Reading the library involves no tracking of you personally, and creating an account is entirely optional — it's only needed for the food diary. The only personal information the site ever asks for is an email address, either to join the beta list or, separately, to create a diary account.
Two preferences are saved in your browser's local storage. They never leave your device and are never sent to us:
typed-content-mode) — whether you prefer Easy or Complex explanations.typed-stack) — the supplements, foods, and activities you've added to the stack checker, so they're still there next visit.Clearing your browser's site data removes both. Nothing about what you searched for, viewed, or stacked is transmitted anywhere.
"Your stack" (below) is local-only and needs no account. The food diary on the same page is different: to save entries across devices and let you look back on past days, it needs somewhere to store them, so creating an account is required to use it.
Signing up collects your email address and a password. Using the signed-in features then stores, under your account: your diary entries (which food, supplement, or activity, the date, and the amount — including packaged foods you look up by barcode), your weight log if you use the Trends chart, a backup of your stack and its notes, your meal plan, your calendar-feed snapshot and reminder time, and an invite code if you open the account page. All of it is stored by Supabase, a database provider, in a project we control, protected by database-level access rules (Row Level Security) that restrict every row to the account that created it — nobody else using Typed can query or see another person's data, including us in the ordinary course of running the site. Supabase's privacy policy covers their handling of the underlying infrastructure.
We don't sell or share any of it with advertisers, and don't use it for anything besides showing it back to you. You can delete individual entries yourself at any time — and you don't need to write to anyone to leave: the account page has a Download my data button that exports everything above as one JSON file, and a Delete my account button that permanently removes your account and every row of your data, immediately and self-service.
When you look up a packaged food by barcode, the barcode digits are sent to Open Food Facts, a non-profit community food database, to fetch the product's nutrition data (their privacy policy). Only the barcode is sent — not your identity or anything else you've logged. If you use the camera to scan, the video is processed entirely in your browser and never uploaded.
The scanner reads Supplement Facts panels using OCR that runs entirely inside your browser. Your photo is never uploaded to a server, never stored, and never seen by us — it's processed locally and discarded when you leave the page.
The OCR engine itself (Tesseract.js) is loaded from a public code CDN (jsDelivr), which means that CDN sees a request for the script. That's the same as any site loading a shared library; it carries no information about your image.
Pages load typefaces from Google Fonts. Google receives the request for the font files, including your IP address, as it does on any site using their service. No other data is shared with them.
The signup form collects your email address and a note that it came from the Typed landing page. It's used for one thing: to tell you when the beta opens. We don't sell it, rent it, or share it with advertisers.
The address is stored by Netlify Forms, the form-handling service built into our host (Netlify), whose handling of the data is covered by Netlify's privacy policy. You can ask us to delete your address at any time by writing to the contact address below — we'll remove it without asking why.
SIGNUP_ENDPOINT, name it here and link its privacy policy instead.
No analytics or advertising trackers are running on this site today. If that changes, we intend to use a privacy-respecting, cookie-free analytics tool that reports aggregate page counts and cannot identify individuals — and this page will be updated to say which one before it goes live.
Typed sets no cookies. The preferences described above use local storage, which is why there's no cookie banner to dismiss.
Typed isn't directed at children under 13, and we don't knowingly collect their information.
Depending on where you live, you may have the right to access, correct, export, or delete the personal information we hold about you — which, unless you joined the beta list or created a diary account, is nothing. If you have an account, export and deletion are self-service on the account page, no request needed. For anything else — or to remove a beta-list address — write to the address below.
If this policy changes materially, the date at the top will change and anyone on the beta list will be told before the change takes effect.
Questions about privacy, or a deletion request: the contact address.