Privacy and data handling
What Aisle knows about you, and what it refuses to.
Draft for the pilot · last updated 11 September 2026 · not yet reviewed by a lawyer
The short version
- Aisle works without an account. Most people will never create one.
- Your goal, priorities and allergens live on your phone. They are sent with each scan so the answer can be personalised, in request headers that are not written to access logs, and they are never stored against anything that identifies you unless you create an account.
- Aisle counts how the app is used against a random installation id that you can reset. That id is not an identity, and no goal, priority or allergen is ever attached to it.
- Aisle does not know what you bought. Recent scans stay on your phone.
- No brand can pay for a score, and nothing about you is sold or shared for advertising.
Who is responsible
Aisle is operated by [legal name and address to be filled in], the Netherlands. Contact: [email protected].
What is processed, and why
| Data | Where it lives | Why | Legal basis |
|---|---|---|---|
| The barcode you scan or type | Sent to the API; the product record is cached on the server for every shopper | To look the product up and score it | Performance of the service you asked for |
| Your goal, nutrition priorities and allergens | On your phone. Sent as request headers with each scan. Stored on the server only if you create an account | To personalise the verdict and to warn you about allergens | Performance of the service; allergen data is processed on your explicit request when you enter it |
| Recent scans and a saved copy of each result | Your phone only | So you can find a product again, and read a saved verdict when there is no signal | Not transmitted |
| Usage events: a scan happened and how it ended, a comparison was viewed, whether you said a recommendation changed your choice, how long a verdict took | Server, against a random installation id | To learn whether Aisle is useful. The North Star is whether a recommendation changed a purchase | Legitimate interest in improving the product; the id is resettable from the profile screen and carries no profile data |
| Account: email, password hash, your profile, household members and their allergens, prices you enter | Server, only if you create an account | To keep your profile across devices, to buy for other people, and to attribute prices you contribute | Performance of a contract you entered; allergens of household members on your explicit request |
| Products you add for an unknown barcode | Server, in the shared catalogue, attributed to your account if you have one | So the next shopper who scans it finds it | Performance of the service; you are told before submitting |
| Error reports | Sent to an error-tracking service, with your profile stripped from every report | To find crashes | Legitimate interest |
What Aisle deliberately does not do
- It does not attach your goal, priorities or allergens to the installation id, so there is no per-person health history on the server for anonymous users.
- It does not build a record of what you bought. A scan is not a purchase, and Aisle does not pretend otherwise.
- It does not use your data for advertising, sell it, or share it with brands. Scoring cannot be bought.
- It does not talk to Open Food Facts from your phone; only the Aisle server does, so your device is never exposed to a third party.
Your rights
If you have an account you can export everything Aisle holds about you and delete the account from inside the app, without emailing anybody. Deletion removes your account, profile, household, prices and tokens. Products you added to the catalogue stay in the catalogue, with your name removed: they are useful to other shoppers and carry nothing about you once the link is severed. The app shows you exactly this before you confirm.
Without an account, the only server-side data is the usage events against your installation id. Resetting the id from the profile screen makes your installation indistinguishable from a new one. If you want the events deleted as well, send the id shown on that screen to [email protected].
You can also lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens.
Retention
- Account data: until you delete the account.
- Usage events: [retention period to be decided; proposed 24 months].
- Catalogue records, including ones you contributed: indefinitely, as part of the shared catalogue.
- Saved copies on your phone: up to 50 products, replaced as you scan, and gone when you delete the app.
Where
The service runs on servers in the European Union. Error reports, if enabled, go to [provider and region to be confirmed].
Changes
When what the app does changes, this page changes first, and the date above moves.