privacy policy
cooked is a free app that shows you restaurant hygiene grades in new york, chicago, los angeles, las vegas, seattle, austin, boston, london, manchester, and birmingham. this policy explains, in plain english, what the app does and does not do with your information.
account-less by design
- no sign-up, no login — we don't even know who you are.
- camera images never leave your phone, and saved spots stay on your device.
- no advertising id, no cross-app tracking, no ad profile.
here's the long version — the same promise, clause by clause.
no account, no sign-in
cooked has no accounts. it never asks for or collects your name, email, or phone number. there is nothing to sign up for.
location
when you use the camera “scan the block” feature or view the map, the app sends your precise location to the cooked backend (api.yallcooked.com, or cooked-api.vakilventures.com on older versions of the app) to find nearby restaurants and calculate where each grade should appear on screen. it is used only to answer that request.
your location is not tied to any account or identity, not used to build a profile, and not used to track you across other apps or for advertising.
camera
“scan the block” uses your camera for a live street view so grades can float over storefronts in the AR overlay. the camera image is used on-device for that overlay only. it is never stored and never sent to any server.
saved spots
spots you save are stored locally on your device only. they are not uploaded to the backend.
analytics
cooked uses google analytics for firebase. google collects:
- a pseudonymous app-instance identifier (the firebase installation / app-instance id — it identifies your install, not you);
- in-app usage and interaction events (which screens you view, and features you use such as scanning or searching);
- a coarse, approximate location that google derives from your IP address.
this is processed on google's servers and used only for aggregate, anonymous usage to improve the app. it is not linked to your identity and not used to track you across other companies' apps or for advertising. cooked does not collect the device advertising identifier (IDFA on iOS, Advertising ID on Android).
learn more: Google Privacy Policy and “How Google uses information from sites or apps that use our services”. you can limit analytics via your device privacy settings.
this website
yallcooked.com — including the /r/ share pages — uses google analytics 4 to count visits and see which pages people land on. it reports into the same analytics property as the app, so a shared link and the install it leads to show up in one place. it measures pages, not people: no name, no email, no account.
if you're in the uk, the eea or switzerland, no analytics cookie is set unless you say yes to the banner. until you do — and if you never do — google receives only a cookieless ping with no identifier, which cannot be tied to your next visit. we also honor the global privacy control browser signal everywhere, not just where it's law: if your browser sends it, no analytics cookie is set and no banner appears.
advertising storage, ad personalization and ad-user-data are denied on every request, in every country, permanently. we don't run ads on this site and nothing in the interface can turn them on.
session replay (microsoft clarity)
this site also uses microsoft clarity to see how pages are actually used — where people click, how far they scroll, and where the cursor goes. it produces heatmaps and a replay of the page as it was rendered to you. we use it to find layouts that confuse people, on a site where one page template is reused across a quarter of a million restaurants.
it records interactions with the page, not you: no name, no email, no account, and we never link it to anything that identifies you. the only thing you can type on this site is the restaurant search box, and whatever you search is already in the page's own URL.
clarity is held to a stricter rule than the analytics above: if an analytics cookie isn't allowed here, clarity is not loaded at all. so it never runs if you're in the uk, eea or switzerland and haven't said yes; if you said no; if your browser sends global privacy control; or if we couldn't tell which country you're in. google analytics can fall back to a cookieless count in those cases — a replay has no such halfway state, so it simply doesn't happen.
learn more: Microsoft Privacy Statement.
changed your mind? clear this site's cookies and site data in your browser and the banner will ask again on your next visit.
notifications
notifications are optional. if you save a spot and allow notifications, the app registers an anonymous device push token so it can alert you when that saved restaurant's grade changes. this is keyed to an anonymous device identifier — not to your name, email, or any account.
where the grades come from
all grades and inspection results come from official public inspection data — NYC DOHMH, Chicago CDPH, LA County Public Health, the Southern Nevada Health District, Public Health Seattle & King County, Austin Public Health, Boston ISD, and the UK Food Standards Agency's Food Hygiene Rating Scheme for london, manchester and birmingham. grades may be out of date or may not reflect current status, so always verify with the official source. cooked is independent and is not affiliated with, endorsed by, or representing any city, health department, or the FSA.
children
cooked is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
changes
we may update this policy. when we do, we will change the effective date at the top.
contact
questions? email hello@yallcooked.com.
📅 effective July 26, 2026