Privacy Policy
Effective July 19, 2026 · Consumer Transparency Collective, a 501(c)(3) nonprofit
Who we are
Defund Whatever is operated by the Consumer Transparency Collective ("CTC", "we"), a Missouri nonprofit corporation recognized as tax-exempt under IRC section 501(c)(3). Our mission is consumer transparency, not data collection — this policy reflects that.
What we collect, and why
- Account information (optional). If you create an account: your email address, display name, and a securely hashed password (we never store the password itself). If you sign in with Google, Apple, or another provider, we receive your name and email from that provider. Guest mode requires no account.
- Your value preferences. The importance sliders you set (environment, labor, and so on). Stored on your device; synced to our servers only if you have an account, so they follow you across devices.
- Photos and voice recordings you submit. When you analyze a product photo, receipt, or voice query, the image or audio is transmitted to our servers and processed by an AI model (AWS Bedrock) to identify brands. Photos are processed transiently and are not retained after analysis. Voice recordings are stored briefly for transcription processing and are not used for any other purpose.
- Usage counts and cost accounting. We count scans per day per account or device (to enforce fair daily limits) and record the computing cost of analyses (to keep the free tier sustainable). This is bookkeeping, not behavioral tracking.
- Scan history, favorites, and lists. Stored locally on your device. If you create an account, favorites and lists can sync to our servers so they persist across devices.
- Crash and error reports. We use Sentry to collect crash diagnostics (device model, OS version, stack traces) so we can fix bugs. These are not used for advertising or profiling.
What we don't do
- No selling or renting of personal data — to anyone, ever.
- No advertising and no ad-tracking SDKs.
- No collection of your location, contacts, or browsing history.
- No sharing of personal data with the external data sources we query — brand lookups are made by brand name only and contain nothing about you.
Service providers
We rely on a small set of processors to run the service:
- Amazon Web Services — hosting, database, and the Bedrock AI service that performs analyses.
- Sentry — crash and error reporting.
- Stripe — donation and subscription processing. Your card details go directly to Stripe and never touch our servers.
- Expo — app updates and (if you enable them) push notifications.
Data retention and deletion
- You can delete your account at any time in the app (Profile → Delete Account) or by emailing us. Deletion removes your account, preferences, synced favorites, lists, and alerts from our servers.
- Scan history on your device is yours — clear it in the app whenever you like.
- Server logs and crash reports are retained for up to 30 days.
Your rights
Depending on where you live (including the EU/EEA, UK, and California), you may have rights to access, correct, export, or delete your personal data, and to object to certain processing. Email us and we will honor these requests for everyone, regardless of jurisdiction. We do not "sell" or "share" personal information as defined by the California Consumer Privacy Act.
Children
Defund Whatever is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
Security
All traffic is encrypted in transit (TLS). Passwords are hashed with bcrypt. Access tokens are stored in your device's secure storage. Secrets and credentials on our side live in AWS Secrets Manager, not in code.
Changes
If we change this policy, we will update the effective date above and, for material changes, notify you in the app. We will never quietly weaken the commitments on this page.
Contact
Consumer Transparency Collective
Email: josh@ewolfsoft.com