Clean Label Project

Privacy Policy

Effective date: 2026-08-26Last updated: 2026-08-26

1. Summary #

2. Who we are #

Clean Label Project Foundation ("Clean Label Project", "we", "us") is the controller of the personal data described here.

Clean Label Project Foundation
280 E. 1st Ave. #873
Broomfield, CO 80038-0873
United States

Contact: geo.ortiz@cleanlabelproject.org

3. What we collect #

3.1 Information you give us #

What Why Kept where
Email address To create and authenticate your account, and to contact you about your account Firebase Authentication and your user record
Password To authenticate you. Stored only by Firebase Authentication as a salted hash — we never see or store your plaintext password Firebase Authentication
First and last name To personalize your profile Your user record
Profile photo (optional) To display on your profile Cloud Storage
Favorites and custom lists To provide the feature Your private user subcollections

About your profile photo. Only your own account can read it. The App fetches it using your own credentials each time, and we do not store a shareable web address for it — so there is nothing in our records that would let anyone else open your photo, and it is not listed or searchable anywhere.

3.2 Information collected automatically #

Usage analytics — North America only. If your device is in the United States, Canada, or Mexico, we use Google Analytics for Firebase to understand how the App is used. Outside those countries we record none of the following. We record:

We filter search text for personal information before it is sent. If a search looks like it contains an email address or a long run of digits (a phone, card, or ID number), the entire event is discarded rather than recorded.

Analytics events are not linked to you. We never attach your user ID, email, or name to an analytics event. Analytics tells us that "someone searched for X" — it does not tell us that you did, and we cannot reconstruct that.

Collected by Google's SDKs on our behalf, whether or not our code asks for it: a resettable app-instance identifier, your device model, operating system version, app version, and language, a coarse country or region derived from your IP address, and session start and duration.

We collect no advertising identifier on either platform. On Android the analytics SDK would normally collect your device's advertising ID; we block that permission from the App, so it is never available to us. On iOS we do not collect the IDFA. We do not track you across apps or websites, which is why the App never shows you an App Tracking Transparency prompt.

Crash diagnostics. If the App crashes, Firebase Crashlytics records the error, a stack trace, and device state so we can fix it.

3.3 What we do not collect #

To be unambiguous, because the previous version of this policy was not:

Purpose Legal basis (GDPR/UK GDPR)
Creating and running your account Performance of a contract
Providing favorites, lists, search, and scanning Performance of a contract
Understanding usage to improve the App (North America only) Legitimate interests
Diagnosing crashes and bugs Legitimate interests
Security, abuse prevention, enforcing our Terms Legitimate interests
Complying with law Legal obligation

We only collect analytics in North America. If your device is in the United States, Canada, or Mexico, analytics is on by default and you can switch it off at any time under Profile → Settings → Share usage analytics. Anywhere else in the world we collect no analytics at all — the setting does not appear, because there is nothing to switch off. This means no analytics consent question arises for users in the European Economic Area or the United Kingdom, because we do not collect it from them in the first place.

We do not use your data for automated decision-making or profiling that has a legal or similarly significant effect on you.

5. Who we share it with #

We do not sell your personal information. We do not share it for advertising or cross-context behavioral advertising. We share it only as follows.

Google (Firebase) processes essentially all of it, as our service provider, for authentication, database and file storage, analytics, and crash reporting.

The Open Food Facts family of databases — Open Food Facts, Open Beauty Facts, Open Pet Food Facts, Open Products Facts. When you scan a barcode that isn't in our catalog, we send the barcode number to these services to look it up. We send no account information with it, though the request necessarily reveals your device's IP address to them. These are independent, community-run databases with their own privacy practices.

Websites you choose to open. Tapping a link opens it in your browser, and that site's own privacy policy then applies.

We may also disclose information if legally required, to protect our rights or someone's safety, or to a successor in a merger or acquisition — in which case we will give notice before your data becomes subject to a different policy.

6. How long we keep it #

Your account data — profile, favorites, lists, photo — is kept until you delete your account, at which point it is deleted immediately (see §8).

Analytics data is retained for 14 months, then deleted automatically by Google.

Crash reports follow Firebase Crashlytics' retention schedule (currently 90 days for most report data).

7. Your choices and rights #

Depending on where you live you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and not to be discriminated against for exercising these rights.

You can act on most of these directly in the App: view and edit your profile, and delete your account and its data, under Profile → Account.

For anything else — including a copy of your data, or a question about this policy — email geo.ortiz@cleanlabelproject.org. We will respond within the time your law requires (one month under the GDPR and UK GDPR, extendable by two further months for complex requests; 45 days under the CCPA/CPRA; 30 days under PIPEDA).

California residents. We have not sold or shared personal information for cross-context behavioral advertising in the preceding 12 months, and we do not knowingly do so for anyone under 16. The categories we collect, the purposes, and the recipients are listed in §3 and §5.

Canadian residents. You may ask us for access to the personal information we hold about you and to have it corrected. If you are not satisfied with how we handle your request, you may complain to the Office of the Privacy Commissioner of Canada.

Everywhere else. Wherever you live, you can exercise the rights above by emailing us, and you can delete your account and its data yourself from inside the App at any time. We apply the same practices to everyone rather than reserving them for particular jurisdictions.

European Economic Area and United Kingdom. In addition to the rights above, you may object to processing based on legitimate interests, withdraw any consent you have given, and lodge a complaint with your national supervisory authority — the data protection authority for the country you live or work in. You do not need to contact us first, though we would rather hear from you and fix it.

Turning analytics off. If you are in North America: Profile → Settings → Share usage analytics. The switch takes effect immediately and we stop collecting. Events already collected cannot be traced back to you to delete — see §8 — but nothing further is recorded. Outside North America the setting does not appear, because we are not collecting anything to turn off.

8. Deleting your account #

Profile → Account → Delete Account. You will be asked for your password to confirm. Deletion immediately and permanently removes your profile record, your name and email, your profile photo, all of your favorites, and all of your lists and their items, along with your login credentials.

Two things deletion cannot reach, for the same reason:

9. Children #

The App is not directed to children under 13, and we do not knowingly collect their personal information. You must be at least 16 to create an account. If you believe a child under 13 has provided us information, email geo.ortiz@cleanlabelproject.org and we will delete it.

10. Security #

Access to your account data is restricted to your own account by server-side security rules, and data is encrypted in transit. Your password is never stored by us in a readable form. No system is perfectly secure, so we cannot guarantee absolute security.

11. Where your data is processed #

We and Google process and store your data in the United States.

If you use the App from outside the United States, your personal information is transferred to and stored in the United States, where it is subject to US law and may be accessible to US courts and public authorities under that law.

If you are in the European Economic Area or the United Kingdom, that transfer is made under the EU–US Data Privacy Framework and its UK Extension, under which Google LLC is certified. Our agreement with Google — the Firebase Data Processing and Security Terms — provides that the Data Privacy Framework applies to transfers to a certified Google entity in the United States. If Google ceases to rely on it, the transfer falls back to the Standard Contractual Clauses (Module Two, controller-to-processor) incorporated into those same Terms, together with the UK International Data Transfer Addendum.

12. Changes to this policy #

We will update the "Last updated" date when this policy changes, and for material changes we will post the revised policy at the address where you are reading it before the change takes effect.

13. Contact #

Clean Label Project Foundation
280 E. 1st Ave. #873
Broomfield, CO 80038-0873
United States

geo.ortiz@cleanlabelproject.org