ScanIn — Privacy Policy

Effective date: 2 August 2026 · Version 1.0
Applies to the ScanIn mobile application (Android and iOS), package com.scanin.app.

ScanIn is published by TINYANGLESTUDIO (OPC) PRIVATE LIMITED (“TinyAngle Studio”, “we”, “us”), a company registered in India (CIN U62010PN2026OPC255673). This policy explains what ScanIn collects, why, who it goes to, how long we keep it, and how you can get it deleted.

The short version. ScanIn stores your email, the health and diet choices you pick during setup, and your scan history — so it can tell you whether a food product is risky for you. We do not sell your data, we do not show ads, we do not track you across other apps or websites, and we do not use any advertising or analytics SDKs. You can ask us to delete your account and everything in it at any time.

1. Information we collect

a. Account information

b. Health-related information you choose to enter

During setup, and any time afterwards from your profile, you can select:

This is the core of what ScanIn does — the app compares a product’s ingredients against these selections to produce your personal risk score. All of these are optional; the app works with none of them selected, it just gives you a more general result. We treat this as sensitive personal data and handle it accordingly.

c. Household members (paid plan)

If you add family members or others you shop for, we store the name, age group, allergies, health conditions and dietary preferences you enter for them. You are responsible for having the right to enter another person’s information, including a child’s. Do not enter more detail than the app asks for.

d. Scan history

When you scan a product we store: the barcode, the product name, the scan type (barcode or label photo), the date and time, the calculated risk score and category, the reasons behind the score, and the ingredient, nutrition, allergen and regulatory details of the product that was scanned. This is what powers your History screen and your daily summary.

e. Camera and photos

ScanIn only ever accesses the camera when you open a scanning screen, and only accesses a photo from your gallery when you select it yourself.

f. Country / region

ScanIn reads your device’s region setting (for example “IN” or “DE”) to decide which country’s food-additive rules to check a product against, and stores that country code on your profile. This is a device language and region setting — ScanIn does not request, collect or use GPS or any precise or approximate location. You can override the country yourself using travel mode.

g. Information stored only on your device

Your sign-in token is held in the device’s secure storage. Your recent scans, cached product rules and any scans made while you were offline are stored in the app’s own storage on the device so it works without a connection. Uninstalling the app removes all of this local copy.

h. What we do NOT collect

2. Why we use it

WhatWhyLegal basis (GDPR / DPDP)
Email, passwordCreate and secure your account, sign you in, reset your passwordPerformance of a contract
Allergies, conditions, dietary preferencesCalculate your personal risk score — the whole purpose of the appYour explicit consent, given when you enter them
Scan historyShow your history and daily summary; keep your data in sync across your devicesPerformance of a contract
Label photoRead the text on the label so it can be scoredPerformance of a contract, at your request
Country codeCheck the product against the right country’s additive bans and restrictionsPerformance of a contract
Error and reliability informationFix crashes and failuresLegitimate interest in a working app

We do not use your data for advertising, profiling for marketing, or automated decisions that have a legal effect on you. The risk score is nutritional guidance, not a decision about you.

3. Who we share it with

We do not sell your personal data, and we do not share it with advertisers, data brokers or social networks. We use a small number of service providers who process data strictly on our instructions, under contract:

ProviderWhat it handles
Supabase (database, authentication and file hosting)Your account, profile, health selections and scan history are stored here on our behalf.
Anthropic (AI label reading)Receives a label photo only when you take a label scan, purely to extract the text. Not stored, not used for model training.
Open Food Facts (open product database)Looked up by our server using only the barcode, to fetch public product information. No personal data, and no information identifying you or your device, is sent to it.
Google Play / Apple App StoreDistribution, and payments if you buy a paid plan. Their own privacy policies apply.

We may also disclose information where we are legally required to, or to establish or defend legal claims. If TinyAngle Studio is ever acquired or merged, data may transfer to the successor entity, which will remain bound by this policy or one no less protective; we will tell you first.

4. International transfers

We are based in India. Our service providers may store or process data on servers outside your country, including in the United States and the European Union. Where data leaves the EU/UK we rely on the European Commission’s Standard Contractual Clauses with those providers. Whichever country it sits in, the protections in this policy still apply.

5. How long we keep it

6. Your rights, and how to delete your data

You can, at any time:

To delete your account and all your data: email support@tinyanglestudio.com from the email address you signed up with, with the subject “ScanIn account deletion”. We confirm within 7 days and complete the deletion within 30 days. Deletion removes your account, profile, health selections, household members and full scan history. It is permanent and cannot be undone.

These rights are given to you under India’s Digital Personal Data Protection Act 2023 and, where they apply to you, the EU/UK GDPR, US state privacy laws such as the California Consumer Privacy Act, and the privacy law of the country you live in. We give everyone the same rights regardless of where they live. We do not sell or share personal information for advertising, and we do not discriminate against anyone for exercising a privacy right. We answer any request within 30 days and we do not charge for it.

7. Children

ScanIn is not directed at children and is not intended for anyone under 18 to use on their own. We do not knowingly create accounts for children. A parent or guardian may add a child as a household member on their own account. If you believe a child has created an account, contact us and we will remove it.

8. Security

All traffic between the app and our servers is encrypted with HTTPS/TLS. Data is encrypted at rest by our hosting provider. Your session token is kept in your device’s secure keystore. Access to the database is restricted per user by row-level security rules, so one account cannot read another’s data, and staff access to production data is limited and logged. No system is perfectly secure, but if a breach ever affects your personal data we will notify you and the relevant authority as the law requires.

9. Not medical advice

ScanIn gives general nutritional and food-safety information based on product data and the preferences you enter. It is not medical advice, not a diagnosis, and not a substitute for a doctor, dietitian or allergist. Product data can be incomplete, out of date or wrong, and label reading is not perfect. If you have a serious allergy or medical condition, always read the physical label on the packaging and follow your clinician’s advice. Never rely on ScanIn alone to decide whether a food is safe for you.

10. Changes to this policy

If we change this policy we will update the date at the top, and for anything significant we will tell you in the app before the change takes effect. Continuing to use ScanIn after that means you accept the updated policy.

11. Contact us

TINYANGLESTUDIO (OPC) PRIVATE LIMITED
Ashira B 704, Siddhashila EELA, Punawale,
Pune City, Pune 411033, Maharashtra, India
CIN: U62010PN2026OPC255673
Privacy and data requests: support@tinyanglestudio.com
Website: www.tinyanglestudio.com

We are the data controller (data fiduciary) for the information described here. We have not appointed a Data Protection Officer, as we are not required to; write to the address above for any privacy matter.