Bestie
Last updated 30 July 2026 · Effective 30 July 2026
This summary is for orientation only. The numbered sections below are the operative policy.
Bestie is operated by Bestie Labs Inc, a corporation formed in the State of Texas, United States (“Bestie”, “we”, “us”). We are the controller of the personal information described in this policy.
Bestie is a cosmetic-ingredient scanner. You photograph or scan a beauty product, and we return a hazard score for its ingredients together with the published regulatory and scientific sources behind that score.
This policy covers the Bestie iOS app, our API at
api.mybestie.io, and the website at
mybestie.io. It does not cover the practices of the
retailers, brands or public databases whose information we display, or
of Apple, whose handling of your Apple Account is governed by Apple’s
own privacy policy.
We have tried to make this exhaustive rather than illustrative. If a category is not listed here, we do not collect it. A small number of categories are marked not available yet: those describe what we will collect when a feature ships, and nothing is collected under them today.
| What | When | Notes |
|---|---|---|
| Email address | You register with email | Used to identify your account, verify it, and send password resets. |
| Password | You register with email | Stored only as an Argon2id hash. We cannot read your password and cannot recover it for you. |
| Apple user identifier and email | You use Sign in with Apple | If you choose Apple’s Hide My Email, we only ever receive the private relay address, never your real one. |
| Device identifier | Always | A random identifier the app generates and stores in the iOS Keychain. It is not an advertising identifier and is not shared with anyone. |
| Session records | You sign in | A one-way hash of your session token, plus the device identifier and app user-agent, so you can stay signed in and sign out everywhere. |
You may also use Bestie as a guest, without giving us an email address at all. A guest account is tied only to your device identifier.
All of this is optional, all of it improves the guidance you get, and all of it can be changed or cleared in the app:
Allergies and skin tone are treated as sensitive information — see section 6.
Nothing is sold in the app today. There is no paid subscription, and we hold no purchase information about anyone.
When paid subscriptions arrive, Apple will give us a transaction identifier, which product you bought, whether you are in a free trial, the current period end date, and whether the purchase was refunded or revoked. See section 8.
To keep the service running and to investigate faults, our servers record the request method and path, the response status, how long it took, the account and device identifier associated with the request, a request identifier, and any error message and stack trace.
We do not store your IP address in these logs.
If you turn on crash and performance reporting, the app also sends diagnostic reports when something goes wrong — the crash itself, the app version, the device model and OS version, and the sequence of screens leading up to it. The same reports cover performance faults your device records: the app freezing or becoming unresponsive, using too much processor time, or writing an unusual amount to disk. This is off unless you opt in, it goes to our own servers and to Sentry, who process it for us, and it never includes your photos, ingredient text, allergies or email address.
If you subscribe to updates on our website, we store the email address you gave us for that purpose and nothing else.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
Photos you scan leave our servers. To read an ingredient list from a photograph, we send that image to third-party AI model providers, and we send the transcribed text to language models that help produce the explanation you read. This is how the product works; there is no version of Bestie that scores a photo without processing it.
Specifically:
We engage these providers as processors under contract and instruct them not to use your content to train their models. We cannot, however, audit them directly, and their own terms govern their operations.
Photos are associated with your account. If you would rather not have a photo processed this way, scan the product’s barcode instead — a barcode lookup does not involve an image or a vision model.
Two of the things you can tell us are more sensitive than the rest:
Both are entirely optional. Bestie works without them. By entering them you are asking us to use them for the purpose above, and you can withdraw that at any time by clearing the field in the app, which deletes the value.
Where the law requires your consent before we process sensitive information — including under the Texas Data Privacy and Security Act and, for special-category data, the GDPR — we rely on the consent you give when you choose to enter it, and on no other basis. We do not use this information for advertising, profiling with legal effects, or any automated decision-making beyond producing the score and guidance you asked for.
We measure product usage ourselves rather than through a third-party analytics SDK. Events go to our own servers and nowhere else. There is no Google Analytics, Firebase, Meta SDK, or similar in the app.
The design deliberately limits what can be captured:
We use this to answer questions like how many people finish onboarding, or which screens people give up on — not to build a profile of you.
Bestie Premium is not on sale yet. Nothing in the app charges you today, and we receive nothing from Apple about purchases. The rest of this section tells you in advance what will happen when paid subscriptions arrive; none of it applies until then.
Bestie Premium will be sold exclusively through Apple’s In-App Purchase. We will never see your payment details. No card number, expiry, billing address or bank information will reach our servers, because Apple never sends it.
What we will receive from Apple, and store:
To connect a purchase to the right account — including a purchase made before you signed up — we will give Apple an opaque token derived from your account or device identifier. It will contain no email address and no readable personal information. The app sends no such token today.
If you are in the European Economic Area or the United Kingdom, our lawful bases are:
| Information | Kept for |
|---|---|
| Account and profile | Until you delete your account |
| Scan history and photos | Until you delete your account. Deleting a single history entry permanently deletes that entry and any photos associated with it immediately; it cannot be restored. Clearing your whole history does the same thing for every entry at once — the entries and their photos are permanently deleted, not hidden, and cannot be restored. |
| Sign-in sessions | Until they expire or you sign out |
| Password-reset links | 30 minutes, and single use |
| Subscription records — not available yet | We hold none today. Once subscriptions ship, for as long as needed for tax, accounting and dispute purposes |
| Analytics events | 90 days, then automatically deleted. Events linked to your account are also deleted with your account, whenever that happens first. |
| Operational logs | A short rolling window for troubleshooting |
| AI debugging traces (Langfuse) | 30 days, then automatically deleted. Traces linked to your account are also deleted with your account, whenever that happens first. Traces recorded before we introduced account linking cannot be tied to an account, and expire on the same 30-day window. |
| Prompts sent to AI providers (OpenRouter, OpenAI) | Processed to answer your request; retained by those providers, if at all, according to their own policies |
| Newsletter email | Until you unsubscribe |
When you delete your account, the records tied to it — profile, history, photos, sessions, account-linked analytics events and account-linked AI debugging traces — are deleted along with it.
In the app you can, at any time:
Depending on where you live, you may also have the right to access a copy of your information, correct it, delete it, obtain it in a portable form, opt out of sale or targeted advertising (we do neither), withdraw consent, or appeal a decision we make about your request.
To exercise any of these, email privacy@mybestie.io. We will respond within the time the applicable law allows — 45 days under the Texas Data Privacy and Security Act and the California Consumer Privacy Act, one month under the GDPR — and we will tell you if we need an extension. We do not charge for a first request and we will not treat you differently for making one.
If we refuse a request, you may appeal by replying to our response. If we deny the appeal, you may complain to your state Attorney General or, in Europe and the UK, to your supervisory authority.
Bestie is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us information, email privacy@mybestie.io and we will delete it.
Passwords are stored as Argon2id hashes. Session tokens are stored only as one-way hashes, so a copy of our database does not yield a usable login. Traffic between the app and our servers is encrypted in transit, and the app pins our certificate so a network attacker cannot silently intercept it. The app’s database account has only the privileges it needs.
No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you and the relevant regulators as the law requires.
If we change this policy materially, we will update the date at the top and, for significant changes, tell you in the app before they take effect. Continuing to use Bestie after a change means you accept the updated policy.
Questions, requests or complaints: privacy@mybestie.io.
Bestie Labs Inc, Texas, United States.