Scan Your Food is an adult nutrition and wellness tracking app. This page explains what data is used, why, and how you stay in control.
Data we process
Depending on the features you use, the app may process account information; age, sex, height, weight, goals and preferences; meals, calories and macros; hydration; weigh-ins; workouts; notes; AI Coach conversations; user-selected photos; and subscription status.
When optional product analytics are enabled, their events never contain meal names or content, calories, macros, weight, photos, email, free text, AI prompts or responses, advertising IDs or device fingerprints.
Purposes
Data is used to provide accounts, nutrition tracking, calculations, history, backups and sync; run AI features you voluntarily request; verify Premium; protect and diagnose the service; and improve the product only after optional analytics consent.
We do not sell personal data, run targeted ads or track you across other companies’ apps or websites.
Local storage and Supabase
Without a signed-in account, core data remains on the device. With an Apple, Google or email account, Supabase provides authentication, database, server functions and private storage for backups and cross-device sync.
Free access displays the last seven days of nutrition history. This is only a display limit: older data is not deleted or recreated by the lock and remains subject to the retention and deletion rules below.
OpenAI and separate permission
Before the first AI feature, the app names OpenAI and asks for separate permission. If granted, selected photos, the description or question you enter and only the authorized context categories may be sent to OpenAI to provide the requested result. OpenAI permission is independent from optional product analytics.
If permission is declined or later withdrawn, no new content is sent to OpenAI. Manual meal entry remains available without an AI call.
Permission can be revoked in Profile > Privacy. Integrated requests use store: false, while OpenAI may temporarily process or retain some data under its API terms and security obligations. Technical AI logs may record model, request type, status, latency, token counters, estimated cost and a technical hash, but never prompts, responses or photos.
Three included AI analyses
Each account receives three validated and completed AI meal analyses for the entire account lifetime. This is not three analyses per device, reinstall or period. The server-side counter is deleted with the account.
An operation is first reserved with a technical ID to prevent concurrent requests and double counting. It consumes an included analysis only after the server validates a coherent nutrition result. A network error, invalid response or detected abandonment releases the reservation for another attempt.
An active reservation blocks duplicates for no more than three minutes and can then be reclaimed. Released reservations are deleted. Completed operation IDs remain with the counter during the account lifetime to guarantee idempotency and are deleted with the account.
Optional product analytics
Product analytics are strictly optional and off by default. They start only after explicit opt-in under Profile > Privacy. If enabled, the app may send event type and time, platform, version, closed values or bounded counters, and random install, session and event UUIDs to Supabase. These UUIDs do not come from IDFA, IDFV or the Android device ID.
An event created during a signed-in session may be linked to the account by the server using authentication. An event created before sign-in remains anonymous even if sent later.
Opting out stops new events, attempts to interrupt an active upload, clears the local queue, random install ID and deduplication keys, and rotates the session ID. Events already received follow their maximum 180-day retention; account-linked events are also deleted with the account.
Payments and RevenueCat
Apple App Store or Google Play processes payments and retains transaction history under the store’s rules. RevenueCat verifies products, Premium entitlements, expiration dates and restores through a subscriber ID. We never receive card numbers.
The server retains only metadata required for entitlement state, event ordering and idempotent notifications. It does not retain raw RevenueCat webhook bodies or raw subscriber attributes.
Providers and transfers
Supabase provides authentication, database, server functions, private storage, backups, sync and, after opt-in, product analytics ingestion. OpenAI processes only the content needed for voluntarily requested and authorized AI features. RevenueCat manages product and Premium-entitlement verification. Apple and Google may provide sign-in and process purchases on their platforms.
These providers may process data in different countries. Any transfers are covered by their contractual commitments, applicable clauses and security safeguards. Their own retention periods remain subject to their respective policies and obligations.
Retention
- local data: until you delete it or remove the app’s data;
- Supabase backups and private photos: while the account exists;
- sync diagnostics: target purge after 90 days;
- optional product analytics: target purge after 180 days;
- technical AI ledger: target purge after 365 days;
- RevenueCat technical delivery records: target purge after 730 days;
- included-analysis counter and completed operation IDs: for the account lifetime;
- unfinished analysis reservation: released after a detected failure or reclaimable after three minutes.
Access, export and deletion
You can export or import a backup, erase local data, sign out or permanently delete your account in Profile > Account and backup. After confirmation, deletion targets the Supabase account, backups, private photos, synced data, free-analysis counter and operations, and linked authenticated events. The app also erases its local account data after server confirmation and warns you if technical cleanup cannot be confirmed.
Account deletion does not automatically cancel an App Store or Google Play subscription.
Security
Cloud backups and photos use private account-scoped locations. Observability tables are not accessible to app users and server secrets are not shipped in the public build. No Internet transmission can be guaranteed completely risk-free.
Health and minors
The app is for adults aged 18 or older. Analyses, goals, projections and recommendations are general wellness estimates. Scan Your Food is not a medical device and does not diagnose, treat, cure or prevent any condition. Consult a healthcare professional for medical advice, diagnosis or treatment.
Exercise your rights
For a bug or usage question, please use the Support page instead.