Grain Grain
Features Pricing Support

Privacy Policy

Last updated: September 8, 2026

Language English Deutsch Français Italiano Español

The translations are a convenience. The English version governs: if a translation and this page disagree, this page is the one that applies.

Grain ("we," "us," or "our") is operated by Sonder Business. We take your privacy seriously. This policy explains what information we collect, why we collect it, and how you can control it. This policy complies with the EU General Data Protection Regulation (GDPR), the UK Data Protection Act 2018, the California Consumer Privacy Act (CCPA), and Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).

1. Information We Collect

1.1 Information you provide

  • Account information: email address and password. An account is required to use the app. Sign in with Apple optionally shares your name and a relay email address.
  • Health preferences: dietary goals, dietary preferences, allergies, health conditions, ingredients to avoid, preferred certifications, preferred stores. All of these are optional and are stored to personalize your Grain Scores. Some of them are health data, which GDPR treats as a special category (Art. 9), so we collect them only if you choose to enter them and we process them on your explicit consent.
  • People you shop for: if you add Family Members, the name or nickname and the emoji you give each person, plus the allergies, health conditions, ingredients to avoid and preferred certifications you record for them. These rows are stored with your account on our servers, so they follow you between devices. They are never sent to our AI providers, not used for analytics, and never used to decide what anyone else sees. Your data export includes each person's name, emoji, allergies, health conditions and ingredients to avoid, and everything we hold about them is deleted with your account. Please add someone only when they have agreed to it: the person you add does not see a consent screen of their own, so you are the one who has to tell them.
  • Questions and searches you type: the free-text questions you ask Ask Grain and the conversation they belong to, plus the product names and terms you enter in Product Search, Explore, and manual entry.
  • Reviews and favorites: products you save or review.

The questions and search terms you type are sent to our AI provider (Google Gemini) in order to answer them, which is what those features do. Your health preferences are different: they are sent to Gemini when, and only when, you turn on "Personalize AI With Health Profile" in the app. Grain asks for that permission separately, in a dedicated in-app prompt, before the first send; accepting our Terms is not consent for it. If you decline, or have not been asked, those fields are stripped from every AI request before it leaves your device. You can withdraw permission at any time from the Settings panel on your profile tab, and the withdrawal applies to every device signed in to your account. See section 4.

1.2 Information collected automatically

  • Scan history: barcodes you scan and when, tied to your account. A Grain account is required to use the app, so there is no anonymous mode.
  • Device and usage data: app version, device model, iOS version, crash reports, and interaction events such as which screens you view. This is collected through Firebase Analytics and Crashlytics, and only if you opt in: both are switched off in the app as shipped and stay off until you say yes on the first-launch privacy screen. The data is pseudonymous, not anonymous. Every event carries an identifier derived from your account ID (a one-way hash of it), which lets us tell one person's sessions apart and also lets us link them back to your account. Scan and product events send the scanned barcode as a shortened one-way hash instead of the number printed on the pack. Search events send the length of your query and how many results came back, never the search term itself.
  • Push notification token: if you allow notifications, your device's Apple push token, together with your device time zone and the app region you have selected, so that alerts arrive at a sensible local hour and only where the app can display them. The token is registered only after you have granted the iOS notification permission. See section 4.1.
  • Purchase data: your subscription status and its expiry date, reported to us by Apple when you subscribe through the App Store. We do not access your payment method: Apple handles all transactions.

1.3 Photos you choose to submit

Barcode scanning itself happens on your device, and the camera frames used to read a barcode are never uploaded. Some optional features work differently, and we want to be plain about them:

  • Photo Identify: when you photograph a product to identify it, that photo is uploaded to our servers and passed to our AI provider (Google Gemini) to recognize the product. It is used for that analysis.
  • Label completion ("snap the label"): when you photograph an ingredient label or nutrition panel to complete a product's data, that photo is uploaded, analyzed by AI, and retained in a moderation/audit trail alongside the resulting data correction, so we can review contributed product data for accuracy and abuse. These photos should show product packaging, not people, so please keep yourself and others out of frame.
  • Ask Grain attachments: when you attach a photo to a question in Ask Grain, that image is uploaded and passed to our AI provider to answer your question. It is used for that conversation.

Any of these photos may come from your camera or, if you choose, from your photo library. In both cases only the specific image you select is sent. Photos are only ever captured and uploaded when you actively use one of these features. Google does not use data sent through our API agreement to train its models.

1.4 What we do NOT collect

  • We do not collect precise location data.
  • We do not track you across other apps or websites.
  • Grain never reads your photo library. When you choose a photo, iOS hands us only that one image, and the app has no access to the rest of your library. Grain can save a scorecard image to your library, but only when you ask it to. We never upload camera or library imagery outside the features described in section 1.3.

2. How We Use Your Information

  • Provide the service: look up products, generate AI ingredient explanations, personalize scores, save your history.
  • Improve the app: understand which features are used, diagnose crashes, fix bugs. This uses the opt-in analytics described in section 1.2 and nothing else.
  • Communicate with you: respond to support requests and send critical account and security email, for example the message confirming that your password was changed.
  • Alert you: send the push notifications described in section 4.1, if you have allowed them: safety recalls and ingredient changes for products you scanned or saved, and a note when a label photo you sent in completes a product.
  • Comply with the law: respond to valid legal requests, enforce our Terms of Service.

We do not sell your personal information to third parties. We do not show you advertising. We do not use your data to train AI models that are offered to other companies.

3. Legal Basis for Processing (GDPR)

  • Contract: to provide the service you requested (scanning, account, subscriptions).
  • Consent: app analytics and crash reporting, which are off in the app as shipped, are asked for on first launch, and can be changed at any time under Profile, then Privacy; push notifications, which you allow and revoke in iOS Settings; and any optional personalization feature you turn on. Where the processing involves health data, whether your own allergies and conditions or the ones you record for the people you shop for, we rely on explicit consent under Article 9(2)(a): your own, collected through the separate in-app prompt described in section 1.1, and, for anyone else you add, the permission you must obtain from them before you enter their details.
  • Legitimate interest: security and abuse prevention, which covers the moderation trail described in section 1.3 and the rate limits that keep the service available. We do not rely on legitimate interest for analytics or crash reporting.
  • Legal obligation: to comply with applicable law.

4. Third-Party Services

We share limited data with the following service providers, each of whom is contractually obligated to protect your data:

  • Supabase (database and authentication): stores your account, health profile, the people you shop for, scan history, favorites, and your device push token. Hosted by Supabase in the United States (AWS us-east-1).
  • Google Gemini (AI): we send product and ingredient text; the photos you submit when you use Photo Identify or label completion (see section 1.3); the free-text questions you ask Ask Grain, together with the conversation they belong to; the product names and search terms you type; and, only while you have turned on "Personalize AI With Health Profile", your own health-profile fields: dietary goals, dietary preferences, allergies, health conditions, and ingredients you have asked us to avoid. With that setting off, or before you have been asked, those health-profile fields are removed from the request and never reach Google. What you record about the people you shop for is never sent to Google, with that setting on or off. Google does not use this data to train its models under our API agreement.
  • Anthropic (AI, not in use today): our backend contains a model router that can serve one feature, finding healthier alternatives, with Anthropic's Claude model instead of Gemini. It is switched off. The router takes that path only when we have configured both an Anthropic API key and an explicit list of tasks, and no task is on that list, so no data is sent to Anthropic. If we ever turn it on, Anthropic would receive the same product and ingredient prompt that Gemini receives for that one feature, and would not receive your account details, your health profile, or the people you shop for. We will update this policy before enabling it.
  • Serper (image search): when a scanned product has no image on file, we query Serper's image search API to find a product photo. We send only the product name and brand, and no user data. Images are cached permanently so we never re-query the same product.
  • Resend (transactional email): sends account and security emails, for example the notification confirming that your password was changed. Receives your email address and the contents of that message. No marketing email.
  • Firebase (Google): Analytics and Crashlytics, and only if you opted in. Receives pseudonymous device and usage data as described in section 1.2, including the account-derived identifier and the hashed barcodes.
  • Apple (App Store and push notifications): handles all payments and may share transaction IDs with us. Apple also operates the Apple Push Notification service (APNs), which delivers our notifications: Apple receives your device's push token and the message we send to it.

4.1 Push notifications

If you allow notifications, our servers send three kinds of push message and no others. We never send marketing pushes.

  • Safety recalls: a product you scanned or saved in the last twelve months is subject to a recall. These go to any account, free or paid.
  • Ingredient changes: a product you scanned or saved in the last twelve months changes its ingredients, or its nutrition moves enough to change its score. These go to subscribers only, at most one a day.
  • Label photos: a label photo you sent in has been processed, and the product it completes is now rated.

Recall and ingredient-change notifications are held outside quiet hours, 9 p.m. to 8 a.m. in your device's time zone. To deliver any of them we store your device's Apple push token, its time zone and your app region in our database, and we pass the token and the message to Apple's push service. You can turn notifications off at any time in iOS Settings, under Notifications, and iOS stops showing them. When Apple tells us a token is no longer valid, we delete it.

The app itself also raises three reminders on your device: a Sunday recap of your scanning week, a nudge on a day you have an active scanning streak and have not scanned yet, and, if you start a free trial, one reminder two days before it converts. These are scheduled and shown by iOS on the phone. They are not push messages, nothing about them leaves your device, and they never reach our servers or Apple's push service. Turning notifications off in iOS Settings stops them too.

5. Your Rights

Under GDPR, CCPA, PIPEDA, and similar laws, you have the right to:

  • Access: request a copy of all data we hold about you. Use the "Download My Data" button in the app (Profile → Account Settings).
  • Correct: edit any profile information directly in the app.
  • Delete: permanently delete your account and all associated data via Profile → Account Settings → Delete Account.
  • Portability: export your data as a JSON file.
  • Restrict or object: to certain processing. Contact us to exercise this right.
  • Withdraw consent: at any time, for any processing based on consent.
  • Complain: to your data protection authority (e.g. your EU member state's DPA or the UK Information Commissioner's Office).

6. Data Retention

We retain your data for as long as your account is active. When you delete your account, we delete all associated data within 30 days, except where retention is required by law (e.g. transaction records for tax purposes, typically 7 years). Push notification tokens are also deleted as soon as Apple tells us a token is no longer valid, without waiting for account deletion.

7. Data Security

All data is transmitted over HTTPS. Data at rest is encrypted. We use row-level security in our database to ensure users can only access their own data. Passwords are hashed using industry-standard algorithms and we never see them in plain text.

8. International Transfers

Your account, health-profile and scan data are stored in the United States. For users in the EU, UK or Switzerland this is an international transfer: we rely on EU Standard Contractual Clauses (SCCs) with Supabase, and Google Gemini is provided by Google LLC, which is certified under the EU-U.S. Data Privacy Framework and offers SCCs. Your rights under the GDPR and UK GDPR are unaffected by where the data is held.

9. Children's Privacy

You must be at least 16 to use Grain, or 13 or older where local law lets you consent to digital services at that age. Grain is a general-audience app and is not directed at children below that age, and we do not knowingly collect personal information from them (consistent with the U.S. Children's Online Privacy Protection Act, "COPPA", and the UK/EU age-of-consent rules under GDPR Article 8). If you believe a child has provided us with personal information, contact us and we will delete it.

10. Changes to This Policy

We may update this policy from time to time. Material changes will be announced via email (if we have your email) and in the app. The "Last updated" date at the top of this policy always reflects the most recent revision.

11. Contact

For privacy questions, data requests, or to exercise any of your rights:
Email: contact@grainios.com
Data controller: Sonder Business
Postal address: [legal entity and address: owner to supply]

Grain Grain

Know your products. Every scan, every ingredient, every decision — backed by real science.

Product

Features Pricing

Company

Support Contact

Legal

Privacy Policy Terms of Service Accessibility
© 2026 Sonder Business. All rights reserved.
Made with care in Europe.