Last updated 6 September 2026 · Effective 6 September 2026
This summary is for orientation only. The numbered sections below are the operative policy.
Bestie is operated by Bestie Labs Inc, a corporation formed in the State of Texas, United States (“Bestie”, “we”, “us”). We are the controller of the personal information described in this policy.
Bestie analyzes cosmetics and beauty products. You can scan the front of a product or search for it by name. If Bestie cannot identify a scanned product, it asks you to photograph the ingredient label. We return a hazard score and the published regulatory and scientific sources behind it.
This policy covers the Bestie iOS app, our API at
api.mybestie.io, and the website at
mybestie.io. It does not cover the practices of the
retailers, brands or public databases whose information we display, or
of Apple, whose handling of your Apple Account is governed by Apple’s
own privacy policy.
New guest accounts are no longer supported. Existing accounts created under the earlier guest system may retain device-linked records until those records are deleted or expire.
The information we collect depends on the features you use, as described below.
| What | When | Notes |
|---|---|---|
| Email address | You register with email | Used to identify your account, verify it, and send password resets. |
| Password | You register with email | Stored only as an Argon2id hash. We cannot read your password and cannot recover it for you. |
| Apple user identifier and email | You use Sign in with Apple | If you choose Apple’s Hide My Email, we only ever receive the private relay address, never your real one. |
| Device identifier | You use the iOS app | A random identifier the app generates and stores in the iOS Keychain. It is not an advertising identifier and is used to operate and secure Bestie. |
| Session records | You sign in | A one-way hash of your session token, plus the device identifier and app user-agent, so you can stay signed in and sign out everywhere. |
Profile information is optional. Available controls vary by field; you can use the app's profile controls or contact us to request a correction or deletion:
Allergies and skin tone are treated as sensitive information — see section 6.
We also process product identifiers, including barcodes when detected during a scan, to identify the product.
If you search for a product instead, we use the words you enter to return matching products. The app has no saved-search-history feature, but search terms can appear in infrastructure access logs.
To keep the service running and to investigate faults, our servers record the request method and path, the response status, how long it took, the account and device identifier associated with the request, a request identifier, and any error message and stack trace.
We also record selected request and response bodies for troubleshooting, including ingredient text and product image URLs. Credentials and sensitive profile fields are redacted, and sensitive account routes are excluded from body capture. These application logs are retained for 7 days. Network access logs can include IP addresses and requested URLs. Abuse-prevention counters can contain your IP address and email address and are normally pruned after 48 hours. Infrastructure access logs follow the hosting platform's rotation schedule, rather than the application database's 7-day window. These operational and security logs are separate from the optional usage-analytics and crash-reporting controls.
If you turn on crash and performance reporting, the app also sends diagnostic reports when something goes wrong — the crash itself, the app version, the device model and OS version, and the sequence of screens leading up to it. The same reports cover performance faults your device records: the app freezing or becoming unresponsive, using too much processor time, or writing an unusual amount to disk. This is not sent until you agree to share it, it goes to our own servers and to Sentry, who process it for us, and it never includes your photos, ingredient text, allergies or email address.
If you subscribe to updates on our website, we store your email address, signup source and confirmation information to manage delivery and honour your choices. If you contact support, we receive your email address, message, and any information you choose to include.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
Photos you scan leave our servers. To read an ingredient list from a photograph, we send that image to third-party AI model providers, and we send the transcribed text to language models that help produce the explanation you read. This is how the product works; there is no version of Bestie that scores a photo without processing it.
Specifically:
The provider and routing configuration determine which model handles a request. Provider retention and training practices are governed by their applicable terms and settings; we do not promise zero retention across every provider.
Photos are associated with your account. You can search for a product by name without submitting a photo. If you scan a product, start with its front label. Bestie asks for the ingredient label only if it cannot identify the product, and both types of photo are processed as described above.
Two of the things you can tell us are more sensitive than the rest:
Both are entirely optional. Bestie works without them. Where a sensitive-profile entry control is available, we ask for your explicit agreement before saving the information. You can request removal and withdraw consent through available controls or by contacting us. The current iOS app does not provide a skin-tone editor.
Where the law requires your consent before we process sensitive information — including under the Texas Data Privacy and Security Act and, for special-category data, the GDPR — we rely on the explicit consent recorded for that use, and on no other basis. We do not use this information for advertising, profiling with legal effects, or any automated decision-making beyond producing the score and guidance you asked for.
We measure product usage ourselves rather than through a third-party analytics SDK. Usage events go to our own servers. There is no Google Analytics, Firebase, Meta SDK, or similar in the app.
During initial setup, after account creation or sign-in, we ask separately about crash reporting and usage analytics. Unanswered choices start selected. “Save choices” saves the visible selections; “Not now” declines both. You can change these same choices later under Manage Profile → Privacy. Turning a category off stops its collection and discards data waiting to send.
The design deliberately limits what can be captured:
We use this to answer questions like how many people finish onboarding, or which screens people give up on — not to build a profile of you.
If you are in the European Economic Area or the United Kingdom, our lawful bases are:
These bases do not override your optional analytics and crash-reporting choices: we require your agreement before uploading either category, as described in section 7.
| Information | Kept for |
|---|---|
| Account and profile | Until you delete your account |
| Scan history and photos | Until you delete the entry, clear your history, or delete your account. Deleting an entry permanently removes it from your history and cannot be undone. We then attempt to delete its associated photos from storage, unless another history entry still uses them. Clearing history follows the same process for all entries. Photo deletion is separate from history removal. Failed photo deletions remain queued for retry, so storage cleanup may finish later. |
| Sign-in sessions | Usable until expiry or sign-out; expired server session records are pruned after a 30-day grace period |
| Password-reset links | Valid for 30 minutes and single use; expired or used token records are pruned after a 7-day grace period |
| Analytics events | 90 days, then automatically deleted. Events linked to your account are also deleted with your account, whenever that happens first. |
| Operational logs | Application logs: 7 days. Abuse-prevention IP/email counters: 48 hours, followed by the periodic cleanup pass |
| AI debugging traces (Langfuse) | Scheduled for deletion after 30 days. Account deletion also requests removal of linked traces; this provider cleanup is asynchronous. If that request fails, traces remain subject to the normal retention cleanup. Traces recorded before we introduced account linking cannot be tied to an account, and expire on the same 30-day window. |
| Prompts sent to AI providers (OpenRouter, OpenAI, Anthropic, Google) | Processed to answer your request; retained by those providers, if at all, according to their own policies |
| Crash reports held by Bestie | Until account deletion or an erasure request. Disabling crash reporting stops new collection but does not erase reports already uploaded. Sentry applies its own configured retention. |
| Support correspondence | Kept to handle your request and follow-up. Contact us to ask for deletion; any required legal retention may still apply. |
| Newsletter records | Until you unsubscribe, request deletion, or delete an account with the same email address. Unsubscribing deletes the subscriber record and stops newsletter delivery. |
When you delete your account, the records tied to it — profile, history, photos, sessions, account-linked analytics and crash reports — are removed through the account-deletion process. Short-lived security counters and access logs expire under their separate retention schedules. We also delete newsletter records matching your account email and request deletion of linked AI debugging traces, subject to the provider cleanup described above. Newsletter records under a different email address and support correspondence require a separate unsubscribe or deletion request. Photo storage cleanup happens separately from removal of the account records; failed photo deletions are queued for retry, so storage cleanup may finish later.
In the app you can, at any time:
Depending on where you live, you may also have the right to access a copy of your information, correct it, delete it, obtain it in a portable form, opt out of sale or targeted advertising (we do neither), withdraw consent, or appeal a decision we make about your request.
To exercise any of these, email support@mybestie.io. We will respond within the time the applicable law allows — 45 days under the Texas Data Privacy and Security Act and the California Consumer Privacy Act, one month under the GDPR — and we will tell you if we need an extension. We do not charge for a first request and we will not treat you differently for making one.
If we refuse a request, you may appeal by replying to our response. If we deny the appeal, you may complain to your state Attorney General or, in Europe and the UK, to your supervisory authority.
Bestie is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has given us information, email support@mybestie.io and we will delete it.
Passwords are stored as Argon2id hashes. Session tokens are stored only as one-way hashes, so a copy of our database does not yield a usable login. Traffic between the app and our servers is encrypted in transit. Release builds of the iOS app additionally use certificate pinning; browsers use HTTPS and their own certificate trust store. The app’s database account has only the privileges it needs.
No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you and the relevant regulators as the law requires.
If we change this policy materially, we will update the date at the top and, for significant changes, tell you in the app before they take effect. Where a change requires fresh consent, we will ask for it; continued use alone does not replace that consent.
Questions, requests or complaints: support@mybestie.io.
Bestie Labs Inc, Texas, United States.