LabelSaaf

Privacy Policy

Last updated: 14 September 2026

LabelSaaf lets you photograph a packaged food label or scan its barcode and returns nutrition information and a health score. This Privacy Policy explains what we collect and how we use it when you use labelsaaf.com (the "Service").

See also our Terms of Service.

When you scan

Your label photo is processed to show a score. The photograph is sent to Anthropic to read the nutrition label. Images from successful scans are not stored by LabelSaaf.

Images from scans that fail are kept in private storage for up to 30 days so we can diagnose the failure and improve scan accuracy, then deleted.

You do not need an account to scan.

Waitlist

If you submit your email to the waitlist, we store that address so we can contact you about the launch. We do not share or sell waitlist emails.

Device identifier

An anonymous device identifier is used for rate limiting and product analytics. It is not linked to your name or email.

Signing in with Google

Signing in is optional. You can use LabelSaaf without an account.

If you choose to sign in with Google, Google shares the following with us:

Google account data we receive
WhatWhy we need it
Your Google account identifierThe stable key that identifies your account. We use this rather than your email, because emails can change.
Your email addressTo identify your account to you and contact you about it
Your nameTo show who is signed in
Your profile picture URLTo show who is signed in

We do not receive or request access to your Gmail, Google Drive, contacts, or any other Google service. We request only your basic profile and email.

We do not sell this information, and we do not use it for advertising.

Emails we send

If you create an account we may email the address Google shared with us. Mail about your account — security, deletion, legal notices — is always on. Scan updates (when a pack we could not read becomes readable) and Tips (how to use LabelSaaf) can be turned off at Account → Notifications, or from the unsubscribe link in every email.

Those emails come from [email protected]. A reply goes to the same address and a person reads it. We send them through Resend. We do not use your address for advertising.

Your scan history

Before you sign in, scans made in your browser are stored against an anonymous identifier (see below) and are not linked to your name or email.

When you sign in for the first time, the scans that browser has already made become part of your account, so nothing you did before signing in is lost.

For each scan we store the nutrition information read from the label, the product name, brand and barcode where available, the score shown to you at the time, which version of our scoring method produced it, and when it happened.

We store the score you were shown as well as the underlying nutrition information. This means that if our scoring method later improves, we can show you both the current score and the score you originally saw, rather than silently changing your history.

Asking about a scan

In the app you can ask questions about a scan you have already taken — why it scored the way it did, which nutrient cost the most, what a printed serving amounts to. Answers are written by an AI model from Anthropic.

When you ask a question, we send that model three things: the label as we read it and the working behind the score, your question, and the earlier questions and answers in that same conversation. We do not send your name, your email, your account identifier, your preferences, or any of your other scans. Your question is not used to train any model.

We store the conversation against that scan so you can return to it: your question, the answer, and a record of exactly what the model was given, which is what lets us reproduce an answer that turns out to be wrong. We also record what each answer cost us to produce.

If your question mentions a health condition, we do not keep the words. A question that names a condition, a pregnancy, an allergy, a medication or a child is stored as a placeholder instead of what you typed, and it is never sent to our analytics. The model still sees it, because it has to in order to answer — but it answers with what the label says and tells you to speak to your doctor, and it never gives a yes or a no about whether something suits you.

Some answers are not written by the model at all. When you ask what is in a particular quantity, the figures are the label’s own column multiplied out on your device. Nothing is sent anywhere for those.

Your preferences

You can optionally set preferences: things you want called out on the labels you scan. Signed in they are kept with your account; signed out they are kept in this browser (see the end of this section). You can choose:

  • Nutrients to watch: sugar, added sugar, sodium, saturated fat, total fat, trans fat, fibre, protein
  • Ingredients a pack must declare by law: milk, egg, fish, crustacean, nuts, soy, gluten, sulphites. These are the categories Indian labelling rules require a pack to print, so we offer all of them — leaving one out would read as “this pack is clear” rather than “we don’t check that one”. Nuts is a single choice rather than peanut and tree nut separately, because a pack is allowed to declare the whole group as the one word “Nut”.
  • Ingredients a pack need not declare in India: sesame, mustard, palm oil, maida, vanaspati, gelatin, lactose, caffeine, and pure veg or Jain requirements. A pack can contain any of these and never say so, so we can tell you when we find one — never that a product is free of it.
  • Classes of additive:sugar alcohols, added fibres, artificial sweeteners, flavour enhancers, phosphate additives, synthetic colours, preservatives. These are read from the INS numbers a pack prints. Where a pack names a class without a number, we tell you we could not check it — never that it is clear.
  • Ingredient names you type in yourself
  • An age group, as a band such as 31–45. We never ask for your date of birth.

Preferences change what a label calls out, and nothing else. They do not change any score, and they do not filter, hide, or recommend products. The score for a product is the same for every user, whatever their preferences.

Some of these choices can reveal things about you: watching sugar may suggest diabetes, flagging nuts may suggest an allergy, and choosing Jain or pure veg reflects a belief. So we are strict about this data. We only know what you enter directly — we never infer preferences, conditions, or beliefs from your scans or from how you use the Service. We never sell this information, never share it with advertisers, and never use it to profile or segment anyone.

Your age group has exactly one job: the reference amounts we quote, such as an FSSAI daily value, are set for an average adult, and an age group lets us quote one that fits your age — or tell you plainly when none does. It never affects a score. We store your age group today but do not yet use it, because age-aware reference amounts are not built; we will update this section when they are.

A flag is a heads-up, not a medical allergy check. Reading ingredients from a photograph can miss things, and where a pack does not print an ingredient list, we say so rather than implying the product is clear of what you flagged. Always read the pack itself for allergens.

If you are signed in, your preferences are stored on our servers against your account and are permanently deleted when you delete your account.

If you are not signed in, you can still set flags. They are stored in this browser, and they are sent with each scan so we can flag against them — used for that request and not stored on our servers. Clearing your browser data clears them. When you sign in for the first time, flags set in this browser become your account’s preferences, unless that account already has preferences saved — in which case yours are left exactly as they were. We never take an age group this way; it is only ever set by you, signed in.

The anonymous identifier

To keep your scan history together before you sign in, we set a cookie in your browser containing a random identifier. It is not linked to your name, email, or any other identifying information, and it cannot be read by JavaScript on the page.

If you have signed in, we also set a second, separate cookie that simply records that you have an account — its value carries no identifying information and nothing else about you. Unlike the identifier above, this one can be read by JavaScript on the page, which is what lets the Service recognise you as signed-in immediately, before it has finished checking your session with our server.

Both cookies are strictly necessary for the Service to remember your scans and sign-in state across page loads. Neither is used for advertising or cross-site tracking.

If you clear your cookies, that identifier is lost and your unsaved scan history starts fresh.

How long we keep things

  • Scans linked to an account: kept until you delete them or delete your account.
  • Preferences: kept until you change or remove them, or until you delete your account.
  • Scans not linked to an account: Scans not linked to an account are retained while we develop the service; we are introducing automatic deletion and will update this policy when it is live.
  • Questions you ask about a scan: kept with that scan until you delete it or delete your account.
  • Images from failed scans: Images from scans that fail are kept in private storage for up to 30 days so we can diagnose the failure and improve scan accuracy, then deleted.

Deleting your account and data

You can delete your account from within the Service at any time. When you do, we permanently delete your account record, your Google account link, your active sessions, your saved scan history, the questions and answers in any conversation you had about a scan, and your preferences. The identifier in your browser is also reset, so the deleted history cannot be recovered or re-linked.

Deletion is immediate and cannot be undone.

Who processes your data

We use the following service providers. Each processes only what is needed to run LabelSaaf.

Service providers that process LabelSaaf data
ProviderPurposeWhere
GoogleSign in with GoogleGlobal
Fly.ioApplication hostingMumbai, India
SupabaseDatabaseMumbai, India
UpstashRate limitingMumbai, India
CloudflareDNS, security, bot protectionGlobal
Cloudflare R2Failed-scan image storageGlobal
AnthropicReading nutrition labels from photographs, and answering questions about a scanUnited States
ResendTransactional emailUnited States
MixpanelProduct analyticsEuropean Union
New RelicError and performance monitoringGlobal

Photographs you submit are sent to Anthropic to read the label. They are not used to train any model.

Product information is also drawn from Open Food Facts, a public database, under the Open Database License.

Your rights

Under India's Digital Personal Data Protection Act, 2023, you may request access to the personal data we hold about you, ask us to correct it, ask us to delete it, and withdraw consent for processing.

Account and scan-history deletion is available directly in the Service. For anything else, contact us at [email protected] and we will respond within 30 days.

Health information

LabelSaaf’s scores use no information about you. Every score is calculated from the product’s label alone and is identical for every user. We never infer anything about your health, medical conditions, allergies, or dietary requirements from your scans or from how you use the Service.

If you set preferences, you are choosing to tell us what to flag. We store exactly what you enter and nothing more, and we treat it as described in “Your preferences” above.

The same care applies to questions you ask about a scan. If a question names a condition, we keep a placeholder rather than your words, and we never build a profile from it. See “Asking about a scan” above.

Some of those choices can suggest something about you — watching sugar may suggest diabetes, flagging nuts may suggest an allergy, and choosing to watch trans fat, phosphate additives or sugar alcohols may suggest a heart, kidney or digestive concern. That is why we ask you directly rather than inferring it, why a preference is never sold or used to profile you, and why it is deleted with your account. A preference is a request to read the label a certain way. It is not a medical record, we do not treat it as one, and nothing in the app gives medical advice.