Privacy policy
Last updated September 9, 2026
willithurt.me lets you scan a product barcode and get a plain-language answer about whether the product may harm you. To do that we process a small amount of personal data. This policy explains what we collect, why, on what legal basis, who we share it with, how long we keep it, and what rights you have under the EU General Data Protection Regulation (GDPR).
We have written this in plain English on purpose. If anything is unclear, email us at privacy@willithurt.me.
1. Who is responsible (the controller)
The controller for the personal data described here is willithurt.me, operated by Scott Agirs, Riga, Latvia. Contact for anything privacy-related: privacy@willithurt.me.
We are a small, independent service and are not required to appoint a data protection officer; the address above reaches the person responsible directly.
2. What data we collect
We collect only what the service needs to work. Depending on how you use willithurt.me, that is:
- Account data — when you sign in: your email address, an optional display name, your preferred language and country, and the sign-in method used (magic link by email, or Google). Nothing more is imported from Google than your email address and name.
- Anonymous session identifier — before you sign in, we create a random anonymous account so that your scan history follows you on the same device. It contains no name or email. If you later sign in, the anonymous history is merged into your account.
- Scan history — the barcodes you look up, when, the country and language of the request, and the product they resolved to. This powers your History page.
- Contributions — when you add or correct a product: the photos you upload (barcode, front of pack, ingredient label), the text you type, and the fact that your account made the contribution. Photos should show packaging only; please do not include people, receipts or anything personal in them.
- Reports — when you report a problem: the reason and details you give, an optional contact email, your account identifier (including anonymous ones) and a one-way hash of your IP address used only to limit abuse.
- Technical logs — standard server logs (request path, timestamp, user agent, response status) with the IP address stored only as a salted one-way hash, kept for security and rate-limiting. We do not build profiles from these logs.
- AI processing data — the label photos and ingredient text you submit are sent to an AI provider to read the label and produce the analysis (see section 5). The text of the analysis is stored with the product, not with you.
We do not collect payment details, precise location, contacts, or device identifiers, and we do not use advertising identifiers of any kind.
3. Why we use it, and on what legal basis
Under the GDPR every use of personal data needs a legal basis. Ours are:
- Providing the service you asked for (Art. 6(1)(b) GDPR — contract): creating and maintaining your account, showing your scan history, storing and displaying your contributions, answering your reports.
- Our legitimate interests (Art. 6(1)(f) GDPR): keeping the service secure and free of abuse (rate limiting, hashed IP logs, audit logs of moderation actions), improving the product database and analyses through community contributions, and understanding aggregate, cookieless usage. We have balanced these interests against yours and believe the impact on you is minimal; you can object at any time (section 9).
- Your consent (Art. 6(1)(a) GDPR): optional features that are off until you turn them on — for example signing in with Google, or giving us a contact email when you file a report. You can withdraw consent at any time; this does not affect processing that already happened.
- Legal obligations (Art. 6(1)(c) GDPR): keeping records of content-moderation decisions and reports as required by the EU Digital Services Act, and answering lawful requests from authorities.
4. Cookies and local storage
willithurt.me uses only strictly necessary cookies: a session cookie that keeps you signed in (including the anonymous session) and a short-lived cookie that protects sign-in forms. These are needed for the site to function and require no consent banner under the ePrivacy rules.
We do not use tracking, advertising or cross-site cookies. Aggregate usage statistics are collected with Vercel Analytics, which is cookieless and does not identify individual visitors.
Your browser may also store a copy of the app (a "service worker") and your language choice locally so the site loads offline. This data never leaves your device and you can clear it through your browser settings.
5. Who we share data with (processors)
We do not sell personal data and we do not share it with advertisers. To run the service we rely on a small number of providers who process data on our behalf under written data-processing agreements:
- Vercel Inc. — hosting, edge network and cookieless analytics. Servers in the EU where available; some edge locations may be outside the EU (see section 8).
- Neon Inc. — the Postgres database that stores accounts, scan history, contributions and reports. Region: EU (Frankfurt, Germany).
- Cloudflare Inc. (R2) — storage of uploaded product photos. Region: EU.
- Anthropic PBC — AI processing of ingredient-label photos and text to read the label and generate the analysis. Anthropic does not use data sent through its API to train its models. Photos are sent only for processing and are not retained by Anthropic beyond what is needed to provide the service.
- Resend Inc. — sends transactional email only (sign-in links, replies to your reports). No marketing email.
- Google LLC — only if you choose "Sign in with Google". Google's own privacy policy applies to that sign-in step.
Open data we contribute back to public databases (see the Terms and the Data sources page) never includes your account details — only product facts and photos of packaging, credited to a generic willithurt.me account.
We may also disclose data where the law requires it, for example to comply with a court order, or to establish or defend legal claims.
6. How long we keep data
- Scan history — until you delete it (History → Clear, or by deleting your account).
- Anonymous sessions — 30 days after the last activity, unless converted into a signed-in account.
- Account data — for as long as your account exists. When you delete your account, your account data is removed and your contributions are anonymised (the product data stays, without any link to you).
- Contributions and product photos — kept as part of the product database; the link to your account is removed when you delete the account.
- Reports — 24 months from the decision, so that we can show our handling of notices if asked.
- Audit logs of moderation and admin actions — 12 months.
- Technical logs (hashed IP) — up to 30 days.
- Rate-limit counters — rolling windows of at most one hour.
7. Security
All traffic is encrypted in transit (TLS). Data at rest is encrypted by our hosting providers. Access to production data is limited to the operator and is logged. IP addresses are stored only as salted hashes. Sign-in uses one-time magic links or Google; we never store passwords.
No system is perfectly secure. If we become aware of a personal-data breach that is likely to put you at risk we will notify you and the supervisory authority as the GDPR requires.
8. International transfers
We choose EU regions where our providers offer them (database and image storage are in the EU). Some providers — Vercel, Anthropic, Resend, Cloudflare and Google — are established in the United States or operate edge infrastructure worldwide, so some data may be transferred outside the European Economic Area.
Where that happens we rely on the European Commission's Standard Contractual Clauses (SCCs) incorporated into each provider's data-processing agreement, together with the EU–US Data Privacy Framework where the provider is certified, and on supplementary measures such as encryption. You can ask us for a copy of the relevant safeguards at the contact address above.
9. Your rights
You have the following rights regarding your personal data. Most of them you can exercise yourself from the Account page; for the rest, email privacy@willithurt.me. We answer within one month.
- Access (Art. 15) — see what we hold about you. Account → Export your data downloads a machine-readable copy.
- Rectification (Art. 16) — correct inaccurate data. You can edit your name, language and country in Account.
- Erasure (Art. 17) — Account → Delete account removes your account, scan history and personal links to contributions.
- Portability (Art. 20) — the export above is in JSON, a common machine-readable format.
- Restriction (Art. 18) and objection (Art. 21) — you may object to processing based on our legitimate interests, and ask us to restrict processing while we look at it. Email us and tell us what you object to.
- Withdraw consent — for optional features, at any time, without affecting earlier processing.
We do not make decisions about you that have legal or similarly significant effects based solely on automated processing. Product verdicts are generated automatically, but they are about products, not about you.
If you believe we are handling your data unlawfully you have the right to lodge a complaint with a supervisory authority. Our lead authority is the Latvian Data State Inspectorate: Datu valsts inspekcija, Elijas iela 17, Riga, LV-1050, Latvia — www.dvi.gov.lv. You may also complain to the authority in the EU country where you live or work.
10. Children
willithurt.me is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child has created an account, contact us and we will delete it.
11. Changes to this policy
We will update this page when our processing changes and adjust the "last updated" date above. For material changes we will show a notice in the app. Earlier versions are available on request.