← Back to Snifff

YOUR PRIVACY

Privacy policy.

Last updated: 6 September 2026

Snifff is a browser extension that rates the ingredient list of a cosmetic product against EU and Indian cosmetic regulation while you are looking at the product page. This policy describes what the extension sends, what is stored, and what happens if you join the optional mobile-app launch list.

Where Snifff runs

The extension loads on nykaa.com and nowhere else. It is not installed into, and cannot read, any other website you visit. The public website contains the optional mobile-app launch list.

Besides the Nykaa page you are already looking at, the extension can reach exactly one server: the Snifff scoring service, hosted on Supabase. There is no other network destination in the extension.

What leaves your browser

When you open a Nykaa product page, the extension reads the listing and sends the following to the Snifff scoring service, anonymously, so the product can be scored:

These extension requests carry no name, no email address, no account, no advertising identifier, no device identifier, and no session identifier.

When you submit the launch-list form on the website, the website sends the email address you entered to Snifff's site server.

What never leaves your browser

What is stored on your device

Display preferences only:

These sit in the browser's local extension storage on your own machine. They are never synced to an account and never transmitted anywhere. Removing the extension removes them.

What is stored on Snifff's servers

Anonymous scan records. Each scan writes one row containing: the time, the retailer, the version of the ingredient database used, the product category that was resolved, the share of the ingredient list that matched the database, and the names of any ingredients that were not found. That last field is the point of the record — unmatched ingredient names are what tell us which substances to research and add next.

Each row also carries a salted, irreversible hash of the product-ID path. This identifies the product, so a missing ingredient can be ranked by how many products it affects rather than by raw traffic. The raw path is never stored, and the hash cannot be reversed back into it. No row in this table has a user column, a session column, a device column, or an IP column.

Rate-limiting counters. To stop the service being abused, incoming requests are counted per network address. Your IP address is combined with a secret salt and a time window and only the resulting irreversible hash is stored, as a counter. These counters are deleted within an hour. The raw IP address is never written to the database and never written to a log.

Image-text cache. When the server reads a concentration figure off a product image, the result is cached against the product and the image contents so that rescanning the same page costs nothing and a replaced image is never read from stale data.

Mobile launch list. If you submit the optional form, we store your email address and the date you joined. We use this list only for Snifff product updates, development progress, and the iOS and Android launch. We do not automatically add extension users to it.

Who else sees anything

Selling and sharing

Snifff does not sell your data. Snifff does not share it for advertising or marketing. We use launch-list email addresses only for Snifff updates and launch news.

Children

Snifff is not directed at children. Do not submit an email address for someone under 13.

Your choices

You can remove the extension at any time from your browser's extensions page; this deletes the preferences held on your device.

You can leave the mobile launch list at any time by emailing help@snifff.app and asking us to remove your address. Because the anonymous scan records hold no identifier of any kind, there is no way — for us or for anyone else — to link them back to you, and therefore nothing personal to look up, export, or delete on request.

If you would prefer nothing be sent from the extension at all, removing or disabling it stops it completely.

Changes to this policy

If what Snifff sends or stores changes, this page is updated and the date at the top changes with it. Material changes will also appear in the extension's Chrome Web Store listing notes.

Contact

Questions about this policy, the mobile launch list, or the data described in it: help@snifff.app

The same address sits behind the Send feedback link in the extension's settings panel.