LabelproofPrivacy Policy
The short version
- Your health information stays on your phone. Allergy profiles, scan history, your reaction diary, emergency cards and medications are stored only on your device. We never receive them.
- No account. You don't sign up, and we don't know who you are.
- No ads, no analytics, no tracking. We don't sell or share data, and we don't track you across apps or websites.
- Photos are read on the phone. Label and menu photos are processed by on-device text recognition and are never uploaded.
- To look things up, the app sends us a few non-personal details, such as a barcode number. The rest of this page lists exactly what.
This policy explains how the Labelproof app for iPhone, Apple Watch and Android (“Labelproof”, “we”, “us”) handles information. If you have a question, email proconverted@gmail.com.
1. Information that stays on your device
Everything you enter or create in Labelproof is stored in a private database on your device:
- household profiles: names you give them, colours, the allergens and ingredients each person avoids, and how severe each one is;
- scan history, saved products, notes and your shopping list;
- your reaction diary: dates, symptoms, severity, suspected foods, notes and any photos you attach;
- emergency cards (contacts, blood type, conditions, doctor, action plan) and medications with their expiry dates;
- settings such as your chef-card language.
We have no copy of this information and cannot read, restore or delete it for you. It is included in your device's own backups (for example iCloud or Google backups) according to your device settings.
Camera and photos. The camera is used to read barcodes, ingredient labels and menus. Photos you take or choose are read on the device by Apple's Vision framework (iPhone) or Google's on-device ML Kit text recognition (Android). The images are not uploaded. A photo is kept only if you attach it to a diary entry.
Apple Watch and widgets. If you use the Apple Watch app or home-screen widgets, the app copies a summary (for example your emergency cards and recent verdicts) to your own watch and widgets. This uses Apple's and Google's on-device mechanisms and does not pass through our servers.
Reminders. Medication-expiry reminders are scheduled locally on your device.
2. Information that leaves your device
Some features need the internet. When they do, the app sends only what the feature needs, and none of it identifies you or includes your profiles:
| Feature | What is sent | Sent to |
|---|---|---|
| Barcode lookup | The barcode number | Our server, which gets the product's ingredients from Open Food Facts and caches the product data |
| Recall alerts | Nothing about you. The app downloads the public list of food recalls and checks it against your profiles on the phone | Our server |
| Safer alternatives | The scanned product's category and country of sale | Our server, which searches Open Food Facts |
| Explain an ingredient (only when you tap it) | The single ingredient word you picked, such as “lecithin” | Our server and our AI provider, DeepSeek |
| Menu “usual ingredients” (only when you tap it) | The dish name and description as printed on the menu | Our server and our AI provider, DeepSeek |
| Subscriptions | Purchase and receipt details, an anonymous app user ID, and basic device and app information | Apple or Google, and RevenueCat |
AI features. Ingredient explanations and dish guesses are produced by DeepSeek, which processes requests in the People's Republic of China. Only the word or menu text shown above is sent, never your allergies or anything about you. Answers are cached on our server so that the same question is not sent twice.
Payments. Apple (App Store) or Google (Google Play) processes payments. We never see your card or billing details. We use RevenueCat to confirm whether your subscription or lifetime purchase is active. RevenueCat assigns a random, anonymous ID that is not linked to your name or email.
Server logs. Like any web server, ours records each request's IP address, time and requested address (which can include a barcode number). These logs are used only for security, preventing abuse and fixing problems, are not combined with other data, and are deleted on a rolling basis. IP addresses are also held briefly in memory to rate-limit requests.
3. What you choose to share
When you export or share something, such as a diary PDF for your allergist, an emergency card image or PDF, a chef card or your shopping list, it goes to the app or person you pick in your device's share sheet. From then on, the recipient's privacy practices apply.
4. What we don't do
- We don't use advertising, analytics or crash-reporting SDKs.
- We don't sell, rent or share personal information, and we don't “share” it for cross-context behavioural advertising.
- We don't track you across other companies' apps or websites.
- We don't use your information to train AI models, and we don't send your health information to any AI service.
5. Service providers
- Contabo hosts our server.
- Open Food Facts supplies product data (privacy policy).
- DeepSeek powers the optional AI explanations (privacy policy).
- RevenueCat manages purchase status (privacy policy).
- Apple and Google process purchases and provide on-device text recognition.
Our recall alerts use public notices from the U.S. FDA, the U.S. Department of Agriculture (FSIS) and the UK Food Standards Agency. Our server fetches these. Your device does not contact those agencies.
6. How long we keep things
- Data on your device is kept until you delete it in the app or delete the app.
- Our server's caches hold product data, recall notices and AI answers. They contain no personal information and are refreshed or removed over time (for example, AI answers after 90 days).
- Server logs are kept only as long as they are needed for security and troubleshooting.
7. Your choices and rights
You control your data in the app. You can edit or delete any profile, scan, diary entry, card or medication, and deleting the app removes everything stored by it. You can skip the AI features and never send anything to DeepSeek. You can turn off camera, photo and notification access in your device settings.
Depending on where you live (for example, the EU, UK or California), you may have rights to access, correct, delete or object to the processing of personal information. We hold almost nothing that can identify you, but if you'd like to make a request or have a question, email proconverted@gmail.com. We'll answer within 30 days. You may also complain to your local data-protection authority.
8. Health information
Allergy and reaction information is sensitive health information. That is why Labelproof is designed so that we never receive it. It is processed only on your device, and it leaves your device only when you share or export it yourself.
9. Children
Labelproof is meant to be used by adults, including parents managing a child's allergies. A parent may add a profile for a child, and that profile stays on the parent's device like every other profile. We don't knowingly collect personal information from children. If you believe a child has sent us personal information, contact us and we will delete it.
10. Security
Connections between the app and our server are encrypted with HTTPS. Data on your device is protected by your device's own security, such as your passcode and device encryption, so keep your device locked.
11. International transfers
Our server and service providers may be located outside your country, including in the European Union, the United States and, for the optional AI features, China. The information sent to them is limited to the non-personal details described in section 2.
12. Changes
If we change this policy, we will update it on this page and change the effective date. If a change affects how your information is handled in a significant way, we'll also tell you in the app.
13. Contact
Email proconverted@gmail.com.