CyborgDev
Legal

Privacy Policy — Flipside

Last updated: September 6, 2026  ·  CyborgDev

Flipside scans food labels and scores them. This policy says what the app does with information, in plain language.

Three things are worth knowing up front, and the rest of this page is the detail behind them:

What stays on your phone

All of this is stored on your device and is never sent anywhere:

Deleting the app deletes all of it. "Reset everything" in Settings does the same without uninstalling.

Photographs of labels

When a product is not in our catalogue, or its record is missing the parts we need to score it, Flipside offers to read the label with your camera. You are asked for a photograph of the ingredients label, and one of the front of the pack so that other people can recognise the product.

Those photographs are sent to a reading service to be transcribed. They go to our own server, which passes them to Google's Gemini API and receives back the words printed on the label — the ingredient list, the nutrition figures, the brand and the product name. That is all the service is asked for; it is not asked to judge the food, and the score itself is worked out on your phone afterwards.

What that means in practice:

What a reading shares with other users is the text from the panel and the picture of the front of the pack — see "Label readings you contribute" below, including why there is no longer a switch for the text.

Explaining an ingredient

Tapping a marked word in an ingredient list opens what that substance is, what it is doing in the food, and its published daily limit where one exists. All of that is written into the app and works with no signal at all.

Under it there is a button reading Explain this in plain words. Only if you press it, we send to the same reading service: the name of that one ingredient, the sentence the app has just shown you, the product's name, and the language the app is set to — and, in one case only, the name of an allergen you asked to be warned about. The answer comes back, is shown under the sentence you already had, and is kept in memory until you close the app.

About that allergen. If you have told Flipside to warn you about milk, and the app has already warned you about milk on the product you are looking at, then pressing that button also sends the word Milk — so the answer can say which of the ingredients is the reason you are being warned. That is the whole of it, and the limits are worth stating plainly:

An allergy is health information, which is why it is described here in this much detail rather than folded into the sentence above. If you would rather it never left the device, do not press the button, or remove the allergen in Settings.

If the service cannot be reached the app simply keeps the explanation it already gave you.

What leaves your phone

Photographs you take of a label are one of these, and they are described in full in the section above, as is the ingredient explanation. The rest is below.

1. The barcode you scan

Only when the phone does not already hold the product. If you have downloaded the products file described above and the barcode is in it, the score is worked out on your device and no request is made at all. What follows applies to the rest — new products, products the file does not cover, and every scan on a phone that has not downloaded it.

To look a product up, the barcode is sent to:

When our record for a barcode has no ingredient list, we also ask Open Food Facts whether it holds another record of the same product — the same database, one further request, carrying the product's brand and name rather than anything about you.

We do not keep a record of which barcodes you scanned. The history is on your phone only.

2. Label readings you contribute

When you photograph a panel we could not otherwise read, the figures from it are added to a shared record, so the next person who scans that product gets them too. This is how the app gets better: every label read once is a product nobody else has to photograph.

The photograph of the panel is never part of this — only the words that were printed on it. The photograph of the front of the pack is shared, as its own thing, under the rules in "Photographs of labels" above: only if the reading service confirms it is a packaged food, only the first one per barcode, named after the barcode and carrying nothing else.

What is sent:

What is not sent, and is not stored anywhere in that record:

Because no identifier is stored, two people photographing the same tub produce identical entries. There is no way for us — or for anyone reading the database — to tell which readings came from which person, or to link any two readings together. That is also why we cannot offer to delete "your" contributions: once made, there is nothing that marks them as yours.

There used to be a switch for this in Settings, and it was removed on 18 August 2026. What travels is an ingredient list and a nutrition panel — the text on the outside of a packet, carrying nothing about the person who read it — and asking permission for that suggested a risk that is not there. If you would rather a particular reading were not in the shared record, write to us and we can remove or suppress entries for a barcode.

3. Reports

"This looks wrong" on a product sends us a report when you tap it. What is sent is the barcode, the label the score was calculated from, the score itself and which version of the scoring produced it — the same shape, and the same rules, as a shared label reading:

We send it because the disagreement is only useful with the label attached: most reports turn out to be products whose public record is too thin to score well, and with the label we can rebuild exactly what the app did and check it. Nobody can read that table back out — reports go in and are never readable from the app or by anyone using it.

Crash reports are sent automatically to Sentry so that we can fix the place where the app broke. A report contains the error message and readable stack trace, the Flipside version and build, the exact over-the-air update and runtime, the operating-system version, device model and JavaScript engine. Sentry keeps error reports for 30 days on its free plan.

Crash reporting is configured without session replay, screenshots, performance monitoring, logs, request capture or automatic breadcrumbs. Reports do not contain scan history, photographs, preferences, barcodes, product or request contents, an account or a device identifier. IP addresses are not stored. A filter in the app removes those fields before a JavaScript report is sent, and the same server-side rules cover native crash reports.

The error screen still offers a separate share-sheet report. That copy leaves only if you choose to send it, and it goes wherever you choose.

4. Counts of what the app could not do

Flipside keeps a small number of daily counts on our own server, so that we can see when the app is failing at something. This is separate from Sentry crash diagnostics, and nothing follows a person between screens, between scans or between days.

What is counted is a closed list of things that either worked or did not: a scan that began, a scan that produced a score, a scan we refused to score, a scan where we could only read part of the label, a barcode our catalogue does not hold, a label read in the cloud, a label read on the phone instead, a photograph that still did not yield enough to score, and whether a product had any better options to show.

Seven of those counts carry the barcode — the ones about a product we could not answer for. That is how we find out which products are failing, so we can fix them. A barcode is a fact about a packet on a shelf, not about the person holding it.

The rest of the list is about the app rather than about a product: the app was opened, the app fell over, camera permission was refused, setup and its product demonstration were begun or finished, a search result, saved product or better option was opened, and a product was saved. Subscription counts cover the price being shown, purchase and restore attempts, purchase, cancellation, restoration, an empty or failed restore, a purchase waiting for parental approval, and a purchase the App Store refused. Those are the numbers that tell us whether the app is working for the people who install it, and none of them carries a barcode or anything else.

The one about falling over is still only a tally. It records that the error screen appeared and nothing else. The diagnostic report described in section 3 is sent separately to Sentry.

What is stored is a running total per day. What is not stored, anywhere in it:

Nothing here follows a person from one screen to the next. Each of these is its own daily total, and they cannot be joined up: "forty people opened the app" and "nine people finished the setup" are two numbers, and there is no way for us to know whether any particular one of the forty was one of the nine.

Because there is no identifier and no timestamp finer than the day, a count is a number and nothing else: there is no way for us, or for anyone else, to tell which phone added to it, or to link any two counts together. Nobody can read that table back out through the app.

We added this because the alternative was worse. Every fault we have fixed was found by testing on our own phone; anything that only goes wrong on somebody else's simply stayed broken, quietly, for everybody. A count that says "one scan in twelve of this barcode ends with no score" is the difference between that and a fix.

5. Your subscription

Subscriptions are handled entirely by Apple. Payment details are never seen by Flipside — we receive only whether a subscription is active. Apple's privacy policy covers that transaction.

Children

Flipside is not directed at children under 13, and we do not knowingly collect information from them. The app has a setting for scanning food for children; that preference is stored on the phone and sent nowhere.

Your rights

Data protection law gives you rights to access, correct, and delete personal information held about you.

There are no accounts and no profiles, and nothing in our records identifies a person — so there is no file to send you, correct or delete. Deleting the app removes everything held on your phone.

If you believe a shared label entry is wrong, tap "This looks wrong" on the product or write to us — we can remove or suppress entries for a barcode.

If you are in the UK or the European Union

This section says the same things again in the words the UK GDPR and the EU GDPR use. Nothing in it describes anything the app does that is not already described above.

Who is responsible. CyborgDev is the data controller for this app. You can reach us at support@cyborgdev.co, which is the only address we use.

What we rely on to do it. Almost nothing here is information about a person, and where the law would call something personal data, this is why we process it:

How long anything is kept. A contributed label reading and a report stay for as long as the product is in the shared record, because that is the whole point of them — they are facts about a packet, not about a person. A daily count is a number in a row per day and is kept indefinitely; there is nothing in it to expire. What is on your phone stays until you delete it.

Where it goes. Our server and the shared label record are in the United States (Virginia). A label photograph is passed from there to Google's paid Gemini API, which does not use it for training. So information you send leaves the UK and the EU. We rely on the standard contractual clauses our providers offer for that transfer.

Your IP address. Like every request on the internet, the connection itself carries your IP address to the server that answers it. It is not written into any record we keep — not the shared label record, not a report, not a count — and we do not read our providers' connection logs.

Nothing here decides anything about you. A score is a judgement about a food, not about a person. There is no profiling, no automated decision with a legal or similarly significant effect, and no advertising.

Your rights. You can ask us for access to personal data we hold about you, and for it to be corrected, deleted, restricted or handed to you in a portable form, and you can object to our processing it. In practice there is nothing to send you: there are no accounts, nothing we store carries an identifier, and nothing in our records can be traced to a person, so there is no file with your name on it to find. If you believe a shared label entry is wrong, write to us and we can remove or suppress the entries for a barcode.

And you can complain. If you think we have got this wrong, you can complain to your national data protection authority — the ICO in the United Kingdom, the CNIL in France, your Land's authority in Germany — as well as, or instead of, writing to us.

Changes to this policy

If this changes, the date at the top changes with it, and any change that affects what leaves your phone will be said plainly in the app before it takes effect.

Contact

Questions about this policy, or about anything above:

support@cyborgdev.co