ScanIn is published by TINYANGLESTUDIO (OPC) PRIVATE LIMITED (“TinyAngle Studio”, “we”, “us”), a company registered in India (CIN U62010PN2026OPC255673). This policy explains what ScanIn collects, why, who it goes to, how long we keep it, and how you can get it deleted.
1. Information we collect
a. Account information
- Email address and password — required to create an account and sign in. Passwords are never stored in readable form; they are hashed by our authentication provider and are not visible to us.
- Display name — optional, shown in the app only.
b. Health-related information you choose to enter
During setup, and any time afterwards from your profile, you can select:
- Allergies (for example milk, nuts, egg, gluten)
- Health conditions (for example diabetes, high blood pressure)
- Dietary preferences (for example vegetarian, vegan)
This is the core of what ScanIn does — the app compares a product’s ingredients against these selections to produce your personal risk score. All of these are optional; the app works with none of them selected, it just gives you a more general result. We treat this as sensitive personal data and handle it accordingly.
c. Household members (paid plan)
If you add family members or others you shop for, we store the name, age group, allergies, health conditions and dietary preferences you enter for them. You are responsible for having the right to enter another person’s information, including a child’s. Do not enter more detail than the app asks for.
d. Scan history
When you scan a product we store: the barcode, the product name, the scan type (barcode or label photo), the date and time, the calculated risk score and category, the reasons behind the score, and the ingredient, nutrition, allergen and regulatory details of the product that was scanned. This is what powers your History screen and your daily summary.
e. Camera and photos
- Barcode scanning — the camera preview is processed on your device to read the barcode. The image is not uploaded and not stored.
- Label scanning — when you photograph or choose a picture of an ingredients or nutrition panel, that image is sent over an encrypted connection to our AI text-extraction provider so the text can be read. The image is used only to produce that one result. Neither we nor the provider store the image afterwards, and it is not used to train any AI model. Only the extracted text (product name, ingredients, nutrition values) is saved with your scan.
ScanIn only ever accesses the camera when you open a scanning screen, and only accesses a photo from your gallery when you select it yourself.
f. Country / region
ScanIn reads your device’s region setting (for example “IN” or “DE”) to decide which country’s food-additive rules to check a product against, and stores that country code on your profile. This is a device language and region setting — ScanIn does not request, collect or use GPS or any precise or approximate location. You can override the country yourself using travel mode.
g. Information stored only on your device
Your sign-in token is held in the device’s secure storage. Your recent scans, cached product rules and any scans made while you were offline are stored in the app’s own storage on the device so it works without a connection. Uninstalling the app removes all of this local copy.
h. What we do NOT collect
- No precise or approximate location
- No contacts, calendar, SMS, call logs, files or other apps on your device
- No advertising identifiers, device fingerprints or cross-app tracking
- No payment card details — if paid plans launch, payment is handled entirely by Google Play or Apple, who never give us your card number
2. Why we use it
| What | Why | Legal basis (GDPR / DPDP) |
|---|---|---|
| Email, password | Create and secure your account, sign you in, reset your password | Performance of a contract |
| Allergies, conditions, dietary preferences | Calculate your personal risk score — the whole purpose of the app | Your explicit consent, given when you enter them |
| Scan history | Show your history and daily summary; keep your data in sync across your devices | Performance of a contract |
| Label photo | Read the text on the label so it can be scored | Performance of a contract, at your request |
| Country code | Check the product against the right country’s additive bans and restrictions | Performance of a contract |
| Error and reliability information | Fix crashes and failures | Legitimate interest in a working app |
We do not use your data for advertising, profiling for marketing, or automated decisions that have a legal effect on you. The risk score is nutritional guidance, not a decision about you.
3. Who we share it with
We do not sell your personal data, and we do not share it with advertisers, data brokers or social networks. We use a small number of service providers who process data strictly on our instructions, under contract:
| Provider | What it handles |
|---|---|
| Supabase (database, authentication and file hosting) | Your account, profile, health selections and scan history are stored here on our behalf. |
| Anthropic (AI label reading) | Receives a label photo only when you take a label scan, purely to extract the text. Not stored, not used for model training. |
| Open Food Facts (open product database) | Looked up by our server using only the barcode, to fetch public product information. No personal data, and no information identifying you or your device, is sent to it. |
| Google Play / Apple App Store | Distribution, and payments if you buy a paid plan. Their own privacy policies apply. |
We may also disclose information where we are legally required to, or to establish or defend legal claims. If TinyAngle Studio is ever acquired or merged, data may transfer to the successor entity, which will remain bound by this policy or one no less protective; we will tell you first.
4. International transfers
We are based in India. Our service providers may store or process data on servers outside your country, including in the United States and the European Union. Where data leaves the EU/UK we rely on the European Commission’s Standard Contractual Clauses with those providers. Whichever country it sits in, the protections in this policy still apply.
5. How long we keep it
- Account and profile — for as long as your account exists.
- Scan history — for as long as your account exists, unless you delete individual scans.
- Label photos — not retained; discarded as soon as the text has been read.
- After you delete your account — removed from our live systems within 30 days, and from encrypted backups within 90 days. We keep nothing except what the law requires us to keep (for example a record of a purchase for tax purposes).
6. Your rights, and how to delete your data
You can, at any time:
- See and change your health, allergy and dietary selections in the app’s Profile screen
- Delete individual scans from your History
- Ask for a copy of your data
- Correct anything that is wrong
- Withdraw your consent for us to hold your health selections (this stops personalised scoring)
- Ask us to delete your account and all data in it
- Complain to your data protection authority — in India, the Data Protection Board; in the EU/UK, your national supervisory authority; elsewhere, the privacy regulator for where you live
These rights are given to you under India’s Digital Personal Data Protection Act 2023 and, where they apply to you, the EU/UK GDPR, US state privacy laws such as the California Consumer Privacy Act, and the privacy law of the country you live in. We give everyone the same rights regardless of where they live. We do not sell or share personal information for advertising, and we do not discriminate against anyone for exercising a privacy right. We answer any request within 30 days and we do not charge for it.
7. Children
ScanIn is not directed at children and is not intended for anyone under 18 to use on their own. We do not knowingly create accounts for children. A parent or guardian may add a child as a household member on their own account. If you believe a child has created an account, contact us and we will remove it.
8. Security
All traffic between the app and our servers is encrypted with HTTPS/TLS. Data is encrypted at rest by our hosting provider. Your session token is kept in your device’s secure keystore. Access to the database is restricted per user by row-level security rules, so one account cannot read another’s data, and staff access to production data is limited and logged. No system is perfectly secure, but if a breach ever affects your personal data we will notify you and the relevant authority as the law requires.
9. Not medical advice
10. Changes to this policy
If we change this policy we will update the date at the top, and for anything significant we will tell you in the app before the change takes effect. Continuing to use ScanIn after that means you accept the updated policy.
11. Contact us
TINYANGLESTUDIO (OPC) PRIVATE LIMITED
Ashira B 704, Siddhashila EELA, Punawale,
Pune City, Pune 411033, Maharashtra, India
CIN: U62010PN2026OPC255673
Privacy and data requests: support@tinyanglestudio.com
Website: www.tinyanglestudio.com
We are the data controller (data fiduciary) for the information described here. We have not appointed a Data Protection Officer, as we are not required to; write to the address above for any privacy matter.