BadFood is an independent food-recall information app operated by Javier Santos under the Operant Construct name. It is intended for a general audience in the United States. This policy explains how information is handled when you use BadFood, visit its privacy and support pages, or contact us.
Information stored on your device
You do not need an account to use BadFood. The app stores saved recalls, preferences, onboarding progress, and cached recall information on your device. The cache can also contain search text and filter values associated with requests you have made. BadFood does not upload your saved list as an account record or synchronize it across devices. It does send individual recall identifiers to the recall service when retrieving details or checking saved recalls for updates.
BadFood does not separately encrypt its local database. Protect access to your device using its security settings. Cached information may be replaced or removed as you use the app; saved recalls remain until you remove them or reset the app's local data.
In Settings, you can:
- Clear cached data to remove cached responses and their stored request information while keeping your saved recalls and preferences.
- Clear saved recalls to remove your saved list. This does not also clear the response cache.
- Reset all local data to remove saved recalls and cached information, restore default preferences, and restart onboarding.
Resetting restores the crash-reporting preference to its default, which is on. That preference does not activate reporting in a version where it is unavailable. Clearing local data does not delete support emails or server records. Using the app again can create new cached information and service requests.
Deleting the app removes its active local storage. Offloading an iOS app can retain its documents and data, and deleting the app does not erase copies that may already exist in a device backup. Do not rely on reinstalling the app to recover saved recalls.
Requests to the recall service
BadFood uses our recall service, hosted on DigitalOcean, to retrieve FDA and USDA recall information. Requests can include search text, agency and date filters, pagination information, and individual recall identifiers. We process these values to return the requested information.
Internet requests also expose an IP address and technical connection information to the infrastructure handling them. The service uses IP addresses temporarily to limit excessive requests and protect availability.
Our application request logs and configured API access logs record technical details such as a random identifier for each request, request type, response status, timing, and response size. Those request logs are configured to omit raw IP addresses, search text, full request URLs, headers, and individual recall identifiers. The request identifier identifies a request, rather than an account or a device. We use operational records to maintain the service, investigate faults, and protect it against misuse.
The request logs described above are configured for daily rotation with 14-day retention settings. Daily DigitalOcean server backups are retained for seven days and can contain copies of logs removed from the active server. These backup copies may therefore outlast the original log files.
We also keep database backups and copies made before deployments or server changes for recovery. These can contain older operational records and are separate from the daily request-log rotation. Routine database backups on the server become eligible for automatic cleanup after eight days. Deployment and server recovery copies become eligible after 30 days; when only a creation date is known, that period starts at the end of that day. Cleanup is scheduled daily, and actual deletion occurs during the next successful run.
Crash reports and diagnostic information
BadFood uses Sentry to help identify and fix crashes and application errors. Reporting is on by default and can be turned off in Settings. Reports contain the app version and build, build environment (beta or production), operating-system version, device model, event time, an identifier for the individual event, general error information, and technical stack and build information needed to locate the problem.
Reports sent to Sentry are filtered to exclude searches, saved recalls, raw error messages, request details, breadcrumbs, screenshots, attachments, and persistent user or device identifiers. Sentry receives your IP address when accepting a report. Our project settings prevent its inclusion in stored crash events and filter geographic values added by Sentry. Crash and error events are stored in Sentry's United States region under our plan's 30-day event-retention period. That period does not describe every provider record, support or alert email, or local crash file. We receive Sentry alert emails in our support inbox. These email copies are deleted manually as needed, with no fixed automatic deletion schedule.
Some crash information may be stored temporarily on your device for delivery after the app reopens or a connection becomes available. These local crash files may contain original error messages and additional technical details before reports are filtered for transmission. Turn off Settings > Crash-reporting preference to stop reporting and discard queued reports. This cannot retract reports Sentry has already received. If you turn reporting back on, restart BadFood when prompted. Reset all local data restores the preference to on. In versions where reporting is unavailable, the preference does not activate it.
You can choose Settings > Copy diagnostic information to copy a technical report to your clipboard. It includes the app version and build, platform, operating-system version, device model, build environment, and the time the report was created. When available, it also includes an error category, HTTP status, and a request identifier. It excludes search text, filter values, saved recalls, raw error messages, and persistent device or installation identifiers. Copying the report does not send it to us; you choose whether to paste it into an email or another app.
Information you choose to send to support
When you email contact@operantconstruct.io, we receive your email address, message, and any attachments or diagnostic information you include. We use this information to respond to your request and investigate problems you report.
Our public support address uses Porkbun email forwarding to a Gmail inbox. Porkbun and Google process messages to provide these services. Only the app operator has access to the support inbox. Support messages are deleted manually as needed; there is no fixed automatic deletion schedule. You can request deletion of messages you sent by contacting the same address.
Please avoid including medical information, passwords, or other sensitive information in a support request. Review diagnostic reports and screenshots before sharing them.
Advertising, analytics, and external services
BadFood does not include advertising or a product-analytics SDK. We do not sell personal information or share it with advertisers or data brokers. Apple may provide app-store statistics and diagnostics under its own settings and privacy practices.
If you test BadFood through TestFlight, Apple collects crash logs, usage information, and feedback you submit and makes testing information available to the developer. Apple's TestFlight terms and privacy practices apply to that processing separately from BadFood's own crash-reporting controls.
The privacy and support pages are hosted using Cloudflare Pages. Visiting them sends your IP address and technical request information, such as the requested page and browser details, to the hosting service. Cloudflare also runs browser checks to protect the website against automated abuse and may use security cookies for those checks. Supporting browsers may send network-error reports to Cloudflare to help diagnose connection problems. Website performance analytics through Cloudflare Real User Measurements is disabled. Cloudflare's security and operational processing continues, with retention that depends on the service and purpose; the API-log and Sentry-event periods above do not apply to every Cloudflare record. The pages do not require a BadFood account. Cloudflare describes its handling of this information in its privacy policy.
Links to official FDA and USDA notices open in your browser. Those websites receive information associated with your visit and have their own privacy practices. BadFood does not operate those websites.
Privacy requests and changes
For privacy questions or requests about information you sent to us, email contact@operantconstruct.io. Include enough information to identify the message or issue concerned, without sending unnecessary sensitive information. Saved recalls and cached information can be removed using the controls in Settings.
We may update this policy as BadFood or our practices change and will update the effective date when we do. For help using the app, visit BadFood Support.