Cartly

Privacy Policy

Effective date: April 18, 2026 Last updated: April 18, 2026

This Privacy Policy explains how Cartly (“Cartly,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use the Cartly mobile app (the “Service”). By using Cartly, you agree to this Policy.

1. Who we are

Cartly is operated by Tyler Piwowarski, an individual sole proprietor based in California, United States. In this Policy, “we” refers to this operator acting under the Cartly brand. If you have any questions, you can reach us at privacy@usecartly.com.

Business succession. In the event Cartly is sold, transferred, merged, or discontinued, user data may be transferred to a successor entity. We will provide reasonable advance notice to users by email, and any successor will be required to honor this Privacy Policy or obtain fresh consent before making material changes to how your data is handled.

2. Information we collect

We intentionally collect as little data as possible. The information we collect is:

Account information

Dietary preferences

Scan and cart data

Subscription status

Camera and photo library access (only when you scan)

What we do not collect

We do not collect or store:

We currently do not use any third-party analytics, advertising, or attribution SDKs.

3. How we use your information

We use your information solely to:

We do not sell your personal information. We do not use your personal information for advertising or for profiling outside the scope of the Service.

4. How your photo is handled when you scan

When you capture or select a photo to scan:

  1. The photo is read into memory on your device and encoded as base64.
  2. It is sent over a TLS-encrypted connection to our Supabase Edge Function.
  3. The Edge Function forwards it to the Google Gemini API for analysis.
  4. The text analysis is returned to your device and saved to your scan history.

Cartly does not save your photo. The image is never written to our database, to Supabase Storage, to server-side logs, or to any cache we control. Only the resulting text analysis (score, ingredients, highlights, etc.) is retained in your scan history.

Google Gemini’s retention and use of the image is governed by Google’s terms — see Section 5 below.

5. Third-party services we use

The Service relies on a small number of third parties. Each handles the data described below under its own privacy terms. We rely on our providers’ standard Data Processing Agreements (DPAs), as required under GDPR Article 28, to govern their processing of personal data on our behalf.

Supabase (database, authentication, and server-side functions; hosted on AWS) Supabase stores your account, dietary preferences, scan history, cart, and subscription status. Data is encrypted at rest and in transit. See the Supabase Privacy Policy.

Google Gemini API (AI analysis of scans and product information) When you scan or search for a product, the image and/or text is sent to Google’s Gemini API through our Edge Function so the AI can analyze it. Cartly uses the paid (billed) tier of the Gemini API. Under Google’s paid-tier Gemini API terms, Google does not use the content you submit — prompts, images, or the responses Google generates — to train or improve their AI models. Google may retain the content for a limited period for abuse detection, safety, and legal-compliance purposes, but not for machine-learning training. See the Google Gemini API Additional Terms of Service and the Google Privacy Policy.

Apple (Sign in with Apple, StoreKit for subscriptions) Apple handles authentication when you sign in with Apple and handles all payment processing for Cartly Pro. Apple’s handling of that data is governed by Apple’s Privacy Policy.

Google (Sign in with Google, if you choose it) If you sign in with Google, Google handles that authentication. See the Google Privacy Policy.

6. How long we keep your data

7. Your rights and choices

You can:

Appeals. If we decline to take action on a data request described above, you may appeal by emailing privacy@usecartly.com with the subject line “Privacy Request Appeal” and a brief description of the original request and why you believe the denial was incorrect. We will respond in writing with an explanation of our decision within 45 days. If your appeal is denied, you may submit a complaint to your applicable state attorney general or data protection authority.

8. European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR)

If you are in the EEA, the United Kingdom, or Switzerland, the General Data Protection Regulation (or the UK GDPR) gives you specific rights.

Data controller. Tyler Piwowarski, operating Cartly, is the data controller for the personal data described in this Policy. You can reach the controller at privacy@usecartly.com.

Legal bases we rely on.

Your rights. You have the right to access, rectify, erase, restrict, or object to our processing, the right to data portability, and the right to withdraw consent. Email privacy@usecartly.com to exercise any of these.

Right to lodge a complaint. You also have the right to complain to your local data protection supervisory authority.

International transfers. Your data is stored and processed in the United States (Supabase / AWS) and transmitted to Google’s Gemini API for analysis. Where required, we rely on Standard Contractual Clauses and our providers’ own transfer mechanisms.

9. California residents (CCPA / CPRA)

If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you specific rights.

Categories of personal information we collect. Identifiers (email, user ID); customer-account information (name, subscription status); commercial information (products you’ve scanned, saved, or added to cart); internet/other electronic network activity (interaction with the Service); and user content (photos you submit for scanning, processed in real time and not retained by Cartly).

Categories of sources. Directly from you; from Apple or Google at sign-in; and generated by your use of the Service.

Purposes. Only to provide and secure the Service, as described in Section 3.

Third parties we share with. Service providers only, as listed in Section 5. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have not done so in the past 12 months.

Your rights under the CCPA/CPRA. You have the right to know what we collect, to delete your personal information, to correct inaccurate information, to opt out of sale or sharing (not applicable — we do neither), to limit the use of sensitive personal information (we do not collect sensitive personal information), and not to be discriminated against for exercising these rights.

How to exercise your rights. Email privacy@usecartly.com, or use Settings → Delete Account in the app. We will respond within 45 days. We verify requests by matching the email address on your account.

10. Additional U.S. state privacy rights

Residents of Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, and Virginia may have additional rights under their applicable state privacy laws, including the right to access, correct, delete, and obtain a portable copy of their personal information, and to opt out of targeted advertising, the sale of personal information, or profiling that produces legal or similarly significant effects. We do not engage in targeted advertising, the sale of personal information, or such profiling, so the opt-out rights do not currently apply to any processing Cartly performs — but the access, correction, deletion, and portability rights are fully available to you.

To exercise these rights, email privacy@usecartly.com. We will respond within 45 days. We verify requests by matching the email address on your account. If we decline your request, you may appeal as described in Section 7.

11. Children’s privacy

Cartly is not directed at children under 13, and we do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has created an account, email privacy@usecartly.com and we will delete the account and any associated data.

Cartly is rated 4+ on the App Store because it contains no objectionable content, but the service itself is intended for general audiences 13 and older.

Teen users (13–17). Users between the ages of 13 and 17 may use Cartly only with the consent of a parent or legal guardian. By using the Service, users under 18 represent that they have obtained such consent. In jurisdictions that require parental consent for users under 16 (such as certain EEA member states under GDPR Article 8), that higher age threshold applies instead. Parents or guardians may request deletion of a minor’s account by emailing privacy@usecartly.com.

12. Apple Sign In and “Hide My Email”

If you sign in with Apple and choose Hide My Email, Apple gives us an anonymized relay email address (ending in @privaterelay.appleid.com) instead of your real email. Messages we send to that address are forwarded by Apple to your real inbox. We cannot see your real email address and cannot unmask it. Deleting your Cartly account works the same way whether you use a real or relay email.

If you revoke Cartly’s access to Sign in with Apple (iOS Settings → Apple ID → Password & Security → Apps Using Apple ID → Cartly → Stop Using Apple ID), you will be signed out of Cartly and unable to sign back in with that Apple ID. To also delete your stored data, use Settings → Delete Account in the app before revoking.

13. Security

We protect your data with industry-standard measures:

No system is perfectly secure. If we discover a breach affecting your personal information, we will notify you as required by applicable law.

14. Changes to this Policy

We may update this Policy from time to time. If we make a material change, we will update the Effective Date at the top and notify you in the app or by email. Your continued use of the Service after an update constitutes acceptance of the updated Policy.

A diff history of every change is publicly visible in the Git history of the repository that hosts this page.

15. Contact

For questions or requests about this Policy or your data, email:

privacy@usecartly.com

Tyler Piwowarski, operating Cartly California, United States