Munchable
Why MunchableHow it worksFAQPricing

Privacy Policy

Version 1.2. Last updated 8 September 2026.

Munchable exists to give you a clear answer at the shelf without learning anything about your health. This notice explains what we handle, why we handle it, who we hand it to, how long we keep it, and the rights you have over it. It covers the Munchable mobile app, the web app at app.munchable.app, this website, and the email we send you.

The short version. The conditions you pick, your sensitivities and your scan history are held on your device and are never sent to us. Verdicts are worked out on the device itself. On our servers we hold an email address, a subscription record, and any product labels you have contributed. We run no advertising or analytics trackers of any kind, we set no tracking cookies, and we have never sold or shared personal data with anyone for marketing. You can download everything we hold, or erase it permanently, from inside the app without asking us.

Who we are

Munchable is built and operated by Sonacode Ltd, a company registered in England and Wales. Sonacode Ltd is the data controller for the personal data described here, which means we decide what is collected and why, and we are the ones answerable for it.

You can reach us about anything in this notice at hello@munchable.app. We are a small team and privacy requests are handled by us directly rather than by a ticketing system. We have not appointed a Data Protection Officer because we do not meet the conditions in Article 37 of the UK GDPR that would require one: we are not a public authority, our core activity is not large scale monitoring of people, and we do not process special category data at scale, for the reason described in the next section.

Why your health data never reaches us

Information about a digestive condition is health data, which the law treats as a special category needing extra protection. The simplest way to protect it is not to hold it, so that is the architecture we built.

The conditions you select, the ingredients you have marked as personal sensitivities, and the history of what you have scanned are written to storage on your own phone or browser and stay there. The rules engine that turns an ingredient list into Good fit, Caution or Avoid runs on the device, so the verdict is produced locally and is never transmitted anywhere. We cannot read any of it, we cannot recover it for you if you lose your device, and there is nothing in it for us to hand over if we were ever asked for it. Uninstalling the app, clearing its storage, or deleting your account all remove it.

What we collect, why, and our lawful basis

Under UK and EU data protection law every use of personal data needs a lawful basis. Here is each category we hold, in full, with the basis we rely on for it.

Your account

When you create an account we hold your email address and an account identifier generated for you, along with the sign in timestamps and technical metadata our authentication provider records as part of keeping the session secure. An account is required because the free tier is metered at five scans a month and Premium has to be attached to somebody. Your account record contains no condition, no sensitivity and no scan. Lawful basis: performance of our contract with you (Article 6(1)(b)).

Your subscription

If you subscribe to Premium, Stripe processes the payment under its own privacy policy and its own controller relationship with you. We store your plan, your subscription status, the date it renews, and the Stripe customer and subscription identifiers we need to manage it. We never receive or store your card number, and card details are never sent through our servers. If you earn contribution rewards we also store the calendar month, how many accepted products it covers, the resulting percentage, and the identifier of the discount coupon applied to your bill. Lawful basis: performance of our contract with you, and our legal obligation to keep accurate tax records (Articles 6(1)(b) and 6(1)(c)).

Product labels you contribute

When you scan a product we have no data for, you can photograph its label to add it. The photograph is sent once to our optical character recognition step, the ingredient text and product name are read out of it, and the image is then discarded. We do not store label photographs at any point, and there is no gallery of them anywhere. What we keep is the barcode, the ingredient text and product name as read, the confidence score of the read, the timestamp, and your account identifier so that quality checks, contribution rewards and abuse prevention have something to work with. Your conditions are never attached, because they were never sent. If you delete your account, the link to you is replaced with an anonymous marker and the product data stays in the shared catalogue, so that other people are not made worse off by your leaving. Lawful basis: our legitimate interest in building an accurate, trustworthy product database (Article 6(1)(f)). We consider this proportionate because the data is about a product on a shop shelf rather than about you, and the only personal element is a contribution link you can sever at any time.

Reports about a product

When you use the report control on a product that looks wrong, we store the barcode, your account identifier and, if you wrote one, your reason. The account identifier is what enforces one report per person per product, so that a single account cannot repeatedly demote a correct entry. Lawful basis: our legitimate interest in keeping the catalogue accurate and in preventing manipulation of it (Article 6(1)(f)).

Your record of acceptance

When you create an account we record that you accepted this notice and our Terms of Service, which version of each, and when, alongside your email address. This is what lets us demonstrate the agreement exists and email you if the documents change in a way that matters. Lawful basis: compliance with our accountability obligations under Article 5(2), together with our legitimate interest in being able to evidence the contract (Articles 6(1)(c) and 6(1)(f)).

Email we send you

We use Resend to deliver sign in codes, receipts, notices that these documents have changed, and replies to your support messages. We do not run a marketing list and we do not send promotional email, so there is nothing here to unsubscribe from. Lawful basis: performance of our contract with you, and our legitimate interest in answering the messages you send us (Articles 6(1)(b) and 6(1)(f)).

Keeping the service standing up

Our hosting and rate limiting layers process your IP address, your account identifier and request counts, in short lived counters, so that one client cannot exhaust the service for everyone else or run up our costs by looping a request. These counters hold a number against a key, expire on their own within minutes to a day, and are never used to build a profile of you. Analytics collection on the rate limiter is switched off in code. Lawful basis: our legitimate interest in the security and availability of the service (Article 6(1)(f)).

What we deliberately do not collect

Some of the strongest guarantees in this notice are about absences, so they are worth stating plainly rather than leaving you to infer them.

  • No health data on our servers. No condition, no sensitivity, no verdict, no scan history. Not encrypted on our servers, not pseudonymised on our servers, not there at all.
  • No photographs. Label images are read once and discarded. There is no image store, no backup of them, and no way for us to look at one later.
  • No advertising or analytics trackers. No Google Analytics, no advertising pixels, no session recording, no third party analytics or attribution software development kits, on the website or in the app.
  • No advertising identifier, location, contacts or biometrics. The app asks for the camera so it can read a barcode and a label. It does not ask for your location, your contacts or your photo library beyond the image you choose to send, and it does not read a device advertising identifier.
  • No sale or sharing of personal data. We have never sold personal data, we have never shared it for cross context behavioural advertising, and we do not intend to.

What a barcode lookup reveals

Scanning a product sends its barcode to our servers to fetch the ingredient list. The request carries the barcode and nothing about you or your health, and the verdict is worked out afterwards on your device, so the lookup never sees it.

We do count how often each barcode is looked up, because that is how we decide which products to improve next. That counter is a barcode and a number in a list for the calendar month, with no account identifier, no device identifier, no IP address and no timestamp finer than the month itself. It expires automatically after two months. It cannot be turned back into anybody’s scan history, including yours, because the information needed to do that was never recorded.

Cookies

This website sets strictly necessary cookies only, and their whole job is to keep you signed in and to keep the sign in flow safe. We set no analytics, advertising or preference tracking cookies, which is why you have not been shown a cookie banner: consent is required for non essential cookies, and we do not set any. The mobile app keeps your session in the device’s own secure storage rather than in cookies.

The fonts on this site are served from our own domain rather than from a font network, so simply loading a page does not disclose your IP address to a third party.

Automated decisions

Verdicts are produced by a deterministic rules engine on your device, from rules we have written down, and not by a model forming a view about you. There is no profiling of you, no scoring of you, and no decision with a legal or similarly significant effect being made about you automatically, so the additional rights in Article 22 of the UK GDPR do not arise.

Automated checks do apply to contributions. A label you submit is checked for read confidence, for agreement with other submissions of the same product, and for signs of abuse, and it can be held back or set aside on that basis. If you think a contribution of yours was wrongly rejected, email us and a person will look at it.

Who else processes your data

We use a small, deliberately short list of service providers. Each acts on our instructions under a written data processing agreement, except Stripe, which is an independent controller for payment data as well as our processor. We do not add a provider to this list without a reason that survives the question of whether the feature is worth the exposure.

  • Supabase hosts our authentication and our database, so it holds your email address, account identifier, subscription record, consent record and contributions.
  • Vercel hosts this website and our application programming interface, so it processes the requests your device makes and the connection metadata that comes with them.
  • Upstash holds the short lived rate limiting counters and the monthly barcode counts described above.
  • Stripe takes payments and manages subscriptions. It receives your card details directly from you, not through us.
  • Resend delivers our transactional email, so it processes your email address and the content of those messages.
  • Expo delivers the mobile app and its over the air updates.
  • OpenAI reads the text off a label photograph you contribute and helps us normalise ingredient wording. It receives the image and the words on it, never your conditions and never your account. We use it under terms that exclude our data from training.

Beyond these, we disclose personal data only where we are legally required to, such as a valid court order or a lawful request from a regulator or the police, and only to the extent required. If we are ever bought or merged, your data would transfer to the buyer under this same notice, and we would tell you before anything about it changed.

Sending data outside the UK

Several of the providers above operate from, or store data in, the United States and other countries outside the United Kingdom and the European Economic Area. Where personal data is transferred out, we rely on the safeguards Article 46 of the UK GDPR provides for: the UK International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses, or, for a provider certified under it, the UK Extension to the EU United States Data Privacy Framework. You can ask us at any time which mechanism covers a particular provider and we will tell you.

How long we keep things

  • Account, subscription and consent records are kept for as long as your account exists, and are erased when you delete it.
  • Contributions stay in the catalogue as product data. On erasure the personal link to you is replaced with an anonymous marker, so what remains is a fact about a food rather than a fact about you.
  • Reports about a product are deleted with your account.
  • Rate limiting counters expire on their own, within a minute to a day depending on the limit.
  • Monthly barcode counts expire after roughly two months and contain nothing personal in the first place.
  • Payment and tax records are kept by Stripe, and by us in summary form, for the six years HM Revenue and Customs requires for records supporting a tax return. We cannot delete these on request, because keeping them is a legal obligation.
  • Backups containing deleted records roll off on their normal cycle rather than being edited in place, so a short window can exist between erasure and the last backup expiring.

Your rights

Under the UK GDPR and the EU GDPR you have the right to be informed, the right of access, the right to rectification, the right to erasure, the right to restrict processing, the right to data portability, the right to object to processing based on legitimate interests, and the right not to be subject to solely automated decisions with significant effects. Exercising any of them is free, and we will respond within one month.

Two of these are self service, because a right you have to ask for is weaker than a right you can simply take:

  • Download your data. In the app, open Profile and choose Download my data. On the web, open the account menu at the top right and choose the same. You get a machine readable file containing every field we hold against your account. Your conditions and scan history are not in it, because they are on your device and were never sent to us.
  • Delete your account. In the app, open Profile and choose Delete my account; on the web, the account menu has the same option. This cancels any subscription, erases your account, email address, subscription record, consent record and reports, anonymises your contributions, and wipes the data held on your device. It is immediate and it cannot be undone.

For anything else, including rectification, restriction, or an objection to processing we base on legitimate interests, email hello@munchable.app and we will deal with it. We may need to confirm you control the account email before acting on a request, which is a protection for you rather than an obstacle.

If you are unhappy with how we have handled your data, please tell us first so we have a chance to put it right. You also have the right to complain to a supervisory authority at any time. In the United Kingdom that is the Information Commissioner’s Office, at ico.org.uk or on 0303 123 1113. In the European Economic Area it is the data protection authority for the country you live in.

If you are outside the UK and Europe

We apply the standard described here to everyone who uses Munchable, wherever you are, rather than running a weaker policy for people whose local law asks for less. If you live in California, note in particular that we do not sell personal information and do not share it for cross context behavioural advertising, and that the access and deletion controls above are open to you on the same terms as everyone else.

Security

Our database is reachable only through our own server side connection. The tables holding account, consent, reward and contribution data have row level security enabled with no public policies, which means they cannot be read through the public application programming interface even with a valid client key: the server is the only reader. Traffic is encrypted in transit, secrets live in the deployment environment rather than in the codebase, and payment credentials never touch our infrastructure.

The strongest control we have, though, is the one built into the product. Health data cannot leak from a server that never received it. If we suffer a breach that is likely to risk your rights and freedoms, we will report it to the Information Commissioner’s Office within 72 hours and tell you without undue delay where the law requires it.

Children

Munchable is for people aged 16 and over. It is not designed for children, it is not directed at them, and we do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, email us and we will delete it and the data attached to it.

Changes to this notice

This is version 1.2. When we change this notice we update the version and the date above. If a change is material, we email account holders and show a notice in the app on your next visit, so a change cannot pass you by simply because you did not think to reread this page. Continued use after a material change means you accept the updated notice.

Contact

Questions about privacy, or about exercising any right described here, go to hello@munchable.app. Please say which account email you are writing about, so we can find you.

Munchable

A condition first gut health companion. Scan a product, know if it fits your gut.

Product

Why MunchableHow it worksFAQPricing

Guides

ConditionsRecipesIngredient answers

Company

AboutSupportContact

Legal

PrivacyTermsLicenses

Not a medical device. Munchable is a wellness tool that helps you follow your chosen eating pattern. It does not diagnose, treat, or prevent any condition, and it is not a substitute for advice from your doctor or dietitian.

Allergy warnings, not allergy safety. Munchable warns you about the allergies you list when the product data names them. That only ever goes one way: it adds a warning, and it never tells you a product is free from anything. It cannot see every label, recipe change or production line, so always read the physical label and follow medical advice for food allergies.

Verdicts are based on a product's listed ingredients. Always read the physical label.

© 2026 Munchable. All rights reserved.