Plainr

Privacy Policy

Last updated: 27 September 2026

1. Introduction

Plainr ("we," "us," "the app") helps you understand the processing level of food products you scan. This policy explains what data we collect, why, and how you can control it.

Plainr is not a medical device and does not provide medical advice. Always consult a healthcare professional for dietary or health decisions.

Plainr contains no advertising and no analytics or tracking software. We do not sell your data, and nothing in the app profiles you for advertising.

Data We Collect

Account data: your email address, and the account identifier from Google if you sign in with Google. Passwords are handled by our authentication provider and are not stored by the app.

Profile: the username you choose, and — only if you add one — a profile photo. See Section 3 for how profile photos are stored, because they are the one piece of your data reachable from outside the app.

Health and goal data you provide: your year of birth, sex, height, weight, activity level, what brought you to Plainr (e.g., avoid processed food, lose weight), how you heard about Plainr, your calorie/protein/carb targets, your daily water goal, weight log entries, and water intake log entries.

Your year of birth, not your date of birth. The app asks for a birthday during sign-up so the question reads naturally, but only the YEAR is kept. It is used for one thing: the age term in the formula behind your calorie target. A full date of birth would identify you more precisely for no benefit, so it is not stored.

Usage data: your scan history (the product, its score, and when you scanned it), what you logged to your food diary, and a log of the actions that move your streak, daily quests, badges, XP, and weekly league. This is your own progress record: it is what the app shows you on Home, Stats, and Profile, and it is deleted with your account.

Your time zone: the app records your device’s time zone alongside each action, and stores it on your account as a fallback. It is used only to work out which local day an action belongs to, so that a scan late at night counts toward the right day’s streak and quests. We do not collect GPS or any precise location.

Payment data: none. This version of the app takes no payments and collects no card details.

Photos

The app uses photos in three places, and they are treated differently.

Ingredient label photos. When you scan a label, the photo is sent to Google’s Gemini API so the text can be read and, where needed, translated. We do not store the photo on our servers. It is held in your device’s memory only, so a failed scan can be retried on the shot you already took, and it is discarded once the scan resolves or when you close the app. Only the extracted ingredient text is kept.

Meal photos. When you estimate a meal from a photo, the photo is sent to Google’s Gemini API in the same way and is likewise not stored on our servers — it is held in your device’s memory only and discarded when you leave the screen. What is saved is the result you confirmed: the food names and their estimated portions and macros, stored on your device.

Profile photos. A profile photo is cropped and resized on your device and uploaded to our file storage as a single file belonging to your account. That file can be opened by anyone who has its exact web address. The address contains your account identifier, the storage cannot be browsed or listed, and nothing in the app shows your photo to any other user — but it is not private, so do not use a photo you would mind being seen. Only you can upload or replace it. You can delete it at any time from Settings → Delete profile photo, and it is deleted with your account.

Third-Party Services We Use

  • Supabase — database, authentication, and file storage hosting
  • Open Food Facts — public product/ingredient database, looked up by barcode
  • USDA FoodData Central — public product/ingredient database (US), looked up by barcode
  • Google (Gemini API) — reading text from photos of ingredient labels, estimating meals from photos, and translating non-English ingredient text
  • Apple / Google — app distribution, and the account you use if you sign in with Google

We send each of these only what it needs to do its job. Open Food Facts and USDA FoodData Central receive a barcode and nothing else. The Gemini API receives the photo or the ingredient text and nothing else. Neither your email address, nor your username, nor your account identifier is sent to Open Food Facts, to USDA, or to the Gemini API. Supabase hosts your account and is the only one of these that holds your personal data; if you sign in with Google, Google knows you signed in to Plainr. Each provider handles what it receives under its own privacy terms.

5. Why We Collect This Data

  • To work out your calorie and protein targets — a starting point based on the figures you give us, not a recommendation about what to eat
  • To calculate the processing score of what you scan
  • To run the streak, XP, daily quests, badges, and weekly league
  • To let you track your own history and progress over time
  • To read ingredient labels you photograph, and translate them where they are not in English
  • To keep your data in step across the devices you sign in on

6. What Other People Can See

Nothing you do in Plainr is shown to other users. There is no leaderboard, no friends list, no public profile, and no sharing. The weekly league is a level you move up and down on your own — it is not a table of other people, and no other user’s data is ever sent to your device, or yours to theirs.

The single exception is a profile photo, which can be opened by anyone holding its exact web address, as described in Section 3.

7. Data Retention and Deletion

We keep your data for as long as your account exists. You can delete your account at any time from Settings → Delete Account, and it takes effect immediately — your profile photo is removed from storage first, then the account itself, and everything attached to it (scans, diary, logs, streak, badges, quests, league standing) goes with it. The app also clears your data from that device. This cannot be undone.

One thing is deliberately not deleted: the app keeps a shared cache of product information — what a barcode is, its ingredients, and its score — so that scanning is faster for everyone. Those records describe products, not people. They are not linked to any account and contain nothing about you.

8. Your Rights

Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to certain processing. Deletion is available directly in the app (Section 7). For anything else, contact us at support@plainr.app.

9. Children’s Privacy

Plainr is not directed at children under 16. We do not knowingly collect data from children under this age. If you believe a child has provided us data, contact us and we will delete it.

10. Data Security

Connections to our servers are encrypted, and every table holding your data is protected so that your account can read and write only its own rows. However, no system is completely secure, and we cannot guarantee absolute security.

11. International Data Transfers

Your data may be processed in countries other than your own, including the United States, where some of our service providers operate.

12. Changes to This Policy

We may update this policy from time to time. The date at the top of this document says when it last changed, and material changes will be communicated in-app or by email.

13. Contact

Questions about this policy: support@plainr.app