Privacy Policy
Last updated: August 2026. This policy applies to the Tayyib app and to this website.
Controller
Harith Al-Ani
Max Schwarze Weg 27A
46236 Bottrop
North Rhine-Westphalia, Germany
Phone: +49 2041 3894257
Email: [email protected]
Principle: data minimisation
Tayyib is built around data minimisation. There is no user account. Your settings, in particular the school of law (madhhab) you choose, and your scan history are stored solely on your device and are not transmitted to us. No information about your religious affiliation is collected or stored.
Product lookups
When you check a product, the scanned or entered barcode is sent to Open Food Facts (servers in France) in order to retrieve the product data. For technical reasons, your IP address is transmitted to that server in the process. No personal profiles are created.
The same barcode is additionally sent automatically to our own server (api.thetayyib.de, Cloudflare, data centre in the EU) on every product check, to see whether a correction reviewed by us exists for that product. Here too, your IP address is transmitted for technical reasons. This is a pure lookup: we do not store the barcode for this lookup, and your scan history is not transmitted to us. Without any action on your part, a barcode is stored by us in one single case: if you have switched anonymous usage data on and neither Open Food Facts nor we know the product, the barcode is kept as a record of that gap, see the section “Anonymous usage data (optional)”. Contributions and reports, by contrast, you send yourself, and there the barcode is part of the details you transmit to us, see the section “Reports & contributions”. As with any web server, short-lived technical logs (including time, IP address and the requested address) are generated for operation and abuse prevention, and are deleted automatically. No personal profiles are created from them.
Camera
The camera is used solely on-device, to scan barcodes and ingredient lists. Text recognition (OCR) runs on the device. No images are stored or transmitted without your involvement.
Reports & contributions
If you send feedback, report a problem or contribute a missing product, the details you enter (your text, where applicable the product name/brand/barcode, and your optional contact details) are transmitted to our server (Cloudflare, data centre in the EU) and stored so that we can process them. For every action, you decide yourself whether and what you send. If you provide a contact email address and we reply to you, your email address and our reply are processed via the email service provider Resend (Resend, Inc., USA); any transfer to the USA takes place on the basis of the EU standard contractual clauses.
Anonymous usage data (optional)
Anonymous usage data is switched on by default. Unless you turn it off in the app under “Settings → Usage data”, Tayyib transmits such data to our server (api.thetayyib.de, Cloudflare, data centre in the EU).
The following events are then recorded: the app opening and closing, finishing the intro, which screens are opened, product checks started and completed together with how the check was started (barcode, a repeat from your history, manual entry or photo text recognition), their result, their source and how long the check took, scanned barcodes we have no product for yet, failed and low-confidence text recognition, the fact that you submitted a product contribution, a report or feedback (the fact only, never the content), failed server requests, a missing network connection, denied camera permissions and crash signatures.
A crash signature consists solely of the kind of error and a single line of the call stack. The error message and the full call stack are never transmitted. For a failed server request and for a missing network connection, the fixed address of the endpoint and the status code are transmitted as well, never the request parameters and never the content.
The following is transmitted along with those events: a random, anonymous identifier (not a device identifier and not an advertising identifier), a random session identifier that changes after 30 minutes without use, the time of each event, the platform, the app version, whether a membership is active on this device (a yes or no only, no purchase or payment data) and the country derived from the connection (e.g. “DE”). Your IP address is not stored. Your school of law and your scan history are never transmitted, and no personal profiles are created.
The barcode of a product we could not find is a product identifier, not information about you. We use it solely to see which products are missing from our catalogue.
You can switch usage data off again at any time under “Settings → Usage data”; this takes effect for the future. Under “Settings → Delete my data” you can also have everything stored with us under your anonymous identifier deleted straight away.
Advertising (Google AdMob)
The app shows advertising via Google AdMob (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland; parent company Google LLC, USA). Device and usage data may be processed in this context, including the device's advertising ID, IP address, device information and interactions with ads. Personalised advertising takes place solely with your consent (Art. 6(1)(a) GDPR, Sec. 25(1) TDDDG), which is obtained before the first ad is shown via a consent banner (Google User Messaging Platform); without consent, only non-personalised advertising is served, in so far as it is available. You can withdraw or change your consent at any time in the app under “Settings → Ad consent”. A transfer to the USA may take place in this context; Google is certified under the EU-US Data Privacy Framework; in so far as the DPF does not apply, the transfer takes place on the basis of the EU standard contractual clauses. Members see no advertising. Further information: policies.google.com/privacy.
Purchases (Google Play)
When you take out a membership in the app, the payment is handled entirely by Google Play (Google Ireland Limited). We receive no payment data, only the information as to whether an active subscription exists, in order to unlock the membership features. This information stays on your device. Only if you have switched anonymous usage data on is it additionally transmitted, as part of that data, whether a membership is active on the device (a yes or no only, no purchase or payment data), see the section “Anonymous usage data (optional)”.
Contributions through the website (Stripe)
If you make a voluntary contribution under “Support us”, the payment is handled entirely by Stripe (for users in the EEA: Stripe Payments Europe, Limited, Ireland). The checkout takes place on a page belonging to Stripe, not to us, and we never receive your card details at any point. From Stripe we receive the amount, the time, the email address you entered and the country, so that the payment can be recorded in our books. The legal basis is Art. 6(1)(b) GDPR for handling the payment and Art. 6(1)(c) GDPR for the retention duties under commercial and tax law. Stripe may also transfer data to the USA and relies on the standard contractual clauses for this. Stripe's privacy policy is at stripe.com/privacy. A contribution is voluntary, nothing is provided in return, and it unlocks nothing in the app.
Legal bases
Product lookups and the provision of this website are based on our legitimate interest (Art. 6(1)(f) GDPR) in the core function. The processing of your reports, contributions and feedback is likewise based on Art. 6(1)(f) GDPR. Anonymous usage data is switched on by default after the intro and rests on our legitimate interest (Art. 6(1)(f) GDPR) in improving the app; you can switch it off in the intro or under “Settings → Usage data” at any time with effect for the future. Advertising takes place solely with your consent (Art. 6(1)(a) GDPR, § 25(1) TDDDG), which you can withdraw at any time under “Settings → Ad consent”. Unlocking Premium after a purchase serves the performance of a contract (Art. 6(1)(b) GDPR).
Retention period
We store the reports, product contributions and feedback you send only for as long as is necessary to process them, and for no longer than 12 months; after that they are deleted automatically. Individual anonymous usage events are deleted after 90 days; the anonymous daily totals formed from them are kept indefinitely, they consist of numbers only and cannot be linked to a person. Anonymous statistics identifiers and their associated anonymous counters are deleted after no more than 24 months without renewed use. Reports and contributions we delete are removed permanently after 30 days.
Your rights
You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21) under the GDPR. To exercise your rights, or if you have questions about data protection, write to [email protected]; we reply within one month. You also have the right to lodge a complaint with a data protection supervisory authority, for North Rhine-Westphalia, the State Commissioner for Data Protection and Freedom of Information NRW (LDI NRW).
Data source
This website and the app contain information from Open Food Facts (openfoodfacts.org), made available under the Open Database License (ODbL, opendatacommons.org/licenses/odbl).