Privacy Policy
Effective August 29, 2026
Media Nutrition Label is built to need as little of your data as possible. This policy describes exactly what we collect, why, who else receives it, and what your choices are. Plain language on purpose — there is no fine print that says otherwise. Where it says something is true, we checked it against the code that actually runs.
Who we are
Media Nutrition Label (“the app,” “we”) is an independent media-literacy app, built and run by one person in Connecticut, United States. We are responsible for the data described here. Privacy questions or requests about your data: support@mnl-app.com. We aim to answer within 30 days.
What we collect
Account: your email address, a display name, and a securely hashed password (we can never read the original). App data: the labels you choose to save, your in-app preferences, a daily count of how many scans you run (used to enforce the plan limit and to prevent abuse), and whether MNL Pro is on your account. Your IP address is seen by our server on every request, as any web server sees it; we hold it in memory only, to rate-limit sign-in and sign-up attempts, and it is never written to our database. No advertising identifiers, no location, no contacts, no cross-app tracking.
What happens when you scan
The screenshot, screen-recording frames, message text, or fetched post preview and caption you submit are sent over an encrypted connection (HTTPS) to our server, which forwards them to Anthropic (United States) — the company behind the Claude AI model — solely to generate your label. Anthropic handles it as our service provider, under commercial terms that forbid training their models on it, and deletes it within 30 days; content their automated safety systems flag may be held for up to two years, which is their policy and not something we can shorten. If you scan a screen recording, the audio is transcribed by software running on our own server and the file itself never leaves it. Our server holds your media only for the seconds the read takes and then discards it — it is never written to our database. Only the label is saved, and only to your account. We ask your permission before your first scan, we name Anthropic when we ask, and scanning stays off until you give it. You can withdraw it in Settings → Your Data at any time.
Video and links
If you scan a screen recording, our server samples frames across the timeline and transcribes the audio itself, with speech-recognition software running on our own machine — the video file is never sent to a third party. If you paste or share a link, our server fetches that public post on your behalf (the site sees our server, not your device) and sends the post's preview image and caption to be read — not the page itself. The label it produces may stay in the server's memory for up to a day so that repeat scans of the same public post are instant. That cache is not linked to your account.
Deeper research
If you tap “Dig deeper,” the claim from your label — not your original media — is sent to the AI model, which searches the public web to research it.
Your Brain, Labeled
The monthly Brain report sends aggregate statistics about your scan history — counts of technique types and emotional-pull levels, not the labels themselves — to the AI model, which returns a profile describing patterns in what you have been reading. That is profiling: it produces inferences about you, not only about the media. It runs only when you ask for it, the result is stored in your account until you delete it, and everything else in the app works if you never use it.
Analytics and crash reports
We use PostHog (United States) as our analytics processor, to see how the app is used in aggregate and to receive crash reports. PostHog receives event names, counts, your app and OS version, which update your phone is running, and a randomly generated anonymous identifier stored on your device. It does not receive label text, technique names, scan content, transcripts, captions, URLs, your email address, your name or your user id — that is enforced in code by an allowlist, not by policy. We never call PostHog’s identify function, so no person profile is created; there is no session replay and no screen recording. Your IP address reaches PostHog as part of ordinary network traffic, and PostHog may derive an approximate region from it.
Where your data lives
Our server and database run on Fly.io in the United States. Saved labels are kept until you delete them or your account, and the app keeps at most your 200 most recent. Password-reset codes are stored only as a keyed hash and expire within minutes. The link cache and the rate-limiting counters live in the server’s memory and do not survive a restart.
What we never do
We don’t sell or rent your data, and we don’t share it for advertising of any kind. We don’t build advertising profiles. We don’t share your content with anyone except the processors named above — Anthropic, Fly.io and PostHog — each of which is required to use it only to provide the service. We may disclose data where the law requires it, and we will tell you if that happens unless we are prohibited from doing so.
Your controls
Settings → Your Data exports everything we hold as JSON, or clears your history. Individual labels can be deleted from your diary. Deleting your account (Settings → Edit profile) permanently removes your profile, your labels, your preferences, your usage counts and your reports from our database, and cannot be undone. You can also sign out everywhere, which invalidates every existing sign-in token, and correct your display name at any time. Depending on where you live — Connecticut included — you may have the right to confirm, access, correct, delete or export your data and to opt out of profiling; the controls above cover most of that directly, and anything they do not, we will handle within 30 days of your asking. If we refuse a request you can appeal by replying, and we will answer the appeal within 60 days.
Security
Passwords are hashed with scrypt, sign-in tokens are signed and can be revoked account-wide, all traffic is encrypted in transit, and the sign-in and sign-up endpoints are rate limited. No system is perfectly secure — if we learn of a breach affecting your data, we will notify you at your account email and notify regulators as the law requires.
On your device
Your sign-in token is kept in the device’s secure storage. Reminder and digest notifications are scheduled locally on your phone — nothing about what you scan leaves your device to power them. The anonymous analytics identifier and a small queue of pending events are stored locally too. Deleting the app removes all of that; it does not delete your account, which is what the in-app deletion is for.
Children
The app is not directed to children under 13, is not marketed to them, and we don’t knowingly collect their data. To create an account you must be at least 13. If you believe a child under 13 has one, contact us and we will delete the account and its data promptly.
Where the app is available
Media Nutrition Label is offered in the United States. It is not offered in, marketed to, or intended for users in the European Economic Area or the United Kingdom. If that changes, we will update this policy before it does.
Changes
If this policy changes materially, we’ll say so in the app before the change takes effect. The date above always reflects the current version, and we keep the previous one available on request.