Privacy
Last updated 11 August 2026
LabelRay scans food barcodes and explains what is on the label using open data. This page describes what the app actually stores and sends, in the same words the code uses. It is short because the app collects little.
Without an account, nothing on this page is collected. Scanning, scores, history and the allergen profile all work on the device alone. Signing in is optional and exists for two things: keeping your history when you change phones, and contributing product data.
What is collected when you sign in
| Data | Where it comes from | Why |
|---|---|---|
| Email address | The identity token from Apple or Google. If you use Apple's "Hide My Email", we only ever see the relay address. | Identifies the account. |
| Name | The same token, once, at first authorisation, and only if you choose to share it. | Nothing but display; the app works if it is absent. |
| Account identifier | Issued by our server. | What history and contributions hang from. |
| Scan history | The products you open. | Synchronised so it survives a new phone. |
| Achievements and allergen profile | Your use of the app and your own settings. | Carried with the account across devices. |
| Photographs of packaging | Only the ones you take for a contribution. | Text extraction and moderation. |
What is not collected
- Location. Not from the device, and not from photographs: GPS and all other EXIF metadata are stripped on the server before an image is stored, and the original file is deleted immediately after.
- Search history. Name searches reach our server, but the cache is keyed by the query and language and shared by everyone. Nothing is written against a person.
- Contacts, advertising identifiers, diagnostics. There is no advertising SDK and no analytics SDK in the app.
- Tracking of any kind. Nothing is shared with data brokers, and nothing is used to follow you across other apps or websites.
Who else sees it
- Apple and Google — sign-in only. They tell us who you are; we tell them nothing about what you scan.
- OpenAI — reads the text on packaging photographs you submit. Storage is switched off for these requests, and neither the images nor the full response are written to our logs.
- Open Food Facts — the open database the product facts come from, and where approved contributions are sent back. See below.
- OVH — the server is a single machine in France. The database is not reachable from the internet.
Server logs record request identifiers and timings, not personal data. Barcodes appear in request URLs; they identify a product, not a person.
Contributions are published, and that is not reversible
Nothing you submit reaches Open Food Facts until a moderator approves it. Until then it is a private draft: the photographs are visible only to you and to a moderator, and they count for nothing — no score, no allergen, no product card changes because of them. If the submission is rejected, or you never finish it, the photographs are deleted.
One thing does leave your phone before that, and it is not publication: the photographs are sent to OpenAI to read the text off them, right after you upload. Storage is switched off for those requests, and neither the images nor the full response are written to our logs.
Once a moderator approves a submission, the facts and the front photograph are published to Open Food Facts under an open licence — product data under the ODbL, the image under CC-BY-SA 4.0. Open data is copied, mirrored and re-published by others, so we cannot promise to retract it afterwards. The app says this before your first upload, and it is the one thing on this page worth reading twice.
Only the front photograph is published. The pictures of the ingredient list and the
nutrition table stay private and are kept as evidence for the moderator. What goes out is the
product: its name, ingredients, nutrition values and the picture of the packaging. Not your
name, not your email, not your account. The public export at
/v1/catalog/export/products.jsonl.gz contains no personal data at all.
How long things are kept
- Photographs of a submission that was never finished, failed, or was rejected are deleted after 7 days.
- A submission waiting for moderation keeps its photographs until it is decided. There is no deadline on that, which is a reason we keep the queue short.
- Photographs that were approved and published are kept indefinitely: an approved revision links to the image, and revisions do not change.
- Everything else lives as long as the account does.
Deleting your account
Settings → Account → Delete account, inside the app. It removes your email, name, history, settings, session and any submissions still awaiting moderation, along with their photographs. Contributions that were already accepted are anonymised rather than deleted — they are part of a public database by then, and the paragraph above applies.
Children
LabelRay is not directed at children and does not knowingly collect anything from them.
Changes
If what the app collects changes, this page changes with it, and the date at the top moves. There is no mailing list to notify, because we do not keep one.
Contact
Questions, corrections, or a request about your data: contact@labelray.app.