Privacy policy
Last updated 9 October 2026
In short
Checkly keeps your answers, your scan history, your shelf and your beauty profile on your phone. It has no account and no analytics. What leaves your device: the barcode you scan and anything you type into search, to look products up; a product you add, once Checkly's shared database is switched on (it is off today, so additions stay on your phone); a product you ask Checkly to score or report; on iPhones without Apple Intelligence, the text read from an ingredient list or the front of a pack, so Checkly's server can find the list or the product's name in it; a question you type to Mira, Checkly's beauty assistant, unless you turn that off in the app's Profile; a daily request for Checkly's list of better swaps, which carries nothing about you; and your App Store purchase, which Apple handles. Photographs and camera frames never leave it at all.
Who is responsible
Checkly is made by Nave, trading as Checkly, Jan Nautahof 46, Amsterdam, the Netherlands. KVK 80502474, VAT NL003447574B73. The one address for everything — support, privacy requests, legal notices — is info@get-checkly.com.
For the purposes of the EU General Data Protection Regulation (GDPR), Nave is the controller of the little personal data this policy describes.
What you give Checkly
During the introduction you tell Checkly what you want to check. That answer, every scan you make and every product you put on your shelf — with the date you opened it — are written to this device's storage and are never transmitted.
Checkly does not ask for your name, your email address, your date of birth or your location, and it has no login.
Information collected automatically. None.
Checkly has no analytics, no crash reporting and no advertising SDK. It does not collect usage data, session data, device identifiers or an advertising identifier. Your preferences, scan history and shelf are written only to this device's storage and are never transmitted. The only data that leave the device are (a) the barcode number, (b) any text you type into Search, (c) a product you add, (d) a product you ask Checkly to score or report, (e) on iPhones without Apple Intelligence, the text read from an ingredient list or the front of a pack, (f) a question you type to Mira, Checkly's beauty assistant, unless you have turned that off in the app's Profile, and (g) your App Store purchase, which is handled entirely by Apple.
Checkly does not track you across other companies' apps or websites, and so it never asks for App Tracking Transparency permission. It sells nothing, and it holds nothing about you beyond the products you add.
Barcode lookups
When you scan a product, the barcode number is sent to Open Beauty Facts. If the product is filed in one of its sister databases — Open Food Facts, which holds many makeup products, Open Pet Food Facts or Open Products Facts — Open Beauty Facts passes the request on. These databases are run by a French non-profit and are independent controllers of the requests they receive: world.openbeautyfacts.org/privacy.
The same number is sent to Checkly's own product database, to see whether another Checkly user has added the product. Only the number is sent, without any identifier, and the lookup is not stored.
Search
The text you type is sent to world.openbeautyfacts.org and world.openfoodfacts.org to find matching products. It is not sent anywhere else, it is not stored by us, and it is not linked to you or your device. Both are run by the same French non-profit, an independent controller of the requests it receives: world.openbeautyfacts.org/privacy.
Products you add
When a product is in no database, you can add it: Checkly reads its ingredient list with the camera, and you give it a name. It is kept on your device, and the barcode, the name, the brand, the category and the ingredient list — never a photo — are sent to Checkly's product database, so that anyone who scans the same barcode sees them. That is what adding a product is for, so every product you add is shared. Until the database is switched on in the app, nothing is sent: products you add — including those added with an earlier version of Checkly — wait on your device and are sent the first time the app can reach it.
So that you can remove what you added, and so that misuse can be stopped without stopping everyone, each shared product carries a random contributor number created for that installation of the app. It is not linked to your name, your email address, your Apple ID or your device. The same number is attached to any report you send about a product, with the reason and any note you write.
The database is hosted for us by Supabase, Inc. in Frankfurt (EU), as our processor under a data-processing agreement. Shared products stay until you remove them in Profile › Products you added, or until we remove them; reports are kept as long as the product they concern. We process this on the basis of our legitimate interest in running a shared product database (Article 6(1)(f) GDPR): the data describe products, not you, and you can remove anything you added at any time. Please don't type anything personal into a product's name or a report.
Asking for a product to be scored
When Checkly can't score a product — it is in no database, or its record has no ingredient list — you can ask for it to be scored, and you can report a problem with any product. The barcode, the product's name and brand where known, and for a report the reason and any note you write, are sent to Checkly's product database with the same random contributor number described above, so that repeated requests can be counted and misuse stopped. Requests are kept until the product is added or for at most one year, on the same legal basis and with the same processor as products you add.
Finding the ingredient list
After the text recogniser has read a photo, Checkly works out which part of that text is the ingredient list. On an iPhone with Apple Intelligence, Apple's on-device language model does this on the phone, with no network. On other iPhones the recognised text — never the photo — is sent to Checkly's server at get-checkly.com, hosted for us by Vercel Inc., which asks Claude, a model from Anthropic, to find the list and sends the answer straight back. The text is not linked to you, your device or an account, and Checkly does not store it.
Anthropic processes the text for us, as our processor. Under its commercial terms it does not use the text to train its models and deletes it within 30 days, or keeps it for up to two years if it is flagged under Anthropic's usage policy. We rely on our legitimate interest in reading the list you asked Checkly to read (Article 6(1)(f) GDPR). A photo of a pack rarely holds anything personal; a screenshot can, so choose one that shows the ingredient list. If the server can't be reached, Checkly finds the list on the phone with its own rules.
When you photograph the front of a pack, Checkly reads the product's brand, name and shade from the words on it in the same way: with Apple's on-device model where there is one, and otherwise by sending the recognised words — never the photo — to Checkly's server, which asks the same Claude model and sends the answer straight back. The same processors, terms and legal basis apply, and nothing about you goes with the words. If the server can't be reached, Checkly names the product on the phone with its own rules, or leaves the name for you to type.
Mira, Checkly's beauty assistant
Mira, Checkly's beauty assistant, answers questions about makeup with Checkly's goal guides, which run on your phone and send nothing. When you type a question of your own, Checkly first tries to understand it on the phone, with Apple's on-device model where there is one. When that isn't possible, the question is sent to Checkly's server at get-checkly.com, hosted for us by Vercel Inc., which asks Claude, a model from Anthropic, and sends the answer straight back. The chat says so under Mira's greeting. At most 30 questions a day go to the server.
What is sent: your question, up to six earlier messages of the same conversation, the app's language, the market you shop in (the Netherlands or the US), the answers in your beauty profile that are not about your face — skin type, whether products sting, whether you break out easily, contact lenses or sensitive eyes, the finish you like and your budget — and the kinds of products on your Shelf ("mascara", never the products themselves). Never a photo, your skin tone, undertone or colour season, or anything else that comes from your face, and nothing that identifies you. Checkly does not store the messages.
Anthropic processes them for us, as our processor: under its commercial terms it does not use them to train its models and deletes them within 30 days, or keeps them for up to two years if they are flagged under Anthropic's usage policy. We send your question because that is how Mira answers the question you asked, under our terms with you (Article 6(1)(b) GDPR). You can turn this off at any time in the app, in Profile › Your data; Mira then answers on the phone and with the goal guides, and nothing more goes to the server. Answers written by the model are marked "AI", can be wrong and are not medical advice. Products are only ever suggested by Checkly's own ranking, by score — never by the model.
Where the server work happens
Checkly's server code runs in Vercel's Frankfurt region, in the EU. Vercel Inc. is a US company whose main processing facilities are in the United States, and Claude is provided to us by Anthropic Ireland Limited, which works with Anthropic, PBC: Anthropic stores data in the United States and may route a request to servers in the United States, Europe, Asia or Australia. So a question you type to Mira, and the words read from an ingredient list or from the front of a pack, can be processed outside the European Economic Area. Vercel's and Anthropic's data processing agreements cover those transfers with the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914). Write to info@get-checkly.com for a copy of the clauses that apply.
Your beauty profile and photo
Your shades can come from a photo of your face or from four questions; the photo is never required. When you use one, Checkly reads it on your phone with Apple's Vision framework: where your features are, the colour of your skin and eyes, and the light. From the photo and your answers it works out your profile — skin depth, undertone, colour season, contrast, eye colour and face shape. None of this is used to identify you, and Checkly never guesses your age, gender or ethnicity.
The profile, your answers, the products and goals you save, and one photo kept for previewing looks are stored only on this phone and are left out of iCloud and device backups. The photo and anything that comes from your face are never sent anywhere — not to Checkly, Mira, analytics or anyone else; a question you send to Mira carries only the answers listed above. Any other frames the camera took are discarded once the photo has been read.
You can change any of it, retake or replace the photo, and delete it all with Delete my photo and profile in Profile › Beauty profile, at any time and with or without a subscription (behind the subscription screen, through its Beauty profile link). Reset Checkly removes it too.
Look previews and the Mirror
Looks are drawn on your photo on this phone, by Checkly's own renderer; nothing is uploaded. Until you add a photo, they are shown on an AI-generated model, labelled as one. Every preview carries a "Checkly preview" mark, and so does a picture you share; sharing is always your choice, through the share sheet.
Live try-on uses Apple's ARKit face tracking on the front camera: the camera frames and the face mesh are processed on this phone in real time to draw the look, and are never stored or sent anywhere — not to Checkly, analytics or anyone else; a still you take stays on the phone unless you share it.
The Mirror uses the front camera only while it is open. Nothing is recorded, saved or sent: a frame you freeze stays in memory until you close the Mirror.
Camera and text recognition
The camera is used to read barcodes, ingredient lists and the front of a pack. Every frame is processed on this device by Apple's Vision framework — the barcode detector and the text recogniser run on the phone, with no network. A still taken of an ingredient list is held in memory while it is read and then discarded: it is never written to disk, never uploaded, and never added to the scan record. What is kept is the recognised text, on this device, as part of the result.
A photo of a pack's front is kept on this device, re-encoded so that no location or other metadata stays with it, to show the product in its result, your history and your shelf. It is never uploaded, and it is deleted once neither your history nor your shelf shows the product, or when you reset Checkly.
Checkly asks to use the camera the first time you scan, take a photo for your beauty profile or open the Mirror, and for nothing else.
Photos
Reading an ingredient list from a photo or a screenshot uses the system photo picker, which hands Checkly only the one image you choose; Checkly never asks for access to your photo library and cannot see anything you did not pick. The picked image is read on the device by the same text recogniser and is not stored or uploaded. A photo of a product's front, taken or picked, is stored on your device only, re-encoded so that no location or other metadata stays with it, and is never uploaded.
Reminders
Expiry reminders are local notifications, scheduled on this device by the app and delivered by iOS. They involve no server and no push service. Checkly asks for permission to show notifications the first time a reminder is needed, and you can turn them off in Profile or in Settings at any time.
On-device cache
Products you look up are cached in the app's Caches folder for 7 days so re-scans are instant. iOS may clear it at any time; deleting the app removes it.
Share card
Sharing a result creates an image on your device and hands it to whichever app you choose. Nothing is uploaded by Checkly.
Better swaps
Better swaps are chosen and ordered on your device, from a list of products Checkly publishes; nothing about you is sent anywhere to do it. Once a day the app downloads the latest list from get-checkly.com: a plain request that carries nothing about you, though Vercel Inc., which hosts the site, sees the request's IP address as any website would. Swaps you save stay on your device.
Purchases
Subscriptions are sold and billed by Apple. Checkly sees only whether an entitlement is active, which is stored on this device so the app still opens when you have no signal. Checkly never sees your card details, your billing address or your Apple ID. Apple's privacy policy applies to the payment itself: apple.com/legal/privacy.
Partner offers
Some free trials come with a voucher from a partner — in October 2026, Qlear, for trials started in the United States, the United Kingdom or Australia. To know whether an offer is running, the app downloads a small file from get-checkly.com; the request carries nothing about you, and our host sees it the way it sees any web request. Your App Store country is read on your phone; the request doesn't include it. Nothing about you goes to the partner: the code is the same for everyone in your country, so it cannot identify you, and whether you claimed it stays on your device. If you open the partner's shop, their own terms and privacy policy apply there.
If you email us
If you write to info@get-checkly.com, we use your email address and what you wrote to answer you, which is our legitimate interest in replying (Article 6(1)(f) GDPR). We keep that correspondence no longer than 24 months after the matter is closed, and we do not use it for anything else.
This website
get-checkly.com sets no cookies and runs no analytics or advertising scripts. It is a set of static pages hosted by Vercel, which, like any web host, processes the technical data needed to deliver a page to you, such as your IP address, under its own privacy policy. The App Store badge is loaded from Apple.
Your rights
Under the GDPR you may ask for access to your personal data, and for its correction, deletion or restriction, and you may object to its processing. In practice Checkly holds almost nothing about you that we can reach: your answers, your history and your shelf are on your device, and Profile › Your data removes them at any time; your beauty profile and photo are too, and Profile › Beauty profile deletes them. Deleting the app removes them too. What reaches us is the products you added and any report you sent, linked only to a random contributor number; Profile › Products you added removes shared products, and for anything else write to us with the product's barcode.
Requests and questions go to info@get-checkly.com. If you are not satisfied, you may complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the supervisory authority where you live.
Children
You must be at least 16 to use Checkly. Checkly is not directed at children, and it holds no date of birth, because collecting one would create personal data the app otherwise does not hold.
Changes
If this policy changes, the date at the top of this page changes with it and the new version ships in an app update.