Privacy Policy
Last updated 8 September 2026
SnackProof scans food ingredient labels and returns a verdict on the additives it finds. This policy explains exactly what the app collects, what it deliberately does not, and how to have your data removed.
SnackProof has no accounts, no sign-up and no login. We never ask for your name, email address, phone number or password, and we cannot identify you personally. The app creates an anonymous identifier so your scan history and subscription follow your install — nothing more.
1. What we collect
Anonymous account identifier
On first launch the app creates a random, anonymous account identifier. It is not linked to your identity and is used only to keep your scan history, free-scan count and subscription status attached to your install.
Label photos
When you scan a label, the photo is sent to our server, forwarded to the OpenAI API to extract the printed text, and then discarded. Photos are never written to storage or a database, are never associated with your history, and are not used to train any model. Only the extracted text moves on to the next step.
Scan results
So the History screen works, we store the outcome of each scan: the extracted ingredient text, product name and brand where available, the letter grade and score, the number of flags, the scan method (camera or barcode) and the time of the scan.
Your preferences
Who you are scanning for, which concerns you want flagged and any dietary toggles (halal, kosher, vegan) are stored on your device. They are applied locally when scoring a label.
Diagnostics
For each scan we log the response time, the token count and which model version ran, tied to the anonymous identifier. This is used to monitor cost and reliability.
Purchases
If you subscribe, our payments provider records the transaction and entitlement. We never see or handle your card details — payment is processed entirely by Apple or Google.
Advertising (free tier only)
Free users are shown banner ads by Google AdMob, which may use your device's advertising identifier. On iOS you will first be asked for permission through Apple's App Tracking Transparency prompt; declining is completely fine — the app works identically and you simply see less relevant ads. Subscribers are shown no ads and no ad SDK request is made for them.
Analytics and crash reporting
Where enabled, we use product analytics to understand which screens are used and crash reporting to find bugs. Both are tied to the anonymous identifier, never to you.
2. What we never collect
- Your name, email address, phone number or postal address.
- Your passwords — there is no account to have one.
- Your payment card details.
- Your precise location.
- Your contacts, calendar, microphone or photo library beyond a label you pick.
- The label photographs themselves, which are discarded after text extraction.
3. Who processes your data
We share data only with the providers needed to run the app:
| Provider | Purpose | What it receives |
|---|---|---|
| OpenAI | Reading the text on a label | The label photo, transiently |
| Supabase | Database and anonymous authentication | Anonymous id, scan results, diagnostics |
| RevenueCat | Subscription status | Anonymous id, purchase events |
| Apple / Google | Processing payment | Your payment details, which we never see |
| Google AdMob | Banner ads for free users | Advertising identifier, ad interactions |
| PostHog | Product analytics | Anonymous id, screen and feature events |
| Sentry | Crash and performance reporting | Anonymous id, crash and performance data |
| Open Food Facts | Barcode product lookup | The scanned barcode number only |
We do not sell your data, and we do not share it with data brokers.
4. How long we keep it
Scan results are kept until you delete them or request deletion of your data. Diagnostic logs are retained for up to 90 days. Label photos are never retained at all.
5. Your rights
You can delete an individual scan from the History screen at any time. To erase all data associated with your install — your scan history, its diagnostic logs and the anonymous identifier itself — open Settings › Your data › Delete my data in the app, which takes effect on our server immediately. You can also email us at deepfaiinc@gmail.com from the device in question and we will action it within 30 days. Full instructions are on the Delete your data page.
Depending on where you live, you may also have the right to access, correct, export or restrict processing of your data, and to lodge a complaint with your local data protection authority. Because SnackProof holds no information identifying you personally, we may be unable to locate your records without the anonymous identifier shown in the app.
6. Children
SnackProof is designed for parents and carers, not for children. It is not directed at children under 13, and we do not knowingly collect data from them. Choosing to scan “for a toddler” is a scoring preference stored on your device — it collects no information about any child.
7. Security
Data is transmitted over encrypted connections and stored with per-user access rules enforced at the database level, so one install cannot read another's data. API credentials are held server-side and are never shipped inside the app.
8. Changes
If this policy changes materially we will update the date at the top of this page and note the change in the app.
9. Contact
Questions about this policy or your data: deepfaiinc@gmail.com.
← Back to SnackProof