Privacy Policy
Effective 3 September 2026 · version 2026-09-04
FaveMark is a photo notebook. You take a photo, an AI reads it and suggests tags, you give it a rating, and later you find it again by tag, date, place, a similar photo, or by asking. Making that work means sending your photos to companies other than us. This page says exactly which ones, exactly what they get, and what we keep.
It describes the app as it is actually built today, not as it is planned. Where something is designed but not built, it says so.
1. What we collect
- Your account. Your email address and a one-way hash of your password — we never store the password itself. Signing up creates a short-lived email-verification token; signing in creates a random session token.
- Your photos. We keep the original file exactly as you sent it, byte for byte, and generate a small thumbnail from it. Note that some cameras write metadata — including GPS coordinates — inside the image file itself. FaveMark does not strip that metadata out of the stored original.
- What you record about a photo. Your rating, anything you type, the tags and categories the AI suggested or you corrected, the brand and any text the AI read off the item, a venue if you attach one, and a source URL if you saved something from the web.
- Location — only if you switch it on. FaveMark never asks for location by itself. The system permission dialog appears only after you tap to enable it. While it is enabled and granted, a capture records the coordinates where it happened. See §3 for what is done with them — the short version is that they never leave our server.
- A similarity fingerprint of each photo — a list of numbers produced by an embedding model, which is what makes “find similar” work across your own library.
- A record of each AI call: your account id, which feature ran, which model, how many tokens, and an estimated cost. The contents of the call are not stored in this record.
- Your settings — the language your tags are shown in, which scripts you read, how much effort the AI spends on your requests, and your image-processing agreement: whether you have agreed, which version of this disclosure you agreed to, and when.
We do not use analytics, advertising SDKs, crash reporting, or any third-party tracker. There are none in the app.
2. Who else receives your data
Four outside services are involved. Two of them receive your photographs. What each of them does with what it receives is governed by its own policy, linked below; we have no arrangement with them beyond their standard terms for developers.
Anthropic (Claude)
Reads your photos and your text to suggest tags, identify items, search your library, and answer in the assistant.
What we send them
- A downscaled JPEG copy of a photo (longest side 1024 px), re-encoded by our server from the image rather than forwarded as the file you uploaded.
- Text you or the app produced: tag and category labels, note text, brand and label text already read from an item, typed search queries, manually added item names, venue names, and your assistant conversation.
- An identifier for your account, so the model is told whose request it is answering.
When
- Tagging a capture, and re-tagging it
- “Find similar” — matching a new snap against your library
- “Identify this” — researching an item in a photo
- “Get the official picture” — looking up the maker's own page for an item you rated, which happens automatically in the background on a paid account when the barcode path could not answer
- A label or price-tag shot attached to an existing note
- The assistant, including any photo you attach to a message
- Search — expanding and parsing what you typed
- Filling in tag labels in your chosen language, reconciling a suspected duplicate, categorising a manually added item or a venue, and the periodic tidy-up of your tag vocabulary
Their policy: https://www.anthropic.com/legal/privacy
Voyage AI
Turns a photo — and some tag labels — into a numeric fingerprint so “find similar” can work.
What we send them
- The same downscaled JPEG copy of a photo that Anthropic receives.
- Tag and category label text during the periodic tidy-up of your tag vocabulary.
- An identifier for your account.
When
- Tagging a capture — the fingerprint is computed in the background
- “Find similar” — the query snap is fingerprinted to compare against your library
- The periodic tidy-up of your tag vocabulary
Their policy: https://www.voyageai.com/privacy-policy
Open Food Facts
Looks a packaged food up by its barcode, so the item's own manufacturer photo and official details can be shown beside the photo you took.
What we send them
- The barcode digits read off the packaging in your photo — nothing else. No image, no note text, no tags, and no identifier for your account: the request carries a product number and cannot be tied to you by them.
When
- “Get the official picture” — after you rate an item whose barcode was legible
Their policy: https://world.openfoodfacts.org/privacy
Microsoft (Exchange Online) or Resend
Delivers the handful of transactional emails the app sends — currently the address-verification message.
What we send them
- Your email address and the contents of the message we send you.
- No photos, no notes, no tags.
When
- Signing up — the verification email
- Asking us to resend that verification email
Their policy: https://privacy.microsoft.com/privacystatement
Agreeing to this, and taking it back
The app asks before your first photo is processed. The screen describes the processing — what is sent, why, and that it runs both automatically and when you ask — and points here for the companies currently doing it (see §9 for why it is worded that way). It records which agreement you accepted. You can decline, and you can change your mind later in Settings → Image processing.
Your agreement covers processing, not just uploading. While it is switched off, no photo of yours is sent to either company — not a new capture, and not one already stored on our servers. That includes re-tagging a photo, re-framing it, making a different photo the main one, “find similar”, reading a label shot, looking up the maker's own page for something you rated, and asking the assistant about a note that has a photo. Those last ones matter because they happen after the capture, at a moment of your choosing rather than ours, and until August 2026 several of them ran without consulting your agreement at all. They no longer do.
Two limits, stated plainly. Turning it off does not reach back into anything already sent — see §5. And notes without a photo still work: asking the assistant about one sends text, not an image, so it is not held back.
A note on web search
“Identify this” and the assistant's research answers use a web-search tool that runs inside Anthropic's service. Search terms derived from your photo or your question are sent by Anthropic to its search provider and reach the public web. We do not control or see that onward step beyond the results that come back.
Since 23 August 2026 this can also happen without you asking. On a paid account, when you rate something and we cannot identify it from a barcode, the app sends that photo to Anthropic in the background and asks it to find the manufacturer's own page for the item. It is the same company, the same downscaled copy and the same web search as “Identify this” — what is new is that nothing you tapped named the item. The agreement the app asks for covers this: it says plainly that processing runs both automatically and when you ask, with no condition attached. §9 explains when a change would make us ask you again — and why this kind does not.
Fetching a picture from the maker's website
When that lookup finds the manufacturer's page, our server downloads the product photograph published on it and stores it beside your own, labelled as not yours. Those websites receive nothing about you. The request is made by our server rather than by your phone, so the site sees our address and the picture we asked for — never your IP address, your account, your photo, or your notes.
They are not listed above with the four named services because they are not a fixed set with a policy we could link: it is whichever page turns out to describe the thing you photographed. If you hold rights in such a picture, §10 says how to have it removed.
3. What never goes to an AI model
These are properties of how the app is built, not statements of intention:
- Your location coordinates. When location is on, coordinates are used only by our own server, as arithmetic that re-orders candidates the model already produced — nudging results toward things you have recorded near this spot. They are never placed in a prompt and never leave our server. The consent you grant in the app does cover place features that would include where you captured something; no such feature exists yet, and this policy's version will move — and this line with it — before one does.
- Your email address, your password, and your session token. Prompts carry an opaque account identifier so the request can be scoped — never your credentials or your address.
- Anyone else's photos, notes, or tags. Every database read is filtered to your account before anything reaches a model.
- Your library, in our own testing. The evaluation and prompt-tuning tools we run against this app operate on fixed test cases, our own prompt files, and screenshots of public pages. They never read a real library.
4. Where your data is kept
- Photo files sit on the filesystem of a single rented virtual server. Your notes, tags, ratings, coordinates and account record sit in a PostgreSQL database on the same machine.
- Both are backed up nightly, and the backup set is copied to a second server, where roughly the last two weeks are retained.
- Not encrypted at rest. Neither the photo files nor the database are encrypted on disk. Anyone with access to those servers — which means the operator and the hosting provider — can read them. Traffic between your device and us is encrypted in transit (HTTPS).
- No guaranteed processing region. We do not operate region-pinned infrastructure and make no claim about which country your data is processed in. Anthropic, Voyage AI, Open Food Facts and the email provider may process it in countries other than yours.
5. How long we keep it, and how to delete it
- Photos are kept until you delete them. There is no automatic expiry. Deleting a photo in the app removes the original file, the thumbnail, the note attached to it, its tag links and its similarity fingerprint — immediately and permanently from the live system.
- Backups lag deletion. Something you delete can survive in nightly backup copies for roughly two weeks before those copies age out.
- You can delete your whole account, from inside the app. Settings → Account → Delete account, confirmed with your password. That removes everything at once — every photo and every version we derived from it, notes, ratings, comments, tags, saved places, assistant conversations, settings and the account itself — immediately and permanently, and signs you out on every device. We cannot restore it afterwards. Your email address is released, so you can sign up again later; it will be a new, empty account. If you no longer have the app installed, see favemark.app/delete-account.
- Some smaller things you still cannot delete yourself. Tags, and venues you have saved, have no individual in-app delete in the current build — notes and photos do, and so does the account as a whole. Email us at privacy@favemark.app and we will delete them by hand.
- What has already been sent out is out of our hands. Deleting a photo here does not reach back into Anthropic's or Voyage AI's systems, or into your email provider's. Their retention is governed by their policies.
6. Who can see your library
Only you, and the operator of the service. Every request is checked against your account before anything is read, and another account's photo is indistinguishable from a photo that does not exist.
FaveMark has no sharing. There are no public profiles, no shared libraries, no groups or circles, and no way for another user to see anything of yours. Sharing has been designed but not built. If it ever ships, this page changes before it does. The one thing that is shared is described just below, and it holds nothing of yours.
One thing that is shared: a product index — and nothing of yours
When the packaging in one of your photos is read clearly enough to be sure what the product is, FaveMark records that product's identity — as printed on the pack — in a shared index, and links your note to the entry. It is how the app comes to know a product exists at all: entries are grown by use rather than bought or hand-built, so the next person who photographs the same thing meets it already there.
What it holds
- The product's identity as read off the packaging: brand, product name, variant, and the pack sizes it has been seen in — kept in a canonical form (lowercased, accents folded) so that two readings of the same product meet each other, alongside the spelling that founded the entry.
- Public facts about the product — ingredients, nutrition, specifications, certifications, awards, third-party ratings — each stored as a value with a link to the page it was taken from, the kind of source it was (the maker's own site, a retailer, a review, an aggregator), and when it was fetched. At most one attributed sentence of quoted text is kept beside a value; no article text, no prose and no images are copied. A fact with no source link is discarded rather than stored.
What it never holds
- Any photo, or any pointer to one: no photo id, no crop, no thumbnail, no similarity fingerprint.
- Your account, or any pointer to it: no account id, no email address, no session.
- Anything you recorded: your notes, your ratings, your comments, your tags, your assistant conversations, or anything else you typed.
- Any count of how many people have photographed a product, or when the first of them did.
Any signed-in user, through the same authenticated routes as the rest of the app. The entries are about products, not about people: nobody reading one can tell who photographed the thing, or that you did. What an entry does reveal is that someone, at some point, photographed that product — and that is all it can reveal, because nothing in it points back at a person. Your own library is untouched by this; the first paragraph of this section still holds in full.
7. Cookies and device storage
The website sets one cookie, favemark_session, which identifies your signed-in session. It is strictly necessary — without it you cannot stay signed in. There are no analytics or advertising cookies.
The mobile app uses no cookies. Its session token is held in the device's own secure keystore (the iOS Keychain, the Android Keystore), not in ordinary app storage.
8. Children
FaveMark is not directed at children under 13 and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will remove it.
9. Changes to this policy
This page carries a version stamp (2026-09-04). When what we disclose here changes materially — a new company receiving your data, a new category of data leaving our servers — the version moves, so you can always tell which text you were shown.
What you agree to in the app is a category of processing, not a list of companies. The in-app agreement says what leaves (a downscaled copy of what you capture, text, an opaque account identifier — and, if you allow location, where you captured something, for place features), why (to tag, identify, organize and answer questions about it, including looking things up on the web), and that it runs both automatically and when you ask. The companies doing that processing are named on THIS page, which is versioned — so we can change an AI provider or model, for the same processing, by updating this page rather than by switching your photo features off until you re-agree. Your agreement covers the processing, not the vendor.
When would we ask you again? When the category itself widens: a kind of data leaving our servers that the agreement does not name, or a genuinely new purpose. Using your photos to train a model, for advertising, selling data, or showing your content to other users are all outside every agreement this app has ever asked for — any of those would be a fresh, explicit question, never an update to this page. And a new feature that needs more than you agreed to (place features are the example above) asks its own question at that feature's door — it does not switch off what you already use.
Not every change is that kind of change, and we would rather say so than imply a promise we do not keep. On 20 August 2026 we added Open Food Facts to the list above. It receives the barcode digits read from a photo's packaging and sends back the manufacturer's own picture of that product — it never receives a photo of yours. Nothing about where your photos can go became broader, so this page's version moved and you were not asked again.
On 3 September 2026 we added the shared product index described in §6. Nothing new leaves our servers and no photo is involved; what is new is that the identity of a product, read off its packaging, is kept in a table that is not yours alone. That is a change to what we keep and where, not to where your photos can go — so this page's version moved and you were not asked again.
One correction, for the record. The 23 August 2026 revision of this page said we had asked everyone to agree again, after the automatic lookup in §2 outgrew wording that had been tied to you asking. That re-ask was queued but never reached anyone's device, and on 26 August 2026 we replaced it with the category-based agreement described above — which covers the automatic lookup outright instead of re-asking you about a condition we should never have promised. Nobody's photo features were switched off, and nothing about where your photos can go widened between those two texts.
10. Contact
Questions, corrections, or a deletion request from someone who no longer has the app installed (in the app it is Settings → Account → Delete account): privacy@favemark.app.
Reporting a picture we fetched. Some notes carry a manufacturer's product photo — pulled either from Open Food Facts, where contributors publish them under a licence that asks for credit, or, since 23 August 2026, from the maker's own website, where we hold no licence at all. Each is shown only to the person whose note it is, is stored with the page it came from and whatever credit that page carries, and is labelled in the app as not your own photo.
If you hold rights in such a picture and want it removed, write to the address above with the product or the page it came from. These images are derived and disposable, so removing one is a delete on our side and nothing else is lost. We can also switch the maker's-website step off outright, for everyone, without a release — so a request about a whole catalogue does not have to be answered one picture at a time.