Privacy

Un-Process Me — Privacy Policy

EFFECTIVE 6 AUGUST 2026

Un-Process Me ("the app") lets you scan food barcodes and see how ultra-processed a product is, using data from the Open Food Facts database. It's made by ButteredToast Software Ltd ("we", "us"). This policy explains what data the app handles, where it goes, and the choices you have.

Data controller
ButteredToast Software Ltd
Registered
England & Wales
Registered office
71-75 Shelton Street, London, WC2H 9JQ, United Kingdom
Contact
support@butteredtoastsoftware.com

The short version

Data stored only on your device

The following stay in the app's local storage on your phone and are never sent to us or anyone else, unless you choose to sign in. If you do, the items marked below also sync to your account. Everything here is removed when you clear the app's data, uninstall the app, or, for synced items, delete your account:

Optional account and sync

Signing in is entirely optional and doesn't change anything about how the app works day to day. It only adds backup and cross-device sync for the diary-related data above. You sign in with your existing Google or Apple account through Firebase Authentication, a Google service, and we never see or store a password.

WhatSent toWhy
The name and email address your Google or Apple account shares during sign-in. Google Firebase Authentication. To identify your account and show who you're signed in as inside the app. We don't use this to contact you outside the app.
Your diary entries, weekly check-ins, favourites, content language, and store preference. Google Cloud Firestore, hosted in London (europe-west2). Access is restricted to your own signed-in account: nothing is world-readable, and we don't read, share, or analyse the contents of your diary. To back up this data and keep it in sync if you use the app on more than one device.

You can sign out at any time; that leaves all local data on the device in place and simply stops syncing. You can also permanently delete your account from the app's account screen, which removes your synced data from our servers first, then deletes the sign-in account itself. Deleting your account never touches what's stored locally on your device. Step-by-step instructions, including how to request deletion without the app, are on the account deletion page.

Data that leaves your device

WhatSent toWhy
The barcode you scan or search terms you type, plus your selected country/language and your IP address (inherent to any internet request). Open Food Facts (a non-profit; see its privacy policy) and our own API, which runs on Cloudflare's network (see Cloudflare's privacy policy) and delivers offline database downloads. To look up product information and keep the offline database fresh.
A product's label text and your selected language, when you tap Translate on a product that isn't in it. Our API on Cloudflare, where Google's Gemini model (called through Cloudflare AI Gateway) translates the text. The label text is public product data, not something about you. To show the product's ingredients in your language.
Product information you choose to contribute: photos of the product and its label, the details read from them (ingredient list, nutrition values, category, packaging, origin, and the product's name, brand, and weight), and the product barcode. Open Food Facts, routed through our own infrastructure. Depending on your app version, label photos are read either on your device or by our label-reading service: photos are uploaded to our API, read by Google's Gemini model (called through Cloudflare AI Gateway), and staged on Cloudflare storage, where they delete automatically within about a week. Once you submit, your reviewed contribution is held briefly on our infrastructure — where the app shows it to you and to other users of the app straight away — and forwarded to Open Food Facts. Contributions are published in the public Open Food Facts database under its open-data licence (ODbL) and can't be fully recalled once published. Contributions are submitted under our shared contributor account, not an identity of yours. Only when you use the contribution flow, and nothing is submitted to Open Food Facts until you've reviewed it. Take care not to include people or personal items in product photos.
A device integrity token from Google (Play Integrity on Android, App Check on iOS), when you use the label-reading contribution features. Google Firebase App Check, then our API, which exchanges it for a short-lived pass valid for 24 hours. To check requests come from a genuine copy of the app and to rate-limit the label-reading service, which costs us money per use. The pass counts requests; it isn't used to identify or track you.
Usage analytics: screens viewed, buttons tapped, app version, device model, operating system, and Google's app-instance identifiers. No food diary contents are included. Google Firebase Analytics (see Google's privacy policy). To understand which features are used and improve the app.
Crash reports: stack traces, device model, operating system, and app state at the time of a crash. Google Firebase Crashlytics. To find and fix bugs.
Feedback you choose to send: your message, the category you pick, build details (app version, release track, platform, your region and language settings, and which screen you sent it from), and a screenshot — only if you attach one or keep the one the app offers. Our API, stored on Cloudflare's network until we've read and acted on it. Only when you use the Send feedback sheet, which shows what will be included before you send. Screenshots can show your diary or other in-app content — remove the screenshot before sending if you'd rather not share it.

Our servers, including the API hosted with Cloudflare, also keep short-lived operational logs (IP address, endpoint, timestamp) for abuse prevention and debugging. They don't run a separate account system of their own, and they don't build profiles.

Supporting the app

The app has an optional tip jar. Tips are one-off purchases handled entirely by Google Play or Apple's App Store billing: we receive confirmation that a tip was made, never your card or bank details, and a tip unlocks nothing. Where store billing isn't available, the support screen links to our Ko-fi page instead — an external site with its own privacy policy.

Legal basis (UK/EU GDPR)

Where GDPR applies, we process product lookups, contributions (including reading your label photos), feedback you send, tips, and optional account sync because they're necessary to provide the service you've asked for (the "contract" basis). Signing in specifically also relies on your consent, which you can withdraw at any time by signing out or deleting your account. We process analytics, crash reports, operational logs, and the device integrity check on the basis of our legitimate interest in maintaining, improving, and protecting the app. Contributions to Open Food Facts happen at your initiative.

Retention

On-device data stays until you delete it, by clearing the app's data or uninstalling. Synced account data (diary, check-ins, favourites, and preferences) stays in Firestore until you delete the item or your account; either way, it's then gone from our servers. Label photos staged for reading delete automatically within about a week, cached label text within about a month, and a submitted contribution is held on our infrastructure only until Open Food Facts has published it. Firebase Analytics data is retained per Google's standard retention periods, and crash reports are kept while relevant to a supported app version. Feedback you send is kept while we work on it and deleted, screenshot included, within about a month of being marked as handled. Published Open Food Facts contributions persist in that public database. Server logs rotate automatically within days.

Your rights

If you've never signed in, most data we hold can't be linked back to you, and you can reset analytics identifiers via your device's settings or delete all local data by clearing the app's storage or uninstalling. If you have an account, you can view and delete your synced data yourself from the account screen at any time. If you're in the UK, EU, or EEA, you also have rights of access, rectification, erasure, restriction, and objection. Contact us at the email above and we'll help, including passing correction or deletion requests for contributed product data on to Open Food Facts. You can also complain to your supervisory authority, the ICO in the UK.

Children

The app is not directed at children under 13 and we don't knowingly collect personal data from them.

Changes

We'll post any changes to this policy at this URL and update the effective date above. Significant changes will be highlighted in the app's release notes.