OvineTrust & Security

Trust & Security

Last updated: 10 July 2026. This page is maintained by Ovine to answer common security and privacy questions about Faye and ovinewithfaye.com. It is editable project content, not an independent audit or certification.

Shared responsibility

Ovine builds and operates Faye. The underlying hosting, database, authentication, and email infrastructure are provided by our platform partner (Lovable / Supabase). Platform capabilities described below are factual features of that infrastructure. They are not certifications issued by Ovine, Lovable, or Supabase, and you (as a customer) are responsible for keeping your own account credentials safe.

Access & authentication

The public site, the privacy policy, and the mailing-list signup do not require an account. Faye's free features in the Chrome extension (the verdict, fibre breakdown, toxin/microplastic risk, and certification checks) also work without an account or login.

Ovine+ subscribers sign in to unlock the deeper analysis. Signed-in requests carry a secure authentication token so our server can confirm the subscription is active before returning the paid content. The token identifies your account to deliver the paid features, and it isn't used to build a browsing profile or track the pages you visit for advertising. You can clear it by signing out of the extension or removing it.

The admin dashboard used by Ovine staff is gated behind email/password authentication and a server-side admin role check; access is restricted to named Ovine team members.

Passwords are never stored by Ovine in plain text. Authentication is handled by the underlying platform's auth service.

Hosting & platform

Faye and ovinewithfaye.com run on Lovable Cloud, which uses Supabase (Postgres) for the database and Cloudflare's edge network for serving the site. Data is stored in EU regions where supported by the platform.

Connections to the site and to backend APIs are served over HTTPS.

What we collect

We keep what we collect deliberately small. The current categories are:

  • Mailing list & app waitlist: your email address when you choose to sign up (including the "coming to iOS and Android" waitlist), plus the date and which page you signed up from. Collected with your consent to contact you about Ovine; you can unsubscribe or request deletion at any time.
  • Anonymous analytics events: page views and interactions used to understand which features people find useful. Stored without an account identifier (only a rotating per-day key), and no name, email, or browsing history outside our own site.
  • Thumbs feedback: when you tap thumbs up or thumbs down, we record only the rating (up/down) and optional comment you type.
  • Product-page analysis (Faye extension): the visible product content of the page you are looking at, only at the moment you ask Faye to analyse it.
  • Community product contributions: when you photograph and confirm a product label, the extracted text (product name, brand, ingredients, nutrition) is saved and shared with other users who scan the same product so Faye can recognise it. Product information is shared; your identity is not. Your account identifier and a timestamp are stored with the contribution server-side for moderation only. Lawful basis: legitimate interests (a shared product database that benefits everyone) plus your explicit action to contribute.
  • Label photos (on-device only): when you photograph a food nutrition panel, a clothing care label, or a skincare / personal-care INCI list, the image is read on your device using Apple's Vision framework (iOS) or Google ML Kit (Android). No image bytes leave the phone. Only the confirmed text is sent to Faye for grading.
  • Reference photos (on-device only): the optional photo you can attach to a wardrobe or skincare item so you recognise it later is written to the app's private sandbox on your device and never uploaded. Deleting the item, tapping the bin on the photo, tapping “Clear all reference photos” in Preferences → Privacy, or uninstalling the app all remove them.
  • Your personal records (signed-in users): items you actively save or log against your account: personal care shelf, saved catalogue items / wishlist, wardrobe items, user profile, frequently eaten / frequently used items, and food diet logs (including photo-estimated meals). These are your own records, kept for you to view and manage; you can delete them in the app or request full removal.
  • Ovine+ account & auth token (subscribers only) works like this: if you sign in to an Ovine+ subscription, an authentication token is stored in the extension's local browser storage and sent with requests for premium features so our server can confirm the subscription is active before returning the deeper analysis. Free users don't sign in and no token is created. Lawful basis: performance of a contract. The token can be cleared by signing out of the extension or removing it.

For full detail, see our Privacy Policy.

Subprocessors & integrations

The third parties that process data on our behalf are:

  • Lovable Cloud / Supabase: application hosting, database, authentication.
  • Cloudflare: DNS and edge delivery.
  • Brevo: sending transactional emails (welcome messages) and any list updates from Ovine.
  • Lovable AI gateway (routing to Google Gemini and other model providers), used to generate Faye's analysis of product text. No label photos or reference photos are sent to the gateway; all image OCR runs on-device.

Cookies & analytics

We use first-party cookies only for things that are required to keep the site working (for example, keeping you signed in to the admin area). We do not use third-party advertising trackers.

Retention & deletion

Mailing-list emails are kept until you ask to be removed. Anonymous analytics events are retained to help us improve the product. If you want your email removed from the list, email us at the address below or use the unsubscribe link in any email we send.

Privacy requests

UK and EU residents have rights under data protection law, including the right to access, correct, or delete personal data we hold about you. To make a request, email hello@ovinewithfaye.com and we will respond within 30 days.

Reporting a security issue

If you believe you have found a security vulnerability in Faye or ovinewithfaye.com, please email hello@ovinewithfaye.com with details and steps to reproduce. Please give us a reasonable opportunity to investigate and fix the issue before disclosing it publicly.

Not medical advice

Faye is an educational and advisory tool, not a medical service. Nothing Faye says, including any pregnancy-safe, kids-safe, allergy, or ingredient-risk guidance, is medical advice, a diagnosis, or a substitute for professional care. Faye is not a doctor, midwife, pharmacist, or dermatologist. Always confirm anything specific to your health, your pregnancy, or your child's health with your GP, midwife, pharmacist, or another qualified healthcare professional.

Compliance

Ovine is a UK-based business and aims to handle personal data in line with the UK GDPR and Data Protection Act 2018. We do not currently hold independent certifications such as SOC 2 or ISO 27001. If a certification or specific contractual term (e.g. a data processing agreement) is required for your use case, please contact us.