Privacy policy
This policy describes the Knowsie app for iPhone, version 1.2.0, including the updates we deliver inside the app. Until a new version of the app renames it, your phone may still show its earlier name, Malvi.
Knowsie (“we”) is an app that scans packaged food, reads the ingredients and rates them. This policy explains what we collect, why, who processes it, and the choices you have. We don’t show ads, we don’t track you across other companies’ apps or websites, and we don’t sell your data.
Knowsie is run by Malwina Stachurska, who is responsible for your data (the “data controller”). For anything about your data, write to privacy@knowsie.app.
What we collect
You can use Knowsie without an account. We collect only what the features you use need.
| What | When | Where it’s kept |
|---|---|---|
| Email address and password | You create an account with email | Our sign-in provider. Your password is stored only in scrambled (hashed) form, so we never see it. We don’t send a confirmation email or any marketing email. If you ask to reset your password, we email you a link to set a new one, from our mailbox. |
| Your email address, name, profile picture link and Google’s ID for you | You sign in with Google | Our sign-in provider. Google passes these on automatically, and they’re saved with your account. |
| Your email address (or Apple’s private relay address, if you hide yours) and Apple’s ID for you | You sign in with Apple | Our sign-in provider. Apple may offer to share your name, but we don’t keep it. We may also keep a token from Apple that lets us ask Apple to end Knowsie’s access when you delete your account. It’s deleted with your account. |
| When you created your account and last signed in, and the IP address and device type of each sign-in | You’re signed in | Our sign-in provider, until you sign out on that device or delete your account. Deleting the app without signing out doesn’t end a sign-in. |
| Your preferences: allergies, allergens you type in, diets (vegan, vegetarian, halal, kosher), nutrition goals and watch list, and whether you finished or skipped the first-run setup | You set them when you first open the app, or later in Profile → Preferences | On your phone, whether or not you’re signed in. When you’re signed in, also in your account. Preferences you set without an account are added to your account when you sign in. |
| Scan history: barcode, product name, score and time | You scan a barcode while signed in and the app finds and scores the product. Opening a product from History updates its entry. Opening one from Search doesn’t add anything. | Your account. One entry per product, with the latest time. The saved score includes the effect of your goals. |
| A product you send in: photos (front, ingredients, nutrition label and any extras), its barcode, and the name, brand, ingredients, nutrition values, serving size and organic seal | You add a missing product, add a missing ingredients list, or update a product whose package looks different | Our database and private photo storage, reviewed by our team. If you’re signed in, it’s linked to your account. If not, it isn’t linked to anyone. |
| A problem report: your note, an optional photo and the product’s barcode | You tap “Report a problem with this data” on a product | Same as a product you send in |
| Feedback: the type you pick (idea, problem, name or logo idea, or other), your message, the app version, and your phone’s operating system and its version | You use Profile → Send feedback | Our database, read by our team. Linked to your account if you’re signed in. |
| Emails you send us: your email address, your message and anything you attach | You write to one of our email addresses | Our mailbox, hosted by Google Workspace |
| Barcodes you scan and words you search for | You scan or search | Sent to Open Food Facts and to our database to find the product. They aren’t saved to your account, except as scan history (above). |
| Names of ingredients we don’t recognize yet, with the product’s barcode | A product you look at contains an ingredient we don’t know | Our database, not linked to you. We use it to grow our ingredient list. |
| Crash and error reports, and a short stability report each time you use the app | Every time you use the app, and when something goes wrong | Our crash reporting provider (Sentry). See “Who processes it”. |
| Subscription details: an anonymous ID, or your account’s random ID, and your purchases once there’s something to buy | Each time you open the app | Our subscription provider (RevenueCat). Knowsie doesn’t sell anything yet. |
| Technical details: IP address, device model, operating system and app version, language, and random installation IDs | Whenever the app talks to one of our service providers | Each provider, as described under “Who processes it” |
We don’t collect your location or contacts, and we don’t read your photo library. The camera is used only to read barcodes (that happens on your phone) and to take the product photos you choose to send. Please keep people and personal details out of those photos. The app doesn’t send push notifications and doesn’t ask to.
What stays on your phone
- Your preferences, and how far you’ve got in the app tour.
- Your sign-in, so you stay signed in until you sign out. It includes your email address, your account’s random ID and, with Google sign-in, your name and profile picture link.
- Your light or dark mode choice.
- A count of your first 5 scored scans. It’s used once, to ask Apple to show its rating window (only if you installed Knowsie from the App Store). Apple handles any rating you give, and nothing about it is sent to us.
- A copy of our ingredient database, and the photos you take in the app, in the app’s temporary storage until iOS clears it.
- Random IDs that our crash reporting, update and subscription providers keep for this installation.
How we use it
- To score products. The base score is the same for everyone. If you choose nutrition goals, they can move your score up or down by up to 15 points. Your allergies, typed allergens and diets add warnings, and the alternatives we suggest leave out products whose information conflicts with them. Your watch list adds alerts. None of these four change the score.
- To keep your preferences and scan history in your account when you’re signed in, so they’re there on your other devices.
- To read the label photos you take and fill in the product’s details for you to check.
- To review products and reports you send in, and add them, or the corrections, to our product database, where every user can see them. A front photo you send, or a photo from a problem report, may become the product’s picture.
- To read your feedback and your emails, and answer them.
- To find and fix bugs and keep the app stable, using crash, error and stability reports.
- To run your account and, later, your subscription.
- To grow our ingredient list from the ingredient names we don’t recognize.
We don’t use your data for advertising, and we don’t sell it.
Who processes it
Knowsie relies on these services. Each receives only what its job needs.
| Service | What it does for Knowsie | What it receives |
|---|---|---|
| Supabase | Hosts our database, accounts, photo storage and server functions. Its servers are in the United States (Oregon). | Everything we keep on our servers, listed under “What we collect”, except crash reports, subscription details, update checks and emails. Also the IP address and device type of each sign-in, and short-lived logs of the app’s requests (kept for 1 day on our current plan). These logs include IP addresses and the barcodes and search words looked up, and can show which account made a request. |
| Anthropic (Claude) | Reads your label photos to fill in the name, brand, ingredients, nutrition values and organic seal. During our review, it also suggests a product category. | The front, ingredients and nutrition photos you’ve taken. They’re sent as soon as you add an ingredients or nutrition photo, before you tap Submit, and even if you then cancel. For a category suggestion, only a product’s name, brand and ingredients. Requests go through our server, so Anthropic doesn’t get your account, IP address or device details. Anthropic deletes this data within 30 days, unless the law requires it to keep it longer or its safety systems flag it as breaking Anthropic’s usage policy. By default, Anthropic doesn’t use this data to train its models. |
| Open Food Facts | The public, collaborative product database the app looks products up in. It’s based in France. | The barcodes you scan and the words you search for. When we look for alternatives: a product’s category and country, or words from its name and brand if it has no category. Like any website, it also sees your IP address, including when product pictures load from its servers. We never send it your account, preferences or photos. |
| Sentry | Crash and error reports | A short stability report every time you use the app. When something goes wrong: device details (such as model, operating system, memory, language and time zone settings), app version and update, a random installation ID, and the app’s recent activity before the problem. That activity includes which buttons you tapped (by their names in our code) and the web addresses the app called, with barcodes, search words, account IDs and email addresses removed before the report leaves your phone. Never your name or email. Your IP address isn’t stored with the reports. Sentry keeps them for 30 days, in the United States. |
| RevenueCat | Will manage subscriptions. It already runs on iPhone from version 1.2.0, before anyone can buy anything. | An anonymous ID, or your account’s random ID when you’re signed in. Your device, operating system and app version, language, App Store country and IP address. Once subscriptions start, the purchases Apple confirms. Never your card details. Its servers are in the United States. |
| Expo (EAS Update) | Delivers app updates | Each time you open or return to the app, it checks for an update. The check includes the app version and update, your phone’s platform, a random installation ID and your IP address. It doesn’t include your account or anything you’ve entered in the app. |
| Apple | Sign in with Apple, if you choose it. App Store payments once subscriptions start, and the rating window. | What you agree to share with Apple. Apple handles payments, so we never see your card details. |
| Sign in with Google, if you choose it. Google Workspace also hosts our email. | What you agree to share with Google, the emails you send us and our replies, and the password reset emails we send |
Product information from Open Food Facts is available under the Open Database License (ODbL).
Ingredient pages link to research and official sources. If you open one, that website sees your visit, and its own privacy policy applies.
Our website, knowsie.app, is hosted by GitHub Pages. GitHub logs visitors’ IP addresses for security. The website serves its own fonts, and it uses no cookies and no analytics. Its password reset page, which opens from the link in a reset email, loads Supabase’s sign-in code from jsDelivr, a public service that delivers code to websites, so jsDelivr sees your IP address when you open that page. The new password you type there goes straight to Supabase, our sign-in provider, over an encrypted connection.
Health information
Allergies, typed allergens and nutrition goals can count as health information. Halal and kosher diets can reveal religious beliefs, and vegan or vegetarian diets can reveal other beliefs. We use them only to personalize the app: your warnings, the effect of your goals on your scores, and the alternatives we suggest. We never use them for advertising, and we never sell them.
They’re optional. You can choose them when you first open the app or later. You can leave them empty, change them or clear them at any time in Profile → Preferences. If you’re not signed in, they stay on your phone. If you’re signed in, they’re also saved in your account.
How long we keep it
- Account, preferences and scan history: until you delete your account. Deleting it removes all three from our servers right away. Our current database plan doesn’t include backups, so we don’t keep a backup copy.
- Sign-in records (IP address and device type): until you sign out on that device or delete your account. Deleting the app without signing out doesn’t end them.
- Preferences on your phone: if you’re not signed in, until you clear them or delete the app. If you’re signed in, until you sign out or delete your account in the app. If your sign-in ends some other way, for example because you deleted your account on another phone, they stay on that phone until you sign out there or delete the app.
- Products and problem reports you send in, with their photos: kept while we review them. Approved ones become part of our product database and stay there. Ones we reject are deleted, with their photos, 90 days after we reject them.
- Feedback: deleted 12 months after you send it.
- Emails you send us: kept in our mailbox while we need them to help you. Ask us and we’ll delete yours.
- Password reset emails: our mailbox keeps a copy of each one we send until we delete it. Ask us and we’ll delete yours. The link in it works only once, for a limited time.
- Server request logs: 1 day on our current plan.
- Crash and error reports: 30 days.
- Subscription records: kept by RevenueCat until we delete them. Write to us and we’ll have yours deleted.
- Update checks: handled by Expo under its own privacy policy. They don’t include your account.
- Label photos read by Anthropic: deleted by Anthropic within 30 days, except in the cases described under “Who processes it”.
Your choices and rights
- Use Knowsie without an account. Your preferences then stay on your phone. The barcodes, searches, photos, reports and feedback you send still leave your phone, as described above.
- Change or clear your preferences at any time in Profile → Preferences. Clearing them, or deleting your account, withdraws your consent to us keeping them.
- Sign out in Profile. That also clears your preferences from that phone.
- Delete your account in Profile → Account settings → Delete account. It takes effect right away. Products, reports and feedback you sent stay (until the times listed above), but the link to your account is removed. A few things don’t go away on their own yet. Write to privacy@knowsie.app and we’ll remove them:
- Our photo storage still notes which account uploaded each photo.
- RevenueCat keeps its record of your account’s random ID.
- Copies of your preferences on your other phones stay until you sign out there or delete the app.
- If you signed in with Apple, check that Knowsie no longer has access: on your iPhone, open Settings, tap your name, then tap Sign in with Apple (on some versions of iOS, it’s under Sign-In & Security). If Knowsie, or Malvi, its earlier name, is still listed, choose it and tap Delete. You can also check at account.apple.com, under Sign-In & Security → Sign in with Apple.
- There’s no way yet to delete single scan history entries in the app. Write to us and we’ll do it.
- Ask us to see, correct, export or delete your data, or object to how we use it, by writing to privacy@knowsie.app. Depending on where you live (for example the EU, the UK or California), these may be legal rights. We’ll answer within 30 days. In the EU and the UK, you can also complain to your data protection authority (in Poland, that’s the UODO).
- We don’t sell your personal information, and we don’t share it for advertising, in the sense California law uses those words.
- If you’ve forgotten your password, tap “Forgot password?” on the app’s log-in screen, and we’ll email you a link to set a new one. If that doesn’t work, or you can’t sign in, write to support@knowsie.app from the email address you signed up with, and we’ll help.
Children, security and international transfers
Children. Knowsie isn’t meant for children under 16, and we don’t knowingly collect their data. If you think a child has given us data, write to us and we’ll delete it.
Security. Data travels encrypted between the app and our services. On your phone, your sign-in is kept in the app’s own storage, which other apps can’t read. Apart from the AI service that reads label photos (see “Who processes it”), only our team can open the photos you send before they’re approved. If we approve a product and use one of its photos as the product’s picture, that photo becomes public: anyone with its web address can see it. No system is completely secure, so we can’t guarantee it.
International transfers. Supabase, RevenueCat and Sentry keep the data they receive from Knowsie in the United States. Anthropic, Expo, Apple, Google and GitHub (which hosts our website) are US companies, and may process data there too. Open Food Facts is in France.
Changes and contact
If we change this policy, we’ll update the date at the top. For important changes, we’ll also tell you in the app first.
Knowsie is run by Malwina Stachurska.