Privacy
befood works without an account. What follows is everything the app can hold about you, and how to remove it.
Without an account
Scans, your basket, your preferences and the shopping country stay on your phone, in the app's own storage. Nothing about you reaches our servers except the requests needed to look up a product: the barcode or the words you search, and the shopping country, so results match your shelves.
With an account
Signing in stores your email address and, if you choose a password, a salted hash of it, never the password itself. The account then keeps what you ask it to keep: scans with their product records, receipts read from photos as text, shopping areas as a town or postal code, preferences and notification choices.
Face ID and Touch ID
On an iPhone you can turn on Face ID or Touch ID after you sign in. That keeps a random token in the iPhone Keychain, unlocked only by your face or finger, so the next sign-in on that phone does not need a code or a password. The server stores only a hash of the token, never a biometric. Scan, compare and receipts work without it. Turning the setting off in the profile, or deleting the account, removes the token.
Photos
Barcodes, receipts and labels are read on the phone. Photos are not uploaded and are not kept by the app. What leaves the phone is the text the app read from a receipt, if you save it to your account.
Position
At first opening the app can use your position once, to set the shopping country. The country is kept; the position is not. Finding shops near you sends a town, a postal code or the current coordinates to OpenStreetMap for that search only, and stores none of it beyond the town or postal code you typed.
Notifications
If you turn notifications on, the phone's push token is stored with your account so we can reach that phone. Each kind of notification can be switched off in the profile; turning all of them off removes the token.
Where the data lives
Accounts run on Cloudflare Workers and a Cloudflare D1 database. Sign-in emails are sent by Resend from hello@befood.co. Product data comes from Open Food Facts and the USDA FoodData Central; shop data from OpenStreetMap; recalls from the FDA and RappelConso. We send those services only what a lookup needs, never your email.
Deleting everything
In the profile, "Delete my account" removes the account and every row filed under it at once: scans, receipts, areas, preferences, notification registrations, Face ID tokens, sessions. It cannot be undone. Data kept only on the phone goes away by deleting the app.
Questions
Write to hello@befood.co.