Lookt · support@lookt.app

Who we are

Lookt (“Lookt,” “we,” “us”) makes the Lookt app, which scans food barcodes and lot codes and checks them against recall and outbreak notices published by the U.S. Food and Drug Administration (FDA), the U.S. Department of Agriculture (USDA), and the Centers for Disease Control and Prevention (CDC). This policy explains what information the app and its servers collect, how we use it, and how you can delete it.

Lookt is not affiliated with, endorsed by, or operated by the FDA, USDA, CDC, or any other government agency.

Information we collect

Account information

Scanning food and browsing the recall feed need no account. Creating a Pantry requires signing in with Apple or Google — Lookt does not offer email-and-password sign-in. When you sign in, we receive and store only:

We do not receive or store your name, your profile photo, the sign-in tokens Apple or Google issue for that sign-in, or the IP address of the request that created your session.

Pantry

If you save an item to your Pantry, we store the barcode, the product name and brand, an optional product photo, the lot code and best-by date if you provide them, and whether the item is currently linked to a recall.

Push notifications and device

To send Pantry alerts and reminders, we store your device’s push token, its platform (iOS or Android), its time zone, and its language (English or Spanish).

Notification and state preferences

If you have an account, we store your notification toggles and, if you choose to set one, the U.S. state you’d like recall alerts for.

Approximate location

To suggest a state for the recall feed, our server reads the approximate location of your network connection from the request itself. We do not use GPS, and we do not ask for location permission. This approximate location is not stored unless you choose to save a state as a preference.

Crash reports

If the app crashes, we receive an automated crash report. Before it leaves your device, we strip barcodes, lot codes, email addresses, tokens, and your Pantry contents from it, and reduce any account reference to an anonymous identifier.

What we don’t collect

Product data from Open Food Facts

To show a product’s name and photo after you scan a barcode, the app queries Open Food Facts, an independent, open database, directly from your device using the barcode alone. Your account information and sign-in session are never sent to Open Food Facts. Product data and photos are provided by Open Food Facts under its own open license and attribution terms.

How we use your information

How we protect your information

Session credentials are stored securely on your device, not in plain storage. Server-side secrets are kept in Cloudflare’s secret storage, never in our source code. Every account and device request is scoped to your own account; our tests check that one account can never read or change another’s data. API requests are rate-limited.

Keeping and deleting your data

You can delete your account and everything tied to it at any time, from the app or by email — see our account deletion page. Deletion is immediate and permanent: it removes your Pantry items, device and push-token records, notification preferences, and account record, and revokes your Apple sign-in grant if you signed in with Apple.

Children

Lookt is not directed to children under 13, and we don’t knowingly collect information from children under 13. Before you can create an account, we ask a neutral birth-year question; if it shows you’re under 13, we don’t let you create one. If we later learn that we have an account belonging to a child under 13, we delete that account and its data.

Changes to this policy

If we make a material change to this policy, we’ll update the effective date above and, where required, notify you in the app.

Contact us

Questions about this policy? Email support@lookt.app.