Ovine & Faye — Privacy Policy
Last updated: 30 July 2026. This page is maintained by Ovine to answer common privacy questions about the Faye Chrome extension, the Ovine mobile app, and ovinewithfaye.com. Ovine is currently an early-stage validation prototype; this policy will be expanded as the product develops.
Who we are
Ovine with Faye is independently made by its founder — a UK-based self-employed project (currently registering with HMRC) building Faye, an AI guide that helps people understand what's really in the products they shop for. No brand pays to be listed. No result is sponsored. This policy covers the Faye Chrome extension, the Ovine mobile app, and ovinewithfaye.com.
Single purpose of the Faye extension
Faye analyses the product page a shopper is currently viewing and flags toxin, microplastic, and certification concerns, then suggests genuinely natural and certified alternatives.
What Faye reads
When you visit a regular web page, the Faye extension renders a small pinned tab on the right edge of the page. This tab is drawn locally from assets bundled inside the extension — no page content is read and no network request is made at this point.
Page content is only extracted and sent to our analysis service after you click the tab to open the panel (or open the toolbar popup) on that tab. We then read product descriptions, fibre/ingredient composition, and certification information from the page you’re currently viewing. Faye does not read your browsing history, does not read other tabs, and does not run in the background.
What we collect
- Page content for analysis — sent to our analysis service to generate your result. Not linked to your name or identity.
- Feedback — if you use thumbs up/down, your rating, any comment, and the page it relates to are sent to us to help improve Faye.
- Email address — if you sign up for app updates (including the "coming to iOS and Android" waitlist), we store your email solely to contact you about Ovine. Collected with your consent for that purpose; you can unsubscribe or ask us to delete it at any time.
- Local preferences — settings like Kids Safe mode and theme are stored locally in your browser and aren't sent to us.
- Ovine+ account & auth token (subscribers only) — if you subscribe to Ovine+ and sign in, an authentication token is stored in the extension's local browser storage and sent with requests for premium features (the deeper analysis) so our server can confirm your subscription is active before returning that content. Free users don't sign in and no token is created.
- Subscription status (subscribers only) — when a signed-in request arrives, we check whether your account has an active Ovine+ subscription. Lawful basis: performance of a contract (delivering the paid service you've signed up for). The token can be cleared at any time by signing out of the extension or removing it; the underlying account can be closed by emailing us.
- Personal care shelf (
personal_care_products) — skincare, haircare, and cosmetic items you save to your shelf, stored against your account so you can revisit them. - Saved catalogue items / wishlist (
catalogue_saves) — clothing items you save from the Faye-verified catalogue. - Wardrobe items (
wardrobe_garments) — garments you've added to your digital wardrobe, kept for you to view and manage. - User profile (
user_profile) — profile fields you've filled in (e.g. onboarding preferences), stored against your account. - Frequently eaten / frequently used items (
frequently_eaten,frequently_used) — a shortcut list of foods and personal-care products you interact with often, kept against your account so we can surface them quickly. - Sensitivity profile and allergen flags — health data. If you set a sensitivity profile (eczema, pregnancy, breastfeeding, allergy, sensory, baby-skin) or turn on food allergen / dietary flags (e.g. coeliac, milk, peanut), this is special-category health data under UK GDPR Art. 9. See Health & special-category data below.
- Food diet logs — health data (
logged_meals). The meals you add (photo-estimated or scanned) describe what you eat, so they are treated as special-category health data under UK GDPR Art. 9. See Health & special-category data below. - Apple HealthKit samples (iOS app only) — health data. If you connect Apple Health, Ovine reads sleep and step samples read-only. Details in Health & special-category data below.
Community product contributions
When you photograph a product label and confirm the reading, the extracted text — product name, brand, ingredients, and nutrition where applicable — is saved to help identify that product in future. This applies to community contribution tables including community_products, garment_composition_contributions, catalogue_verifications, unmatched_tag_reads, and off_contribution_queue.
- Shared with other users. The contributed product information is shared with other Faye users who scan the same product, so Faye can recognise items she couldn't before. What's shared is the product information, not personal information — other users don't see who contributed it.
- Contributor audit trail. Your account identifier and a timestamp are stored alongside each contribution. This identifier is not shown to other users; it's retained server-side so we can maintain data quality and prevent abuse (moderation).
- Lawful basis. Legitimate interests — building a shared product database that improves the service for everyone — together with your explicit action to submit the contribution. The audit trail relies on the same legitimate-interests basis for moderation.
- Removal. You can ask us to remove your contributions at any time under the rights described in Your rights below.
Product photos
If you choose to share a product photo with Faye, it's uploaded to our secure storage and processed once by an AI image service (via our platform provider Lovable and Google's Gemini API) to create a clean catalogue image. Under the applicable terms, these providers don't use your photo to train their AI models; Google may retain it briefly solely for abuse-prevention checks. By sharing a photo you give Ovine permission to use it to create and own the catalogue image. Your original photo is kept only until a person has reviewed the AI-enhanced version against it, and is then deleted; if the enhancement fails, the original is kept for retry for a maximum of 30 days and then deleted automatically. Your care label, ingredients, and nutrition photos are different: they're read entirely on your device and never leave your phone — only the extracted text is sent to us. You can ask us to delete any photo you've shared at support@ovinewithfaye.com.
Label photo OCR (mobile app)
When you photograph a food nutrition panel, a clothing care label, or a skincare / personal-care ingredient panel, the image is processed on your device using Apple's Vision framework (iOS) or Google ML Kit (Android) to read the text. These label photos are not uploaded, transmitted, or stored anywhere off your device — only the text read from them is sent to Faye for grading, and only after you review and confirm the reading. This includes INCI lists: cosmetic label photos never leave the phone. Front-of-product photos you choose to share are the exception — see Product photos above.
Reference photos — the optional photo you can attach to an item in your wardrobe or skincare shelf so you recognise it later — are saved only on this device, inside the app's private sandbox (iOS Filesystem / Android app storage on the native app; browser IndexedDB on the web). They are never uploaded, never backed up to our servers, and the database stores only a local reference — never the image bytes. You can delete a reference photo at any time from the item, or clear every reference photo in Preferences → Privacy. Uninstalling the app removes them all.
Data types under Chrome Web Store categories
For clarity with the Chrome Web Store user-data disclosure, here is how what we collect maps to Google’s data-type categories:
- Website content — the text content of the product page you actively choose to analyse.
- User activity — anonymous, aggregated usage statistics (e.g. which features you used, how often you returned). Not linked to your identity.
- Personally identifiable information — only your email address, and only if you choose to sign up for Ovine updates.
The Chrome extension itself does not collect health information, financial information, authentication information, personal communications, location data, web history, or any other category of user data beyond those listed above. Health-related information collected by the Ovine mobile app and website (sensitivity profile, food diet logs, Apple HealthKit samples) is covered separately in Health & special-category data below and is not sent to or accessed by the browser extension.
Health & special-category data (UK GDPR Art. 9)
Some Ovine features involve information about your health, body, or diet. Under UK GDPR this is special-category data and needs a separate, explicit lawful basis. For every feature below, the lawful basis is Art. 6(1)(a) (your consent) and Art. 9(2)(a) (your explicit consent for special-category data). We ask for this consent separately, in a discrete affirmative step — it is not bundled into acceptance of our general Terms, and we do not use a single "accept all" prompt. You can withdraw any of these at any time in Preferences → Health data & consent; withdrawal stops the processing immediately and, where the data is held on our servers, we offer to delete it.
- Sensitivity profile & allergen / dietary flags. What you tell us about eczema, pregnancy, breastfeeding, allergies, sensory sensitivities, baby skin, and food allergen / dietary needs (e.g. coeliac, milk, peanut, egg, tree nuts, soy, gluten, fish, shellfish). Used only to flag matching ingredients on scans. Stored on this device (
ovine.sensitivityProfile,faye.food.allergenPrefsin localStorage) — not sent to our servers. Consent record:ovine.healthDataConsent.*, stored on-device with the copy version and timestamp. Retention: until you withdraw or clear browser storage. Withdrawal in Preferences clears these preferences. - Food diet logs (
logged_meals). The meals you add — photo-estimated, scanned, or typed — describe what you eat, so we treat them as health data. Stored against your account on our servers so Faye can show your daily and weekly view. Retention: until you delete them, or ask us to remove your account. Withdrawal in Preferences deletes every meal you have logged. - Apple HealthKit samples (iOS app only). If you connect Apple Health, Ovine reads sleep analysis and step-count samples read-only. These samples are processed on your iPhone and the raw values are never sent to our servers. In line with Apple's HealthKit rules, we do not use HealthKit data for advertising or similar services, and we do not share HealthKit data with any third party. Only the user can revoke HealthKit permission itself, from iOS Settings → Health → Data Access & Devices → Ovine; withdrawing consent in Ovine stops us from reading new samples on the device.
We do not use any of the above to make automated decisions with legal or similarly significant effects about you, and we do not sell or share it for advertising.
Where your data goes — processors we use
We use a small number of third-party processors to run Ovine. Each is bound by a written data-processing agreement and only acts on our documented instructions:
- Supabase — our managed database, authentication, and storage backend (Supabase, Inc., US, with EU data-residency for our project). Stores your account, catalogue saves, wardrobe, personal-care shelf, food logs, and community contributions.
- RevenueCat — subscription infrastructure for Ovine+ (RevenueCat, Inc., US). Receives your Apple-issued subscriber ID and receipt so we can confirm your subscription is active. Does not receive your email, name, or Ovine account contents.
- Apple — App Store, in-app purchases, and (on the iOS app only) HealthKit and Sign in with Apple (Apple Inc., US, with EU data-residency for App Store data). Apple is the seller of record for Ovine+ and issues the durable-medium receipt for your purchase.
- LLM provider — Google Gemini via the Lovable AI gateway — performs the language-model analysis that produces Faye's verdict, ingredient explanations, and tips. We send the page or label text; we do not send your email, name, or Ovine account identifier. Requests are not used to train the model.
- Lovable Cloud — the managed application platform on which our analysis backend runs (Lovable AB, EU).
- Resend — sends the email you receive when you sign up for product updates (Resend, Inc., US). Receives only your email address.
- Open Food Facts — independent non-profit food database queried server-side by us so your IP address is not passed on. See openfoodfacts.org.
Data is transmitted over HTTPS. We do not sell user data, and we use and transfer it only for the purposes described in this policy.
International data transfers
Some of the processors above are based in the United States. Where personal data leaves the UK / EEA to reach them, we rely on the following safeguards to meet UK GDPR Chapter V and EU GDPR Chapter V:
- For transfers to the US, the UK–US Data Bridge (the UK extension to the EU–US Data Privacy Framework, in force from 12 October 2023), where the recipient is self-certified under the DPF. This is the case for Apple and Google.
- Otherwise, the EU Standard Contractual Clauses (2021/914) plus the UK International Data Transfer Addendum (IDTA / UK Addendum) issued by the ICO, together with a documented Transfer Risk Assessment.
You can request a copy of the safeguards for a specific transfer by emailing us at the address in the Contact section.
Usage statistics
We collect anonymous usage data to help us understand how Faye is used and to improve her — including which types of products are analysed, which features (like Kids Safe or Sun Safe) are used, and how often people return to use Faye. This data is aggregated and not linked to your identity or browsing history.
Ovine barcode scanner (mobile app & web)
The Ovine scanner lets you scan a clothing barcode to check whether the product is already in our Faye-verified catalogue. It is available in the mobile app and on the website at ovinewithfaye.com/scan. We treat camera and scan data as follows:
- Camera access — the camera is only activated when you open the scanner. The video feed is processed entirely on your device to detect a barcode. No video or camera frames from scanning are uploaded to us or to any third party (front-of-product photos you deliberately choose to share are covered under Product photos above).
- Barcode (GTIN) lookup — once a barcode is detected, only the resulting digits (the GTIN) are sent to our backend to look it up against the public Ovine catalogue. The lookup is not tied to your name, email, or device identifier.
- Scan history — a list of barcodes you have scanned (found or not found) is stored locally on your device so you can review your scanned wardrobe. It is not sent to us and is not backed up to the cloud. You can clear it at any time from the scan history screen. We keep a maximum of 200 recent scans.
- "Help map it" submissions — if a barcode is not in our catalogue yet, you can optionally tell us the brand and product name you see on the label. This is sent to our review queue so we can verify and add the item. It is submitted anonymously — not tied to your name, email, or device identifier.
- No background scanning — the scanner only runs while you have the scanner screen open, and stops the moment you leave it.
- Local preferences — app and site settings (e.g. theme) are stored locally on your device and are not sent to us.
You can revoke camera permission at any time in your device or browser settings; the rest of the app and site continues to work without it.
Food scanning (mobile app & web)
When you scan a food product, Faye reads the barcode on your device and looks it up in Open Food Facts, an independent non-profit product database. We treat food scan data as follows:
- Camera & barcode — same as our clothing scanner: the camera is only on while the scan screen is open, and no video frames from scanning leave your device (front-of-product photos you deliberately choose to share are covered under Product photos above).
- Open Food Facts lookup — once the barcode is read, only the digits (the GTIN) are sent, via our backend, to Open Food Facts to fetch product name, ingredients, and nutrition. The lookup is made server-side, so your IP address is not passed on to them. See openfoodfacts.org for their own privacy notice.
- The shop you're in — when Faye asks "Which shop are you in?", your answer is saved in your browser's sessionStorage under
faye.food.currentStoreso she can tune tips and "better options" to the shelf you're standing in front of. It never leaves your device and is cleared automatically when you close the tab. You can clear or change it any time via the "Change shop" link on any food result. - AI grade & tips — the product data (name, nutrition, ingredients) is sent to our Lovable AI gateway to write the one-line verdict and Faye's tips. Nothing about you personally is attached to the request.
Storage on your device (PECR)
Under UK PECR (as clarified by ICO guidance on 29 April 2026), anything Faye stores in your browser — cookies, sessionStorage, localStorage — must have a lawful basis. We don't use any advertising or analytics storage, so no consent banner is required, but here's every item we do store and why:
| What | Where | Why we're allowed to store it |
|---|---|---|
| Sign-in session | localStorage | Strictly necessary — keeps you signed in to a service you asked for. |
Your current shop (faye.food.currentStore) | sessionStorage | Strictly necessary — set only after you actively choose a shop, required to deliver the store-personalised food tips you requested. |
| Compare-view origin | sessionStorage | Strictly necessary — needed to complete a Compare you initiated. |
| Catalogue cache (extension) | sessionStorage | Strictly necessary — caches results of a search you asked Faye to run. |
| Tier-2 session flag | sessionStorage | Strictly necessary — set when you follow a Tier-2 link you clicked. |
| Tier-2 persistent opt-in | localStorage | Functionality — remembers your explicit toggle preference. |
| Sensitivity profile | localStorage | Functionality — remembers a preference you set (eczema, pregnancy, etc.). |
| Personal scan history (max 200) | localStorage | Functionality — your scanned wardrobe, never leaves the device. |
| Theme (light / dark) | localStorage | Functionality — remembers your visual preference. |
| Dismissed banners | localStorage | Functionality — so we don't keep re-showing something you've dismissed. |
| "Splash played" flag | sessionStorage | Functionality — stops the intro splash replaying mid-session. |
You can clear any of these by clearing your browser's site data for ovinewithfaye.com (or removing the extension for the extension items).
What we don't do
- Free features work without an account. You can use Faye's free features — the verdict, fibre breakdown, toxin/microplastic risk, and certification checks — without an account or login. If you subscribe to Ovine+, you'll sign in, and signed-in requests for the deeper analysis include a secure authentication token so our server can confirm your subscription is active before returning the paid content. That token identifies your account to deliver the paid features; it isn't used to build a browsing profile or track the pages you visit for advertising.
- We do not sell or transfer user data to third parties outside of the approved use cases described above.
- We do not use or transfer user data for purposes that are unrelated to Faye’s single purpose.
- We do not use or transfer user data to determine creditworthiness or for lending purposes.
- We don’t track your browsing outside the page Faye is actively analysing.
How long we keep it — retention
| Category | Retention |
|---|---|
| Account (email, sign-in identifiers) | Until you close the account. On closure, deleted within 30 days. |
| Ovine+ subscription status & Apple receipt | Duration of your subscription plus 7 years (UK VAT / financial-records retention). |
| Wardrobe, personal-care shelf, saves, frequently used | Until you delete the item or close the account. |
Food diet logs (logged_meals) | Until you delete a meal, withdraw food_log consent (which erases all logged meals), or close the account. |
| Sensitivity profile & allergen flags | On-device only. Until you clear them or clear browser / app storage. |
| Apple HealthKit samples | Read on-device, not stored on our servers. Revoke in iOS Settings → Health. |
| Community product contributions | Retained as part of the shared catalogue; your contributor identifier is retained for moderation for 3 years, then anonymised. |
| Extension feedback (thumbs up/down + comment) | Up to 24 months for quality analysis, then aggregated and the raw record deleted. |
| Signup email (updates waitlist) | Until you unsubscribe or ask us to delete it. |
| Anonymous usage statistics | Aggregated indefinitely; individual events dropped within 90 days. |
| Consent records (health data, CCR reg. 37) | For as long as we rely on the consent, plus 6 years (limitation period), so we can show it was validly given. |
You can ask us to delete anything ahead of these periods at the email in Contact below — subject to legal-retention obligations (mainly the 7-year VAT / accounting period for paid subscriptions).
Children
Faye isn’t directed at children. The Kids Safe toggle is designed for parents and guardians to use on behalf of children, not for children to use the extension themselves.
Faye Safari extension (iOS & macOS)
Ovine ships a Safari web extension bundled with the iOS app (and available on macOS Safari) that provides the same in-page Faye analysis as the Chrome extension. It behaves the same way: the pinned tab is drawn from bundled assets and reads no page content until you tap it, at which point the product page's visible text is sent to our analysis backend. If you're an Ovine+ subscriber signed into the app, the extension reads a shared authentication token from the app's App Group container (an Apple-provided secure area shared between the app and its extension) so premium features unlock without a second sign-in. No browsing history is collected, no other tabs are read, and the extension does not run in the background. The categories of data listed under What we collect apply to the Safari extension in the same way.
Chrome Web Store — Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Your rights
Under the UK GDPR and Data Protection Act 2018 (and the EU GDPR where it applies to you), you have the following rights over the personal data we hold about you:
- Access — ask what data we hold about you and get a copy.
- Rectification — ask us to correct inaccurate or incomplete data.
- Erasure — ask us to delete data ("right to be forgotten"), subject to legal-retention exceptions listed above.
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — ask us to send the data you have provided to you, or directly to another controller, in a structured, machine-readable format (JSON).
- Objection — object to processing based on legitimate interests, including any community-contribution moderation processing.
- Withdraw consent — where we rely on your consent (health data, marketing email, CCR reg. 37), withdraw it at any time. Withdrawal doesn't affect processing already carried out before withdrawal.
- Not to be subject to solely automated decisions with legal or similarly significant effects — we don't make any such decisions about you.
California residents have equivalent rights under the CCPA / CPRA (know, delete, correct, opt out of "sale" or "sharing" — we do neither).
To exercise any of these, email us at the address below. We will respond within one month.
Right to complain. If you are unhappy with how we have handled your data, you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or by calling their helpline on 0303 123 1113. We'd rather hear from you first so we can put it right, but you can go to the ICO at any time.
Contact
Ovine with Faye — a UK-based sole trader. Correspondence address available on request. Questions, rights requests, or deletion requests? Email us at support@ovinewithfaye.com.