OptVeg

Privacy policy

Last updated: 2026-05-09

Controller: Varun Sharma trading as OptVeg, a United Kingdom sole-trader operation. For questions about this policy or to exercise any of your data rights, email hello@optveg.app.

This page explains what we collect, why, and what we do with it. Plain language. No dark patterns.

What we collect

Search queries. When you use the search bar, we store the dish name you typed, a slugified key, whether we found a cached match, and an anonymous session ID (a random UUID generated server-side per request). We do not store your IP address against the query, and we do not link queries to a user identity.

Email addresses (only when you opt in). If you submit your email via "Notify me when the app launches" or a similar form, we store the email and the trigger context (where you submitted from, e.g. "landing_page" or the dish name from a no-match prompt). We use this to email you once when the iOS / Android apps launch, plus occasional update emails about features that materially change. You can unsubscribe at any time by replying to any email; we'll delete your row.

Analytics. We use Plausible Analytics, a privacy-first, cookie-free analytics service hosted in the EU. Plausible records page views and a small set of custom events (search submitted, swap completed, email captured). It does not track you across sites, does not use cookies, and does not collect personal data. We see aggregate counts only.

What we don't collect

We don't use cookies for tracking. We don't run ads. We don't sell data. We don't run third-party trackers (Google Analytics, Meta Pixel, Hotjar, etc.). We may share anonymised research data with named academic collaborators under the conditions set out in the Research dataset section below — that is the only circumstance in which any subset of your data leaves us.

Where data is stored

Search queries and emails are stored in our Postgres database hosted by Supabase (EU region). The marketing site is hosted on Cloudflare Pages; the app is hosted on Railway. Data is encrypted at rest and in transit.

"Is It Vegan?" packaged-product scanner

When you use the “Is it vegan?” feature (route /scan in the app), we receive a photo of a packaged product's label.

Lawful basis: contract performance (Article 6(1)(b) — you asked for the scan; we ran it). OpenAI is a data processor under our agreement; their privacy commitments apply per their published terms.

Research dataset (signed-in users)

When you create an OptVeg account you opt in to the research dataset. Specifically we log:

We do not log: your email, name, IP address, device fingerprint, location, or anything that could be used to re-identify you. The dataset is exported in aggregate form (k-anonymised hashed pseudonyms — every CSV export uses a fresh random salt that is never stored, so the same user across two exports gets two unrelated pseudonyms and cannot be joined across exports) for the OptVeg clinical-validation study and quarterly Consumer Insights reports.

You can withdraw consent at any time from Settings → Privacy & data. Withdrawal stops new rows landing in the dataset; rows that have already been aggregated into past research reports stay (the link to you is already gone).

Full account + data delete is also a one-tap action on that same page.

Lawful basis, retention, recipients

Lawful basis: Article 6(1)(a) of the UK GDPR — consent. You give consent during account creation; you can withdraw it at any time. We can't process research data without your active consent.

Retention: research-dataset rows are kept for 5 years from the date they were created. After 5 years rows are aggregated to anonymous form and the per-row records are permanently deleted. This window matches the typical timeline of a peer-reviewed clinical-validation study from data collection to journal publication.

Search queries (anonymous, no user_id) are kept indefinitely because they contain no personal data — only the dish strings. Email captures are kept until you ask us to delete them.

Recipients: today, the research dataset is processed only within the controller (Varun Sharma / OptVeg) and our data processors (Supabase EU region for storage; no other third-party processor sees raw rows). When the clinical- validation paper is submitted, an anonymised research extract — hashed pseudonyms instead of user_ids, no timestamps tighter than the hour, no dish strings appearing fewer than 5 times — is shared with named research collaborators. The collaborators' identities are listed in the paper's author and acknowledgements sections. We do not share with advertisers, brokers, AI training providers, or anyone outside the named research collaboration.

Your rights (UK GDPR)

You have the right to: (a) access the data we hold about you (Article 15); (b) rectify inaccurate data (Article 16); (c) erase your data (Article 17); (d) restrict processing (Article 18); (e) data portability (Article 20); (f) object to processing (Article 21); (g) withdraw consent (Article 7(3)). To exercise any of these, email hello@optveg.app and we'll respond within 30 days.

You also have the right to lodge a complaint with the Information Commissioner's Office (ico.org.uk) if you think we've mishandled your data.

You can ask us to delete any email you submitted by replying to any email we send, or by emailing hello@optveg.app. We'll delete the row within 7 days. Search queries are anonymous; there's nothing tying them to you to delete.

For a full Article 15 data export, signed-in users can use the Download my data button in Settings → Privacy & data — it returns every personal-data row we hold about you as a single JSON file, no email required. If you don't have an account but want a copy of any email-capture row tied to your address, email hello@optveg.app.

Changes to this policy

If we change anything material, we'll update the date above and email everyone on the launch list. No surprises.

Contact

hello@optveg.appfor any privacy question, any time.