Lookt · support@lookt.app
Who we are
Lookt (“Lookt,” “we,” “us”) makes the Lookt app, which scans food barcodes and lot codes and checks them against recall and outbreak notices published by the U.S. Food and Drug Administration (FDA), the U.S. Department of Agriculture (USDA), and the Centers for Disease Control and Prevention (CDC). This policy explains what information the app and its servers collect, how we use it, and how you can delete it.
Lookt is not affiliated with, endorsed by, or operated by the FDA, USDA, CDC, or any other government agency.
Information we collect
Account information
Scanning food and browsing the recall feed need no account. Creating a Pantry requires signing in with Apple or Google — Lookt does not offer email-and-password sign-in. When you sign in, we receive and store only:
- An account identifier
- The email address Apple or Google gives us for your account, which may be an Apple private relay address if you choose one
We do not receive or store your name, your profile photo, the sign-in tokens Apple or Google issue for that sign-in, or the IP address of the request that created your session.
Pantry
If you save an item to your Pantry, we store the barcode, the product name and brand, an optional product photo, the lot code and best-by date if you provide them, and whether the item is currently linked to a recall.
Push notifications and device
To send Pantry alerts and reminders, we store your device’s push token, its platform (iOS or Android), its time zone, and its language (English or Spanish).
Notification and state preferences
If you have an account, we store your notification toggles and, if you choose to set one, the U.S. state you’d like recall alerts for.
Approximate location
To suggest a state for the recall feed, our server reads the approximate location of your network connection from the request itself. We do not use GPS, and we do not ask for location permission. This approximate location is not stored unless you choose to save a state as a preference.
Crash reports
If the app crashes, we receive an automated crash report. Before it leaves your device, we strip barcodes, lot codes, email addresses, tokens, and your Pantry contents from it, and reduce any account reference to an anonymous identifier.
What we don’t collect
- We don’t store individual scans. We keep only an aggregate daily count of scans, with no barcode or IP address attached.
- We don’t collect GPS location, contacts, or advertising identifiers.
- We don’t run ads, and we don’t sell or share your information for advertising.
- We don’t record your screen or session activity. No session replay or similar tooling runs in the app or on this site.
- We don’t load fonts from a third party. Every font on this site and in the app is self-hosted, so visiting a page never sends a request to Google Fonts or any other outside font service.
Product data from Open Food Facts
To show a product’s name and photo after you scan a barcode, the app queries Open Food Facts, an independent, open database, directly from your device using the barcode alone. Your account information and sign-in session are never sent to Open Food Facts. Product data and photos are provided by Open Food Facts under its own open license and attribution terms.
How we use your information
- To check a scanned item against current recall and outbreak notices
- To watch your Pantry items and alert you if one is recalled, and to send the best-by and check-in reminders you’ve turned on
- To show recalls for the state you’ve chosen, when you’ve chosen one
- To find and fix crashes
How we protect your information
Session credentials are stored securely on your device, not in plain storage. Server-side secrets are kept in Cloudflare’s secret storage, never in our source code. Every account and device request is scoped to your own account; our tests check that one account can never read or change another’s data. API requests are rate-limited.
Keeping and deleting your data
You can delete your account and everything tied to it at any time, from the app or by email — see our account deletion page. Deletion is immediate and permanent: it removes your Pantry items, device and push-token records, notification preferences, and account record, and revokes your Apple sign-in grant if you signed in with Apple.
Children
Lookt is not directed to children under 13, and we don’t knowingly collect information from children under 13. Before you can create an account, we ask a neutral birth-year question; if it shows you’re under 13, we don’t let you create one. If we later learn that we have an account belonging to a child under 13, we delete that account and its data.
Changes to this policy
If we make a material change to this policy, we’ll update the effective date above and, where required, notify you in the app.
Contact us
Questions about this policy? Email support@lookt.app.