← Back to Catch

Privacy Policy

Last updated: 18 September 2026

Catch has no account and no tracking. Your lists, your pantry and your progress stay on your device. What does leave it: a list photo you choose to scan, which goes to Anthropic (Claude) to be read; the barcode or name of a food being graded, which goes to Open Food Facts to be looked up; on Android, diagnostics from Google's ML Kit, the barcode reader inside the camera scanner, which go to Google; the names of the food on your pantry shelf, if you ask Catch for dish ideas, which go to Anthropic so it can suggest something to cook; and, if you subscribe to Catch Pro, the purchase itself, which goes to RevenueCat so the subscription keeps working when you change phone.

What we collect

Catch has no account system and no advertising SDKs, and it collects nothing about how you use the app — no launches, no taps, no screens, no sessions. There is no identity here to attach anything to, and we do not know who you are. Data leaves your device on the paths described below: scanning a list, looking up a food so it can be graded, and subscribing to Catch Pro. None of them carries your name, a device or advertising identifier, or anything from your lists beyond the one item being looked up. On Android, one component also reports to its own maker: Google's ML Kit, described under Food grades and product lookups.

Data stored on your device

The following is stored only locally on your phone and never leaves it:

This data lives in your device's local storage. Deleting the app removes it permanently.

Camera and photos

You can grant or revoke camera and photo access at any time in your phone’s settings — Settings → Catch on iOS, Settings → Apps → Catch → Permissions on Android.

Food grades and product lookups

Catch tells you whether something is a good buy, and stocks your pantry from what you actually bought. Those verdicts come from Open Food Facts, a free, public, crowdsourced food database. Two things ask it a question:

A lookup carries the barcode or the one food name, plus the identification Open Food Facts asks every client to send: the app's name, its version, and an address to write to if the app misbehaves — ours, not yours. Nothing else goes with it. Depending on the build, the name search either goes to Open Food Facts directly or through a small caching relay we run, which forwards the same query and keeps the answer against that search term for about a week, so the next person asking is served without troubling them again. Neither we nor Open Food Facts can tie these requests to you beyond the network address that every internet request necessarily reveals. Unlike scanning a photo, these lookups are not behind a separate consent prompt: they are what makes a grade honest rather than guessed, and they carry nothing that identifies you.

On Android, the barcode itself is read on your phone by Google's ML Kit, the component the camera scanner uses to recognise barcodes. Reading it sends nothing, but ML Kit reports its own diagnostics to Google: how the scanner performed (for example, how long a scan took), how it was configured, and an identifier for this installation that Google describes as not intended to identify you or your device. Google uses this to maintain and improve ML Kit and does not pass it to third parties. We never receive it, and it cannot be switched off from inside the app. On iPhone, barcodes are read by Apple's own frameworks and nothing is sent anywhere for that.

Dish ideas

If you have Catch Pro, the pantry offers to suggest a few dishes from what you have been buying. This is off until you ask for it: the first time you press the button, Catch tells you what it is about to send and does nothing unless you agree, and you can withdraw that at any time in Profile → Settings → Dish ideas.

Sharing

When you tap "Share" on a list, your device's standard share sheet opens so you can send the list text via the app of your choice. Catch does not transmit anything on its own.

Third parties

Catch includes no third-party tracking or advertising, and nothing watches how you use the app. The outside services that receive anything are these. Anthropic receives a scanned list photo, only after you have consented, and only to perform text recognition; and, if you separately ask for dish ideas, the names of the food on your pantry shelf, only to suggest something to cook. The two are asked for separately and can be turned off separately. Open Food Facts receives a barcode or a single food name, and only to return that food's public nutrition data. Google, on Android only, receives ML Kit's diagnostics about the barcode scanner — its performance, its configuration and a per-installation identifier — and not the barcodes themselves. RevenueCat receives your App Store or Google Play purchase if you subscribe to Catch Pro, so the subscription can be validated and restored on a new device; it identifies your install by an anonymous ID it generates itself, never by a name or an account, and we use its dashboard to see how many people subscribe and stay — which is analytics on purchases, and on nothing else. The two relays described above — the one holding the Anthropic key, the one caching food searches — are small serverless functions on hosting we rent from Vercel, which carries that traffic on its way through as any host in the path does.

Children's privacy

Catch does not collect personal information to build a profile of anyone, including children. The app is rated 4+ and contains no objectionable content.

Changes to this policy

If this policy changes, the "Last updated" date above will change accordingly. Material changes will be reflected in an app update.

Contact

Questions? Email clemalb@gmail.com.