Privacy Policy

Last updated 8 September 2026

SnackProof scans food ingredient labels and returns a verdict on the additives it finds. This policy explains exactly what the app collects, what it deliberately does not, and how to have your data removed.

SnackProof has no accounts, no sign-up and no login. We never ask for your name, email address, phone number or password, and we cannot identify you personally. The app creates an anonymous identifier so your scan history and subscription follow your install — nothing more.

1. What we collect

Anonymous account identifier

On first launch the app creates a random, anonymous account identifier. It is not linked to your identity and is used only to keep your scan history, free-scan count and subscription status attached to your install.

Label photos

When you scan a label, the photo is sent to our server, forwarded to the OpenAI API to extract the printed text, and then discarded. Photos are never written to storage or a database, are never associated with your history, and are not used to train any model. Only the extracted text moves on to the next step.

Scan results

So the History screen works, we store the outcome of each scan: the extracted ingredient text, product name and brand where available, the letter grade and score, the number of flags, the scan method (camera or barcode) and the time of the scan.

Your preferences

Who you are scanning for, which concerns you want flagged and any dietary toggles (halal, kosher, vegan) are stored on your device. They are applied locally when scoring a label.

Diagnostics

For each scan we log the response time, the token count and which model version ran, tied to the anonymous identifier. This is used to monitor cost and reliability.

Purchases

If you subscribe, our payments provider records the transaction and entitlement. We never see or handle your card details — payment is processed entirely by Apple or Google.

Advertising (free tier only)

Free users are shown banner ads by Google AdMob, which may use your device's advertising identifier. On iOS you will first be asked for permission through Apple's App Tracking Transparency prompt; declining is completely fine — the app works identically and you simply see less relevant ads. Subscribers are shown no ads and no ad SDK request is made for them.

Analytics and crash reporting

Where enabled, we use product analytics to understand which screens are used and crash reporting to find bugs. Both are tied to the anonymous identifier, never to you.

2. What we never collect

  • Your name, email address, phone number or postal address.
  • Your passwords — there is no account to have one.
  • Your payment card details.
  • Your precise location.
  • Your contacts, calendar, microphone or photo library beyond a label you pick.
  • The label photographs themselves, which are discarded after text extraction.

3. Who processes your data

We share data only with the providers needed to run the app:

ProviderPurposeWhat it receives
OpenAIReading the text on a labelThe label photo, transiently
SupabaseDatabase and anonymous authenticationAnonymous id, scan results, diagnostics
RevenueCatSubscription statusAnonymous id, purchase events
Apple / GoogleProcessing paymentYour payment details, which we never see
Google AdMobBanner ads for free usersAdvertising identifier, ad interactions
PostHogProduct analyticsAnonymous id, screen and feature events
SentryCrash and performance reportingAnonymous id, crash and performance data
Open Food FactsBarcode product lookupThe scanned barcode number only

We do not sell your data, and we do not share it with data brokers.

4. How long we keep it

Scan results are kept until you delete them or request deletion of your data. Diagnostic logs are retained for up to 90 days. Label photos are never retained at all.

5. Your rights

You can delete an individual scan from the History screen at any time. To erase all data associated with your install — your scan history, its diagnostic logs and the anonymous identifier itself — open Settings › Your data › Delete my data in the app, which takes effect on our server immediately. You can also email us at deepfaiinc@gmail.com from the device in question and we will action it within 30 days. Full instructions are on the Delete your data page.

Depending on where you live, you may also have the right to access, correct, export or restrict processing of your data, and to lodge a complaint with your local data protection authority. Because SnackProof holds no information identifying you personally, we may be unable to locate your records without the anonymous identifier shown in the app.

6. Children

SnackProof is designed for parents and carers, not for children. It is not directed at children under 13, and we do not knowingly collect data from them. Choosing to scan “for a toddler” is a scoring preference stored on your device — it collects no information about any child.

7. Security

Data is transmitted over encrypted connections and stored with per-user access rules enforced at the database level, so one install cannot read another's data. API credentials are held server-side and are never shipped inside the app.

8. Changes

If this policy changes materially we will update the date at the top of this page and note the change in the app.

9. Contact

Questions about this policy or your data: deepfaiinc@gmail.com.

← Back to SnackProof