DL DirektLabel
Features The Score Pro Support

Privacy Policy

Last updated: August 25, 2026

The short version. DirektLabel has no accounts and no sign-up. When you scan a label, the photo is sent to our server and passed to Google's Gemini AI to read the ingredients; we don't keep the photo. Your scan history, settings, and ingredient alerts stay on your phone — we can't see them. We don't run any analytics SDK, we don't know your name or email unless you write to us, and we don't sell data. Free users see ads from Google AdMob.

This policy explains how DirektLabel ("we," "our," "us") handles information in the DirektLabel mobile app (the "App") for iOS and Android. By using the App you agree to the practices described here.

1. How a scan actually works

This section describes the technical flow, because it determines everything else in this policy.

  1. You capture or select a photo of an ingredient label. The image is resized on your device.
  2. The image is sent over an encrypted (TLS) connection to our backend, a Supabase Edge Function that we operate. The image itself leaves your device — text extraction does not happen on your phone.
  3. Our backend forwards the image to Google's Gemini API, which extracts the label text and returns a structured list of ingredients, the product type, and any declared allergens.
  4. Our backend returns that result to your device. The scoring itself runs entirely on your device using a rule table that ships inside the App.
  5. The image is held only in memory for the duration of the request. We do not write it to any database or file storage, and we do not retain it after the response is returned.

The App keeps a short-lived cache on your device that maps an image to its result, so re-scanning the same photo does not make another network request. That cache is local to your device.

2. Information we process

2.1 Label images and extracted ingredient text

Processed as described in Section 1, for the sole purpose of returning your analysis. Not stored by us and not associated with any identity beyond the anonymous identifier described below.

2.2 An anonymous identifier

The App signs in anonymously to our backend on first launch. This creates a random identifier that is not connected to your name, email address, phone number, Apple Account, or Google account. We use it for one purpose: counting how many scans and comparisons an installation has performed on a given day, so the free-tier daily limit can be enforced. We store, per identifier: the date, the action type, and a count.

2.3 Device integrity signals

To prevent abuse of our API, the App may ask the operating system to vouch that it is a genuine, unmodified copy — Apple's App Attest / DeviceCheck on iOS, Google's Play Integrity on Android. Our backend stores the resulting attestation key reference and, where verification fails, a short reason code. These signals identify the app installation, not you.

2.4 Subscription status

If you subscribe to DirektLabel Pro, the purchase is made and validated through the App Store (iOS) or Google Play (Android). We receive whether an entitlement is active. We never receive or store your card details, billing address, or store account credentials.

2.5 Advertising identifiers (free users only)

Google AdMob serves ads in the free version and may access your device's advertising identifier and approximate location derived from IP address. See Section 5.

2.6 Support correspondence

If you email us, we receive your email address and whatever you choose to include, and keep it for as long as needed to resolve your issue.

3. Information that never leaves your device

The following are stored locally on your phone and are not uploaded to us:

  • Your saved scan history, including product names you type
  • App preferences — theme, haptics, auto-save, history limit
  • Your custom ingredient alerts
  • Achievement and statistics data, which is computed on-device from your local history
  • The local image-to-result cache described in Section 1

Because this data never reaches us, we cannot retrieve it, back it up, or restore it. Uninstalling the App deletes it.

4. What we do not collect

To be explicit, DirektLabel does not:

  • Require or offer an account, username, or password
  • Collect your name, email address, or phone number through the App
  • Include any analytics, telemetry, crash-reporting, or attribution SDK
  • Collect precise GPS location, contacts, calendar, health data, or your photo library beyond the single image you choose
  • Sell or share personal information for cross-context behavioural advertising as those terms are defined under US state privacy laws
  • Use your scans to train AI models

5. Third-party services

5.1 Supabase

Supabase, Inc. hosts our backend — the Edge Function that relays scans and the database holding anonymous usage counts and attestation records. Supabase acts as our processor. See the Supabase Privacy Policy.

5.2 Google Gemini API

Label images are sent to Google's Gemini API to extract and identify ingredients. This is the paid Gemini API accessed with our own key from our server; your device never contacts Google directly for this. Google's handling is governed by the Gemini API Additional Terms of Service and the Google Privacy Policy.

5.3 Apple App Store and Google Play billing

Subscriptions are sold and processed by Apple or Google depending on your platform. Their respective privacy policies apply to the payment itself.

5.4 Apple App Attest and Google Play Integrity

Used for the anti-abuse checks described in Section 2.3.

5.5 Google AdMob

Serves advertising to free users. AdMob may collect and use data for ad delivery, frequency capping, and measurement. See how Google uses information from sites or apps that use its services.

6. Advertising

The free version displays ads from Google AdMob. These may be personalised using your device's advertising identifier, coarse location derived from IP address, and your activity in the App.

On iOS, the App asks for permission through Apple's App Tracking Transparency prompt before any tracking identifier is used. If you decline, ads are served without it. You can change this later under Settings → Privacy & Security → Tracking.

On Android, you can reset or delete your advertising ID under Settings → Google → Ads.

DirektLabel Pro removes all advertising.

7. Data retention

  • Label images: not retained — held in memory for the duration of the request only.
  • Anonymous usage counts: retained as daily rows tied to the anonymous identifier, kept for operational and abuse-prevention purposes and periodically purged.
  • Attestation records: retained while needed for abuse prevention; challenge records are swept automatically.
  • Locally stored data: retained on your device until you delete it or uninstall the App.
  • Support emails: retained until the matter is resolved and for a reasonable period afterwards.

8. Security

All traffic between the App and our backend uses TLS. Our API key for the AI provider is held only on the server and never ships inside the App. The database tables holding usage and attestation data are locked down with row-level security and are reachable only by our backend service role. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Your rights and choices

  • Access and deletion of local data: everything the App stores about your scanning is visible in the App and can be deleted from Settings → Clear History, per-scan from the History tab, or wholesale by uninstalling.
  • Server-side data: because there is no account, the only data we hold is tied to an anonymous identifier. If you want it deleted, email us and we will remove the records for that identifier — you may need to help us locate it, since we cannot connect it to you.
  • Advertising: opt out as described in Section 6, or subscribe to Pro.
  • Camera and photo access: revocable at any time in your device settings; the App simply will not be able to scan.

10. Children's privacy

DirektLabel is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us at support@direktlabel.app and we will delete it.

11. International data transfers

Our backend and the AI provider operate infrastructure in multiple countries, including the United States. When you scan a label, the image and extracted text may be processed outside your country of residence. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses for these transfers.

12. Changes to this policy

We may update this policy. Material changes will be reflected here with a revised "Last updated" date. Continued use of the App after a change constitutes acceptance of the revised policy.

13. Contact us

Questions about this policy or our data practices: support@direktlabel.app

14. US state privacy rights

If you are a resident of California or another US state with a comprehensive privacy law, you may have the right to know what personal information is collected, to request deletion or correction, to opt out of sale or sharing, and not to be discriminated against for exercising these rights.

We do not sell personal information and do not share it for cross-context behavioural advertising as those terms are defined by the California Consumer Privacy Act. To exercise any right, email support@direktlabel.app. Note the practical limit described in Section 9: with no account, we may be unable to associate a request with a specific individual.

15. European and UK privacy rights (GDPR)

If you are in the European Economic Area, the United Kingdom, or Switzerland, you have the rights of access, rectification, erasure, restriction, objection, and data portability, and the right to lodge a complaint with your supervisory authority.

Our legal bases for processing are:

  • Performance of a contract — processing your label image to return the analysis you requested, and managing subscription entitlements.
  • Legitimate interests — enforcing free-tier limits, verifying app integrity, and preventing abuse of our API.
  • Consent — personalised advertising, where required, collected through the platform's tracking prompt and withdrawable at any time.

To exercise these rights, email support@direktlabel.app, keeping in mind the identification limit noted in Section 9.

DL DirektLabel

A processing score for the ingredient list on the back of the package.

Product

Features The Score Pro Download

Support

Help Center Manage Subscription Contact Us

Legal

Privacy Policy Terms of Service

© 2026 DirektLabel. All rights reserved.

DirektLabel is not medical or nutrition advice.