Privacy
TODO(founder) — Opening: the plain-language summary of what we collect and what we don’t, and the tone-setting promise.
What happens to your photo
- When you photograph a label, the image is uploaded to private storage only so we can read the ingredient list off it.
- As soon as we’ve read the label successfully, the photo is deleted. We keep the extracted text of the ingredient list — never the photo itself.
- If we couldn’t read a photo, we hold it for up to seven days so we can figure out what went wrong, then a daily job deletes it.
- Pasting an ingredient list as text never touches storage at all.
TODO(founder) — Turn the mechanics above into final, legally reviewed privacy copy, and add anything counsel requires (data-controller details, retention specifics, user rights).
Accounts and saved scans
TODO(founder) — Explain magic-link sign-in, what a saved scan stores, and how to delete an account and its data.
Cookies and analytics
TODO(founder) — Cover the anonymous session cookie used for rate limiting, and any product analytics (Vercel Analytics only, no third-party SDKs).
Where barcode data comes from
When you scan a barcode we don’t already know, we look it up in Open Beauty Facts, a free, community-maintained product database, to fetch the ingredient list and product name. That data is made available under the Open Database Licence (ODbL). We send the barcode number to their public API; we don’t send them anything about you.
Contact
TODO(founder) — How to reach us with a privacy question or request.