Privacy Policy
Effective 2026-08-01 · Ethos is operated by Opsibyte · supersedes the 2026-07-27 version, which incorrectly stated Ethos has no accounts
The short version
Ethos requires a free account to use the app — an email address and a one-time sign-in code, no password. Once you're signed in, your value preferences, usage counters, brand-lookup history, and follows sync to our servers so they carry across your devices; they are not kept only on your phone. We do not run advertising, sell your data, or share it for cross-context advertising. This page names every outside service that touches your data and what each one sees.
Creating and using your account
- Sign-in — you enter your email address and we send a 6-digit one-time code to it. Entering the code creates a session; there is no password. Identity is handled by Better Auth, a service we operate ourselves at auth.ethosscan.com — it is not a third-party identity provider.
- What that account record holds — your email address; an account id; and a session record each time you sign in, including the device's IP address and browser/user-agent string (used for session security, e.g. spotting a stolen sign-in code before it's used).
- Sending the code — the sign-in email itself is delivered by Resend, a transactional-email provider; it receives the email address you entered and the code.
What syncs to our servers once you're signed in
- Value weights and directions — every preference you set during onboarding or later in the value legend, stored against your account and used to compute your scores. Two of the available preferences — favoring or steering away from brands' political-giving records, and favoring or steering away from documented faith-based partnerships or campaigns — are optional and default to "No position" until you choose otherwise. See "Special-category data" below.
- Brand lookups and your scored-brand history — when you search a brand or scan a barcode, the request is sent with your session's access token, and the record is stored against your account. An earlier version of this policy said lookups "are not linked to an account or advertising identifier" — that has not been accurate since accounts became required; we're correcting it here.
- Usage counters — how many lookups and scans you've used in the current billing month, enforced server-side so they can't be reset from the app.
- Follows — brands you choose to follow, for change alerts we plan to add.
- Subscription status — whether your account currently holds a paid entitlement, set by RevenueCat webhook events tied to your account id (see Service providers).
The app keeps a local, on-device cache of the above for offline use; that cache mirrors the server copy rather than replacing it.
Barcode scanning
Scanning a barcode sends the barcode number to our servers, which query Open Food Facts and, if that has no match, UPCitemdb, to resolve it to a brand or product name. Only the barcode number is sent to those two providers — not your account identity, email, or preferences.
What we don't do
- No advertising SDKs, no data brokers, no sale of personal information, no sharing for cross-context behavioral advertising.
- No collection of your contacts, photos, or precise location. The camera is used only to read barcodes, on-device; images are not stored or uploaded.
Crash reporting
Sentry crash reporting is active in the current app, not a future feature. If the app crashes or hits an error, Sentry receives the device model, OS version, and stack trace. We configure it with default PII collection turned off, so it does not automatically attach your IP address or other identifiers, and crash reports are tagged only with the project name — not your account or lookup history.
Website analytics
On ethosscan.com — the marketing website, not the app — we run Umami, a self-hosted, cookieless analytics tool. The tracking script and collection endpoint are proxied through our own domain, so your browser never contacts Umami's server directly; Umami hashes your IP address for same-visit counting rather than retaining it, and does not fingerprint you across other sites. This applies only to the website, not the app.
Service providers
These are the outside services that can see some part of your data, and what each one sees:
- Better Auth (self-hosted by us, auth.ethosscan.com) — your email, session records including IP address and user agent, one-time-code verification.
- Resend — delivers the sign-in code to the email address you provide.
- Supabase (our database and edge functions, hosted in the EU and US) — brand records plus your synced weights, usage counters, follows, and scored-brand history.
- Anthropic API — automated brand research; requests contain the brand name being researched only, never your account identity or preferences.
- Open Food Facts and UPCitemdb — barcode-to-brand resolution; requests contain only the scanned barcode number.
- RevenueCat — manages subscription/entitlement state; receives your account id (to link a purchase to your account) and purchase events forwarded from Apple.
- Apple (App Store) — processes payment for subscriptions, where offered; we never see or store your card details.
- Sentry — crash diagnostics, described above.
- Umami (self-hosted by us) — website analytics only, described above.
Special-category data (EU/UK GDPR Article 9)
Two of the optional value spectra — political-giving and faith-conduct — ask you to state a preference about brands' political donations or faith-based activity. Choosing a position on either could reveal something about your own political opinions or religious beliefs, which EU/UK law treats as a special category of personal data requiring a specific lawful basis (most likely your explicit, informed consent) beyond the general basis that covers the rest of this policy. Both default to "No position," and nothing is stored for either until you actively choose a position. We have not yet finished determining and documenting that lawful basis, and have not added a distinct consent step ahead of that specific choice. If you've already set either of these and would rather we not hold it, set it back to "No position" in the app or email [email protected] and we'll clear the stored value.
Data retention & account deletion
Deleting your account from the app removes your synced weights, usage counters, follows, and scored-brand history from our database. As of this policy's effective date, that action does not yet also delete the underlying Better Auth account record (your email and session history) — that part of deletion is still being built. Until it ships, email [email protected] and we'll delete that record manually within 30 days. Brand lookup requests are otherwise logged briefly for abuse prevention and then aggregated or discarded. Waitlist and contact email addresses submitted on our website are kept until you ask us to remove them.
Your rights
Wherever you're located, you can ask us to tell you what account data we hold about you, correct it, export it, or delete it (subject to the in-progress deletion gap noted above). If you're in the EU/UK, these are your rights under GDPR; if you're in California, similar rights exist under the CCPA/CPRA. Email [email protected] and we'll respond within 30 days.
Children's privacy
Ethos is not directed at children under 13, and we don't knowingly create accounts for or collect personal data from anyone under that age. If you believe a child has an Ethos account or has contacted us directly, email us and we'll delete it.
International data transfers
Our infrastructure and service providers may process data outside your country of residence, including in the United States and the European Union as noted above. Where required, we rely on standard contractual clauses or equivalent safeguards recognized under applicable data-protection law for these transfers.
Security
We use industry-standard measures — encryption in transit (HTTPS/TLS), row-level access controls on our database, and short-lived session tokens — to protect the account data described above. No system is 100% secure.
Your choices
- Set the political-giving or faith-conduct spectrum back to "No position" to stop syncing that value going forward.
- Delete the app to remove the on-device cache; email us to also remove your synced account data as described under "Data retention & account deletion" above.
- Email us to remove a waitlist address.
- Corrections to brand records: [email protected].
Contact
Privacy questions, requests, or complaints: [email protected]
Records published in Ethos are compiled automatically from cited public sources and may contain errors — verify sources before acting. This policy will be updated as the product evolves, including once account deletion is complete and the special-category lawful-basis review above is finished; material changes will be noted here.