Peel Privacy Policy

On this page

Effective date: [EFFECTIVE DATE]
Who we are: Peel is an app published by Matthew Jacome ("Peel", "we", "us"), [ADDRESS]. Contact: [CONTACT EMAIL].

The short version

1. What happens on your device

WhatWhere it staysDetails
CameraOn your devicePeel uses Apple's on-device text and barcode recognition (VisionKit) to read a PLU sticker or barcode. Frames are processed in memory while the scanner is open. They are not saved, not uploaded, and not used for anything else. Only the number read from the sticker or barcode is used, as described in section 2.
SearchOn your deviceThe app downloads a list of all produce items (the same list for everyone) and searches it locally. Your search terms are not sent to us.
Your benchmark choiceOn your deviceYour choice of comparison standard (for example EU or Canada) is stored in the app's local settings.
AI featuresOn your deviceWhere Peel offers AI-written explanations or Siri and Shortcuts actions, they use the on-device models built into your phone's operating system (for example Apple Foundation Models). Your inputs are not sent to us or to an AI provider.

Data stored on your device is deleted when you delete the app. It may be included in your device backups (for example iCloud Backup), which Apple manages under its own privacy policy.

| Scan history, favorites and My Basket (Peel+) | On your device | Items you scanned, saved or added to your basket, how often you buy them, and past basket averages. Stored in the app's local database; not sent to us (recall alerts send only the watch list described in section 2C). | | Free recall check | On your device | When the app opens, it downloads the public list of recent FDA recalls (the same file for everyone, GET /v1/recalls/recent) and compares it with your history, favorites and basket on your phone. | | Subscription status | On your device | Whether Peel+ is active is read from Apple's StoreKit or Google Play Billing on your device. |

2. What reaches our servers

Peel's scores are prepared in advance and published as static files. When you open a score, the Today screen or Search, the app downloads the files it needs from our content delivery network (Amazon CloudFront, operated by Amazon Web Services, "AWS").

What each request contains. Like any internet request, it includes:

Requests carry no account, name, advertising identifier or device identifier. (If you opt in to sharing barcode matches, those requests also carry a random install ID; see section 2A.)

What is kept. AWS processes this information to deliver the file and to protect its network. Access logging is currently turned off on our distributions, so we do not keep a record of which items were looked up or from which IP address. We see only aggregated service metrics (for example the total number of requests and error rates), which cannot identify you.

If we turn logging on. We may enable CloudFront access logs later to investigate outages or abuse. If we do, the logs would contain the information listed above for each request. We will: use them only for security, abuse prevention and keeping the service running; keep them for no longer than [RETENTION PERIOD, e.g. 30 days]; not combine them with other data to identify you; and update this policy before logging starts.

2A. Barcode matches you choose to share (optional)

Some packaged produce has a barcode Peel doesn't know yet. You can tell the app what's inside (from the text Peel reads on the package, from a list, or after identifying it by photo). If you turn on Share barcode matches (it is off until you say yes, and you can turn it off in Settings at any time), the app also sends that answer to us so that, once enough shoppers agree, the barcode shows the right score for everyone.

What is sent (one small request per match, over HTTPS to POST /v1/matches):

FieldExampleWhy
Barcode012345678905The product being matched
Item you pickedromaine-conventionalThe answer
How you picked itpackage_text, picker or photoTo weigh answers and spot problems. The photo itself is never sent; identification happens on your device.
Install IDa random code such as 3f2b8c1e-…To count different shoppers who agree, keep one answer per shopper per barcode, and limit abuse
Platform and app versionios, 0.1.0 (1)To find bugs in a particular version
App integrity proofan Apple App Attest signature (iPhone) or a Google Play Integrity token (Android)To check the answer comes from the real Peel app on a real device, so scripts can't fake shoppers (below)

No name, email, account, advertising identifier, Apple/Google device identifier, location or photo is sent.

The install ID. The app creates a random ID when you turn sharing on and deletes it when you turn sharing off; turning sharing on again creates a new, unrelated ID. It is not derived from your device or from anything about you. Before storing anything, our server replaces the ID with a keyed hash (HMAC-SHA256 with a secret key that stays on our server), so the ID itself is never stored or logged. The hash lets us tell answers from different installs apart, and nothing more. We have no way to connect it to you.

Checking that answers come from the real Peel app. Because anyone could otherwise invent install IDs and pretend to be several shoppers, the app proves that each answer comes from a genuine copy of Peel:

Apple and Google process information about your device to provide these checks, under their own privacy policies (Apple: apple.com/legal/privacy; Google: policies.google.com/privacy). With each stored answer we keep only whether it was verified and a short result code. An answer that can't be verified (for example from a device that doesn't support these checks) is still accepted, but may not count toward publishing a match.

Your IP address. Like every internet request, this one carries your IP address, which Amazon Web Services (Amazon CloudFront and Amazon API Gateway) uses to deliver it and to protect the service. We don't store IP addresses with matches and don't log them. Our request log records only a request ID, the time, the route, the response status and how long it took, and is deleted after 30 days. Rate limits apply to the service as a whole and to each install ID, not to IP addresses.

How answers are used. Only to match barcodes to produce. Each week our data pipeline counts the answers for each barcode. A barcode is published for everyone only when at least 3 different installs picked the same item and they are at least 75% of the installs that answered for that barcode. What is published is the barcode, the item and the number of installs that agreed (for example, "Matched by Peel shoppers (4 agree)"). Individual answers, install IDs and hashes are never published. Product data published by brands (USDA FoodData Central) always takes precedence over shopper matches.

How long we keep it. Each stored answer is deleted automatically 180 days after you last sent an answer for that barcode (a newer answer for the same barcode replaces the older one). Automatic deletion normally happens within about two days of that date. An iPhone's App Attest key record is deleted 180 days after it was last used, and challenges within 5 minutes. A daily counter used for the per-install limit (the hashed ID, the date and a count) is deleted after 2 days. Our databases' continuous backups, kept for disaster recovery, may hold deleted answers and key records for up to 35 more days. The weekly pipeline copies answers only into temporary working storage for the run, which is discarded when the run ends; they are not added to our long-term archives.

Where it is stored. In an Amazon DynamoDB database in the AWS US East (N. Virginia) region, encrypted at rest and in transit.

Deleting your answers. Turning sharing off deletes the install ID, the app's record of its App Attest key, and any matches still waiting on your device. Because we only hold a keyed hash of an ID that no longer exists, we can't find which stored answers were yours; they expire on the schedule above.

2B. Peel+ subscription (optional)

Peel+ is an optional subscription. Apple (App Store) or Google (Google Play) handles the payment, renewals, refunds and cancellation under their own terms and privacy policies. We never receive your card details, name, email or Apple/Google account. Whether Peel+ is active is checked on your device, and everything Peel+ unlocks except recall alerts works without our server.

Recall alerts are the exception, because our server spends effort and stores a push token for you, so it checks the subscription once each time the app registers (turning alerts on, changing what you watch, and a periodic refresh):

What we keep: only (1) an "entitled until" date (the end of the current period plus 3 days, and never more than 35 days ahead, so a refund stops alerts within about a month), and (2) a keyed hash (HMAC-SHA256 with a secret key that stays on our server) of the subscription's original purchase number, used only to allow at most 10 devices with alerts per subscription (for example a family). We do not store Apple's transaction record, the transaction or order numbers, the Play purchase token, prices, your country or anything else in them. They are not logged.

2C. Recall alerts (Peel+, optional)

If you turn on Alert me about recalls, Peel can notify you when the U.S. Food and Drug Administration (FDA) publishes a recall that matches something you scanned or saved. Alerts are off until you turn them on, and the app asks for notification permission only then.

What the app sends (over HTTPS to PUT /v1/alerts/registrations/{id}, when you turn alerts on, when your watch list changes, and to refresh it about weekly):

FieldWhy
A random registration ID the app creates when you turn alerts on (a new one each time you turn them back on)To update or delete your registration without an account
Your device's push token (from Apple Push Notification service or Firebase Cloud Messaging) and the platformTo deliver the alert to this device
The barcodes of packaged items you scanned or savedTo alert you when a recall lists that exact barcode
Only if you also turn on commodity alerts (off by default): the kinds of produce in your basket and favorites, for example "spinach"To tell you about new FDA recall records involving that produce
The subscription proof in section 2B, and the app versionTo check Peel+ is active (the app version is checked, not stored)

What we store, in an Amazon DynamoDB database (AWS US East, N. Virginia), encrypted at rest: the push token (in readable form, because it's needed to send), keyed hashes of the registration ID, of each watched barcode and of each watched kind of produce, the "entitled until" date and purchase hash from section 2B, whether commodity alerts are on, the platform (and for iPhone, which Apple push gateway to use), the time of the last update, and for commodity alerts, when we last notified you about each kind of produce (so we send at most one per kind per week).

The hashes are pseudonymous, not anonymous. They mean a copy of our database doesn't list barcodes or produce in readable form. But our server holds the key and can compute the hash of any barcode or kind of produce, which it does to match recalls. We use this only to send your alerts, and we never publish, sell or share the watch lists.

How matching works. Once a day our server downloads FDA's recall records (openFDA, public data), and compares new recalls with registrations. A notification uses FDA's own words and links to the item in Peel: "Recalled" is used only when FDA's notice lists the exact barcode you saved; notices about a kind of produce say they may not involve what you bought. Alerts can be late, missed or wrong: FDA's enforcement records often appear days or weeks after a company's own announcement. Always check fda.gov/recalls.

Who delivers the notification. Apple (Apple Push Notification service) on iPhone and Google (Firebase Cloud Messaging) on Android. We send them your push token and the text of the notification (FDA's recall text and the product or kind of produce); they process it under their own privacy policies. On Android the app includes Google's Firebase Cloud Messaging library, which uses a Firebase installation ID to deliver messages; Firebase Analytics is not included and data collection by it is turned off.

Your IP address reaches Amazon Web Services with each registration request, as with any request; we don't store or log it. Our request log keeps only a request ID, the time, the route, the response status and how long it took (not the registration ID, which is in the request path), for 30 days. Our function logs record only outcomes and counts, never tokens, IDs, barcodes or hashes.

How long we keep it.

3. Information from Apple and Google

Apple (and Google, once the Android app is released) handles downloads, payments and optional crash reports. If you have chosen to share analytics with app developers in your device settings, Apple may give us crash reports and aggregated usage statistics. These do not identify you to us. Apple's and Google's own privacy policies apply to the data they collect.

5. What we don't do

6. Planned features

We'll update this policy before any of these launch, and describe exactly what each one uses:

7. Children

Peel is a general-audience shopping tool. It is not directed to children under 13, and we don't knowingly collect personal information from children under 13. Because Peel has no accounts, keeps no IP addresses, stores shared barcode matches only under a keyed hash of a random ID and keeps recall-alert watch lists only as keyed hashes next to a push token, we hold no information that identifies a child. If you believe a child has sent us personal information (for example by email), contact us and we'll delete it.

8. Your privacy rights (U.S. states)

Residents of California and other states with consumer privacy laws (for example Colorado, Connecticut, Virginia, Texas and Oregon) may have rights to know, access, correct and delete personal information, and to opt out of its sale, sharing, targeted advertising and profiling.

To make a request, email [CONTACT EMAIL]. You may use an authorized agent. We'll respond within the time the law requires.

9. Users outside the United States

Peel is operated from the United States, and our content network serves files from AWS locations worldwide. If you use Peel from outside the U.S., the limited technical data in section 2 is processed by AWS to deliver the files you request, and, if you opt in, the barcode matches in section 2A and recall-alert registrations in section 2C are stored in the United States. Where laws such as the EU or UK GDPR apply, our legal basis is our legitimate interest in delivering and securing the app (and, for shared barcode matches, your consent, which you can withdraw by turning sharing off; for recall alerts, performing the Peel+ service you asked for, which you can stop by turning alerts off), and you may have rights to access, erase or object. Contact [CONTACT EMAIL].

10. Retention

11. Security

All traffic between the app and our servers is encrypted (HTTPS only, with HTTP Strict Transport Security). Our API is read-only except for the optional barcode-match endpoints, which accept only the fields in section 2A, check that answers come from the real app (App Attest / Play Integrity) and store install IDs and key identifiers only as keyed hashes, and the optional recall-alert registration endpoint (section 2C), which requires a verified Peel+ subscription, limits each subscription to 10 devices and stores registration IDs, barcodes, produce and purchase numbers only as keyed hashes. We hold no accounts or contact details. Credentials for Apple and Google push services and the Play check are kept in AWS Systems Manager as encrypted parameters. Stored data is encrypted at rest. No method of transmission or storage is completely secure, but holding no personal data is our main safeguard.

12. Changes

If we change this policy, we'll update the effective date above. If a change means we collect new kinds of information, we'll say so in the app before it takes effect.

13. Contact

Matthew Jacome [ADDRESS] [CONTACT EMAIL]