Privacy

Privacy policy

Last updated 1 August 2026

Who holds this data

No operating entity is named yet. Typed is not currently published by a registered company, so this policy names no data controller. Under the UK GDPR, the EU GDPR and the CCPA that is a gap, not a design choice, and it is stated plainly here rather than filled with a plausible-looking name.

What the policy describes below is accurate: it is what the site actually stores, where, and for how long. The processors named — Supabase for accounts and Netlify for hosting — are the real ones. What is missing is the party legally answerable for them.

When an entity exists, its legal name, registered address, the controller contact and, where required, a representative in the UK or EU belong here.

The short version

Reading the library involves no tracking of you personally, and creating an account is entirely optional — it's only needed for the food diary. The only personal information the site ever asks for is the email address you use to create that account.

What stays on your device

Around thirty small values are saved in your browser's local storage. With one exception, noted at the end, they never leave your device. They fall into four groups:

  • How you like to read — reading level (typed-content-mode), card or table view, saved filter presets, your region, and whether you've seen the welcome panel.
  • Your stack (typed-stack, and its notes, costs and start dates) — the supplements, foods, and activities you've added to the stack checker, so they're still there next visit.
  • Things you're planning — your pantry, meal-plan day templates, shopping-list ticks, and a movement plan.
  • Things about you — the profile you fill in for personalised targets, your sex where a page adjusts for it, and any test results you enter into the blood-test panels (typed-test-logs). These stay in this browser. They are not sent anywhere and there is no copy of them on our side.

The one exception is the diary's offline queue (typed-intake-queue). If you log something while signed in with no connection, it waits in local storage and is sent to your account as soon as you're back online — that is the whole point of it. Until it syncs it is only on your device; after it syncs it lives under your account like any other diary entry.

Clearing your browser's site data removes all of them. Nothing about what you searched for, viewed, or stacked is transmitted anywhere.

If you create a diary account

"Your stack" (below) is local-only and needs no account. The food diary on the same page is different: to save entries across devices and let you look back on past days, it needs somewhere to store them, so creating an account is required to use it.

Signing up collects your email address and a password. Using the signed-in features then stores, under your account: your diary entries (which food, supplement, or activity, the date, and the amount — including packaged foods you look up by barcode), any foods you add yourself for things we don't have, your weight log if you use the Trends chart, a backup of your stack and its notes, your meal plan, your calendar-feed snapshot and reminder time, and an invite code if you open the account page. All of it is stored by Supabase, a database provider, in a project we control, protected by database-level access rules (Row Level Security) that restrict every row to the account that created it — nobody else using Typed can query or see another person's data, including us in the ordinary course of running the site. Supabase's privacy policy covers their handling of the underlying infrastructure.

We don't sell or share any of it with advertisers, and don't use it for anything besides showing it back to you. You can delete individual entries yourself at any time — and you don't need to write to anyone to leave: the account page has a Download my data button that exports everything above as one JSON file, and a Delete my account button that permanently removes your account and every row of your data, immediately and self-service. One thing survives it: if you have sent a bug report, the report itself is kept so the fault it describes doesn't vanish from our queue — it is unlinked from your account, but anything you typed into it, including a contact address you chose to attach, stays until you ask us to delete it. See Bug reports below.

Where in the world your data is

Typed is being launched in New Zealand and Australia, and none of your data is stored in either country. It is worth knowing exactly where it does go, so here it is:

  • Your account and everything under it — diary entries, weight log, custom foods, stack backup, meal plan, calendar snapshot, community posts, bug reports — lives in our Supabase database in Singapore (the ap-southeast-1 region). Your browser talks to that database directly; it does not pass through any server of ours on the way.
  • Crash reports and calendar-feed requests go to two small functions hosted by Netlify in the United States (northern Virginia). The crash report is the one described under Error reports below. The calendar function reads your plan out of the Singapore database and turns it into a calendar file.
  • The pages themselves are static files served from Netlify's global network, from wherever is nearest to you.

So if you are in Auckland or Melbourne, your diary is in Singapore, and a crash report about a broken page travels to the United States. Both are ordinary arrangements for a site this size, and both mean your information crosses a border — which you are entitled to know before you decide to create an account.

The calendar feed

If you subscribe to your plan from a calendar app, that app has no way to log in — so the feed works from a secret address containing a long random token, and anyone who has that address can read that plan, without a password. That is how calendar subscriptions work everywhere, but it is worth saying plainly: treat the address like a password, and don't paste it anywhere public. If you think it has leaked, regenerating it on the Diary page immediately breaks the old address. What that address exposes is worth being exact about: which supplements you take and at what times of day, and which workouts you have planned for which days. It does not expose your diary, your weight log, your email, or anything else on your account.

Foods you add yourself

If you eat something we don't have in our records, the Diary lets you add it as your own food — a name and the nutrition off its label — so you don't retype it every time. It stays private. It is stored only under your account, under the same row-level rules as everything else above: it is not published anywhere on the site, not added to our food library, not reviewed or reused by us, and not visible to any other account. Nobody else searching Typed will ever see it. You can edit or delete your own foods at any time, from the Diary or the account page; deleting one leaves the days you already logged it on intact, because each entry keeps its own copy of the numbers it was logged with.

If you post to the community feed

TypedSocial is the one part of the site where what you save is meant to be seen by other people, so it works differently from everything above. Nothing is published automatically: a post you write is held for review and only becomes public if it is approved, and you can delete it at any time.

What becomes public when it is: the post itself — its title, body, any recipe attached to it, and any photo you upload — alongside the display name on your profile. Your display name is readable by anyone, signed in or not, whether or not you have ever posted. Your email address is never shown.

Using the feed also stores, under your account: comments you write, which posts you have liked or saved, who you follow and who follows you, notifications about those, and any report you file about someone else's post. Follows, likes and comments are visible to other members in the ordinary way a feed works; saves are private to you. Reports go only to the two people who run the site.

Deleting your account removes all of it, including your posts and comments.

Barcode lookups

When you look up a packaged food by barcode, the barcode digits are sent to Open Food Facts, a non-profit community food database, to fetch the product's nutrition data (their privacy policy). Only the barcode is sent — not your identity or anything else you've logged. If you use the camera to scan, the video is processed entirely in your browser and never uploaded.

The label scanner

The scanner reads Supplement Facts panels using OCR that runs entirely inside your browser. Your photo is never uploaded to a server, never stored, and never seen by us — it's processed locally and discarded when you leave the page.

The OCR engine itself (Tesseract.js) is loaded from a public code CDN (jsDelivr), which means that CDN sees a request for the script. That's the same as any site loading a shared library; it carries no information about your image.

Fonts

The site's typefaces are served from this site itself, not from Google Fonts or any other third party — loading a page sends no font request to anyone else.

There is no mailing list

Typed collects no email address for marketing. There is no signup form on the landing page and no beta list — the only address we ever hold is the one you use to create an account, and that exists to sign you in, not to be written to.

Analytics

No analytics or advertising trackers are running on this site today. If that changes, we intend to use a privacy-respecting, cookie-free analytics tool that reports aggregate page counts and cannot identify individuals — and this page will be updated to say which one before it goes live.

Error reports

If a script on this site crashes in your browser, the page sends us a short technical report so we can fix it: the error message, the file and line it came from, the stack trace (the chain of functions that led to the crash, trimmed to 1,200 characters), and the address of the page it happened on. At most five reports are sent per page view, so a loop can't flood anything. It contains no account details, no cookies, no device fingerprint and nothing you typed, it goes only to this site's own server logs, and it is not shared with any third party.

Bug reports

While the site is in beta, every page carries a “report a bug” button. Nothing is collected by it until you choose to send a report. When you do, we store what you typed, your answers to its questions, the address of the page you were on, your browser's name and screen size, and — if the page hit a JavaScript error while you were there — that error's text. The report shows you all of this before you send it. You don't need an account and can report anonymously; if you're signed in, the report is linked to your account only so we can tell your reports apart, and your email is attached only if you choose that when it asks. Reports are stored with the same database provider as diary accounts (Supabase), are readable only by the two people who run the site, are used only to find and fix bugs, and are never shared with anyone else. A draft you haven't sent lives only in this browser's local storage. To have a report deleted, write to the contact address below.

Cookies

Typed sets no cookies. The preferences described above use local storage, which is why there's no cookie banner to dismiss.

Children

Typed isn't directed at children under 13, and we don't knowingly collect their information.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete the personal information we hold about you — which, unless you created an account, is nothing. If you have an account, export and deletion are self-service on the account page, no request needed. For anything else, write to the address below.

Changes

If this policy changes materially, the date at the top will change.

Contact

Questions about privacy, or a deletion request: the contact address.