Durat — Privacy Policy
Last updated: 11 September 2026 Published at https://durat.app/privacy
Summary
Durat keeps your food data on your device. You can use the whole app without an account. If you choose to create one, we process your email address and a small log of the barcodes you scan on our server. We show no ads, use no analytics SDKs, and never sell or share your data with advertisers.
Accounts (optional)
Durat works fully in guest mode — no account, no email, nothing sent to our server.
If you choose to sign in, you can do so with an email address and password, or with Sign in with Apple. Authentication is operated for us by Supabase (supabase.com), which stores your email address, a hashed password, and an account identifier. With Sign in with Apple you may choose Apple's private relay address, in which case we never see your real address.
Signing in is required only for features that need a server: your personal scan history and contributions to the shared product database (below).
Data we process
Stored only on your device (never sent to us):
- Food items, expiry dates, quantities, prices, categories
- Consumption and waste history, statistics, shopping list
- Nutrition information attached to items
- App settings (theme, notification preferences)
You can export this data (backup/CSV) and delete it at any time by deleting items or uninstalling the app. Uninstalling removes all locally stored data.
Stored on our server (only while you are signed in):
- Scan log: when you scan a barcode, we store the barcode, product name, category, brand, package size, and nutrition values, linked to your account identifier. This lets you see what you have scanned before. Guest sessions have no account identifier and these records are rejected — nothing is stored.
- Shared product database: confirmed product details (barcode, name, category, brand, package size, nutrition) are added to a community product catalogue so other users get faster lookups. These entries describe the *product*, not you, and are not linked to your account identifier.
- Nutrition submissions: when you confirm a product's nutrition from a photographed label, we store the barcode and the four macro values, linked to your account identifier. This lets us cross-check readings for the same product against other users' submissions to improve accuracy.
Your food inventory, consumption history, waste statistics, prices, and shopping list are never uploaded — they stay on the device even when you are signed in.
Processed transiently for features you trigger:
- Label photos (OCR): expiry dates and nutrition labels are read on your device first. If on-device recognition cannot read them, the photo is sent through our own proxy server to OCR.space (ocr.space) for text extraction. Images are used only to return the text result and are not stored by us. See OCR.space's privacy policy for their processing terms.
- Barcodes: product barcodes you scan are sent to Open Food Facts (openfoodfacts.org) to fetch product name and nutrition data. Barcodes sent to Open Food Facts are not linked to your identity.
- Product photos: where Open Food Facts has a photograph of a product you scanned, your device fetches that image from their image servers to show on the item. This is an ordinary image request and carries no identifier of you beyond your IP address, which every web request carries.
- Recipe search: names of expiring ingredients are sent to TheMealDB (themealdb.com) to fetch matching recipes.
Third-party processors
- Supabase — authentication, scan log, shared product database
- Cloudflare — hosts our OCR proxy
- OCR.space — cloud text recognition fallback
- Open Food Facts — product lookup
- TheMealDB — recipe lookup
- Apple — Sign in with Apple, app distribution
What we do NOT do
- No advertising, no ad tracking, no analytics SDKs
- No sale or sharing of personal data
- No marketing emails (we have no email list)
- No upload of your fridge contents, consumption history, or spending
Notifications
Expiry reminders and the daily digest are scheduled locally on your device. Disable them anytime in the app's Settings or in iOS Settings → Notifications → Durat.
Your rights (EU/GDPR)
Because most of your data lives on your device, you exercise most rights directly: access and portability via the in-app backup export, erasure by deleting items or uninstalling.
You can delete your account from inside the app: Settings → Account → Delete account. This removes your account, your scan log, and your nutrition submissions from our server immediately, and also erases everything Durat stores on the device itself — your items, history, statistics, shopping list and settings. It cannot be undone. Entries you contributed to the shared product catalogue remain, because they describe products and are not linked to you.
For access, correction, or export of that data, contact us at support@durat.app; we will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
Legal bases: performance of contract (providing your account and scan history), legitimate interest (fulfilling the OCR, product-lookup, and recipe features you trigger, and maintaining the shared product catalogue).
Children
Durat is not directed at children under 13 and does not knowingly process their data.
Changes
We will update this policy here and change the date above. Material changes will be noted in the App Store release notes.
Contact
support@durat.app