Vegan Scanner: Food Check — Privacy Policy
Effective Date: August 10, 2026
Vegan Scanner: Food Check ("the App") is developed by Mobile Card Games & Travel Apps LLC. This Privacy Policy explains what data the App collects, how it is used, and how your privacy is protected.
1. Data We Collect
Vegan Scanner collects the following data that you provide directly through your actions in the App:
- Photos of food and ingredient labels: Photos you take with your camera or select from your photo library to have their ingredients checked for animal-derived ingredients.
- Ingredient text: Ingredient lists you scan or type in for analysis.
- Barcode numbers: The numeric barcode (UPC/EAN) of products you scan.
- Your profile setting: The strictness setting you choose, stored on your device.
- Purchase information: Transaction records for in-app subscriptions, managed by Apple and RevenueCat.
The App does not collect your name, email address, location, contacts, or advertising identifiers. It contains no analytics SDKs, serves no ads, and does not request the iOS App Tracking Transparency permission because it does not track you.
2. How We Use Your Data
Your data is used solely to tell you whether a product is vegan:
- When you photograph or select a label image, the photo is sent to OpenAI's AI model for ingredient analysis. The same applies to ingredient text you scan or type.
- When you scan a barcode, only the numeric barcode is sent to Open Food Facts, a public food-product database, to look up the product and its ingredients. No photo or identity data is included in that request.
- The analysis result (vegan status, detected ingredients, recommendations) is shown to you and saved as text in your on-device scan history.
3. Third-Party Data Sharing
Your data is shared only with the services needed to perform a scan:
- OpenAI (openai.com): Receives the photo or ingredient text you submit to perform the vegan analysis. Data is transmitted through AIProxy (aiproxy.com), a secure API relay, over an encrypted HTTPS connection. Per OpenAI's API data usage policies, data sent through the API is not used to train their models.
- Open Food Facts (world.openfoodfacts.org): Receives only the numeric barcode you scan. The request identifies the App (not you) via a standard User-Agent header.
- Apple and RevenueCat (revenuecat.com): Purchases are processed by Apple; the App never sees your payment card details. RevenueCat receives purchase transaction tokens and a random anonymous app-user ID — never your name or email.
We do not sell, rent, or share your data with anyone else.
Abuse prevention: every AI request the App sends also includes your device's Apple identifier-for-vendor and an Apple DeviceCheck token. These are used solely to prevent abuse and rate-limit AI requests; they are not linked to your name or identity and are not used for advertising or tracking.
4. Data Storage and Retention
- On your device: Your scan history is stored locally as text (scan results, counters, timestamps) — the photos themselves are not saved by the App after analysis. Your profile setting, free-scan counter, and a short-lived (24-hour) cache of barcode lookups are also stored locally.
- On our servers: We do not operate any server that stores your data. Photos and ingredient text exist in transit only during the API request to OpenAI.
- Deletion: You can clear your scan history in the App at any time; uninstalling the App removes all locally stored data.
5. Data Security
All network requests are made over encrypted HTTPS connections. AI requests are routed through AIProxy so that API keys are protected and never embedded directly in the App.
6. Your Rights
You have the right to:
- Clear your scan history and settings in the App at any time, or remove all App data by uninstalling the App.
- Deny camera permission, which prevents the App from taking photos or scanning barcodes; you can still analyze photos you choose from your library or ingredient text you type.
Depending on where you live, privacy laws such as the European Union's General Data Protection Regulation (GDPR) and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) give you rights over your personal data, including the rights to know, access, correct, and delete it. Because we do not hold your data on servers we operate, there is typically nothing for us to access or delete on request — deleting the App deletes your data. Where the App does process data in transit, or a third-party service described above collects data, you may contact us at the email below to exercise your rights, and we will respond as required by applicable law.
7. Children's Privacy
The App is not directed at children under 13, and we do not knowingly collect data from children under 13. In some regions, including the European Union, a higher minimum age applies to consent for data processing; the same statement applies there — we do not knowingly collect data from anyone under the applicable age.
8. Data Breach Notification
In the unlikely event of a data breach affecting user data on any system we operate, we will notify affected users as required by applicable law.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be reflected by updating the "Effective Date" at the top of this page.
10. Contact Us
If you have questions about this Privacy Policy or your data, please contact us at:
v5cqpsj4e3u4@opayq.com