Privacy Policy

Version 1 · Last updated: 2026-09-09

Barcodepedia stores as little about you as a public wiki can. This page says exactly what, why, for how long, and what you can do about it.

1. Who is responsible

The data controller is Moltke Benjaminsen ApS (MB Alpha), CVR 45555399, Denmark. Contact: [email protected]. The registered address is on record in the Danish Central Business Register under that CVR number.

2. Reading the site

You can read every page without an account. When you do, our server receives your IP address, the page requested, the time and your browser's user agent, as any web server does. We keep no request log of our own; Cloudflare, our proxy, processes connection data under its terms. If we add an access log it will be kept 30 days and this page will say so first.

Traffic passes through Cloudflare, which provides DNS, TLS and proxying and processes connection data under its own terms as our processor.

When analytics are enabled we use Umami, self-hosted on our own server. It sets no cookie, stores no IP address and cannot identify you. There are no third-party trackers, and no advertising today. If advertising is added later, this policy will be updated first and the change will be visible on this page.

3. Accounts

Editing requires an account, and accounts are created by signing in with GitHub. We receive and store from GitHub: your numeric user id, your login (handle), your primary verified email address, your display name and your avatar URL. We do not store a password for GitHub accounts. Sign-in is GitHub only; one administrator account created at setup carries a hashed password that is not usable for sign-in while that is the case.

We set one cookie, the session cookie, which keeps you signed in. It is strictly necessary for the service and needs no consent. See Cookies.

Your handle is public. It appears on every version you save and in the history of every page you edit. Your email address is never shown.

A review you post on a product page is stored with your account id, the barcode, the stars, the text and the times you wrote and last changed it, and is shown publicly under your handle. Unlike page versions, reviews are yours to edit and delete at any time, and deleting your account deletes them.

4. Contributions are public and permanent

Every edit you make is stored as a version with your handle, the time and your change note, and is visible to everyone in the page history. Reverting an edit creates a new version; nothing is deleted. This is what makes the site trustworthy, and it is the reason the erasure right below has a caveat.

If you delete your account, or ask us to, we erase your personal data: email, display name, avatar, GitHub id and login. Your versions stay, because they are part of a public, permanent edit history that the site and other contributors rely on (a legitimate interest under GDPR Article 6(1)(f), and the archiving exception in Article 17(3)(d)); they are re-attributed to a pseudonymous "former user" label so nothing on the site links them to you. If a version itself contains personal data about you, tell us and we will remove that data from the current page and, where the law requires it, from history.

5. Bot passes

Some edits are made through the site's task endpoint by an AI agent that an operator runs on their own account and their own machine. For each such run we store the operator's handle, the name of the pass, the model identifier the agent reported, the result, its summary and the sources it cited. We do not collect the agent's session transcript. The handle, pass and model are shown publicly on the page. Transcripts are not public. Transcripts are kept for as long as the version they produced exists, as its provenance record, and not published.

6. Where data lives

On a dedicated server in Germany operated by MB Alpha, including the database and its backups. Nothing is sent to third parties except as described above (GitHub for sign-in, Cloudflare for delivery).

7. Legal basis

Server logs and abuse prevention: our legitimate interest in running a secure service. Account data and session cookie: performance of the agreement you enter by creating an account. Public attribution of contributions: the same agreement, and the legitimate interest of every reader in knowing who wrote what. Analytics: legitimate interest, made proportionate by using a cookieless, non-identifying tool.

8. Retention

  • Account data: while the account exists.
  • Versions and page history: permanently (see section 4).
  • Server logs: none kept today (see section 2).
  • Bot transcripts: not collected since 12 September 2026. Runs before that date keep the transcript submitted then, as that version's provenance record; not public.
  • Backups: rotated with the server's backup schedule; deleted data leaves backups as they age out.

9. Your rights

Under the GDPR you can ask for access to the data we hold about you, have it corrected, have it erased (with the contribution caveat in section 4), receive a copy in a portable format, and object to processing based on legitimate interest. Write to the contact address in section 1. You can also complain to the Danish Data Protection Agency, Datatilsynet, datatilsynet.dk.

10. Age

You must be at least 16 to create an account.

11. Changes

Changes to this policy are versioned like everything else here; the version and date are at the top. Material changes are announced on the site before they take effect.

Moltke Benjaminsen ApS (MB Alpha), CVR 45555399, Denmark
Contact · Privacy · Terms · Licence