Back to Bestie

Privacy Policy

Last updated 6 September 2026 · Effective 6 September 2026

The short version

This summary is for orientation only. The numbered sections below are the operative policy.

1. Who we are

Bestie is operated by Bestie Labs Inc, a corporation formed in the State of Texas, United States (“Bestie”, “we”, “us”). We are the controller of the personal information described in this policy.

Bestie analyzes cosmetics and beauty products. You can scan the front of a product or search for it by name. If Bestie cannot identify a scanned product, it asks you to photograph the ingredient label. We return a hazard score and the published regulatory and scientific sources behind it.

2. What this policy covers

This policy covers the Bestie iOS app, our API at api.mybestie.io, and the website at mybestie.io. It does not cover the practices of the retailers, brands or public databases whose information we display, or of Apple, whose handling of your Apple Account is governed by Apple’s own privacy policy.

New guest accounts are no longer supported. Existing accounts created under the earlier guest system may retain device-linked records until those records are deleted or expire.

3. Information we collect

The information we collect depends on the features you use, as described below.

3.1 Account information

What When Notes
Email address You register with email Used to identify your account, verify it, and send password resets.
Password You register with email Stored only as an Argon2id hash. We cannot read your password and cannot recover it for you.
Apple user identifier and email You use Sign in with Apple If you choose Apple’s Hide My Email, we only ever receive the private relay address, never your real one.
Device identifier You use the iOS app A random identifier the app generates and stores in the iOS Keychain. It is not an advertising identifier and is used to operate and secure Bestie.
Session records You sign in A one-way hash of your session token, plus the device identifier and app user-agent, so you can stay signed in and sign out everywhere.

3.2 Profile information you choose to give us

Profile information is optional. Available controls vary by field; you can use the app's profile controls or contact us to request a correction or deletion:

Allergies and skin tone are treated as sensitive information — see section 6.

3.3 Scan information

We also process product identifiers, including barcodes when detected during a scan, to identify the product.

If you search for a product instead, we use the words you enter to return matching products. The app has no saved-search-history feature, but search terms can appear in infrastructure access logs.

3.4 Operational logs and crash diagnostics

To keep the service running and to investigate faults, our servers record the request method and path, the response status, how long it took, the account and device identifier associated with the request, a request identifier, and any error message and stack trace.

We also record selected request and response bodies for troubleshooting, including ingredient text and product image URLs. Credentials and sensitive profile fields are redacted, and sensitive account routes are excluded from body capture. These application logs are retained for 7 days. Network access logs can include IP addresses and requested URLs. Abuse-prevention counters can contain your IP address and email address and are normally pruned after 48 hours. Infrastructure access logs follow the hosting platform's rotation schedule, rather than the application database's 7-day window. These operational and security logs are separate from the optional usage-analytics and crash-reporting controls.

If you turn on crash and performance reporting, the app also sends diagnostic reports when something goes wrong — the crash itself, the app version, the device model and OS version, and the sequence of screens leading up to it. The same reports cover performance faults your device records: the app freezing or becoming unresponsive, using too much processor time, or writing an unusual amount to disk. This is not sent until you agree to share it, it goes to our own servers and to Sentry, who process it for us, and it never includes your photos, ingredient text, allergies or email address.

3.5 Newsletter

If you subscribe to updates on our website, we store your email address, signup source and confirmation information to manage delivery and honour your choices. If you contact support, we receive your email address, message, and any information you choose to include.

3.6 What we do not collect

4. How we use it

We do not sell your personal information, and we do not share it for cross-context behavioural advertising.

5. Photos and AI processing

Photos you scan leave our servers. To read an ingredient list from a photograph, we send that image to third-party AI model providers, and we send the transcribed text to language models that help produce the explanation you read. This is how the product works; there is no version of Bestie that scores a photo without processing it.

Specifically:

The provider and routing configuration determine which model handles a request. Provider retention and training practices are governed by their applicable terms and settings; we do not promise zero retention across every provider.

Photos are associated with your account. You can search for a product by name without submitting a photo. If you scan a product, start with its front label. Bestie asks for the ingredient label only if it cannot identify the product, and both types of photo are processed as described above.

6. Health and sensitive information

Two of the things you can tell us are more sensitive than the rest:

Both are entirely optional. Bestie works without them. Where a sensitive-profile entry control is available, we ask for your explicit agreement before saving the information. You can request removal and withdraw consent through available controls or by contacting us. The current iOS app does not provide a skin-tone editor.

Where the law requires your consent before we process sensitive information — including under the Texas Data Privacy and Security Act and, for special-category data, the GDPR — we rely on the explicit consent recorded for that use, and on no other basis. We do not use this information for advertising, profiling with legal effects, or any automated decision-making beyond producing the score and guidance you asked for.

7. Analytics

We measure product usage ourselves rather than through a third-party analytics SDK. Usage events go to our own servers. There is no Google Analytics, Firebase, Meta SDK, or similar in the app.

During initial setup, after account creation or sign-in, we ask separately about crash reporting and usage analytics. Unanswered choices start selected. “Save choices” saves the visible selections; “Not now” declines both. You can change these same choices later under Manage Profile → Privacy. Turning a category off stops its collection and discards data waiting to send.

The design deliberately limits what can be captured:

We use this to answer questions like how many people finish onboarding, or which screens people give up on — not to build a profile of you.

8. Who we share information with

The providers below support the purposes listed. Apple handles Apple Account information under its own privacy policy. The legal disclosures described after the table may also apply.

Provider Purpose What it can see
DigitalOcean Hosting, database, photo storage Everything we store, as our infrastructure provider
OpenRouter Routes requests to AI model providers Scanned photos, ingredient text, and profile details included in personalized scoring prompts, processed to answer each request; any retention on their side is governed by their own policies
OpenAI, Anthropic and Google (directly or through OpenRouter) Vision, language and embedding models Ingredient text, photos where needed, and scoring prompts including profile details needed to personalize your result, processed to answer each request; any retention on their side is governed by their own policies
Langfuse Debugging AI model requests The content of model requests, which can include ingredient text; allergies, skin tone and preference text are stripped before traces are recorded. Traces are linked to your account, and we request their deletion when you delete your account. Provider cleanup is asynchronous; a failed request can leave traces until the normal retention cleanup
Sentry Crash and performance reporting, unless you decline it at the diagnostics prompt or turn it off later Crash and app-freeze diagnostics, app version, device model and OS — no photos, ingredient text, allergies or email address
Resend Sending account and newsletter confirmation email Your email address and the message content
Apple Sign in with Apple Sign-in data, per Apple’s own privacy policy
Price-comparison sources Finding where a product is sold and for how much The product being looked up — never your identity or profile

We may also disclose information if we are legally required to, to protect our rights or someone’s safety, or in connection with a merger or acquisition — in which case we will tell you before your information becomes subject to a different policy.

Our providers are primarily in the United States. If you use Bestie from outside the US, your information will be transferred to and processed there.

10. How long we keep it

Information Kept for
Account and profile Until you delete your account
Scan history and photos Until you delete the entry, clear your history, or delete your account. Deleting an entry permanently removes it from your history and cannot be undone. We then attempt to delete its associated photos from storage, unless another history entry still uses them. Clearing history follows the same process for all entries. Photo deletion is separate from history removal. Failed photo deletions remain queued for retry, so storage cleanup may finish later.
Sign-in sessions Usable until expiry or sign-out; expired server session records are pruned after a 30-day grace period
Password-reset links Valid for 30 minutes and single use; expired or used token records are pruned after a 7-day grace period
Analytics events 90 days, then automatically deleted. Events linked to your account are also deleted with your account, whenever that happens first.
Operational logs Application logs: 7 days. Abuse-prevention IP/email counters: 48 hours, followed by the periodic cleanup pass
AI debugging traces (Langfuse) Scheduled for deletion after 30 days. Account deletion also requests removal of linked traces; this provider cleanup is asynchronous. If that request fails, traces remain subject to the normal retention cleanup. Traces recorded before we introduced account linking cannot be tied to an account, and expire on the same 30-day window.
Prompts sent to AI providers (OpenRouter, OpenAI, Anthropic, Google) Processed to answer your request; retained by those providers, if at all, according to their own policies
Crash reports held by Bestie Until account deletion or an erasure request. Disabling crash reporting stops new collection but does not erase reports already uploaded. Sentry applies its own configured retention.
Support correspondence Kept to handle your request and follow-up. Contact us to ask for deletion; any required legal retention may still apply.
Newsletter records Until you unsubscribe, request deletion, or delete an account with the same email address. Unsubscribing deletes the subscriber record and stops newsletter delivery.

When you delete your account, the records tied to it — profile, history, photos, sessions, account-linked analytics and crash reports — are removed through the account-deletion process. Short-lived security counters and access logs expire under their separate retention schedules. We also delete newsletter records matching your account email and request deletion of linked AI debugging traces, subject to the provider cleanup described above. Newsletter records under a different email address and support correspondence require a separate unsubscribe or deletion request. Photo storage cleanup happens separately from removal of the account records; failed photo deletions are queued for retry, so storage cleanup may finish later.

11. Your rights and choices

In the app you can, at any time:

Depending on where you live, you may also have the right to access a copy of your information, correct it, delete it, obtain it in a portable form, opt out of sale or targeted advertising (we do neither), withdraw consent, or appeal a decision we make about your request.

To exercise any of these, email support@mybestie.io. We will respond within the time the applicable law allows — 45 days under the Texas Data Privacy and Security Act and the California Consumer Privacy Act, one month under the GDPR — and we will tell you if we need an extension. We do not charge for a first request and we will not treat you differently for making one.

If we refuse a request, you may appeal by replying to our response. If we deny the appeal, you may complain to your state Attorney General or, in Europe and the UK, to your supervisory authority.

12. Children

Bestie is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us information, email support@mybestie.io and we will delete it.

13. Security

Passwords are stored as Argon2id hashes. Session tokens are stored only as one-way hashes, so a copy of our database does not yield a usable login. Traffic between the app and our servers is encrypted in transit. Release builds of the iOS app additionally use certificate pinning; browsers use HTTPS and their own certificate trust store. The app’s database account has only the privileges it needs.

No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you and the relevant regulators as the law requires.

14. Changes and contact

If we change this policy materially, we will update the date at the top and, for significant changes, tell you in the app before they take effect. Where a change requires fresh consent, we will ask for it; continued use alone does not replace that consent.

Questions, requests or complaints: support@mybestie.io.

Bestie Labs Inc, Texas, United States.