Privacy policy
Last updated September 24, 2026
FoodCode is a reference app for the Ohio Food Code, on iPhone and on the web. This policy explains, in plain language, what information FoodCode collects, why, and what you can do about it. It covers the iPhone app, the web app at app.foodcodebuddy.com and this website.
The short version
- We collect what it takes to run your account and keep the app working, and nothing more.
- No ads. No tracking across other apps or websites. We don't sell or rent your data to anyone.
- Crash and error reports identify you only by an internal account number, never your name or email.
- You can delete your account, and your own data with it, from the app or the web at any time.
What we collect, and why
Your account
Sign-in is handled by Clerk, our authentication provider. When you create an account, Clerk stores your email address, your name and your password (we never see your password). If you sign in with another provider, such as Sign in with Apple where it is offered, Clerk receives the name and email address that provider shares with us. FoodCode keeps its own copy of your email address and name, an internal account id, and the time you last signed in, so that it can show your data to you and nobody else.
What you create
Your tag groups, and the tags, notes and rule links inside them, are stored on our servers so they sync between your devices. If you belong to an organization, such as a health district, we store that membership and your role in it. An organization's tag groups belong to the organization and are visible to its members.
On your devices
The iPhone app stores the Ohio Food Code and a copy of your data on your phone, so it works offline. The web app stores your preferences, such as recent searches and that you've read the disclaimer, in your browser, and Clerk sets the cookies needed to keep you signed in. None of this is used for advertising or tracking.
Crash reports and diagnostics
To find and fix problems we use Sentry. When the app or our server hits an error, Sentry receives a report: what went wrong, the device model and operating system version, the app version, and recent app log messages. On iPhone this also includes system diagnostics about crashes and hangs, and a short replay of the screen in the moments before an error, with all text and images masked. At most, a report carries your internal account id, never your email or name. Sentry is set not to store IP addresses, and our server removes request contents, such as what you searched for or typed into a note, before a report leaves it.
Feedback you send
You can send feedback from the iPhone app by shaking your phone or from Settings › Send Feedback. The feedback form sends your message and the diagnostics described above, and does not ask for your name or email. It also sends any screenshots you choose to include: the form attaches a screenshot of the screen you were on, which you can remove before sending, and you can add more from your photos. If you are a beta tester, you can also send a screenshot with a comment through TestFlight, which passes it to us with your name, email address and device details.
Beta testers, please note: feedback you send, both TestFlight screenshots with their comments and the in-app feedback form, is filed as an issue in FoodCode's private GitHub repository so we can track and fix what you report. Only the people who build FoodCode can see that repository. Please don't include anything in feedback that you wouldn't want stored there.
Beta requests
When you request beta access, we store your name, email address, and the organization, role and message you choose to give. We use them to decide on and send your invitation, and to contact you about the beta. To invite you, we send your name and email address to Apple, which runs TestFlight. To stop abuse, the form is rate limited by IP address; that address is held briefly in memory and is not stored.
Email to support
Mail to support@foodcodebuddy.com is delivered through Cloudflare's email routing to our inbox. We use what you send only to answer you.
This website
This website sets no cookies and runs no analytics or third-party scripts. It is hosted on Cloudflare, which processes the standard technical information any web server receives, such as your IP address, to deliver the pages and protect them from attacks.
What we don't do
- We don't show ads.
- We don't track you across other companies' apps or websites.
- We don't sell, rent or trade your personal information.
- We don't use your notes or tags for anything except showing them to you and your organization.
Who processes your data
We use a small number of service providers, each only for the job listed:
- Clerk: accounts and sign-in.
- Railway: hosts our servers and database, in the United States.
- Sentry: crash reports, diagnostics and in-app feedback, in the United States.
- GitHub: stores beta feedback as issues in our private repository.
- Apple: TestFlight and the App Store.
- Cloudflare: this website, our domain and support email.
We may disclose information if the law requires it, and only as far as it requires.
How long we keep it
We keep your account and what you create until you delete your account. Beta requests are kept while the beta runs; email us to have yours removed sooner. Crash reports and diagnostics are kept only for Sentry's limited retention period and then deleted.
Deleting your account
In the FoodCode iPhone app, go to Settings → Account → Delete Account. The screen lists what will be deleted, and you confirm before anything happens. On the web, go to Settings → Delete Account (under Danger Zone) and confirm. Both do exactly the same thing.
This permanently deletes, right away:
- your account and your sign-in;
- your own tag groups, including every tag, note and section link in them;
- your organization memberships.
Tag groups that belong to an organization, such as the State of Ohio groups, stay with that organization. The Ohio Food Code already downloaded to your phone keeps working offline without an account. On the phone, the app signs you out and removes your account's data from the device.
You need an internet connection to delete your account; the button is disabled while you're offline. Deletion can't be undone. If you sign up again with the same email, you start with a new, empty account.
If you signed in with Apple, you can also remove FoodCode's access to your Apple ID: on your iPhone, go to Settings → [your name] → Sign in with Apple → FoodCode → Stop Using Apple ID.
Can't sign in, or want us to do it for you? Email support@foodcodebuddy.com from the address on your account.
Children
FoodCode is a professional tool and is not directed at children under 13. We don't knowingly collect their information.
Changes to this policy
If we change this policy, we'll update it here and change the date at the top. If a change is significant, we'll also tell you in the app.
Contact
Questions, or a request to see, correct or delete your information: support@foodcodebuddy.com.