Peel Privacy Policy
On this page
Effective date: [EFFECTIVE DATE]
Who we are: Peel is an app published by Matthew Jacome ("Peel", "we", "us"), [ADDRESS]. Contact: [CONTACT EMAIL].
The short version
- Peel has no accounts. We don't ask for your name, email, phone number or any other detail about you.
- The camera reads produce stickers and barcodes on your device. Camera images are never saved and never sent to us.
- Search runs on your device. What you type in Search never leaves your phone.
- When you look up an item, the app downloads that item's score from our content server. The request says which item and which benchmark you're looking at, but not who you are. We don't currently keep logs of these requests.
- Sharing barcode matches is optional and off until you turn it on. If you do, when you tell Peel what's inside a package it doesn't recognize, the app sends the barcode, the item you picked and a random install ID (never your name, email or device identifier). We store the install ID only in scrambled form (a keyed hash), delete matches after 180 days, and use them only to match barcodes to produce for everyone (section 2A).
- Peel+ (optional subscription) is paid through Apple or Google. We never see your card or your Apple/Google account. Only for recall alerts does our server check that a subscription is active, and it keeps just an "active until" date and a scrambled (keyed-hash) form of the purchase number (section 2B).
- Recall alerts (Peel+, optional) need your phone's push token and the list of items you asked to watch, stored with the items in scrambled (keyed-hash) form. They are deleted when you turn alerts off, or automatically 7 days after your subscription stops being active (section 2C). The free recall check in the app downloads one public list for everyone and matches it on your device.
- We have no advertising, no advertising identifiers, no third-party analytics or tracking tools, and we don't sell or share personal information.
1. What happens on your device
| What | Where it stays | Details |
|---|---|---|
| Camera | On your device | Peel uses Apple's on-device text and barcode recognition (VisionKit) to read a PLU sticker or barcode. Frames are processed in memory while the scanner is open. They are not saved, not uploaded, and not used for anything else. Only the number read from the sticker or barcode is used, as described in section 2. |
| Search | On your device | The app downloads a list of all produce items (the same list for everyone) and searches it locally. Your search terms are not sent to us. |
| Your benchmark choice | On your device | Your choice of comparison standard (for example EU or Canada) is stored in the app's local settings. |
| AI features | On your device | Where Peel offers AI-written explanations or Siri and Shortcuts actions, they use the on-device models built into your phone's operating system (for example Apple Foundation Models). Your inputs are not sent to us or to an AI provider. |
Data stored on your device is deleted when you delete the app. It may be included in your device backups (for example iCloud Backup), which Apple manages under its own privacy policy.
| Scan history, favorites and My Basket (Peel+) | On your device | Items you scanned, saved or added to your basket, how often you buy them, and past basket averages. Stored in the app's local database; not sent to us (recall alerts send only the watch list described in section 2C). |
| Free recall check | On your device | When the app opens, it downloads the public list of recent FDA recalls (the same file for everyone, GET /v1/recalls/recent) and compares it with your history, favorites and basket on your phone. |
| Subscription status | On your device | Whether Peel+ is active is read from Apple's StoreKit or Google Play Billing on your device. |
2. What reaches our servers
Peel's scores are prepared in advance and published as static files. When you open a score, the Today screen or Search, the app downloads the files it needs from our content delivery network (Amazon CloudFront, operated by Amazon Web Services, "AWS").
What each request contains. Like any internet request, it includes:
- the file requested, which shows the item code (a PLU or barcode number) or the list being loaded, and the benchmark you selected, for example
/v1/produce/4011?benchmark=EU; - your device's IP address, which the network needs to send the answer back;
- standard technical headers, such as a user agent (the app's name and version and the operating system's networking library version), the date and time, and language preferences.
Requests carry no account, name, advertising identifier or device identifier. (If you opt in to sharing barcode matches, those requests also carry a random install ID; see section 2A.)
What is kept. AWS processes this information to deliver the file and to protect its network. Access logging is currently turned off on our distributions, so we do not keep a record of which items were looked up or from which IP address. We see only aggregated service metrics (for example the total number of requests and error rates), which cannot identify you.
If we turn logging on. We may enable CloudFront access logs later to investigate outages or abuse. If we do, the logs would contain the information listed above for each request. We will: use them only for security, abuse prevention and keeping the service running; keep them for no longer than [RETENTION PERIOD, e.g. 30 days]; not combine them with other data to identify you; and update this policy before logging starts.
2A. Barcode matches you choose to share (optional)
Some packaged produce has a barcode Peel doesn't know yet. You can tell the app what's inside (from the text Peel reads on the package, from a list, or after identifying it by photo). If you turn on Share barcode matches (it is off until you say yes, and you can turn it off in Settings at any time), the app also sends that answer to us so that, once enough shoppers agree, the barcode shows the right score for everyone.
What is sent (one small request per match, over HTTPS to POST /v1/matches):
| Field | Example | Why |
|---|---|---|
| Barcode | 012345678905 | The product being matched |
| Item you picked | romaine-conventional | The answer |
| How you picked it | package_text, picker or photo | To weigh answers and spot problems. The photo itself is never sent; identification happens on your device. |
| Install ID | a random code such as 3f2b8c1e-… | To count different shoppers who agree, keep one answer per shopper per barcode, and limit abuse |
| Platform and app version | ios, 0.1.0 (1) | To find bugs in a particular version |
| App integrity proof | an Apple App Attest signature (iPhone) or a Google Play Integrity token (Android) | To check the answer comes from the real Peel app on a real device, so scripts can't fake shoppers (below) |
No name, email, account, advertising identifier, Apple/Google device identifier, location or photo is sent.
The install ID. The app creates a random ID when you turn sharing on and deletes it when you turn sharing off; turning sharing on again creates a new, unrelated ID. It is not derived from your device or from anything about you. Before storing anything, our server replaces the ID with a keyed hash (HMAC-SHA256 with a secret key that stays on our server), so the ID itself is never stored or logged. The hash lets us tell answers from different installs apart, and nothing more. We have no way to connect it to you.
Checking that answers come from the real Peel app. Because anyone could otherwise invent install IDs and pretend to be several shoppers, the app proves that each answer comes from a genuine copy of Peel:
- On iPhone, the app uses Apple's App Attest. When sharing is turned on, the app creates a new signing key that stays in your iPhone's secure hardware (a new key each time sharing is turned on, so it can't connect answers from before and after). The first time you share, Apple certifies to us that the key belongs to the real Peel app, and after that each answer is signed with it. We keep the key's public half (which can only check signatures), a counter, whether it came from a development or App Store build, the keyed hash of the install ID it belongs to, and the dates it was created and last used. Apple's certificate and the key's identifier are not stored; we store the key under a keyed hash of its identifier. A short random "challenge" we issue for the first step is deleted within 5 minutes.
- On Android, the app asks Google Play's Integrity API for a token that covers that one answer, and our server asks Google to check it. Google tells us whether the app is Peel as installed from Google Play and whether the device passes Google's integrity checks. We keep only the result (for example "verified by Play Integrity"), never the token or anything Google returns about the device.
Apple and Google process information about your device to provide these checks, under their own privacy policies (Apple: apple.com/legal/privacy; Google: policies.google.com/privacy). With each stored answer we keep only whether it was verified and a short result code. An answer that can't be verified (for example from a device that doesn't support these checks) is still accepted, but may not count toward publishing a match.
Your IP address. Like every internet request, this one carries your IP address, which Amazon Web Services (Amazon CloudFront and Amazon API Gateway) uses to deliver it and to protect the service. We don't store IP addresses with matches and don't log them. Our request log records only a request ID, the time, the route, the response status and how long it took, and is deleted after 30 days. Rate limits apply to the service as a whole and to each install ID, not to IP addresses.
How answers are used. Only to match barcodes to produce. Each week our data pipeline counts the answers for each barcode. A barcode is published for everyone only when at least 3 different installs picked the same item and they are at least 75% of the installs that answered for that barcode. What is published is the barcode, the item and the number of installs that agreed (for example, "Matched by Peel shoppers (4 agree)"). Individual answers, install IDs and hashes are never published. Product data published by brands (USDA FoodData Central) always takes precedence over shopper matches.
How long we keep it. Each stored answer is deleted automatically 180 days after you last sent an answer for that barcode (a newer answer for the same barcode replaces the older one). Automatic deletion normally happens within about two days of that date. An iPhone's App Attest key record is deleted 180 days after it was last used, and challenges within 5 minutes. A daily counter used for the per-install limit (the hashed ID, the date and a count) is deleted after 2 days. Our databases' continuous backups, kept for disaster recovery, may hold deleted answers and key records for up to 35 more days. The weekly pipeline copies answers only into temporary working storage for the run, which is discarded when the run ends; they are not added to our long-term archives.
Where it is stored. In an Amazon DynamoDB database in the AWS US East (N. Virginia) region, encrypted at rest and in transit.
Deleting your answers. Turning sharing off deletes the install ID, the app's record of its App Attest key, and any matches still waiting on your device. Because we only hold a keyed hash of an ID that no longer exists, we can't find which stored answers were yours; they expire on the schedule above.
2B. Peel+ subscription (optional)
Peel+ is an optional subscription. Apple (App Store) or Google (Google Play) handles the payment, renewals, refunds and cancellation under their own terms and privacy policies. We never receive your card details, name, email or Apple/Google account. Whether Peel+ is active is checked on your device, and everything Peel+ unlocks except recall alerts works without our server.
Recall alerts are the exception, because our server spends effort and stores a push token for you, so it checks the subscription once each time the app registers (turning alerts on, changing what you watch, and a periodic refresh):
- On iPhone, the app sends Apple's signed record of your latest Peel+ transaction. Our server checks Apple's signature on our own servers, without contacting Apple, and reads the product, the expiry date and whether it was refunded.
- On Android, the app sends the Google Play purchase token and the product name. Our server asks Google Play (Google Play Developer API) once whether the subscription is active and when the current period ends.
What we keep: only (1) an "entitled until" date (the end of the current period plus 3 days, and never more than 35 days ahead, so a refund stops alerts within about a month), and (2) a keyed hash (HMAC-SHA256 with a secret key that stays on our server) of the subscription's original purchase number, used only to allow at most 10 devices with alerts per subscription (for example a family). We do not store Apple's transaction record, the transaction or order numbers, the Play purchase token, prices, your country or anything else in them. They are not logged.
2C. Recall alerts (Peel+, optional)
If you turn on Alert me about recalls, Peel can notify you when the U.S. Food and Drug Administration (FDA) publishes a recall that matches something you scanned or saved. Alerts are off until you turn them on, and the app asks for notification permission only then.
What the app sends (over HTTPS to PUT /v1/alerts/registrations/{id}, when you turn alerts on, when your watch list changes, and to refresh it about weekly):
| Field | Why |
|---|---|
| A random registration ID the app creates when you turn alerts on (a new one each time you turn them back on) | To update or delete your registration without an account |
| Your device's push token (from Apple Push Notification service or Firebase Cloud Messaging) and the platform | To deliver the alert to this device |
| The barcodes of packaged items you scanned or saved | To alert you when a recall lists that exact barcode |
| Only if you also turn on commodity alerts (off by default): the kinds of produce in your basket and favorites, for example "spinach" | To tell you about new FDA recall records involving that produce |
| The subscription proof in section 2B, and the app version | To check Peel+ is active (the app version is checked, not stored) |
What we store, in an Amazon DynamoDB database (AWS US East, N. Virginia), encrypted at rest: the push token (in readable form, because it's needed to send), keyed hashes of the registration ID, of each watched barcode and of each watched kind of produce, the "entitled until" date and purchase hash from section 2B, whether commodity alerts are on, the platform (and for iPhone, which Apple push gateway to use), the time of the last update, and for commodity alerts, when we last notified you about each kind of produce (so we send at most one per kind per week).
The hashes are pseudonymous, not anonymous. They mean a copy of our database doesn't list barcodes or produce in readable form. But our server holds the key and can compute the hash of any barcode or kind of produce, which it does to match recalls. We use this only to send your alerts, and we never publish, sell or share the watch lists.
How matching works. Once a day our server downloads FDA's recall records (openFDA, public data), and compares new recalls with registrations. A notification uses FDA's own words and links to the item in Peel: "Recalled" is used only when FDA's notice lists the exact barcode you saved; notices about a kind of produce say they may not involve what you bought. Alerts can be late, missed or wrong: FDA's enforcement records often appear days or weeks after a company's own announcement. Always check fda.gov/recalls.
Who delivers the notification. Apple (Apple Push Notification service) on iPhone and Google (Firebase Cloud Messaging) on Android. We send them your push token and the text of the notification (FDA's recall text and the product or kind of produce); they process it under their own privacy policies. On Android the app includes Google's Firebase Cloud Messaging library, which uses a Firebase installation ID to deliver messages; Firebase Analytics is not included and data collection by it is turned off.
Your IP address reaches Amazon Web Services with each registration request, as with any request; we don't store or log it. Our request log keeps only a request ID, the time, the route, the response status and how long it took (not the registration ID, which is in the request path), for 30 days. Our function logs record only outcomes and counts, never tokens, IDs, barcodes or hashes.
How long we keep it.
- Turning alerts off (or removing the last watched item, or the app noticing your subscription ended) deletes your registration immediately.
- If your subscription lapses without that, alerts stop at the "entitled until" date and the registration is deleted automatically 7 days later (usually within about two days of that date).
- If Apple or Google tell us the push token is no longer valid (for example the app was deleted), the registration is deleted at the next alert.
- Our database's continuous backups, kept for disaster recovery, may hold deleted registrations for up to 35 more days.
3. Information from Apple and Google
Apple (and Google, once the Android app is released) handles downloads, payments and optional crash reports. If you have chosen to share analytics with app developers in your device settings, Apple may give us crash reports and aggregated usage statistics. These do not identify you to us. Apple's and Google's own privacy policies apply to the data they collect.
4. Links and sharing
- Links to other sites. Recall information links to the U.S. Food and Drug Administration (FDA) website, and data-source credits link to the organizations that publish the data. Those sites have their own privacy policies.
- Sharing a score. If you tap Share, the text you share goes through your phone's share sheet to the app you choose. We don't see it.
5. What we don't do
- We don't sell personal information, and we don't "share" it for cross-context behavioral advertising (as those terms are defined in California law).
- We don't show ads, use advertising identifiers, or track you across other companies' apps and websites. Peel does not ask for App Tracking Transparency permission because it doesn't track.
- We don't collect precise location, contacts, photos, health records or payment card details.
6. Planned features
We'll update this policy before any of these launch, and describe exactly what each one uses:
- Offline mode (Peel+). Downloads a bundle of the same public score files for use without a connection. Nothing about you is sent beyond a normal download request (section 2).
- Farmers markets near you. Location would be used only when you ask, approximately, and not stored by us.
- Grocery links. Some links to retailers may be affiliate links, which means we may earn a commission. Once you open a retailer's site or app, its privacy policy applies.
7. Children
Peel is a general-audience shopping tool. It is not directed to children under 13, and we don't knowingly collect personal information from children under 13. Because Peel has no accounts, keeps no IP addresses, stores shared barcode matches only under a keyed hash of a random ID and keeps recall-alert watch lists only as keyed hashes next to a push token, we hold no information that identifies a child. If you believe a child has sent us personal information (for example by email), contact us and we'll delete it.
8. Your privacy rights (U.S. states)
Residents of California and other states with consumer privacy laws (for example Colorado, Connecticut, Virginia, Texas and Oregon) may have rights to know, access, correct and delete personal information, and to opt out of its sale, sharing, targeted advertising and profiling.
- Sale, sharing and targeted advertising. We don't do any of these, so there is nothing to opt out of. We treat a Global Privacy Control signal as an opt-out request, although Peel doesn't make web requests that would carry one.
- Access and deletion. We don't keep personal information linked to you in our systems. Shared barcode matches are stored only under a keyed hash of a random install ID that we can't connect to you, and they are deleted automatically after 180 days (section 2A). A recall-alert registration is deleted as soon as you turn alerts off in the app, and otherwise 7 days after your subscription stops being active (section 2C); because it is keyed by a random ID that only your app knows, turning alerts off is the way to delete it. If you've emailed us, we'll provide or delete that correspondence on request.
- Sensitive and health data. We don't collect sensitive personal information or consumer health data about you. The produce scores describe food, not you.
- Non-discrimination. We won't treat you differently for using your rights.
To make a request, email [CONTACT EMAIL]. You may use an authorized agent. We'll respond within the time the law requires.
9. Users outside the United States
Peel is operated from the United States, and our content network serves files from AWS locations worldwide. If you use Peel from outside the U.S., the limited technical data in section 2 is processed by AWS to deliver the files you request, and, if you opt in, the barcode matches in section 2A and recall-alert registrations in section 2C are stored in the United States. Where laws such as the EU or UK GDPR apply, our legal basis is our legitimate interest in delivering and securing the app (and, for shared barcode matches, your consent, which you can withdraw by turning sharing off; for recall alerts, performing the Peel+ service you asked for, which you can stop by turning alerts off), and you may have rights to access, erase or object. Contact [CONTACT EMAIL].
10. Retention
- On your device: until you delete the app or change the setting.
- Server request data: not retained while logging is off. If logging is enabled, [RETENTION PERIOD].
- Shared barcode matches (optional): 180 days after your last answer for that barcode, then deleted automatically; up to 35 more days in disaster-recovery backups. App Attest key records (iPhone): 180 days after last use, same backups. Challenges: 5 minutes. Per-install daily counters: 2 days. The barcode-match request log (no IP address or identifiers): 30 days.
- Peel+ subscription check: only the "entitled until" date and the purchase hash, stored on the recall-alert registration and deleted with it (section 2B).
- Recall alerts (optional): until you turn alerts off, or 7 days after your subscription stops being active, then deleted automatically; up to 35 more days in disaster-recovery backups. The alerts request log (no IP address, identifiers or path): 30 days. Records of which FDA recall numbers were already processed (public data, nothing about you): 180 days.
- Emails you send us: as long as needed to answer you, then deleted within [EMAIL RETENTION PERIOD].
11. Security
All traffic between the app and our servers is encrypted (HTTPS only, with HTTP Strict Transport Security). Our API is read-only except for the optional barcode-match endpoints, which accept only the fields in section 2A, check that answers come from the real app (App Attest / Play Integrity) and store install IDs and key identifiers only as keyed hashes, and the optional recall-alert registration endpoint (section 2C), which requires a verified Peel+ subscription, limits each subscription to 10 devices and stores registration IDs, barcodes, produce and purchase numbers only as keyed hashes. We hold no accounts or contact details. Credentials for Apple and Google push services and the Play check are kept in AWS Systems Manager as encrypted parameters. Stored data is encrypted at rest. No method of transmission or storage is completely secure, but holding no personal data is our main safeguard.
12. Changes
If we change this policy, we'll update the effective date above. If a change means we collect new kinds of information, we'll say so in the app before it takes effect.
13. Contact
Matthew Jacome [ADDRESS] [CONTACT EMAIL]