Privacy policy
Simply Pure has no accounts, no ads, no analytics SDKs, and no tracking. We never sell data. This page lists everything the app sends anywhere, and why.
Your profile stays on your phone
Your name, diet preferences, and allergen selections are stored only on your device by default. There is no account to create and no readable profile stored on our servers.
If you choose to sync devices with a pair code, your profile and scan history are encrypted on your device (AES-256-GCM) with a key derived from the pair code, and the encrypted bundle is relayed through our server. The pair code itself is never sent to us, so we cannot read the bundle; it is deleted from the server after 30 days without activity. Pairing the browser extension works the same way and is decrypted only in your browser.
Scanning a product
When you scan a barcode, the app sends that barcode, and nothing else, to our server to look up the product. If our server can't be reached, the app sends the same barcode directly to Open Food Facts, the community database our product data comes from, so the lookup still works; Open Food Facts' privacy policy applies to that request. Results may be cached on your device so previously scanned products work offline.
Searching and alternatives
If you search for a product by name, the app sends your search text directly to Open Food Facts to find matches. Likewise, when a product page suggests better-scoring alternatives, the app queries Open Food Facts with that product's category. Both requests go to Open Food Facts' servers and are subject to their privacy policy; they include no profile or personal data beyond what any web request carries (such as your IP address).
Contributions you choose to submit
If you submit a correction for a product, such as label photos, corrected ingredient text, nutrition values, a store name, or (when you have turned the location toggle on) a coarse "City, State" region, that submission is stored on our server, reviewed by a human, and, if approved, published to all Simply Pure users and forwarded to Open Food Facts under the Open Database License. Nothing is submitted without you tapping submit, and the region tag is only ever attached when the toggle is on.
When you photograph a label, the text is read by on-device recognition on your phone. No photo or text is sent to any AI provider; nothing in Simply Pure sends your data to AI services.
To show what happened to your submissions, the app asks our server about the barcodes it submitted and how often each product has been scanned since your fix went live. Only barcodes travel; the server never knows who submitted what — the record of which submissions are yours lives on your device.
Community answers (opt-in)
If crowdsourcing is on and you answer "Did you buy this product?", your answer is stored as an anonymous yes/no count on that product's barcode — no user identifier and no per-answer timestamp, so it cannot be traced to you. When location tagging is on, a "yes" may carry a coarse "City, State" region; regions are only ever read back as aggregate totals. Nothing is shown to other users until a product has at least ten independent answers.
Recall alerts (opt-in)
If you turn on recall alerts, the app periodically sends your scan history (barcodes, product names, brands) to our server solely to check it against US FDA recall records. The list is checked and discarded; it is not stored.
Supporting Simply Pure
Supporter contributions happen on our website through Stripe Checkout and renew annually until canceled. We never see your card number; payment details go directly to Stripe, and Stripe's privacy policy applies to the checkout page. To unlock premium features without an account, our server stores your supporter code alongside a reference to the Stripe subscription it belongs to — no name, email, or card details. You can cancel anytime from the app's Profile screen or through Stripe using your receipt email; premium then runs to the end of the paid year. Subscriptions bought through the App Store are handled entirely by Apple.
The browser extension
The Simply Pure browser extension reads product pages only on the retailer sites it supports, locally in your browser, to find the product's barcode. It then sends that barcode to our server for a score, exactly like a scan in the app. It has no access to your browsing beyond those sites, and pairing your preferences uses the same end-to-end encryption described above.
Server logs and usage counts
Like nearly every web service, our server keeps standard request logs (IP address, user agent) for a short period, used only for abuse prevention such as rate limiting.
To know how many devices use Simply Pure each day, the server counts each lookup under a one-way hash of the request's IP address and platform. The hashes stay on our server, are not linked to products or profiles, and produce only daily totals. The server also counts how many times each product barcode is looked up per day; those tallies contain no user data. No third party receives any of this.
What we don't do
- No ads.
- No analytics SDKs or third-party trackers.
- No sale or sharing of personal data with anyone.
Because we don't track you across sites or over time, there is nothing for a browser "Do Not Track" signal to turn off; we treat every visitor as if the signal were on.
Infrastructure
Our server runs on OVHcloud and sits behind Cloudflare, which proxies traffic to us. Both act only as hosting and network providers for requests you make; neither is given your data for any other purpose.
Contact
Questions about this policy: [email protected].
Simply Pure is operated from California, United States. If we change this policy, we will update this page and its effective date.