Legal
Privacy Policy
Effective August 2, 2026
Tallow is a food app that helps you see what is inside the products you buy and how clean the restaurants around you are. We built it with the assumption that your scan history is your business. This page explains what we collect, why, which third parties are involved, and how to delete it.
What we collect
- Your email address, used only to sign you in. If you sign in with Apple, we store the private relay email Apple gives us — we never receive your real address.
- The barcodes you scan, the products you save, and your scan history, so we can show it across devices and rebuild a product page instantly the next time you scan it.
- Photos captured while you scan or contribute a product. We upload and store these images so we can show other Tallow users what the product looks like on the product page — your scan photo may appear as the display image for that barcode for everyone who scans it later. Photos are tied to the product, not to your account or identity, and we never publish your name alongside them.
- Your location, only while the restaurant map is open, so we can center it on where you are and show nearby places. Your coordinates are sent to our own servers — rounded to about 11 metres — purely to ask “which rated restaurants are in this box?” They are not written to a location history, not attached to your profile, and never handed to an advertising or analytics company. There is no background location tracking.
- Restaurant ratings, reviews, and any evidence photos you attach to them. These are public: they appear to other Tallow users on the restaurant page and feed its community score, shown next to the username you choose.
- A username, and a profile photo if you add one. Both are public — they appear on the leaderboard and on any restaurant reviews you post. You can change them anytime in Settings. If you sign in with Apple and choose to share your name, we store it as your display name; there is no name field in email sign-up.
- The standards you pick for personalized scoring (for example “no seed oils” or “no ultra-processed”), the restaurant categories you say you care about, and the other onboarding answers you give us (whether you shop for kids, how often you shop, your goals, how you heard about Tallow), so the app can score products and places against what you actually want. Some of those onboarding answers — what you avoid, whether you shop for kids, how often you shop, your goals, and how you heard about us — are also attached to your profile in PostHog, our analytics provider, so we can tell which kinds of shoppers get value out of the app.
- A push notification token, if you allow notifications, so we can send you the alerts you asked for. Turn notifications off in iOS Settings and it stops being used.
- Product usage analytics, crash/error reports, and session replays — which screens you open, which features you use, where the app breaks, and a masked screen recording of the session itself — so we can find bugs and see which parts of the app are worth building on. Session replay is described in detail under PostHog in “Third parties we use” below.
- Your subscription status and purchase history — which plan you bought, its price and currency, and the store’s transaction identifier — so the app knows whether to unlock Premium and so we can measure which ads bring in subscribers. Apple’s App Store or Google Play processes the payment; we never see your card details.
- Device and advertising identifiers: your device’s advertising ID (used by the Meta and TikTok SDKs, see below), a random analytics ID PostHog assigns you (reset when you sign out), and your app version and update channel, so a crash report can be traced to the build it came from.
Third parties we use
We do not sell your data and there are no ads inside Tallow. We do rely on a small number of services to run and grow the app, and we would rather name them than hide behind a blanket “no trackers” claim:
- Supabase — hosts your account, scan history, saved products, ratings, and photos (Postgres and object storage, in the United States).
- PostHog — product analytics, error tracking, and session replay. It receives usage events (screens viewed, scans completed, searches run, paywall interactions, subscription started), crash reports including the error message and stack trace, your onboarding answers as profile attributes, and your account identifier, so we can debug real sessions.
Session replay is on. That means PostHog records a replay of your screens as you use the app, so we can watch back a bug or a place where people get stuck. Everything you type into a field is masked, every image and photo is masked, and the places that display your email address, along with the camera viewfinder, are individually blocked from the recording. Console logs are not captured; network request timing is, because scan speed is the thing we tune. Replay never runs in development builds, and no analytics of any kind are sent from them. - Superwall — runs the paywall, takes you through checkout, and tells the app whether your subscription is active. We send it your account identifier; it handles the purchase itself and so holds the product you bought, its price and currency, and the store transaction identifier, which it reports back to the app. It is sent no scans, ratings, location, or email.
- Apple App Store and Google Play — handle billing, renewals, cancellations, and refunds for Tallow Premium. Your payment details go to them, never to us. Apple additionally reports completed purchases to Meta on our behalf (see below).
- Meta (Facebook) — measures which ads bring in subscribers. The app itself sends Meta no purchase event; the Meta SDK logs app installs and app opens, and Meta derives purchases server-side from App Store data rather than from anything the app sends. Meta receives your device advertising identifier along with those events. On iOS that identifier is only shared if you grant App Tracking Transparency permission when we ask; decline and events are still sent, but without an identifier that can be linked back to you. On Android the advertising ID is used unless you opt out in your Google account settings (Settings → Google → Ads), where you can also reset or delete it. We do not send Meta your scans, ratings, location, or email.
- TikTok— measures which ads bring in subscribers, the same job Meta does. When you start a free trial the app sends TikTok a “subscribe” event, and when you take out a paid subscription it sends a “complete payment” event; either way the event carries the price, the currency, the store product identifier, and the store transaction (order) identifier. The TikTok SDK separately logs app installs, app opens, and whether you came back on day two, and receives your device advertising identifier subject to the same iOS App Tracking Transparency answer and the same Android ad-ID opt-out described above. TikTok is sent no scans, ratings, reviews, location, or email, and no purchase event leaves development builds.
- OpenAI and Google (Gemini) — used to research products we do not already have data for, to read the photos you take when you contribute a product we are missing, and to moderate restaurant reviews and evidence photos before they go public. What we send is the product barcode, name, and label text; the front-of-pack and ingredients-label photos from a contribution, so the pack can be checked and the ingredients read off it; and the review text and any evidence images being moderated — never your identity, email, or history. Requests go to OpenAI first and to Google only if OpenAI fails.
- Open Food Facts — the public product database we look products up in. Their data is re-published under their ODbL terms. When you contribute a product we do not have yet, the front-of-pack and ingredients-label photos you take are forwarded to Open Food Facts so the barcode gets covered for everyone. Those photos go up against the product, not against your name or account.
- Foursquare— supplies the underlying restaurant place data and photos on the map. Place data is loaded into our own database in bulk ahead of time, and photo requests are made by our servers using only the place’s identifier — Foursquare receives nothing about you, including your location.
What we do NOT do
- We never sell or rent your personal data, and we show no ads inside the app.
- We never share your scan history, saved products, ratings, reviews, location, or email with advertisers. All an ad platform receives is the install / app-open, purchase and advertising-identifier data described above.
- No background location tracking. We request location only while the restaurant map is open, only to find the places around you — never in the background, and we never keep a record of where you go.
- Camera frames are only captured at the moment you scan or photograph a product, and only to decode the barcode and produce a product display image — we do not stream, record, or retain camera footage outside of that.
- We never accept payment from the brands or restaurants we rate, so nothing in this policy — or in a score — is for sale.
What is public
Some of what you contribute is meant to be seen by other people, and it is worth being explicit about which: your username and profile photo, your restaurant ratings, reviews and evidence photos, your position on the leaderboard, and any product photos you contribute. Your email, scan history, saved products, and personalized standards are private to your account.
How your data is protected
Every connection the app makes — to our own backend, to PostHog, to Superwall, and to the ad networks named above — runs over HTTPS, so all of the data described on this page is encrypted in transit. Access to the database that holds your account is restricted per-user by row-level security, so one account cannot read another’s private data.
Deleting your account
In the mobile app, go to Settings → Delete account. Your account, scan history, saved products, personalized standards, the restaurant ratings and reviews you posted, your profile photo and any evidence photos or videos you uploaded are permanently removed immediately, and if you signed in with Apple we revoke that sign-in too. There is no soft-delete and no recovery period; the row is gone before the next request lands. Product photos already serving as a barcode’s display image may remain on the product page, since they are stored against the product rather than your identity. If you have trouble, email support@tallow.app and we will purge your data within 7 days.
Children
Tallow is not directed at children under 13. We do not knowingly collect data from minors. If you believe a child has signed up, email us and we will delete their data.
Changes
If we materially change this policy, we will surface the new policy in-app the next time you open Tallow and ask you to acknowledge it.
Contact
Questions, requests, or data deletion concerns: support@tallow.app.