Privacy policy
Last updated: September 3, 2026
C.L.E.A.N.® Food Certified (“Company,” “we,” “us,” or “our”) operates C.L.E.A.N.® Standard, an ingredient-label checking service (the “App”). This policy describes the information the App processes when you use it, what it stores, for how long, and what it never collects. It is built to need as little of your data as possible: no accounts, no cookies, no third-party trackers, and nothing sent anywhere except our own servers.
Please read this policy carefully. If you do not agree with these practices, your choice is not to use the App. By accessing or using the App, you agree to this Privacy Policy.
1. Applicability & guest use
Every use of the App today is a guest session: there is no account to create and no sign-in. We never ask for your name, email address, or any other personal identifier. The only identifier involved is an anonymous browser id described in section 2, which identifies an install, never a person. If accounts are ever introduced, this policy will be updated before they launch.
2. Information we process and what we keep
A. A normal scan stores nothing you scanned
- Pasted or photographed ingredient text is sent to our server, analyzed, and discarded. The text is not written to any database, file, or log on our side. Photos sent for text extraction are used only to read the label text and are not retained once the request finishes.
- Barcode lookups put the barcode number (GTIN) in the request URL. Standard server access logs (timestamp, IP address, request path, status code) therefore record scanned GTINs for operational and security reasons; they are kept briefly and rotated. A GTIN identifies the product, not you.
- Camera barcode scanning happens entirely inside your browser: camera frames are decoded on your device and are never uploaded. The App only receives the barcode number that was read.
B. An anonymous browser id
- A random value like
web-…, kept in your browser’s localStorage, rides along on requests so our rate limiting can tell users behind one shared network apart, and so feedback can be grouped. The server keeps it in a scan tally (a small count of scan operations per install). It is not linked to your name, email, or anything else, because we never ask for those.
C. Things you choose to send us
- Feedback reports (“Report this scan”): your note, the scan’s label text or barcode, the verdict, the dictionary version, the label photo when the scan came from a photo, and the anonymous browser id. Nothing leaves the normal flow unless you press Send.
- Product requests (“Add this product”): the product name, brand, barcode, an optional label photo, and the anonymous browser id. A reviewer checks every request before a product appears in the catalog.
- Certification votes (“want this to be C.L.E.A.N. certified”): the product’s barcode number and the anonymous browser id (so one install counts once), plus the row bookkeeping every database record has (an internal id and a timestamp). No note, no photo, no location, nothing else.
D. What we never collect
- No location data of any kind: no GPS, no derived location from your IP address. The App never asks for a location permission.
- No advertising identifiers, device fingerprints, or contact lists.
- No analytics scripts, ad pixels, or third-party trackers. The page’s security policy blocks third-party requests outright, so none can load.
3. Cookies and local storage
The App sets no cookies. It uses your browser’s local storage only, which stays on your device and is never uploaded:
- Your recent-scans list (last 5 scans). The Clear button removes it.
- The anonymous browser id and your display preferences (locale, “hide acceptable rows”). Clearing site data for this origin removes everything at once.
- An offline cache of your recent barcode verdicts (service worker), so a repeat lookup works without a connection.
4. How we use this information
- To provide the App’s core services: the barcode scanner, product search, and ingredient evaluation;
- To review product requests and act on feedback reports;
- To show the certification-interest tally on a product and pass that aggregate demand to the certification program;
- To improve database accuracy and product matching;
- To keep the service running fairly (rate limiting) and prevent abuse;
- To fix defects, using technical error reports that contain the type of error and the place in our code where it happened, never label text, photos, or personal data; and
- To comply with legal obligations.
5. Sharing and disclosure of information
We do not sell, rent, trade, or share your information with anyone. Everything described above is processed and stored on our own servers; we use no third-party analytics, advertising, or data-processing partners. The only exceptions are:
- Aggregate, non-identifying figures: the certification-interest count shown on a product is public by design, and we may share aggregate statistics of that kind (such as how many devices want a product certified) with the certification program. Such figures contain no personal information.
- Legal requirements: if required to do so by law, court order, subpoena, or government regulation.
6. Data retention & security
- Feedback reports and product requests: We keep reports for 30 days, then delete them. Our security backups can hold a copy for up to 14 further days before they, too, are erased. The 30-day deletion is enforced by a scheduled purge job on our servers; it runs on a timer, not on good intentions. A product that a reviewer approves becomes ordinary catalog data (name, brand, barcode) and is kept like any other product.
- Certification votes: Votes are kept while the tally is useful to the certification program; there is no automatic expiry. Because a vote stores nothing that identifies you, we cannot verify which vote is yours afterwards, so selective removal is not offered. Treat tapping as permanent.
- Server logs and error reports are kept briefly for operations and security, then rotated. Error reports stay on our own infrastructure.
- Security measures: all traffic between your device and our servers is encrypted with TLS, access to our servers is restricted to the operating team, and backups are stored on our own infrastructure under the retention limits above.
7. Your rights & choices
Depending on your jurisdiction (including California, Colorado, EU/UK GDPR, and other applicable regions), you may have rights of access, correction, and deletion. Because the App holds so little, here is what each means in practice:
- Feedback reports and product requests: you may ask us to delete a report you sent before its 30 days are up. Tell us roughly when you sent it and what it was about, and include the build number from the about page footer if you can.
- Certification votes: a vote is not linked to you, so we cannot locate or remove yours (see section 6).
- Everything on your device (recent scans, the anonymous id, preferences, the offline cache) is under your control: use Clear or clear site data in your browser.
- Camera access is requested only when you start a camera scan and can be revoked at any time in your browser settings.
- Do Not Track / Global Privacy Control: we honor these signals in the simplest way possible: the App performs no tracking to opt out of.
To exercise any of these rights, please contact us at privacy@cleanfoodcertified.org.
8. Children’s privacy
Our App is directed to a general audience and is not intended for children under 13 years of age (or 16 in certain jurisdictions). We do not knowingly collect personal information from children. If we learn that we have inadvertently collected personal data from a child without verified parental consent, we will take immediate steps to delete that information.
9. Changes to this privacy policy
We may update this Privacy Policy when the App changes. Any changes will be effective upon posting the updated policy on the App with a revised “Last Updated” date, and we update this page before a new kind of data processing goes live, not after. Your continued use of the App following the posting of changes constitutes your acceptance of such changes.
10. Contact information
If you have questions, comments, or concerns regarding this Privacy Policy or our data practices, please contact us at:
C.L.E.A.N.® Food Certified
Attn: Privacy Officer
Email: privacy@cleanfoodcertified.org
See also the terms of use, the allergen & medical advice disclaimer, and the DMCA policy.