What we hold, and what we made sure we could not.
Written to be read rather than to be survived. Where a protection is structural - where we could not hand something over because we never had it - this page says so, because that is worth more than a promise.
Last updated 15 September 2026 · Zabel, India
1. The short version
- The app works without an account. Scanning, reading and reporting a mistake need no sign-in.
- If you set a health profile, it stays on your phone. We never receive it.
- We never store your phone number. Sign in by OTP and what is stored is a one-way hash of it.
- Label photographs are deleted after 90 days.
- We do not sell or broker personal data, and we take no money from the brands we score.
2. Using the app without an account
Your phone generates a random device identifier the first time you open the app. It is not your advertising ID, your IMEI or anything issued by Google, and it is not linked to you - it exists so that a scan you started resolves back to the phone that started it, and so a report you file can be matched to the pack you filed it about.
With no account, two things are held against that identifier and nothing else: the scans it started, and the record that it agreed to a version of our terms on a date. We keep the second because you cannot be asked to agree to something and then have nobody able to say what you agreed to - it names the version, the date and which language you read it in, and nothing about you.
Uninstalling the app ends the identifier; a fresh install generates a new one and has no way back to the old.
3. If you sign in
Signing in is optional and buys exactly one thing: your history and saved list appearing on a second device. Everything else works signed out.
- By phone number. We send a one-time code to it and then store a keyed one-way hash of the number - never the number itself. We cannot print your number, cannot sell a list of numbers, and cannot give one to anyone who asks, because the database does not contain one.
- By Google. We receive the account identifier Google issues for our app, and the name and email address on the account. We do not receive your Google password and we ask for no access to anything else in your account.
4. Your health profile never leaves your phone
If you tell the app you are managing diabetes, hypertension, PCOS or anything else, that is stored on the device and nowhere else. The app downloads a set of public reference intakes - the same set for everybody, revealing nothing about who asked - and does the comparison locally.
This is a design decision rather than a policy one, and the difference matters: a health condition is not transmitted and then protected, it is never transmitted. There is no record on our servers to leak, subpoena, or change our minds about.
5. Photographs of labels
When you photograph a pack, the images are uploaded so the label can be read and so a person can check the reading afterwards. They are pictures of packaging - please do not photograph anything else with it.
They are deleted 90 days after upload, automatically. What survives is the transcribed label - the ingredients and the nutrition figures - which is catalogue data about a product rather than data about you.
6. Scan history and saved packs
Both live on your phone first and work fully offline. They are copied to our servers only if you are signed in, and only so a second device sees the same list. Signed out, they never leave the device. Clearing history in the app clears it on our side too.
7. This website
The pages you are reading set no cookies, run no analytics, and load nothing from a third party - no fonts, no tag manager, no embedded anything. Nothing here is counting you.
If you write to us through the contact form or leave an address for early access, we keep what you typed: your message, your address, and your name if you gave one. We do not record your IP address or your browser alongside it.
8. Who else sees anything
Our hosting and database providers, the AI provider that transcribes an uploaded label, and the SMS provider that delivers a one-time code. Each gets only what its job requires, and none of them is permitted to use it for anything else.
We do not sell personal data. We do not share it with brands, retailers or data brokers. We take no payment from the manufacturers whose products we score, which is what makes that first sentence something we can afford to keep.
9. How long we keep things
- Label photographs: 90 days, then deleted automatically.
- One-time codes: five minutes, then they are useless.
- Your account and its lists: until you ask us to delete them.
- Agreements to these terms: kept, including after an account closes, with the account taken off them. What is left says that a device agreed to version 1.0 on a date, which is the only form in which a record of an agreement is worth anything.
- Messages you send us: as long as we might reasonably need the correspondence, then deleted.
- Catalogue data: kept. A transcribed label is a fact about a product, not about a person, and the whole point is that the next person to scan that pack gets an answer.
10. What you can ask us to do
Ask us what we hold about you, ask for it back, ask us to correct it, or ask us to delete it and close your account. Write to privacy@zabel.app and a person will do it. There is no form to fill in.
One honest limit: we cannot identify you from a phone number, because we hold a hash rather than the number. Ask from the app while signed in, or from the email address on the account, and we can.
11. Children
Zabel is built for adults buying food, including for their children. It is not intended for use by children under 13, and we do not knowingly hold data about them.
12. Changes to this page
The date at the top moves when the substance changes - not when a typo is fixed. If a change affects what we collect or what we do with it, the app will say so rather than leaving it here to be found.
13. Contact
Zabel, India · privacy@zabel.app