Privacy Policy
Last updated: 2026-09-28 — DRAFT, pending owner sign-off
In this version (2026 beta): price features are turned off (no price reports, no price comparison, no prices shown anywhere), recall alerts are shown inside the app only (no push notifications). New in this version: a silent guest account, a shared product database, receipt scanning that scores what you bought, and optional one-time location to recognize a receipt's store.
MilkNHoney ("the app") is developed by MilkNHoney. This policy explains what the app collects, what it shares, and why — in plain language, matching what the app itself tells you in Settings → Privacy.
Account information
If you create a MilkNHoney account, we collect your email address and, if you choose a password, a securely hashed copy of it (via Supabase Authentication) to let you sign in. You can also sign in with a one-time code sent to your email, or with Google (or Apple on iPhone); in that case we receive your email address and an account identifier from that provider, never its password. This is never sold, shared with advertisers, or shared with any public database.
When you're signed in, your settings, scan history, shopping lists, and dietary/health preferences (diet, skin, household, and medical sensitivities you've selected) are also synced to your account, so they follow you if you sign in on another device or after reinstalling. This data is stored in our database, tied to your account, encrypted in transit, and readable only by you (enforced at the database level, not just in the app) — it is never sold, shared with advertisers, or made public.
- First sign-in on a phone that already has data: the app asks whether to add this phone's scans, lists and preferences to your account, or to start fresh with only what's in the account. Nothing is uploaded until you choose.
- Signing in as a different person: the previous person's data is removed from the phone first (it stays in their account) — one account's data is never copied into another's.
- Signing out: the app asks whether to keep your data on this phone or remove it. Either way it stays in your account.
- Deleting your account (Settings) deletes your account and your synced data from our database and removes it from the phone. Products and prices you chose to contribute publicly (see below) stay published.
Guest (anonymous) account
So the app can save products to the shared database and apply fair daily limits without asking you to sign up, it creates a guest account for this install in the background (Supabase anonymous sign-in). It has no email, name or password — only a random account identifier. It is used for: the products you save to the shared database, contribution photos, your private receipt prices, and per-account daily limits. Your scan history, lists and preferences are not synced to a guest account. If you later sign in with email (or Google/Apple), the app treats it as a normal first sign-in. Deleting your account (Settings) also deletes a guest account's data. In Private Mode no guest account is created and nothing is sent.
Location
Location is used only when you scan a receipt, and only if the receipt has no store address printed on it, to recognize which store it came from. The app first explains why and asks; if you agree, your phone's system asks for "while using the app" permission, and the app reads your location once. It is never tracked in the background (background location is not requested at all), never stored with your location on our server, and never shared. What is saved is only the recognized store (its OpenStreetMap id and name), with your private receipt prices. To recognize the store, the store name/address or your approximate coordinates are sent to OpenStreetMap services (Nominatim, Photon, Overpass). You can say no; the app then uses the store name printed on the receipt.
Camera
The app requests camera access only to scan barcodes, photograph an ingredients list for reading, photograph a product you are adding ("Add this product"), and photograph a receipt. Ingredients and receipt photos are sent to OCR.space for text extraction (see below) and are not kept afterward — neither on your phone nor on our server. Card numbers are masked out of receipt text before anything is saved. Price-proof photos are turned off in this version.
Receipts
When you scan a receipt, the app reads its lines, matches them to products, scores every item it recognizes, and adds them to your history. The prices on the receipt, with the store and date, are saved privately to your account (guest or signed in): only you can read them (enforced by the database), they are not shown in the app in this version, and they are not published or shared with anyone, including Open Prices. They are deleted when you delete your account.
Shared product database
Products the app looks up or rates (barcode, name, brand, category, ingredients text, nutrition facts, the score, and where each piece of data came from) are saved to MilkNHoney's shared product database so every user gets faster, better results. This is product information, not personal information; it is readable by other app users and is not shown with your name. Which account saved which product is recorded internally (not public) to limit abuse, and that link is removed when you delete your account. The product data itself stays.
What gets published publicly
Price reports are turned off in this version. When price reporting is enabled, an explicitly submitted price report's price, product identifier, store location, date and proof photo are first checked by a MilkNHoney moderator (moderators can see those details of the reports they review), then sent to Open Prices (an Open Food Facts project) and published publicly and permanently, under the Open Database License 1.0 (data) and CC BY-SA 4.0 (photos). Anyone can view and reuse this data. Your MilkNHoney account email is never included in it. Please don't include anything personal in the photo itself.
When you add a missing product ("Add this product"), the barcode, name, ingredients text and the front/ingredients photos you take are stored for a MilkNHoney moderator to review. Photos are kept only as small thumbnails (640 pixels) in a folder only your account can write to.
Contributions to Open Food Facts. Product information in the shared database that comes from a label you photographed or typed (not from estimates, and not data that looks wrong) is sent once a day to Open Food Facts by MilkNHoney's own Open Food Facts account, filling only fields Open Food Facts doesn't have yet. It then becomes public there, permanently, under the Open Database License 1.0. No account, email or other personal information is ever sent with it. By adding or correcting a product you agree to this. Photos are not sent automatically.
Recall alerts
If a food recall may match something in your scan history or shopping lists, the app shows a banner inside the app. Matching happens on your phone against the public recall list the app already downloads; your history and lists are not sent anywhere for this. There are no push notifications, no notification permission, and no device token. You can turn recall alerts off in Settings.
Read-only third-party lookups
The app looks up product, ingredient, and recall information from Open Food Facts (and related Open*Facts databases), USDA FoodData Central, FDA's openFDA, and OCR.space. These are read-only lookups, but the lookup input must be sent to the provider: barcodes are sent for product lookup, product names or barcodes may be sent for ingredient lookup, and ingredients photos may be sent to OCR.space.
Price lookups (SerpApi/Google Shopping "Compare Online", Kroger, Open Prices) exist in the codebase but are turned off in this version. OpenStreetMap store search is used only to recognize a receipt's store (see Location).
Reporting a wrong or missed diet/ingredient flag
When you tap to report that a dietary or ingredient-safety flag looks wrong or missing, the product's barcode, name, ingredients text, and the specific flag detail are sent to our database for manual review. This is anonymous — it is not linked to your account — and is used only to improve the app's flagging accuracy.
OCR uploads
Ingredients-photo and receipt modes send the captured image to OCR.space when OCR is configured; OCR.space returns the text and the app does not keep the image. Avoid including people, payment cards, or addresses in photos. There is no AI photo identification or AI ingredients web-search feature in the current app.
Crash and error reporting
The app uses Sentry to detect and diagnose crashes and errors — without it, we'd have no way to know the app broke for you short of you telling us. This sends your IP address (used to approximate your country/region for the crash report, standard for this kind of tooling) plus technical details about the crash: device type, OS version, app version, and the code path where the error happened. For a random sample of sessions (10%, or 100% of sessions where an error occurred), Sentry also records a "session replay" — a reconstruction of what was on screen, but with all text, images, and other content masked/blocked out by default, so this is layout and navigation flow, not a literal recording of what you saw or typed. None of this is linked to your MilkNHoney account email or password.
Data we never share
Your account email and password are never shared, sold, or made public. Your scan history, shopping lists, settings, and preferences are stored on your device, and — only while you're signed in with email, Google or Apple — also in our database tied to your account, readable only by you; neither copy is ever sold, shared with advertisers, or made public. Your receipt prices are readable only by you. Without a signed-in account, your history, lists and preferences never leave your device (aside from the lookups, product saves and submissions described above).
Contact
Website: milknhoneyapp.com
Questions about this policy: email support@milknhoneyapp.com.