Privacy Policy
Effective Date: September 24, 2026
The short version: GlutenOrNot is designed with privacy first. We don't collect personal data, don't require accounts, and don't store your photos. Your scan history stays on your device.
Introduction
GlutenOrNot ("we," "our," or "the app") is a free tool that helps people with celiac disease check ingredient labels for gluten. This Privacy Policy explains how we handle your information when you use our web app at glutenornot.com or our iOS mobile app.
Information We Collect
Information We Do NOT Collect
We want to be clear about what we don't collect:
- No user accounts, emails, or personal identifiers
- No device IDs or advertising identifiers
- No precise location — we never access GPS; anonymous analytics include only an approximate region derived from your IP address (see below)
- No advertising or cross-site tracking of any kind
- No record of what you scanned on our servers — ingredient text and images are discarded after processing. The exception is barcode numbers: one that no product database recognizes is written to our server logs so we can see which products are missing, and any barcode can appear in our hosting provider's logs of the lookups we make
- No images are stored — photos are processed and immediately discarded
Anonymous Analytics
To understand whether the app is working — how many scans happen, and how often lookups fail — we record one small, anonymous event per scan. Each event contains: the verdict (safe / caution / unsafe), the scan type (photo or barcode), whether the result was a label or a menu, whether the scan succeeded and why it failed if it didn't, the analysis confidence, for a caution, which kind of reason it gave (for example oats or a may-contain warning), for a barcode scan which product database answered, whether it had ingredient information, and which analysis engine produced the verdict (and, when the fast first check described below ran, what it did and how long it took), the app platform (iOS or web), the app version, which AI model produced the analysis, the detected language, technical quality measurements (the photo's file size, a count of how many characters of text were readable, whether that text or the database record carried a gluten-free claim, whether a safety check held back a “safe” verdict because the ingredient list looked cut off, and how long each step took — never the text itself), and an approximate region (city level, derived from your IP address — the IP itself is never stored, only a one-way hash used to approximate unique-device counts). These events contain no ingredient text, no product names, no photos, and no personal identifiers, and they are not linked to any account or identity. They are processed by PostHog (see Third-Party Services below).
When a barcode lookup comes up empty — the product isn't in our databases, or the database record has no ingredient information — the iOS app offers to photograph the ingredient label instead. To learn whether that offer helps, we record a few additional small, anonymous events for that one attempt: which step you reached (the offer was shown, a photo was started, a result was shown, or you left), why the lookup came up empty, whether a photo came from the camera or your photo library, and, if a result was shown, whether it was a label or a menu and its verdict and confidence. These steps are tied together by a temporary random identifier that exists only for that one attempt: it is created on your device, is not derived from the barcode or your device, is not stored with your recent scans, and is never reused. As with every other event, they contain no barcode, no product name, no ingredient text, and no photo.
When the fast first check on a barcode scan (see TypeSafe under Third-Party Services) gives a clear answer, Claude still analyzes the same product so we can compare the two. We record one more small, anonymous event for that comparison: the two verdicts, the kind of reason Claude gave for a caution, which of the two you were shown, and whether they agreed, with the same platform, app-version and approximate-region fields as every other event. Like the others, it contains no barcode, no product name and no ingredient text.
When the app hands iOS a request to show the App Store rating sheet, or you tap the link to write a review, we record a small anonymous event saying which of those two things happened, carrying the same platform, app-version and approximate-region fields as every other event and nothing more. The rating or review itself goes to Apple's App Store, not to us; our analytics never contain it, and this event is not linked to any rating or review you leave there.
Information Stored Locally on Your Device
The app stores a small amount of data on your device: a simple scan counter (how many labels you've scanned), a flag remembering whether we've asked you to rate the app, and, in the iOS app, your recent scan results (the verdict and analysis for your last 50 scans, so you can look them up again — never the photos themselves). This data:
- Never leaves your device
- Is not linked to any personal information
- Can be cleared in the app (Recents → Clear) or by uninstalling the app or clearing app data
Information Processed (But Not Stored)
When you scan an ingredient label, your photo is temporarily processed to analyze the ingredients. Here's how it works:
- Your photo is sent to our server over an encrypted connection (HTTPS)
- We use Google Cloud Vision API to extract text from the image
- The extracted text (not the image) is sent to Anthropic's Claude API for analysis
- You receive a verdict (safe, caution, or unsafe)
- The image and text are not stored — they are discarded after processing
When you scan a barcode in the iOS app:
- The barcode number is sent to our server over an encrypted connection (HTTPS)
- We look it up in the product databases listed below
- The product's name and ingredient information from the database are sent to Anthropic's Claude API for analysis
- For a product found in Open Food Facts, the ingredient text alone — not the product name or the barcode — may also be sent to TypeSafe's Jev model for a fast first check. When it gives a clear answer, you may see that answer right away, while Claude's analysis still runs to check it
- You receive a verdict (safe, caution, or unsafe)
- Nothing is kept, apart from the server logs described above
Third-Party Services
We use the following third-party services to provide the app's functionality:
Google Cloud Vision API
We use Google Cloud Vision to perform optical character recognition (OCR) on your photos. Google processes the image to extract text. We do not send any personal identifiers to Google. For more information, see Google Cloud Vision's data usage policy.
Product Databases (Barcode Scans)
When you scan a barcode, we look the barcode number up in Open Food Facts, and if it isn't there, in other product databases such as USDA FoodData Central and UPCitemdb. These services receive the barcode number from our server, never any personal information.
Anthropic Claude API
We use Anthropic's Claude to analyze extracted ingredient text. Only ingredient text is sent to Anthropic — the text read from your photo, or, for a barcode scan, the product's name and ingredient information from the database — never the original image or any personal information. For more information, see Anthropic's privacy policy.
TypeSafe (Jev)
For barcode scans of products found in Open Food Facts, we may use TypeSafe's Jev model for a fast first check of the ingredient list. Only the ingredient text from the product database is sent to TypeSafe, from our server — never the product name, the barcode, a photo, your IP address, or any personal information. For more information, see TypeSafe's privacy policy.
PostHog (Analytics)
We use PostHog to process the anonymous analytics events described above — the per-scan event (verdict, scan type, outcome, confidence, analysis engine, platform, detected language, technical quality measurements, approximate region), the comparison event recorded when the fast first check on a barcode scan gives an answer (the two verdicts, the kind of reason Claude gave for a caution, which one you were shown, whether they agreed), the few per-attempt events recorded when a barcode lookup comes up empty (step reached, reason, temporary random identifier), and the event recorded when the app hands iOS a rating-sheet request or you tap the write-a-review link (which of the two happened, nothing more) — none of which contain ingredient text, product names, photos, or personal identifiers. For more information, see PostHog's privacy policy.
Sentry (Mobile App Only)
Our iOS app uses Sentry for crash reporting. If the app hits an error, technical details are sent to Sentry so we can fix the bug — device model, OS version, the error message, and a screenshot of the app at the moment of the error. For more information, see Sentry's privacy policy.
Expo (Mobile App Only)
Our iOS app is built with Expo, which provides standard app update functionality. Expo may collect basic crash reports and app update information. For more information, see Expo's privacy policy.
Vercel
Our web app, and the server both apps use to analyze scans, are hosted on Vercel. Vercel may collect basic server logs including IP addresses for security and performance purposes. For more information, see Vercel's privacy policy.
Data Retention
We do not retain your data, apart from the server logs and crash reports described above. Images are processed in real-time and immediately discarded. We have no database of user scans or personal information.
On your device, the only data that persists is what's listed under Information Stored Locally on Your Device above, and none of it is ever transmitted to us. On our side, the only records are the anonymous analytics events, the server logs, and the crash reports described above.
Data Security
All data transmitted between your device and our servers is encrypted using HTTPS. We do not store sensitive data, which minimizes security risks.
Children's Privacy
GlutenOrNot is not directed at children under 13 years of age. We do not knowingly collect personal information from children. Since we don't collect personal information from any users, this naturally extends to children as well.
Your Rights
Since we don't collect or store personal data, there is no personal information for us to access, correct, or delete. Your scan counter and recent scan results are stored locally on your device and can be cleared in the app (Recents → Clear) or by uninstalling the app or clearing app data.
Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Effective Date" at the top of this page. We encourage you to review this policy periodically.
Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us at:
App Store Information
GlutenOrNot is available as a free app. We do not display advertisements or sell user data. The app is provided as-is to help the celiac community.