Last updated: August 25, 2026
We don't know who you are, and we've built things so we can't find out. No account required, no cookies, no browsing history. If you do create an account (it's optional, always), it stays walled off from everything anonymous — and it now holds one thing that is text you wrote rather than a product id: the conversations you have with Sonion, so they follow you between devices. That one is spelled out in full under “Asking Sonion”. The long version is below.
Greenlens is a web app, a browser extension, and a mobile app (iOS and Android) that show public cosmetics safety ratings from independent sources — on the web, while you shop on supported retailer sites, and when you scan a product's barcode with your phone. None of them require sign-in, and none track you across the web. An optional account exists for one purpose: syncing your shelf, your settings and your conversations with Sonion across devices (see “Optional accounts” below).
When you visit a supported product page, the extension sends the product's publicly visible name, brand, barcode (if present), and ingredient list to our server at usegreenlens.com. This is used solely to look up safety ratings and return them to you. We do not store the content of these requests, with one product-only exception: when a barcode can't be matched to any product, we keep the barcode itself and a count of how often it was scanned — nothing else, and never anything about who scanned it — so we know which products to add to the catalog next. Beyond that we record only an anonymous outcome event (see “Anonymous usage analytics” below). No personal information is included.
The mobile app asks for camera access for exactly one thing: reading product barcodes, live, on your device. While scanning, no photo or video is ever recorded, stored, or uploaded — the camera frames are decoded into barcode digits on the phone and discarded. There is one exception, and you are always the one who triggers it: when a product isn't found, you can choose to photograph its ingredients label and submit it. That photo is uploaded once, read to transcribe the printed label text, and then discarded — we keep only the transcribed text, attached to the product (never to you), and the photo itself is not stored. When a barcode is recognized, only its digits are sent to our server to look up ratings. If the barcode isn't in our catalog yet, our server may fetch that product's public record from Open Beauty Facts and add the product to the shared catalog; the catalog entry describes the product, never you — no account id, device id, or location is attached to it (the app never asks for location at all). If no source knows the barcode, we keep the barcode and a scan count — nothing about you — as our to-do list of products to add. Your shelf, your weights, and your appearance settings are stored on the phone itself. The mobile app records the same kind of anonymous usage events described under “Anonymous usage analytics” below (a random id in the app's storage, an event name, and minimal context like a product id or a scan outcome — never your name, email, location, or the barcode itself), and the Account tab has a “Share anonymous usage data” switch that turns them off entirely. If you sign in, the app stores a sign-in token on your device so you stay signed in.
To understand which features are used and where our catalog falls short, Greenlens records anonymous usage events, for example “a product page on sephora.com matched a rated product” or “a score card was opened”. Each event carries a random identifier stored in your browser, the event name, and minimal context: the site's hostname, a product id, and the match outcome. Events never include your name, email, full page addresses, search history, or any account identifier. Even if you create an account, analytics are never linked to it: the anonymous id and your account are unlinkable by design, on the server as well as in your browser. The web app honors your browser's Do Not Track setting, the extension has a “Share anonymous usage data” toggle on its options page, and the mobile app has the same toggle in its Account tab — each turns this off entirely.
Your rating-source weights (how much you value safety vs. environmental vs. ethical scores), your shelf (the products you have looked up), your avoid-list (the ingredients you asked us to flag for you), and your skin answers (see “Your skin answers” below) are saved in your browser's local storage, the extension keeps a copy of the weights in chrome.storage.local, and the mobile app keeps your weights, your shelf, and your appearance (light or dark) choice in the phone's app storage. By default none of it leaves your device. If you sign in to an optional account, your weights, shelf and avoid-list sync to it so your other devices can see them, and your skin answers sync between the browsers you sign in on (see “Your skin answers” below); the browser also keeps a small local marker of which account it last synced with (see “Optional accounts” below).
Ratings data comes from Open Beauty Facts (openbeautyfacts.org), a public-domain database. Amazon product enrichment uses the Amazon Product Advertising API when credentials are configured; only the product ASIN is sent, not any user identifier. When a scraped product title is too messy for our matcher, our server may send the product's publicly visible fields (title, brand, ingredient list — never anything about you or your device) to an AI service (Anthropic) to help identify which catalog product it is; the AI only picks from our own shortlist and its answer is discarded after the lookup. If you ask Sonion a question, that message goes to the same AI service — see “Asking Sonion” below, which is the one place where text you wrote leaves your device, and the one thing we keep for you rather than discard. Sign-in codes and account emails are delivered through Resend, our email provider. Pro payments, if you start a Pro subscription, are processed by Stripe; we never see or store your card number. Our server sends operational telemetry — traces and logs about server requests, such as which route was hit, response timing, and errors — to Frontman (frontman.sh), a development and monitoring tool. This is technical performance data about the server itself, never your identity, your browsing history, or anything you typed.
Some product pages link to Amazon with an affiliate tag. As an Amazon Associate, Greenlens earns from qualifying purchases. Clicking such a link takes you to Amazon, where Amazon's own privacy policy applies; the link itself carries no information about you beyond what any link click sends. Affiliate income never changes a rating or ranking. We record an anonymous count of affiliate clicks (product id and whether the link was a direct listing), under the same no-PII rules as all our analytics.
If you choose to join the waitlist for Greenlens Pro, we store the email address you give us, when you gave it, and which page you signed up from. That's its entire use: to email you about Pro. It is never linked to your usage analytics, never sold or shared, and you can ask us to delete it at any time by emailing the address below. Everything else on this page stays true: no account required, and nothing about your browsing is ever tied to your email.
You can create a Greenlens account if you want your data to follow you across devices. Sync is the only reason accounts exist; every feature that shows you ratings works without one, and that will stay true. An account stores your email address, the product ids on your shelf, the ingredient names you watch, the ingredients on your avoid-list, your skin answers, your weight settings, your rooms and appearance choices, and your conversations with Sonion. Those last two are the only account records that hold words you typed rather than a product id or a number: an avoid-list entry is a short ingredient name, while a conversation can be anything, which is why it has its own section below. It never stores your browsing history, and it is never joined to the anonymous analytics id described above. Deleting your account takes one click on the account page and removes every account record immediately.
You can tell us three things about your skin: whether it runs dry or oily, whether it reacts easily, and whether you watch for breakouts, redness, an easily-upset barrier, or fragrance. All three are optional, you can answer none of them, and nothing in Greenlens is locked behind them. We ask on the website, in a short introduction shown when you sign in on a browser that has not seen it before, and you can change or remove your answers at any time on the settings page. We do not ask while you are only browsing, and you can open the introduction again yourself from the settings page. The mobile app does not ask for them and does not store them.
What we store is the answers, and only the answers. They are picked from a fixed list of choices, so there is no free text here and nothing you type. They are saved in the browser you gave them in. If you are signed in they are also stored on our server under your account, so the other browsers you sign in on show the same thing. If you are not signed in, they never leave that one browser. The mobile app does not read or write them at all today, so answers you give on the website do not appear in the app.
What we do not store is the reading they produce. When a product page says something like “this list has two fragrance materials in it, and you told us you react to fragrance”, that sentence is worked out on the spot, every time, from your answers and the ingredient list in front of you. It is never saved anywhere, never attached to you, and never sent to anyone. It is also never part of a product's score: the score is the same for everyone, and your skin answers do not move it by a single point.
Your skin answers are never sent to Anthropic or any other outside service, never joined to the anonymous analytics described above, never sold or shared, and never used to advertise to you. Removing them takes one tap on the settings page, and the removal travels to the other browsers you are signed in on the same way the answers did. Deleting your account removes them too, along with everything else.
Sonion is the guide character in the app. If you type a question to him, that message is the one thing on this page that is text you wrote rather than a product fact, so it gets its own paragraph.
What is sent to Anthropic, our AI provider: your message, the recent messages in that same conversation, and the id of the product you are looking at. What is never sent: your name, your email, your account, your analytics id, your location, or anything identifying your device. Anthropic is answering a question about a cosmetic; it is not told whose question it is.
Your conversation is kept, and where it is kept depends on you. It is stored on the device you typed it on, the same way your shelf and your settings are, so that leaving the screen doesn't throw it away. If you are signed in, it is also stored on our server, attached to your account — that is what lets a question you asked on your phone be there on your laptop. Apart from the short ingredient names on your avoid-list, this is the only thing in Greenlens that stores text you wrote, so it gets said plainly rather than buried: it means we hold it, and it means we could in principle read it. We do not use it for anything except showing it back to you. It is never used to train an AI model, never sold or shared, and never joined to the anonymous analytics described above.
If you are not signed in, nothing about your conversation ever reaches our server. It stays on that one device, and no other device will ever see it.
Deleting it takes one tap. “Clear” on the Ask Sonion screen removes the conversation from that device and from every other device it had reached, including our server — a deletion travels the same way a message does. Deleting your account removes it too, along with everything else. We also keep only the most recent 60 messages; older ones fall off on their own.
Sonion can only read the same catalog pages you can, and he can only suggest actions — adding something to your shelf, putting it in a room, changing your weightings. Nothing happens until you tap to confirm it, and the action then runs on your device exactly as if you had done it by hand. He never sees anything about you that this page has not already described.
Questions? Email vihaan.goyal1512@gmail.com.