This Privacy Policy applies globally to all users of Sterling: Dine with Confidence, regardless of country of residence. Sterling is published by Panda Taps LLC. The app shows public health-inspection data for restaurants in supported cities. This policy explains exactly what we do - and don't - with information when you use the app.
1. We do not require an account
Sterling has no sign-up, no sign-in, and no user accounts. We do not collect your name, email, phone number, contacts, or social-media identity.
- No account creation is required to use any feature, including Sterling Pro.
- No email verification, no SMS verification, no OAuth providers.
- Sterling Pro entitlement is tied to your Apple ID via Apple's StoreKit - we never see your Apple ID, name, or payment details.
2. Information collected on your device
The following data is read on your device and used to operate the app. Where listed as "on-device only", the data never leaves your phone:
- Location (Core Location): on-device only, used to show nearby restaurants. Not transmitted to our servers, not stored on our backend.
- Health-filter preferences (Pregnancy / Immunocompromised / Cross-contamination / No Recent Criticals): on-device only, stored in iOS Keychain with after-first-unlock-this-device-only protection.
- Watchlist and bell-alert preferences: stored on-device. The push token associated with a watched restaurant is sent to our backend so we can deliver alerts (see section 4).
- Recent searches and last-used city: on-device only.
- Onboarding selections (city pick, dietary preferences): on-device only.
3. Information our backend receives
When the app loads restaurant data, our backend (Supabase) automatically receives the following request metadata, used solely to operate the service:
- Your IP address, as part of the standard HTTPS request.
- An anonymous Supabase session token, generated by your device and renewed periodically.
- Bounding-box coordinates corresponding to the map view you are looking at (used to return restaurants in that area).
- Search-query strings you type (to return matching restaurants). Searches are not associated with an identity because there is no account.
- These signals are used to operate the app and are not used for advertising or shared with advertisers.
4. Push notifications (Sterling Pro)
If you subscribe to Sterling Pro and enable bell alerts on a restaurant, the following data is sent to our backend so we can deliver push notifications:
- Your iOS APNs push token (generated by Apple, scoped to your device + this app).
- The restaurant ID and alert categories you subscribed to (tier changes, critical violations, any inspection).
- We send an alert only when a watched restaurant's record changes in a way you opted into. We never use this channel for marketing.
- When you turn an alert off, the push subscription row is deleted from our database within a day.
- Notification delivery uses Apple Push Notification service (APNs) and Apple's certificate-pinned HTTP/2 endpoint - no third-party push provider is used.
5. Inspection data and restaurant information
- Restaurant names, addresses, inspection dates, violation descriptions, and severity codes are fetched from each city's official open-data portal (for example, the City of Chicago Department of Public Health, NYC Department of Health and Mental Hygiene, Public Health - Seattle & King County, and equivalent agencies in the other 15 supported jurisdictions).
- Sterling does not inspect restaurants. We process and present the public records that cities themselves publish.
- Sterling computes a 0-100 score and a five-tier label (exceptional / strong / fair / concerning / poor) from these records using a documented algorithm. The algorithm is deterministic and audit-able from the inspection data we read.
6. Subscriptions and payments
Sterling Pro is sold as an auto-renewable subscription via Apple In-App Purchase at $9.99 per year (with a 7-day free trial) or $2.99 per month (with a 7-day free trial). Apple processes all payment information.
- We do not see or store your credit card, Apple ID, billing address, or transaction details.
- Apple delivers an opaque entitlement state to the app via StoreKit 2 - we know only whether your subscription is active or in trial.
- Subscriptions auto-renew until cancelled in iOS Settings > Apple ID > Subscriptions or via the Manage Subscription link in the app's Settings tab.
7. What we do not do
- We do not run third-party advertising SDKs, analytics SDKs, attribution SDKs, or fingerprinting libraries.
- We do not use cookies. Sterling is a native iOS app and does not run a webview that could read cookies.
- We do not track you across other apps or websites.
- We do not collect health data, contacts, photos, microphone, or camera.
- We do not sell your personal information.
- We have no business relationship - financial or otherwise - with any rated restaurant. Restaurants do not pay to appear, do not pay for higher scores, and have no influence over the rating algorithm.
8. Data sharing
- Supabase (our backend hosting): processes the request metadata described above so the app can return inspection data to your device. Supabase is bound by its own privacy policy and our data-processing agreement.
- Apple (App Store, MapKit, Core Location, APNs, StoreKit): processes data on your device or via Apple-owned services under Apple's own privacy policy.
- We do not share your data with any other third party.
- If we are ever required by law to disclose data we hold, we will use reasonable efforts to notify you unless legally prohibited.
9. Your rights
You have the following rights, exercisable by emailing support@pandataps.com from the address you would like us to act on. Because Sterling has no accounts, we may need additional information to identify the data.
- Right to access the data we hold (in practice: limited to push subscription rows tied to your device's APNs token).
- Right to deletion (we will delete any push-subscription rows associated with a confirmed token within 30 days).
- Right to opt out of any sale or sharing - Sterling does not sell or share personal information, so the opt-out is the default.
- California residents have additional rights under the CCPA / CPRA.
- EEA, UK, and Switzerland residents have rights under GDPR (access, rectification, erasure, restriction, portability, objection).
10. Restaurant data corrections
Restaurant operators or anyone else who believes a Sterling rating misrepresents a restaurant's actual data can email support@pandataps.com. Include the restaurant's name and city, and what looks wrong. We aim to respond within 14 days. Corrections are made by reading the latest published inspection record from the source agency.
11. Retention
- Inspection records are public data and are retained as long as the source city publishes them.
- Server logs containing IP and session metadata are retained for up to 30 days for security and abuse prevention, then deleted or anonymized.
- Push subscription rows are retained as long as you have an alert enabled, and removed within a day of you disabling it.
- On-device data (your last-used city, watchlist, search history, health-filter preferences) lives only on your device and is removed when you delete the app.
12. Children's privacy
- Sterling is rated 4+ on the App Store and is not directed to children under 13.
- We do not knowingly collect personal information from anyone, including children. If you are a parent and believe your child has used the app, this Privacy Policy describes the full extent of what we have (essentially, an APNs push token if the child enabled an alert).
13. Changes to this policy
We may update this Privacy Policy periodically. Material changes will be reflected in the app's About > Privacy section and on this page. The "Effective Date" at the top will be updated. Continued use of the app signifies acceptance of the updated policy.
14. Contact
Questions, restaurant data corrections, and general support: support@pandataps.com