Privacy Policy
How Stella Apps, trading as ProvenBatch, collects, uses and protects personal data — said plainly, including the parts most likely to surprise you.
Effective 23 August 2026 · Updated 6 September 2026 · ICO registration ZC217578
1. Who we are
1.1 This Privacy Policy explains how Stella Apps, trading as ProvenBatch (“we”, “us”, “our”) collects, uses, and protects personal data when you use the ProvenBatch service (the “Service”), and when you visit our websites. “ProvenBatch” is the name of the software and service; “Stella Apps” is the sole trader business that operates it and is the data controller for the personal data described in this policy, except where clause 8 explains that we act as your processor instead.
1.2 Stella Apps is a sole trader business; there is no company registration number. Our trading address, and the address at which we can be contacted about this policy in writing, is:
4th Floor, Silverstream House, 45 Fitzroy Street, London W1T 6EB
This is a virtual office — post only, not a visitor address. Our registration with the Information Commissioner’s Office (ICO) is:
ZC217578
1.3 We do not have a dedicated Data Protection Officer — as a sole trader business this is not a statutory requirement for us — but all data protection queries should be sent to support@provenbatch.co.uk and will reach Dave Biley, the owner of Stella Apps.
2. Scope
This policy applies to:
- personal data we collect about you, as a person registering for, administering, or using a ProvenBatch Account (your name, email address, and account activity) — see clauses 3–7, where we act as controller;
- personal data belonging to your own customers, which you may enter into the Service as part of recording orders (for example, a customer’s name or contact details attached to an order) — see clause 8, where we act as your processor and you remain the controller;
- personal data we collect from people who ask for a beta place, or ask to be kept updated about ProvenBatch, using the form on our marketing website — see clause 12, where we act as controller;
- personal data we collect from visitors to our marketing websites (provenbatch.co.uk and stellaapps.com) — see clause 12.
3. What personal data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, password (stored hashed), Business name, Plan selected | You, when you register |
| Usage data | Log-in times, feature use, device and browser type, IP address | Automatically, as you use the Service |
| Business content | Ingredients, supplier products, supplier declarations, recipes, batches, generated Labels | You, as you use the Service |
| Receipt and pack images | Photographs of receipts and food packaging, and any text or data extracted from them | You, when you use receipt scanning or pack-photo features |
| Evidence photos | Photographs you attach to a food-safety check entry or a corrective action as evidence | You, when you use the photo-evidence feature |
| Voice notes | A short voice recording you make to dictate a note, and the text transcribed from it — the recording itself is not kept (clause 5.6) | You, when you use the voice-note feature |
| Assistant conversations | Questions you type to the in-app assistant, and the excerpts of your business records it looks up to answer you — not stored after you close the panel (clause 5.7) | You, when you use the assistant |
| Feedback | The feedback message you choose to send from inside the app, with your Business name and Account email — and, if you attach one, a screenshot of your own screen, which may show whatever your business records had on it at the time | You, when you use Settings → Feedback (clause 7.2) |
| Payment data | Billing name, billing address, and payment method — we do not receive or store your full card number | You and Stripe, when you subscribe |
| Support communications | Emails, messages, and any attachments you send to support@provenbatch.co.uk | You, when you contact support |
| Beta and update-list requests | Your email address; and, if you ask for a beta place, your name, Business name, business type, how long you have been trading, roughly how many products you make in a week, how you label today, how you print those labels, what you find hardest about labelling, how you heard about us, and your website — together with whether you asked to be kept updated | You, when you use the form at provenbatch.co.uk/beta (clause 12.3) |
| Your customers’ data | Names, contact details, and order details you enter about your own customers | You, as our processor — see clause 8 |
4. How we use personal data, and our legal basis
| Purpose | Legal basis (UK GDPR) |
|---|---|
| Creating and administering your Account, providing the Service you have subscribed to | Performance of a contract (Article 6(1)(b)) |
| Processing payment and managing your subscription | Performance of a contract; legal obligation for tax and accounting records |
| Responding to support requests and complaints | Performance of a contract; legitimate interests in resolving your query |
| Sending service-essential emails (confirmation, password reset, billing, service updates) | Performance of a contract; legal obligation |
| Considering and administering a request for a beta place, and emailing you about that request | Steps taken at your request before entering into a contract (Article 6(1)(b)); legitimate interests in running a beta programme |
| Sending optional product or marketing communications | Consent, where you have opted in — you can withdraw this at any time |
| Detecting and preventing fraud, abuse, or security incidents | Legitimate interests, and legal obligation where applicable |
| Improving the Service, in aggregated or anonymised form | Legitimate interests |
| Complying with our own legal and regulatory obligations (for example, tax and accounting records) | Legal obligation |
We do not sell your personal data, and we do not use it for third-party advertising.
5. AI features — photos, voice notes, and the assistant — read this section plainly
5.1 This is the part of the Service most likely to surprise you, so we say it plainly rather than bury it in a table. When you photograph a receipt, a piece of food packaging, or a recipe page and use the Service to read it automatically, that photo is sent to Anthropic, a US-based artificial intelligence provider, for automated transcription (this is sometimes called “AI vision”). We use this because it reads real-world photographs — messy handwriting, faded till receipts, small-print ingredient lists — far more reliably than processing carried out entirely on your device.
5.2 This means the photo genuinely leaves the UK to reach Anthropic’s API. We do not claim, and have never claimed, that this processing happens “on-device” or that your photos “never leave your phone” — that would not be true, and we correct it here explicitly because an earlier internal description of the product said otherwise before this feature existed in its current form. A lower-accuracy, on-device fallback (optical character recognition) is available and is used automatically if the AI reading service is unavailable, but the default, and the more accurate, path sends the image to Anthropic.
5.3 A receipt or pack photo can contain personal data — for example, the last four digits of a card number, a cashier or customer name printed on a receipt, or a store location. We disclose this plainly to you inside the app at the point you take or upload such a photo, as well as here.
5.4 This transfer of personal data out of the UK is documented under the UK Addendum to the EU Standard Contractual Clauses — see clause 9.2 for the mechanism and its source.
5.5 Receipt images you upload are also stored, in a private Supabase storage bucket accessible only to your Account, subject to the retention period described in clause 10. The same is true of evidence photos you attach to a food-safety check entry or corrective action — those are stored as part of your records and are not sent to any AI provider.
5.6 Voice notes are transcribed by a second AI provider, Groq. Where the Service offers to turn a short voice note into text — for example, dictating a corrective-action note or a late-entry reason using the microphone button — the recording is sent to Groq, a US-based AI provider, for automated speech-to-text transcription, and the transcribed text is returned for you to review before anything is saved into your records. The recording leaves the UK to reach Groq’s API, in the same way clause 5.2 describes for photos. We do not store the recording: once the text has been returned, the audio is discarded — what is kept is the text you accept, stored in the UK with the rest of your data. We have also enabled Groq’s Zero Data Retention setting for our account, so Groq itself does not store your recordings or their transcripts either — not even in its own temporary system logs. A voice note recorded in a working kitchen can pick up more than you intend (a name spoken in the background, for example), so record deliberately — or simply type the note instead: every voice feature has a typed alternative, and transcription is never required to use the Service. Clause 9.3 documents this transfer.
5.7 The in-app assistant is powered by Anthropic. When you use the assistant (ProvenBot) to ask a question, your messages — and the specific excerpts of your business records the assistant looks up in order to answer you — are sent to Anthropic, the same US-based provider described in clause 5.1, to generate the reply. The assistant can only read what your own signed-in session is allowed to read, and it cannot change or delete anything. We do not store the conversation: it exists in your browser for as long as you keep the panel open, and what we record is the fact and cost of the calls (for fair-use limits), never what was said. Assistant answers are decision support, not legal or food-safety advice — review them before relying on them, exactly as with every automated feature of the Service.
5.8 To make several features better over time, we keep a small set of anonymous usage statistics each time you use them. This covers seven streams: (a) receipt scans — how many lines were read, how many you corrected, whether the reader’s total matched the lines, and (only when the receipt is from a recognised national retail chain such as a named supermarket) that chain’s name; (b) pack reads — whether a declaration was read cleanly and whether you corrected it, and whether it matched an entry in our own brand-product library (a yes/no flag — never the brand name itself, even when it matches); (c) allergen-declaration checks — when our automatic allergen check fires, is confirmed, is removed, or is added by hand after being missed, we record which of our own fixed list of allergen-detection words matched (for example “milk” or “peanuts”) and which of the 14 legal allergens it relates to — never the declaration text itself; (d) recipe imports — whether the import succeeded and needed correcting; (e) health-check counts — how often each check type is triggered, accepted (“mark as OK for now” — the reason you type stays private to your Account and is never included), and cleared, across all businesses; (f) how long common tasks take — when you begin one of a fixed list of everyday jobs (adding a supplier product, scanning a receipt, starting a batch, and a handful of others), which steps of it you reach, and how long you spent with the app in front of you between them, together with the app version — this is what tells us that a job which should take two minutes is taking nine; and (g) which parts of the app get opened — a short fixed list of moments such as opening the About screen, expanding the roadmap, opening a guide, starting a voice note, starting to write feedback, or asking the assistant a question. This last stream records that the thing was opened, never what you then did, said, wrote or asked.
These are counts, timings, app versions and the names of app screens only. They never include the item names, the prices, the amounts, any image, any declaration text, or the name of any supplier or brand that is not a recognised national chain or brand — so an independent or trade supplier, whose name can itself be personal data, is never identified. We should be precise about the word “anonymous”: these records are stored against your Business, not detached from it, so they are personal data and this policy treats them as such — what makes them low-impact is that they carry no content, not that we cannot tell whose they are. We rely on our legitimate interest in improving the Service. You can turn this off at any time in Settings (“Share usage statistics”); when it is off, no such statistics are recorded for your Account at all, across any of the seven streams — including the part of stream (f) that is worked out overnight on our side rather than sent by the app, which skips an opted-out Business too.
6. Where your data is held
6.1 Your Account data and business content are stored with Supabase, in their eu-west-2
(London) region. This is the basis for our UK data-residency claim: with the exception of the AI
processing described in clause 5, your data is held in the UK.
6.2 Data processed by our AI providers is transmitted to and processed in the United States — photos and assistant conversations by Anthropic (clauses 5.1 and 5.7), and voice-note audio by Groq (clause 5.6). See clause 9 for how we document these transfers.
7. Who we share personal data with
7.1 We share personal data with the sub-processors who help us run the Service. The current, published list — what each one does, and any residency note — is our Sub-processor List, and is summarised here:
| Sub-processor | What it does with personal data |
|---|---|
| Supabase | Hosts our database, authentication, file storage, and backend functions (UK, eu-west-2) |
| Anthropic | Reads photographed receipts, recipe pages, and food packaging, and generates the in-app assistant’s replies (US) — see clauses 5.1 and 5.7 |
| Groq | Transcribes voice notes to text (US) — the recording is not stored; see clause 5.6 |
| Stripe | Processes subscription payments |
| Resend | Sends transactional email and account mail (confirmation, password reset, billing), and the emails we send about a beta or update-list request (clause 12.3) |
| Google Workspace | Hosts our support mailbox, support@provenbatch.co.uk, and the contact list we keep of beta testers (clause 12.5) |
| Cloudflare | Hosts the Service and our websites, and provides DNS |
| GitHub | Receives in-app feedback you choose to send, into our private issue tracker, and runs our scheduled background jobs (US) — see clauses 7.2 and 12.5 |
Our Sub-processor List carries the fuller entry for each one, including its residency note and the transfer mechanism where it is outside the UK.
7.2 Two flows are worth stating individually, because in each one data moves at your own request:
- In-app feedback. If you send us feedback from inside the app (Settings → Feedback), your message, your Business name, and your Account email address are recorded as an item in our private issue tracker, hosted by GitHub, a US-based service — that is what lets us track your suggestion through to a shipped fix. Feedback is the only customer content that reaches our issue tracker, and only when you choose to send it. If you attach a screenshot, the image itself is stored in the UK with Supabase, in private storage only you and we can read — but the issue we raise embeds it as an image, through a link that stays valid for about five years so that the issue is still readable when we come back to it. Because it is embedded rather than merely linked, GitHub also fetches and caches a copy through its own image proxy. Please bear in mind that a screenshot shows whatever was on your screen, which may include your own customers’ details; attaching one is always your choice, and you can ask us to delete a screenshot at any time. GitHub’s infrastructure also runs the scheduled background jobs that keep the Service running — for example, matching newly published FSA food-recall alerts against your supplier products overnight, and sending subscription lifecycle and beta programme emails. Those jobs work on the data in memory, and as of 6 September 2026 their own run logs identify a request or account by internal id, never by email address — but running them is still a real transfer, because your details pass through GitHub’s US infrastructure in memory to do the job even though nothing beyond the id is written down. Clause 9.4 documents the transfer.
- The live inspection view. If you generate a time-limited inspection code and hand it to an environmental health officer, the Service shows the holder of that code a read-only view of your food-safety records (including any evidence photos) until the code expires or you revoke it. That disclosure happens at your instruction, to the person you gave the code to — we never share those records on our own initiative.
7.3 We do not share your personal data with anyone else except: where you have asked us to (for example, an integration you enable); where required by law, court order, or a lawful request from a regulator or law enforcement body; or in connection with a sale, merger, or reorganisation of Stella Apps, in which case we will tell you before your data is transferred to a new controller under different terms.
7.4 We keep this list current. If we add a new sub-processor that materially changes how your data is processed, we will update this list and, for active subscribers, notify you by email in advance where the change is material.
8. Where we process personal data on your behalf (your own customers’ data)
8.1 If you use the Service to record orders, customers, or contacts belonging to your own Business, you are the data controller for that data, and Stella Apps is your data processor. Our Data Processing Agreement sets out the terms on which we process it, and is incorporated into our Terms of Service for every Account that uses order or customer-facing features.
8.2 We only process that data on your documented instructions (given through your use of the Service), and only for the purpose of providing the Service to you. We do not use your customers’ data for our own purposes, and we do not sell it.
9. International transfers
9.1 Most of your data stays in the UK (clause 6.1). The routine exceptions are the AI features described in clause 5 — photo reading and the assistant (Anthropic) and voice-note transcription (Groq) — and the feedback and background-job processing described in clause 7.2 (GitHub). All three providers are US-based.
9.2 The Anthropic transfer relies on the UK Addendum to the EU Standard Contractual Clauses — formally, the International Data Transfer Addendum to the EU Commission’s Standard Contractual Clauses, using the template (version B.1.0) issued by the UK Information Commissioner under section 119A(1) of the Data Protection Act 2018. This is set out in Schedule 3, Part B of Anthropic’s Data Processing Addendum (published at anthropic.com/legal/data-processing-addendum, effective 24 February 2025), which we accept by accepting Anthropic’s Commercial Terms of Service — it is not separately executed.
9.3 The Groq transfer (voice-note audio, clause 5.6) relies on the same class of mechanism as clause 9.2: section 8.3 of Groq’s Data Processing Addendum for GroqCloud Services (effective 15 October 2025) provides that, for transfers subject to the UK GDPR, the International Data Transfer Addendum to the EU SCCs (the ICO’s UK Addendum) forms part of that addendum and takes precedence, with both the EU SCCs and the UK Addendum deemed signed on entering into the Groq Services Agreement — nothing is separately executed. In addition, we have enabled Groq’s Zero Data Retention setting for our account, under which Groq does not store inference inputs or outputs — voice recordings and their transcripts included — even for its own system-reliability logging.
9.4 The GitHub transfer (clause 7.2) is documented under GitHub’s Data Protection Agreement (version October 2025), section 7.B of which covers restricted transfers through GitHub’s self-certification to the EU–US Data Privacy Framework (including the UK Extension) and/or the EU Standard Contractual Clauses, with the UK Addendum applying to personal data protected by the UK GDPR.
9.5 If, in future, we add other sub-processors located outside the UK, we will document the transfer mechanism for each of them here and in our Data Processing Agreement before they process your data.
10. How long we keep personal data
10.1 Receipt images are kept for 6 years by default, matching HMRC’s record-keeping expectations for business receipts. The app separately lets you mark a given receipt to be kept forever, exempting it from that default, with a manual review-and-purge action available to you for anything past its retention age — we mention this here for completeness; how that option works in the app is described in the app’s own help content, not in this policy. Evidence photos you attach to a food-safety check entry or a corrective action are kept as part of that record for as long as the record itself is kept, since the photo is part of the evidence trail; deleting the record, or your Account (clause 10.2), deletes them with it.
10.2 Account data and business content. If you delete your Account, or your subscription lapses into the Archive state and is never resumed, we apply a 30-day grace period before deletion, so that an accidental deletion or a temporary lapse can be reversed. After the 30-day grace period, we permanently delete your Account data and business content, save for what we are required to keep for legal or accounting reasons (for example, invoice records). Deletion overrides the receipt retention setting described in clause 10.1, including any receipt marked keep forever — asking to be erased takes priority over a retention preference you set for your own convenience.
10.3 Support communications are kept for as long as reasonably necessary to resolve your query and for a reasonable period afterwards for quality and complaint-handling purposes (see clause 14 for how to complain).
10.4 Payment records are kept for as long as required by UK tax law (currently at least 6 years from the end of the relevant accounting period).
10.5 Voice recordings and assistant conversations are not retained at all. A voice note’s audio is discarded once its transcribed text has been returned (clause 5.6) — only the text you accept into a record is kept, as part of that record. The assistant’s conversation exists only in your browser while the panel is open (clause 5.7); we retain the usage counts described there, never the content.
10.6 Beta and update-list requests. If you ask for a beta place, and you go on to open an Account, your request is deleted along with the rest of your data when that Account is purged (clause 10.2). If you do not, we keep your request for 12 months from the date you submitted it — or, if we decide not to take your request further (for example, if it is declined or withdrawn), from that decision — and then delete it automatically. You can have yours deleted sooner at any time by writing to support@provenbatch.co.uk, and leaving the updates list (clause 12.4) is a separate, one-click action that does not require you to ask us for anything.
11. Your rights
Under UK GDPR, you have the right to:
- access the personal data we hold about you;
- rectify inaccurate personal data;
- erase your personal data, subject to our legal retention obligations (clause 10);
- restrict or object to our processing of your personal data in certain circumstances;
- data portability — receive your data in a structured, commonly used, machine-readable format, or have it transmitted to another controller (the Service also provides a self-service data export feature that covers your business content directly);
- withdraw consent at any time, where we rely on consent (for example, marketing emails), without affecting the lawfulness of processing before withdrawal;
- complain to the ICO — see clause 14.
To exercise any of these rights, contact support@provenbatch.co.uk. We will respond within one month, as required by law, and will tell you if we need longer for a complex request.
12. Our marketing websites — cookies, analytics, and the beta list
12.1 The Service (the app itself) does not use advertising or tracking cookies. Where our marketing websites use analytics, we choose privacy-friendly, cookieless tools that do not track you across sites and do not require a cookie consent banner under the Privacy and Electronic Communications Regulations (PECR), because they do not process personal data for that purpose. We do not run advertising pixels.
12.2 If this ever changes — for example, if we introduce a tool that does require consent — we will update this policy and add the appropriate consent mechanism before doing so.
12.3 Asking for a beta place. The form at provenbatch.co.uk/beta lets you ask for a place in the ProvenBatch beta before the Service is generally available. It asks for your email address, which is the only part we require, and for context about your business — your name, Business name, what kind of food business it is, how long you have been trading, roughly how many products you make in a week, how you label today, what you find hardest about labelling, how you heard about us, how you print your labels today, and your website. We use it to decide who to invite and in what order, and to email you about your request. Filling the form in again with the same address updates your answers rather than creating a second request. The record is held with Supabase in the UK, like the rest of our data (clause 6.1), and the emails are sent by Resend. It is not visible to any other user of the Service, and nothing you write on that form is used to advertise to you.
12.4 The updates list, and how to leave it. The same page separately lets you ask to be kept updated about ProvenBatch. That is optional and opt-in — you can ask for a beta place without it, and we ask for it with an unticked box, never a pre-ticked one. We rely on your consent for it (clause 4), and every such email carries an unsubscribe link that needs no account, no password and no reply — one click in the mail client’s own unsubscribe control, or one click in the email followed by a confirm button on the page it opens. Either way the updates stop and the rest of your request is untouched. You can also write to support@provenbatch.co.uk. Emails about the request you actually made — an acknowledgement, a decision, an invitation — are sent whether or not you join the updates list, because they answer the thing you asked for.
12.5 Who else handles a beta request, and what leaves the UK. Two of our sub-processors touch it, both already listed in clause 7.1. The detail matters more than a summary would, so:
GitHub. The acknowledgement and the decision on your request are sent by our own backend, as soon as they are earned. A scheduled job running on GitHub’s infrastructure re-sends anything that did not go out, and is what sends the invitation itself when your turn comes. As of 6 September 2026 that job’s own run log identifies which request it acted on by internal id, never by email address — but running it is still a real transfer to the United States, documented as clause 9.4 describes: your details pass through GitHub’s infrastructure in memory to reach Resend, even though nothing beyond the id is written down. Nothing to do with the update list goes through it.
Google Workspace, by way of GitHub. If you are invited to the beta — whether or not you have signed up yet — your name, email address and Business name are exported into a contact list in our Google Workspace account so that we can email the group, along with a short note recording the status of your request and how you came to us. That export is run by hand, on GitHub’s infrastructure, when there is someone new to add; it produces a file which rests on GitHub for one day before we import it. People who have applied but have not been invited are not exported.
13. Children
The Service is intended for use by adults operating or working for a food business. We do not knowingly collect personal data from children, and the Service is not directed at them.
14. How to complain
If you are unhappy with how we have handled your personal data, please contact us first at support@provenbatch.co.uk — see our Complaints Procedure for our process and timescales. You also have the right to complain directly to the UK’s data protection regulator, the Information Commissioner’s Office (ICO):
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner’s Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
15. Changes to this policy
We may update this policy from time to time, for example to reflect a change in the law, a new feature, or a change to our sub-processors or international transfer arrangements. Where a change is material, we will notify active subscribers by email in advance of it taking effect.
16. Contact
Stella Apps, trading as ProvenBatch
support@provenbatch.co.uk
4th Floor, Silverstream House, 45 Fitzroy Street, London W1T 6EB
ICO registration: ZC217578