Chue
How it works Compare FAQ
Get the app

P  PRIVACY

Privacy policy.

Last updated: May 30, 2026. Effective: May 30, 2026.

Who this applies to

This Privacy Policy explains how Chue ("Chue", "we", "us", or "our") collects, uses, shares, and protects personal information when you use the Chue mobile application, the website at chue.app, and any related services (together, the "Services"). It applies whether you reach us on iOS, Android, or the web.

Chue is the operator of the Services described in this policy. For privacy questions you can always reach a human at privacy@chue.app. By using the Services, you agree to the collection and use of information as described here. If you do not agree, please do not use the Services.

The short version

Chue exists so you can see what is in the food and personal-care products you scan. We collect only what we need to score products, sync your history across your devices, and keep the app working. The essentials:

  • We do not sell your data. Not to advertisers, not to brokers, not to brands. We do not run ads inside the app, and no brand can pay to change a score.
  • We collect little. Your email to sign you in, the products you scan, an optional health profile you choose to fill, and basic diagnostics. No precise location, no contacts, no microphone, no advertising identifiers.
  • Sensitive data is yours. Your health profile is visible only to you and is protected by row-level security on our database.
  • You are in control. You can export or delete everything tied to your account at any time, in the app or by email.
  • Payments never touch us. Apple and Google process every transaction. We never see or store your card number.

The rest of this page is the detail behind those promises.

What's in this policy

  • 1. Information we collect
  • 2. How we use your information
  • 3. Legal bases we rely on (EEA / UK)
  • 4. Photo identification and AI features
  • 5. When and with whom we share information
  • 6. Cookies and tracking on the website
  • 7. International data transfers
  • 8. How long we keep your information
  • 9. How we keep your information safe
  • 10. Your privacy rights
  • 11. United States state privacy rights
  • 12. Do-Not-Track and Global Privacy Control
  • 13. Children's privacy
  • 14. Health information
  • 15. Third-party links
  • 16. Changes to this policy
  • 17. Contact and how to exercise your rights

1. Information we collect

We collect the categories below. Most of it you give us directly; some is generated automatically as the app runs.

Account information. When you create an account you provide an email address. If you sign in with Apple or Google, we receive a unique identifier and the email associated with that login (with Sign in with Apple you may choose Apple's private relay address, and that is all we ever see). We use this only to authenticate you and to sync your data across devices. We never receive your Apple or Google password.

Scans and product activity. The barcodes you scan, the score we compute, the regulatory flags and additive matches returned, the product category, whether you tagged an item as "purchased" or "researching", any items you save to your pantry or bookmarks, and your scan history. This is stored against your account so you can review it across devices.

Health profile (optional). If you choose to fill it in, your height, weight, age, dietary goals, and the ZIP code you enter to get a tap-water grade. You are never required to provide this to use the core scanner. It is stored on your account, protected by row-level security, and visible only to you.

Camera input. To scan, the app uses your camera to read a barcode or, in photo mode, to identify a product. Barcode reading happens on your device. In photo mode, the single image you capture is sent for identification (see Section 4) and is not stored by us afterward. We do not record video, we do not access your photo library, and we do not run the camera in the background.

Subscription status. Whether you have an active Chue Premium subscription, the plan, and renewal/expiration status. This comes to us through our subscription processor (RevenueCat) from your App Store or Google Play receipt. We never receive your payment-card details.

Community contributions (optional). If you post to the community feed, we store the text you submit, the product it references, and the time you posted.

Friends and invites (optional). If you connect with friends, we store the friendship relationship and your invite code so the feature can work.

Device and diagnostic data. Basic technical data needed to operate and debug the app — app version, operating-system version, device model, language, coarse error and performance information, and anonymous crash reports. Before any diagnostic log leaves your device, we automatically scrub anything that looks like personal data (for example email addresses and tokens).

We do not collect: your precise GPS location, your contacts, microphone audio, photos beyond the single frame you point at the camera, biometric identifiers, your Social Security number, or advertising identifiers (IDFA). We do not build advertising profiles about you.

2. How we use your information

  • To run the scoring pipeline. A barcode you scan is sent to the public product databases we cite so we can assemble nutrition facts, the ingredient panel, and regulatory flags, then compute a score.
  • To identify products from a photo when you use photo mode (see Section 4).
  • To compute a tap-water grade from EPA Safe Drinking Water records for the public utility serving the ZIP you enter.
  • To sync your account — scan history, pantry, bookmarks, health profile, friends, and community posts — between your devices.
  • To operate subscriptions — to know whether Premium is active and to unlock the right features.
  • To keep the Services secure — to detect, prevent, and respond to fraud, abuse, and technical problems.
  • To support you when you email us, and to send you essential service messages (for example a sign-in link or an important policy change). We do not send marketing email unless you opt in.
  • To improve the app using aggregate, non-identifying measures (how many scans happened this week, the most common product categories, error rates). These do not identify you.
  • To meet legal obligations and enforce our Terms.

3. Legal bases we rely on (EEA / UK)

If you are in the European Economic Area or the United Kingdom, we process your personal data only when we have a valid legal basis:

  • Performance of a contract — to provide the Services you ask for (scanning, syncing, subscriptions).
  • Consent — for optional features such as your health profile, photo identification, and the tap-water grade. You can withdraw consent at any time by deleting that data or by not using the feature.
  • Legitimate interests — to keep the Services secure, to debug and improve the app with non-identifying analytics, and to communicate essential service information. We balance these against your rights.
  • Legal obligation — when the law requires us to retain or disclose information.
  • Vital interests — in the rare case processing is needed to protect someone's life.

4. Photo identification and AI features

Chue's photo-search feature uses artificial intelligence to identify a packaged product from a picture. When you take a photo in this mode, the image is sent to our AI provider, Anthropic (the maker of Claude), which returns the product's likely name and brand. We then run that result through the normal scoring pipeline.

A few commitments about this feature:

  • It runs only when you actively use photo mode. The camera is never analyzed in the background.
  • We do not store the photo after identification, and we do not attach your identity to it.
  • Our AI provider processes the image to return a result and, under our commercial agreement with them, does not use it to train their models.
  • We do not use your scans, photos, or health profile to train any advertising or profiling model.
  • AI identification is a best-effort guess and can be wrong; always confirm against the actual product.

5. When and with whom we share information

We do not sell your personal information and we do not share it for cross-context behavioral advertising. We disclose information only to the service providers ("sub-processors") that make the app work, each of which is bound to use it only on our instructions:

  • Supabase — authentication and database hosting. Stores your account, scans, health profile, and other account data on our behalf.
  • RevenueCat — subscription management. Reads your App Store / Google Play purchase receipt to tell the app whether Premium is active. Never receives your card details.
  • Apple and Google — process all subscription payments and provide the app platforms and (if you choose) social sign-in.
  • Anthropic — AI photo identification, as described in Section 4.
  • Product databases — the barcode you scan is sent to Open Food Facts, Open Beauty Facts, USDA FoodData Central, UPCitemDB, and (when enabled) Nutritionix, FatSecret, and Edamam, so we can assemble the product's facts. These receive only the barcode — never your email or any account identifier.
  • EPA Envirofacts — the ZIP you enter for a water grade is sent to the U.S. EPA's public drinking-water API. No account identifier is attached.
  • Vercel — hosts the chue.app website (this page).

We may also disclose information (a) to comply with the law, a subpoena, or a lawful government request; (b) to protect the rights, safety, and property of Chue, our users, or the public; and (c) in connection with a merger, acquisition, or sale of assets, in which case we will continue to protect your information and notify you of any change in control or use.

6. Cookies and tracking on the website

The Chue mobile app does not use third-party advertising cookies or trackers. The chue.app website uses only the minimal cookies and local storage needed for the site to function and to remember your basic preferences. We do not use the website to build advertising profiles. If we ever add optional analytics, we will request consent where the law requires it and offer a way to opt out.

7. International data transfers

Chue is operated from, and stores data on servers located in, the United States, and our sub-processors may process data in the United States and other countries. If you access the Services from the EEA, the UK, Switzerland, or another region with data-transfer rules, your information may be transferred to a country with different protections. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum) with our sub-processors. You may request a copy of the relevant safeguards by emailing us.

8. How long we keep your information

  • Account, scans, pantry, bookmarks, friends, and community posts — kept until you delete them or delete your account.
  • Health profile — kept until you delete it or your account.
  • Diagnostic logs — kept for up to 30 days, then deleted, and scrubbed of personal data before storage in any case.
  • Photos used for identification — not retained after the result is returned.

We may keep a limited record longer where we must to comply with the law, resolve disputes, or enforce our agreements. When we no longer need information, we delete it or irreversibly anonymize it.

9. How we keep your information safe

We use technical and organizational measures designed to protect your information, including encryption in transit (HTTPS/TLS), encrypted storage at rest, row-level security so each user can only reach their own records, scoped access controls, and PII scrubbing of diagnostic logs before they leave your device. No method of transmission or storage is ever 100% secure, so we cannot guarantee absolute security, but we work to protect your information and to respond quickly if something goes wrong. If a breach affects your personal data, we will notify you and the relevant authorities as required by law.

10. Your privacy rights

Depending on where you live, you have some or all of the following rights over your personal information:

  • Access — get a copy of the data we hold about you.
  • Portability — receive your data in a portable, machine-readable format.
  • Rectification — correct data that is wrong or out of date.
  • Erasure — delete your account and the data tied to it.
  • Restriction and objection — limit or object to certain processing.
  • Withdraw consent — for anything we process based on consent, at any time.
  • Non-discrimination — we will never penalize you for exercising a privacy right.

You can act on most of these yourself: Export by emailing privacy@chue.app from your account address, and we will send a machine-readable copy within 30 days. Delete by opening the app, going to Profile, and tapping "Delete my account" — everything tied to your email is removed within 30 days. You can also email us to correct data or exercise any other right. If you are in the EEA or UK and believe we have mishandled your data, you may lodge a complaint with your local supervisory authority, though we hope you will contact us first.

11. United States state privacy rights

Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have specific rights, including the right to know, access, correct, delete, and obtain a portable copy of their personal information, and to opt out of the "sale" or "sharing" of personal information and of targeted advertising and profiling.

We do not sell your personal information and we do not share it for cross-context behavioral advertising, so there is nothing for you to opt out of in that respect. We do not knowingly process the personal information of consumers we know to be under 16 for those purposes.

In the past 12 months, the categories of personal information we have collected map to the statutory categories as follows:

  • Identifiers (email address, account identifier) — collected; not sold or shared.
  • Customer records (optional health profile you provide) — collected; not sold or shared.
  • Commercial information (subscription status) — collected; not sold or shared.
  • Internet/app activity (scans, in-app interactions, diagnostics) — collected; not sold or shared.
  • Geolocation (the ZIP you enter — coarse, not precise GPS) — collected; not sold or shared.
  • Sensory information (the single camera frame used for photo identification, processed transiently and not retained) — collected; not sold or shared.

We do not collect Social Security numbers, precise geolocation, biometric identifiers, or sensitive categories beyond the optional health profile you choose to share. To exercise a state privacy right, email privacy@chue.app. We will verify your request against your account email and respond within the timeframe the law requires. You may use an authorized agent, and if we deny a request you may appeal by replying to our decision. California's "Shine the Light" law: we do not share personal information with third parties for their own direct marketing.

12. Do-Not-Track and Global Privacy Control

Because we do not track you across third-party websites or sell your data, there is no cross-site tracking to disable. Web browsers and some extensions send "Do-Not-Track" (DNT) or "Global Privacy Control" (GPC) signals; there is no common industry standard for DNT, but as we do not sell or share personal information, our practices already align with an opt-out signal.

13. Children's privacy

Chue is not directed to children. You must be at least 13 years old to use the Services, and we do not knowingly collect personal information from anyone under 13. If you are a parent or guardian and believe your child has provided us personal information, email privacy@chue.app and we will investigate and delete it. Where local law sets a higher age of digital consent, that age applies.

14. Health information

Chue is a consumer information tool, not a healthcare provider, and we are not a "covered entity" or "business associate" under HIPAA. The optional health profile you provide (height, weight, age, goals, ZIP) is used only to tailor what the app shows you and is visible only to you. We do not read data from Apple Health / HealthKit or Google Fit, and we do not use your health profile for advertising, profiling, or training. Chue's scores are informational and are not medical advice — please see the "Not medical advice" section of our Terms of Service.

15. Third-party links

The Services may link to third-party sites or resources (for example a regulator's page or a source database). We are not responsible for the privacy practices of those third parties. This policy applies only to Chue, so please review the policies of any site you visit.

16. Changes to this policy

We may update this policy from time to time. If we make a material change, we will post the updated policy here with a new "Last updated" date and, where appropriate or required, notify you by email or in the app before the change takes effect. Your continued use of the Services after an update means you accept the revised policy.

17. Contact and how to exercise your rights

For any privacy question, request, or complaint, email privacy@chue.app or hello@chue.app. We respond within five business days and complete verified data requests within the timeframe the applicable law requires (generally within 30–45 days). If we are required to designate a data protection officer or EU/UK representative, their details will appear here.

Operator: Chue. Our full registered business name and mailing address will be listed here before public launch.

Chue

Honest scoring, every aisle.

Product

How it works Compare Download FAQ

Legal

Privacy policy Terms of service Data requests

Company

About Contact
© 2026 Chue Built so you can stop reading the back of the box.