Local records
Your rules, settings, product records, and saved history stay in CartKind's local app container by default.
No CartKind account
Tyche Ventures does not operate a CartKind account system or user-profile database.
Limited lookup data
Barcode lookup sends a barcode and ordinary request metadata to the sources described below.
No ad tracking SDKs
CartKind does not include analytics, behavioral-advertising, or cross-app tracking SDKs.
Product results are not allergy or medical guidance
CartKind is an informational shopping reference. Aligned, Review, and Not aligned compare available ingredient text with rules you configured; they do not determine that a product is medically safe. Product data can be incomplete, outdated, or inaccurate. Always read the physical package label and consult a qualified professional about allergies, intolerances, or medical dietary needs.
1. Overview
Tyche Ventures LLC (“Tyche Ventures,” “we,” “our,” or “us”) built CartKind as a free app with optional Premium features. This Privacy Policy describes CartKind's local records, barcode lookup flow, camera use, StoreKit communications, external links, support communications, retention, and deletion.
2. Age and children's privacy
CartKind is intended as a shopping-reference tool for adults, including parents and guardians, and is not directed to children under 13. It does not ask users to create an account or provide a name or email address. A parent or guardian should decide whether supervised use by a child is appropriate.
3. Information stored on your device
Your rules, custom ingredient triggers, custom categories, saved scan history, product records, and app preferences are stored in CartKind's local app container. Tyche Ventures does not automatically upload those local records to a server-side user database.
You can delete individual history items and remove custom rules through available in-app controls. Deleting CartKind normally removes its local app container from that device. Apple-managed device or computer backups may contain copies until you delete them or they expire under Apple's practices. CartKind does not operate its own cloud-sync or backup service.
4. Product lookup and network data
Open Food Facts is queried first
When you scan or manually enter a barcode, CartKind sends the barcode over HTTPS directly from your device to Open Food Facts. Open Food Facts also receives ordinary request metadata, such as your IP address, request time, and CartKind's identifying User-Agent. CartKind does not send camera images, saved rules, custom triggers, custom categories, or scan history with that request.
Open Food Facts describes its retention and use of IP and log data—including security, technical analysis, usage statistics, and product-popularity measurement—in its privacy policy.
USDA is a fallback after a catalog miss
Only after Open Food Facts reports no matching product may CartKind send the barcode to the Tyche Ventures USDA relay at usda-api.tycheventuresllc.com. The relay runs on Cloudflare Workers and forwards the barcode search to USDA FoodData Central.
The relay and Cloudflare can process the barcode together with ordinary technical request metadata, such as an IP address, timestamp, request URL, and headers. The relay does not receive your camera image, saved rules, custom triggers, custom categories, or full scan history. Its code does not intentionally forward your device IP address to USDA.
Limited relay logs
If Cloudflare Workers logging is enabled, invocation logs may include the request URL containing the barcode and related technical metadata. Cloudflare currently documents shorter retention for some Workers plans and up to seven days for others. Because the plan and logging configuration can change, Tyche Ventures conservatively treats these limited proxy logs as potentially retained for up to seven days. They are not used to create a CartKind account, build an advertising profile, or track you across apps or websites. See Cloudflare Workers logging and Cloudflare's Privacy Policy.
5. Camera access
CartKind requests camera access only when you choose barcode scanning. Apple's barcode metadata scanner processes camera frames on the device in real time. CartKind stores the decoded barcode, not camera images; camera frames are not stored, recorded, or transmitted. You can change camera permission in iOS Settings.
6. Recipients and outside services
| Service | When used | Information involved |
|---|---|---|
| Open Food Facts | Every barcode lookup | Barcode and ordinary request metadata, sent directly from your device |
| Tyche/Cloudflare relay and USDA FoodData Central | Only after an Open Food Facts catalog miss | Barcode and relay request metadata; limited invocation logs may remain for up to seven days |
| Apple App Store / StoreKit | Purchase, restore, and subscription-status activity | Transaction and entitlement information needed to determine Premium access; Apple handles payment details |
| External source websites | Only when you choose a source link | Ordinary browser and network information under the destination's policies |
Tyche Ventures does not receive your full payment-card details or Apple ID password. Apple handles App Store information under Apple's Privacy Policy.
7. Product data and licenses
Product information identified as Open Food Facts data is © Open Food Facts contributors. The Open Food Facts database is available under the Open Database License 1.0 (ODbL), and individual database contents are available under the Database Contents License 1.0 (DbCL). See Open Food Facts' terms of use and reuse.
CartKind 1.0.2 does not request or display Open Food Facts product images. Open Food Facts image licensing and third-party packaging rights may apply if a future version adds them.
USDA FoodData Central data is public-domain data published under CC0 1.0 Universal. Source: U.S. Department of Agriculture, Agricultural Research Service, FoodData Central.
8. Analytics, tracking, and sale of data
CartKind does not include third-party analytics, advertising, or cross-app tracking SDKs. Tyche Ventures does not sell personal data or use lookup requests to build advertising profiles. Operational network providers may generate the technical logs described above, and Open Food Facts states that it can use request logs for technical analysis, usage statistics, and product-popularity measurement.
9. Information you choose to send us
If you email support, we receive the email address, message, and attachments you choose to send. Do not include medical information or other sensitive details unless necessary to resolve an issue. We use support communications to respond and troubleshoot and retain them only as reasonably needed for those purposes and legal obligations.
10. Security
CartKind uses Apple's local-storage frameworks for app records. Local data benefits from the security settings and protections on your device. Network requests use HTTPS in transit, while recipients and infrastructure providers process information under their own security and privacy practices. No storage or transmission method can be guaranteed completely secure.
11. Retention, deletion, and your choices
- Local records: Remain until you delete them in CartKind or remove the app, subject to copies in Apple-managed backups.
- Relay logs: If enabled, limited invocation logs may remain for up to seven days as described above.
- Outside services: Open Food Facts, Cloudflare, USDA, Apple, and source websites apply their own retention practices.
- Support communications: Remain only as reasonably needed to respond, troubleshoot, and meet legal obligations.
Because Tyche Ventures does not operate a CartKind account or backend for local app records, we generally cannot access, recover, correct, or delete those records for you. Use CartKind and device controls to manage local data and Apple settings to manage backups and subscriptions.
12. Changes to this policy
We may update this policy if app behavior, third-party services, or legal requirements change. The revised version will appear on this page with an updated date, and we will provide additional notice when appropriate.
13. Contact
For questions about this policy or information Tyche Ventures may hold because you contacted us, email support@tycheventuresllc.com.