1. Scope
This policy applies to the VegiSearch website and mobile app. Third-party sites, stores, or services operate under their own policies and are not controlled by VegiSearch.
2. Information We May Process
Official Website
The Phase 0 website is static and has no product-level member login, behavioral tracking analytics, comment forms, or database submission. Hosting, DNS/CDN, or email-delivery providers may still process IP address, timestamps, browser, or request metadata for security and transmission; this should not be read as a promise that the website creates no network records. If you contact us by email, we receive the message content, sender address, and technical transmission metadata necessary for delivery.
VegiSearch Mobile App
- Camera Permission: Used exclusively for real-time EAN/UPC barcode recognition; video streams and photos are never saved, recorded, or transmitted to remote servers.
- Local Storage: In guest mode or when sync is disabled, dietary preferences and scan history remain entirely on your device in a local SQLite (Drift) database.
- Account & Auth: When registering via Email or Google Sign-In, we process email, verification status, display name, and hashed credentials needed for secure session maintenance. We never request sensitive access to Gmail, Google Drive, etc.
- Explicit Opt-in Sync: Dietary preferences (including alcohol preferences and result-notice display settings) and scan history are transmitted to our servers only after you explicitly opt in within the app. Logging in does not automatically enable sync. These preferences may reveal information about religion, health, or lifestyle and are kept separate from product-improvement telemetry.
OCR/intake status: The current Android Internal Testing build provides barcode lookup only. Ingredient-photo OCR, unknown-product intake, and any public candidate queue are not enabled, so there is no current OCR/intake candidate-retention promise. Before any future enablement, we will define one retention window and complete the schema/migration, purge, health/readiness, primary/standby deployment, backup, and notice gates.
App Scan and UX Telemetry (Explicit Opt-in)
The app's “Help improve VegiSearch” switch is off by default and controls both scan metrics and UX telemetry. Only after you explicitly enable it may the app send allowlisted scan hits or misses, valid barcodes, operation timing, performance, or recognition metrics. Each Layer 3 event may include a UUIDv4 session identifier rotated within 24 hours. The app does not put account tokens, email, camera images, dietary preferences, or alcohol preferences into this telemetry. Barcodes, timestamps, and short-lived identifiers may still become linkable with network or service metadata (such as IP address, request time, and headers), so we do not describe this data as “zero personal data” or “fully anonymous.”
You can turn the switch off at any time. The app then stops future reporting and clears events not yet sent; data already received by the server is not automatically erased by the device switch and remains subject to the retention, deletion, and access-control policy. This switch is separate from the consent to sync preferences and scan history.
3. Purpose of Processing
- Providing product lookup, personalized assessments, and account services.
- Verifying identity, maintaining sessions, security auditing, and abuse prevention.
- Responding to customer support, announcements, and account deletion requests.
- Maintaining, debugging, and improving product catalog accuracy and service uptime.
- Complying with applicable legal obligations and regulatory requirements.
4. Third-Party Services
Website hosting and DNS/CDN are provided by Cloudflare. Email delivery is managed by domain mail routing and email infrastructure. Google Sign-In is available only to invited Android Internal Testers. Apple sign-in is implemented in the backend but remains fail-closed with a 404 at the edge and is not publicly enabled. When these sign-in methods are used, their data handling is also governed by the providers’ terms and privacy policies. VegiSearch never requests extraneous permissions like Gmail or Google Drive. OCR/intake is not currently enabled; before any future external OCR/AI integration, we will complete one retention window plus schema/migration, purge, health/deployment, backup, and notice gates, then update the processing purpose and data scope.
5. Retention & Deletion
Data is retained only as long as necessary to fulfill services, maintain security, and satisfy legal requirements. Upon account deletion, identifiable user data is deleted or de-identified within 30 days; encrypted backups are rotated out within 90 days.
For opted-in app telemetry, Layer 3 UX events are retained for at most 90 days and Layer 1 aggregated scan statistics for at most 365 days. The primary database runs the fixed-floor batch purge functions from the daily vegisearch-auth-maintenance.timer; the maintenance job fails closed if its post-purge overdue-data assertion fails. These telemetry records are not automatically erased by the in-app consent switch and remain subject to the retention and deletion policy; the standby host keeps this maintenance timer disabled.
Security-audit exception: Login, logout, token-revocation, and account-status events are written to append-only audit records. The current maintenance job sets an audit row's session_id to NULL before an expired or revoked session is removed, which breaks the session link; it does not currently purge the audit row itself. We retain only the minimum fields for security operations, disputes, and legal obligations for the necessary period. These audit records are not covered by the 90-day Layer 3, 365-day Layer 1, or 30-day account-linked scan-history purge windows.
You may submit requests per our Account Deletion Instructions.
6. Security
We implement technical and organizational measures appropriate to risk levels, including HTTPS, least privilege, password hashing, opaque session tokens, security audits, and backups.
7. Your Rights
You may request access to, correction of, or deletion of your personal data, or revoke non-essential consent at any time.
8. Children
VegiSearch is not intended for children. We do not knowingly collect personal data from minors below the legally required age.
9. Updates
We update this policy when features, providers, or laws change. Material changes will be notified reasonably.
10. Contact Us
For privacy inquiries, please write to [email protected].