identifiers (and, for Stripe, a customer reference); we never see your card number.
Referral data — your referral code, who referred you, and bonus scans earned.
Device and usage data — push notification token (only if you allow notifications), scan counts, and standard technical logs (IP address, request timestamps) generated when the app talks to our servers.
Contact form — name, email and message if you write to us via get-picky.com.
We do not collect precise location. Group dining shares your first name / display name and your dish verdicts with the other members of a session you choose to join.
| Purpose | Data | Lawful basis |
|---|---|---|
| Providing the Service — accounts, scans, verdicts, subscriptions | Account, scans, payment status | Contract (UK GDPR Art. 6(1)(b)) |
| Personalised verdicts, taste summary, recommendations, confidence profile | Food profile, meal outcomes | Explicit consent (Art. 6(1)(a) and, for health-related data, Art. 9(2)(a)) |
| Age verification (13+) | Date of birth | Legal obligation / legitimate interests (child safety) |
| Push notifications (post-meal check-ins, trip reminders) | Push token | Consent — the iOS permission prompt; withdraw any time in iOS Settings |
| Referral programme | Referral data | Contract / legitimate interests (fraud prevention) |
| Aggregated community safety signals | Meal outcomes, restrictions (aggregated) | Legitimate interests, using data that no longer identifies you (see §6) |
| Service security, abuse and fraud prevention, rate limiting | Technical logs | Legitimate interests |
| Responding to messages | Contact form data | Legitimate interests |
| Payment processing and records | Payment data | Contract / legal obligation (tax and accounting) |
Your food restrictions and related profile data can reveal health information. We only process it to run Picky for you — generating verdicts, learning your taste profile, and (in aggregated, non-identifying form) community signals. We ask for your explicit consent to this when you set up your food profile during onboarding. You can withdraw consent at any time by deleting your food profile or your account (Profile → edit, or Settings). Without this data Picky cannot generate verdicts, so withdrawing consent means the core feature stops working — but that is your choice to make, and we make withdrawal as easy as giving consent was.
We use these providers to run the Service. Each processes data only on our instructions under a data processing agreement:
We do not sell your personal data, and we do not share it with advertisers. We may disclose data where required by law, or as part of a handover of the Picky service to a new operator (for example a company formed to run Picky) — in which case this policy continues to apply and you will be notified before the handover takes effect.
Community signals ("worked for N people with similar restrictions") are computed from meal outcomes across users. They are only ever shown as aggregated counts, are only displayed when at least 5 users with overlapping restrictions have reported outcomes at a place (so an individual can't be singled out), and never include names, profiles or individual meals.
Some of our processors (Anthropic, Stripe, Vercel, Expo, Resend) process data in the United States. Where personal data leaves the UK we rely on the UK International Data Transfer Agreement / Addendum to the EU Standard Contractual Clauses, or an adequacy decision (including the UK–US Data Bridge where the provider is certified), plus each provider's technical safeguards.
Under the UK GDPR you have the right to:
To exercise any right, email hello.picky.ai@gmail.com. We respond within one month. We will never penalise you for exercising your rights.
Picky is not for children under 13. We check date of birth at onboarding and block under-13 signups. If you believe a child under 13 has an account, contact us and we will delete it.
Dish verdicts and taste summaries are generated automatically by AI. They are informational aids for your own decision — they do not produce legal or similarly significant effects on you, and no human review is involved in individual verdicts. They can be wrong: always verify with the restaurant, especially if a mistake could affect your health.
Data is encrypted in transit (TLS) and at rest by our hosting providers. Database access is protected by row-level security so users can only read their own rows. Access to production systems is limited to those who need it. No system is perfectly secure — if a breach affects your data we will notify you and the ICO as required by law.
We will post updates here and, for material changes (such as new purposes or new categories of data), notify you in the app or by email before they take effect and refresh consent where the law requires it.