MilkNHoney

Privacy Policy

Last updated: 2026-09-28 — DRAFT, pending owner sign-off

In this version (2026 beta): price features are turned off (no price reports, no price comparison, no prices shown anywhere), recall alerts are shown inside the app only (no push notifications). New in this version: a silent guest account, a shared product database, receipt scanning that scores what you bought, and optional one-time location to recognize a receipt's store.

MilkNHoney ("the app") is developed by MilkNHoney. This policy explains what the app collects, what it shares, and why — in plain language, matching what the app itself tells you in Settings → Privacy.

Account information

If you create a MilkNHoney account, we collect your email address and, if you choose a password, a securely hashed copy of it (via Supabase Authentication) to let you sign in. You can also sign in with a one-time code sent to your email, or with Google (or Apple on iPhone); in that case we receive your email address and an account identifier from that provider, never its password. This is never sold, shared with advertisers, or shared with any public database.

When you're signed in, your settings, scan history, shopping lists, and dietary/health preferences (diet, skin, household, and medical sensitivities you've selected) are also synced to your account, so they follow you if you sign in on another device or after reinstalling. This data is stored in our database, tied to your account, encrypted in transit, and readable only by you (enforced at the database level, not just in the app) — it is never sold, shared with advertisers, or made public.

Guest (anonymous) account

So the app can save products to the shared database and apply fair daily limits without asking you to sign up, it creates a guest account for this install in the background (Supabase anonymous sign-in). It has no email, name or password — only a random account identifier. It is used for: the products you save to the shared database, contribution photos, your private receipt prices, and per-account daily limits. Your scan history, lists and preferences are not synced to a guest account. If you later sign in with email (or Google/Apple), the app treats it as a normal first sign-in. Deleting your account (Settings) also deletes a guest account's data. In Private Mode no guest account is created and nothing is sent.

Location

Location is used only when you scan a receipt, and only if the receipt has no store address printed on it, to recognize which store it came from. The app first explains why and asks; if you agree, your phone's system asks for "while using the app" permission, and the app reads your location once. It is never tracked in the background (background location is not requested at all), never stored with your location on our server, and never shared. What is saved is only the recognized store (its OpenStreetMap id and name), with your private receipt prices. To recognize the store, the store name/address or your approximate coordinates are sent to OpenStreetMap services (Nominatim, Photon, Overpass). You can say no; the app then uses the store name printed on the receipt.

Camera

The app requests camera access only to scan barcodes, photograph an ingredients list for reading, photograph a product you are adding ("Add this product"), and photograph a receipt. Ingredients and receipt photos are sent to OCR.space for text extraction (see below) and are not kept afterward — neither on your phone nor on our server. Card numbers are masked out of receipt text before anything is saved. Price-proof photos are turned off in this version.

Receipts

When you scan a receipt, the app reads its lines, matches them to products, scores every item it recognizes, and adds them to your history. The prices on the receipt, with the store and date, are saved privately to your account (guest or signed in): only you can read them (enforced by the database), they are not shown in the app in this version, and they are not published or shared with anyone, including Open Prices. They are deleted when you delete your account.

Shared product database

Products the app looks up or rates (barcode, name, brand, category, ingredients text, nutrition facts, the score, and where each piece of data came from) are saved to MilkNHoney's shared product database so every user gets faster, better results. This is product information, not personal information; it is readable by other app users and is not shown with your name. Which account saved which product is recorded internally (not public) to limit abuse, and that link is removed when you delete your account. The product data itself stays.

What gets published publicly

Price reports are turned off in this version. When price reporting is enabled, an explicitly submitted price report's price, product identifier, store location, date and proof photo are first checked by a MilkNHoney moderator (moderators can see those details of the reports they review), then sent to Open Prices (an Open Food Facts project) and published publicly and permanently, under the Open Database License 1.0 (data) and CC BY-SA 4.0 (photos). Anyone can view and reuse this data. Your MilkNHoney account email is never included in it. Please don't include anything personal in the photo itself.

When you add a missing product ("Add this product"), the barcode, name, ingredients text and the front/ingredients photos you take are stored for a MilkNHoney moderator to review. Photos are kept only as small thumbnails (640 pixels) in a folder only your account can write to.

Contributions to Open Food Facts. Product information in the shared database that comes from a label you photographed or typed (not from estimates, and not data that looks wrong) is sent once a day to Open Food Facts by MilkNHoney's own Open Food Facts account, filling only fields Open Food Facts doesn't have yet. It then becomes public there, permanently, under the Open Database License 1.0. No account, email or other personal information is ever sent with it. By adding or correcting a product you agree to this. Photos are not sent automatically.

Recall alerts

If a food recall may match something in your scan history or shopping lists, the app shows a banner inside the app. Matching happens on your phone against the public recall list the app already downloads; your history and lists are not sent anywhere for this. There are no push notifications, no notification permission, and no device token. You can turn recall alerts off in Settings.

Read-only third-party lookups

The app looks up product, ingredient, and recall information from Open Food Facts (and related Open*Facts databases), USDA FoodData Central, FDA's openFDA, and OCR.space. These are read-only lookups, but the lookup input must be sent to the provider: barcodes are sent for product lookup, product names or barcodes may be sent for ingredient lookup, and ingredients photos may be sent to OCR.space.

Price lookups (SerpApi/Google Shopping "Compare Online", Kroger, Open Prices) exist in the codebase but are turned off in this version. OpenStreetMap store search is used only to recognize a receipt's store (see Location).

Reporting a wrong or missed diet/ingredient flag

When you tap to report that a dietary or ingredient-safety flag looks wrong or missing, the product's barcode, name, ingredients text, and the specific flag detail are sent to our database for manual review. This is anonymous — it is not linked to your account — and is used only to improve the app's flagging accuracy.

OCR uploads

Ingredients-photo and receipt modes send the captured image to OCR.space when OCR is configured; OCR.space returns the text and the app does not keep the image. Avoid including people, payment cards, or addresses in photos. There is no AI photo identification or AI ingredients web-search feature in the current app.

Crash and error reporting

The app uses Sentry to detect and diagnose crashes and errors — without it, we'd have no way to know the app broke for you short of you telling us. This sends your IP address (used to approximate your country/region for the crash report, standard for this kind of tooling) plus technical details about the crash: device type, OS version, app version, and the code path where the error happened. For a random sample of sessions (10%, or 100% of sessions where an error occurred), Sentry also records a "session replay" — a reconstruction of what was on screen, but with all text, images, and other content masked/blocked out by default, so this is layout and navigation flow, not a literal recording of what you saw or typed. None of this is linked to your MilkNHoney account email or password.

Data we never share

Your account email and password are never shared, sold, or made public. Your scan history, shopping lists, settings, and preferences are stored on your device, and — only while you're signed in with email, Google or Apple — also in our database tied to your account, readable only by you; neither copy is ever sold, shared with advertisers, or made public. Your receipt prices are readable only by you. Without a signed-in account, your history, lists and preferences never leave your device (aside from the lookups, product saves and submissions described above).

Contact

Website: milknhoneyapp.com

Questions about this policy: email support@milknhoneyapp.com.