Version 1.1 · in effect from 2 September 2026
What OwnedBy knows about you
Short version: there is no shopper account, we do not track you across the web, and the list of what you have looked up stays in your browser. What follows is the long version, and it describes what the software actually does — including the parts that are less flattering than the short version.
Who is responsible for this
OwnedBy is operated by Touch Grass AB, registered as 559484-7435 in Sweden, which is the controller of the limited personal data described here. Because the company is established in the EU and the service is used in Canada, this page is written to the GDPR and to PIPEDA at once, and to CASL for anything sent by email.
Registered office
Idunsgatan 46
214 46 Malmö
Sweden
Where to write about your data
OwnedBy — Touch Grass AB
3950 Lawrence Avenue East
Toronto, Ontario M1G 1R8
Canada
Post is the route for a request about your own data. There is no privacy mailbox to write to yet, and naming one that nobody reads would start a legal clock against an address that bounces. When one exists it will be listed here.
The terms of use cover what the records are, and how to dispute one that names you or your company.
What stays on your device
Your lookup history lives in your browser’s local storage and is never uploaded. That is the list of things you searched or photographed, what we answered, and when. Clearing your browser data deletes it, and we have no copy. It holds the twenty most recent lookups and nothing older.
Alongside it, in the same browser storage:
- Your language choice, so the app opens in the language you picked.
- Whether you have seen the intro screen, so you are not shown it every visit.
- When you last opened History, so the tab can show you what has changed since.
- Which records you gave a thumbs up or down, so the buttons remember your vote. Up to fifty of them.
- Which records you have asked for a report on, or dismissed the offer for, so you are not asked twice. Up to forty of them, and your address is not among what is kept there.
Two more things are kept only for the life of the browser tab and vanish when you close it: the identity read off a product photograph while you confirm it — text only, never the image — and, when a search matches several companies, the list of choices we offered you, so the page still works if you come back to it. That list also expires after a day.
None of this is sent to us. It is not backed up, it does not follow you to another device, and there is nothing on our side to ask us for.
What leaves your device, and why
When you look a brand up, the name of that brand is sent to our server so the research can run. That is the search itself — without it there is nothing to answer.
When you photograph a product, the photo is sent for recognition and is not stored. It is used to read what is on the label, the text that comes back is what continues through the system, and the image is not written to our database or kept in your history. We keep no image files at all; there is no storage bucket in this product for one to land in.
If you tell us an answer looks wrong, we record that a report was made against that record. There is no field for personal information and we do not ask who you are. The button files a fixed sentence against the record — there is nowhere to type, so there is nothing you could type into it that we would then be holding.
If you give a record a thumbs up or down, that vote reaches our server logs with the record identifier and nothing else. It is not written to any table today.
And your country, described in its own section below.
What we keep on our servers
This is the part a short privacy page skips. The research this product produces is durable and public by design, and some of what makes it up came from somebody typing.
- The brand names people search, stored as typed. They become the index that powers suggestions, so a brand you were the first to look up can appear as a typeahead suggestion to the next person. It is a company name rather than anything about you, and it is not stored with any identifier for you — but it does not disappear when you close the tab, and it is right that you know that before you type.
- The research itself: the ownership chain, the sources, the confidence word, the timings, and the intermediate steps that produced them. This is about companies.
- A two-letter country code for the request, described below.
- A one-way keyed hash of your IP address, used only to count requests against a rate limit. The address itself never reaches our database.
- Reports filed against a record: which record, which field, the fixed sentence the button sends, and nothing about the sender.
- If you asked for a report by email: your address, in one row, and a separate row recording which lookup the report was for.
How long. Research records are kept indefinitely, because a record is the product and because keeping the history of a record is how a correction stays visible as a correction rather than a quiet edit. The rate-limit hashes and the request rows have no expiry either. There is no automatic deletion anywhere in this system, and we would rather say that plainly than describe a retention schedule that does not exist. Your email address is the one piece we will erase on request; see below.
Your country
Our host resolves the connection to a country and passes us a two-letter code — CA, SE — on each request. We use it for exactly two things: to record where a question came from, so a record can say which market it was asked about, and as a gentle tiebreak when one brand name matches several companies in different countries.
It is a country and never a city, a region or an address, and we never see the IP address it was derived from in a form we could store. It is saved with the research for the lookup it belongs to. It never decides who owns a company, it never selects a source, and it never changes which product you get: the Canadian directory and the Canadian options are there for everyone.
When it cannot be resolved — a VPN, a proxy, a browser we cannot place — the answer is no country rather than a guess.
Email, and what happens to it
Two features ask for an email address, and nothing else in the app collects one. The first is asking us to send you a finished ownership report; there is no account to make, and the offer appears on a record whose research is still running — a report you can already read on the screen is not worth an email. The second is the launch list on the front page: you tell us where to write and, if you like, which brands you are curious about, and we send you a report on them when we launch. That one is express consent — you typed the address into a field whose whole subject is being written to — so it does not expire the way the six-month window below does, and the same one-click unsubscribe ends it.
Asking for that report also starts an occasional OwnedBy news email. We say so on the form, above the field, before you type anything, because it is the whole reason we are allowed to keep the address at all — and every email we send carries who we are, our mailing address, and a one-click unsubscribe.
- What we collect: the address you type, and nothing else. No name, no device identifier, and the history on your device is not attached to it.
- Why: to send the ownership report you asked for, and occasional news about OwnedBy.
- How long we keep it: while you are subscribed, and after that until you ask us to erase it. Unsubscribing stops the sending; it does not remove the row on its own, and there is no scheduled purge that would.
- Who else sees it: our mail provider, which receives the address in order to deliver the message. It is not sold, not shared for advertising, and never joined to your lookup history.
- What we never do: we do not sell your address, we do not pass it to advertisers, and we do not use it to work out what else you have searched for.
One honest caveat, because the bullet above is narrower than it looks. The row that queues your report records which lookup the report is for. So the address you gave us is connected to the one brand you asked to be emailed about — it has to be, or we could not send you the right report. What is not connected to it is the list of everything else you have looked at, which never leaves your browser and which we do not have.
Why we are allowed to write to you. Canadian anti-spam law treats your own request for a report as an inquiry, which gives implied consent for six months from the last time you asked. That clock is recorded in the database rather than assumed, it restarts if you ask for another report, and it is why there is no consent checkbox: a checkbox beside a request you have already made is theatre.
Unsubscribing. Every message carries a link. One click, no sign-in, no confirmation step, and it takes effect immediately. It stops the news and it never cancels a report you explicitly asked for — that one still arrives, because you asked for it. Marking a message as spam has the same effect as unsubscribing.
The mail arrives from OwnedBy at reports@ownedby.app, its subject line is the answer to the lookup you asked about, and it contains the report itself rather than a link telling you a report is ready. That mailbox sends; it is not read, so a request about your data should go to the postal address above.
Why we are allowed to hold any of this
Under the GDPR every use of personal data needs a lawful basis. Ours, in plain terms:
- Running a lookup and sending you back an answer: performance of what you asked for, and our legitimate interest in operating a research service that works.
- Keeping the searched brand name as part of the research index, so records improve and suggestions exist: legitimate interest. The data is a company name, and no identifier for you is stored with it.
- The country code and the hashed IP: legitimate interest in security, in fair use of a shared research budget, and in showing a record in the right market context.
- Sending the report you asked for: performance of your request.
- Sending occasional OwnedBy news: legitimate interest, on the implied consent that Canadian anti-spam law gives us from your own inquiry, and endable by you at any time with one click.
- Keeping records of corrections and of what we sent: legitimate interest in being able to show what we published and when, and in defending a record that is disputed.
Under PIPEDA the same uses rest on consent — express where you typed an address into a field that told you what it was for, and implied where you used a public research tool for the thing it visibly does. If you think any of these balances is wrong, that is exactly what the objection right below is for, and we would rather hear it than not.
Your rights, and how to use them
Wherever you live, you can ask us what we hold about you, ask for it to be corrected, ask for it to be erased, ask for a copy in a portable form, ask us to restrict what we do with it, and object to our doing it at all. In the EU and the UK these are GDPR rights; in Canada they are your PIPEDA access and correction rights; we do not run two processes.
What we can actually find. Almost everything here is unlinked to you by design, which cuts both ways: if you never gave us an email address, we have no way to connect a request to a row, and honestly saying so is better than a search that theatrically returns nothing. If you did give us an address, that is the key — tell us the address and we can find the subscriber row and the report requests attached to it, correct them, export them, or erase them.
Write to the postal address above. We answer within thirty days, which is the PIPEDA deadline and inside the GDPR’s one month. There is no charge. We may ask you something to confirm the request really comes from the person it is about, and we will ask for as little as will do.
If we get it wrong you can complain to a regulator. In Sweden that is Integritetsskyddsmyndigheten (IMY); elsewhere in the EU or the UK it is your own national authority; in Canada it is the Office of the Privacy Commissioner of Canada. You do not have to come to us first, although we would rather you did.
Who else sees it
Answering “who owns this?” means asking other services. The brand name you searched is sent to some of them; none of them receives your history, your identity, or anything about you.
- A search provider (Serper) receives the brand or company name being researched, as a search query.
- Language model providers (Anthropic, OpenAI, and OpenRouter when it is configured) receive the brand name and the page snippets that search returned.
- When you use the camera, the photograph goes to whichever vision provider is configured — Anthropic, OpenAI, Google Gemini, or OpenRouter standing in for OpenAI. It is used to read the label and is not stored by us.
- Public reference sources (Wikidata, GLEIF, SEC EDGAR, Corporations Canada, OpenCorporates, company websites) receive ordinary web requests for company records. They see our server, not you.
- Supabase stores the research, the lookup index and the subscriber row; Vercel hosts the site and keeps standard server logs; Resend delivers email and receives the address it is delivering to.
Each of these acts on our instructions under a data-processing agreement, and none of them is permitted to use what it receives for its own purposes. We do not sell data to anyone, and none of these is an advertising relationship.
Where in the world it goes
The company is Swedish, most of the people using the site are Canadian, and several of the services above run in the United States. So personal data does cross borders: a lookup made in the EU can be processed on infrastructure outside it, and the reverse is true too.
For transfers out of the EEA we rely on the European Commission’s standard contractual clauses, or on an adequacy decision where one covers the destination — Canada has one for commercial organisations. For personal data handled in Canada, be aware that information stored or processed in another country can be reachable by that country’s courts and law-enforcement agencies, whatever we would prefer. That is true of every service that uses foreign infrastructure, and saying so is a Canadian disclosure requirement rather than an admission of anything unusual.
Server logs and security
Our host keeps standard server logs of requests: the IP address, the time, the address of the page or endpoint, and the browser’s own identification. That is ordinary web hosting and it is how anyone diagnoses a failure or resists an attack.
One consequence worth stating rather than burying: what you type appears in a web address while you are searching, so it appears in those request logs too. We strip it from analytics, described below, and we do not strip it from the host’s own logs, because we cannot. We do not read those logs to work out what any individual searched for, and there is nothing in them that names you.
Everything travels over HTTPS. The database is reachable only through server-side credentials that never touch your browser, row-level security is on and direct table access is revoked, and the routes that write anything are rate limited. No system is perfectly secure and we are not going to claim this one is.
Anonymous usage analytics
We use Vercel Web Analytics to understand aggregate traffic and whether core product flows work. It is cookie-free and does not assign you a persistent identifier. Vercel receives limited request information such as the page type, timestamp, referring site, browser and device type, plus coarse geography derived from the connection. We remove query strings, local result identifiers and searched company names from analytics page addresses before an event is sent.
We do not use session replay, advertising pixels or cross-site tracking, and analytics events never contain a product photograph or the words you typed into search. A handful of product events are also recorded — that a record was opened, that a report was requested — and each one carries only fixed labels and bucketed counts. Anything resembling a query, an identifier or a location is refused by the code that sends them.
Cookies
One, and it holds your language choice. The server needs to know whether to render the page in English or French before the page loads, which is the one thing browser storage cannot do in time, so that single preference is also written as a cookie. It contains the two letters en or fr and nothing else — no identifier, nothing that follows you between sites. It lasts a year. There are no advertising or analytics cookies, which is why this app has no cookie banner to dismiss.
That is the whole story for anyone using the site. The operator consoles behind it set sign-in cookies for the people who run OwnedBy, and those are never set on a shopper’s browser.
What we do not do
- No shopper accounts and no sign-in. An email address only if you ask us to send you a report; that also subscribes you to occasional OwnedBy news, and every email has an unsubscribe link.
- No advertising pixels, session replay or cross-site tracking. Aggregate Vercel Web Analytics is the only analytics client in this app.
- We do not sell personal data or share it for targeted advertising. Limited request data reaches the hosting and research processors described above.
- No storing of your photographs.
- We do not build a personal lookup profile. The device history stays in your browser; individual lookup requests are processed as described above without being assembled into that history.
- No profiling and no automated decisions about you. The research is automated and the judgements it makes are about companies; nothing here evaluates a person or produces an effect on one.
- We do not knowingly collect anything from a child, and there is nothing here to sign up for that would let us.
Research is public information
The ownership records this app publishes are built from public sources — regulatory filings, company registries, companies’ own statements and reporting of record. When one person’s lookup improves a record, the improved record is served to everyone who looks up that brand afterwards. That is about companies, never about the person who searched.
Where a record names a natural person — an owner, a founder, a controlling shareholder — it does so because a public register or a company’s own disclosure names them, and reporting who benefits from a company is a matter of legitimate public interest. If you are named in a record and want it reviewed, the terms of use set out the route, and the rights in this page apply to you as much as to anyone using the site.
Children
OwnedBy is a shopping tool for a general audience. We do not knowingly solicit personal information from children. There are no shopper accounts; the same limited request data described above is processed when anyone uses the public site. If you believe a child has sent us an email address, write to us and we will erase it.
Changes, and how to reach us
If this policy changes, the version number and the date at the top change with it. A change that materially affects what we do with your data will be made visible on the site rather than left for you to notice on a re-read.
Questions about what is written here, or a request about your own data, go to the postal address at the top of this page. A record you think is wrong is faster through the add or correct page, and the terms of use explain how a correction is checked before anything changes.