Skip to main content
葉VegiSearchvegisearch
HomePrivacyTermsDelete Account中文

Privacy Policy

Privacy Policy

This policy explains how VegiSearch handles information across our website and app during the current invited dual-platform testing phase.

Public DraftLast updated: 2026-09-26
Current Status: This policy applies to the current "Invited Dual-Platform Testing Phase" (Android Google Play Internal Testing and iOS TestFlight). Test builds are open to invited testers to evaluate barcode recognition, offline cache, dietary preferences, and cloud sync.

1. Scope

This policy applies to the VegiSearch website and mobile app. Third-party sites, stores, or services operate under their own policies and are not controlled by VegiSearch.

2. Information We May Process

Official Website

The Phase 0 website is static and has no product-level member login, behavioral tracking analytics, comment forms, or database submission. Hosting, DNS/CDN, or email-delivery providers may still process IP address, timestamps, browser, or request metadata for security and transmission; this should not be read as a promise that the website creates no network records. If you contact us by email, we receive the message content, sender address, and technical transmission metadata necessary for delivery.

VegiSearch Mobile App

  • Camera Permission: Used exclusively for real-time EAN/UPC barcode recognition; video streams and photos are never saved, recorded, or transmitted to remote servers.
  • Local Storage: In guest mode or when sync is disabled, dietary preferences and scan history remain entirely on your device in a local SQLite (Drift) database.
  • Account & Auth: When registering via Email, Google Sign-In, or Sign in with Apple, we process email, verification status, display name, and hashed credentials needed for secure session maintenance. We never request sensitive access to Gmail, Google Drive, etc.
  • Explicit Opt-in Sync: Dietary preferences (including alcohol preferences and result-notice display settings) and scan history are transmitted to our servers only after you explicitly opt in within the app. Logging in does not automatically enable sync. These preferences may reveal information about religion, health, or lifestyle and are kept separate from product-improvement telemetry.

No Packaging Photo or Camera Stream Collection via App: VegiSearch focuses on barcode database lookup. The app does not provide camera photo OCR or package image uploads, and does not collect or store product packaging photos, photo library images, or camera streams via the app. Past plans for ingredient photo OCR and unknown-product OCR intake have been abolished, and no packaging photo or OCR candidate data is created or retained. (Voluntary tester feedback with screenshots submitted through test distribution platforms is handled under Section 4 and is not collected by the app.)

App Scan and UX Telemetry (Explicit Opt-in)

The app's “Help improve VegiSearch” switch is off by default and controls both scan metrics and UX telemetry. Only after you explicitly enable it may the app send allowlisted scan hits or misses, valid barcodes, operation timing, performance, or recognition metrics. Each Layer 3 event may include a UUIDv4 session identifier rotated within 24 hours. The app does not put account tokens, email, camera images, dietary preferences, or alcohol preferences into this telemetry. Barcodes, timestamps, and short-lived identifiers may still become linkable with network or service metadata (such as IP address, request time, and headers), so we do not describe this data as “zero personal data” or “fully anonymous.”

You can turn the switch off at any time. The app then stops future reporting and clears events not yet sent; data already received by the server is not automatically erased by the device switch and remains subject to the retention, deletion, and access-control policy. This switch is separate from the consent to sync preferences and scan history.

3. Purpose of Processing

  • Providing product lookup, personalized assessments, and account services.
  • Verifying identity, maintaining sessions, security auditing, and abuse prevention.
  • Responding to customer support, announcements, and account deletion requests.
  • Maintaining, debugging, and improving product catalog accuracy and service uptime.
  • Complying with applicable legal obligations and regulatory requirements.

4. Third-Party Services

Website hosting and DNS/CDN are provided by Cloudflare. Email delivery is managed by domain mail routing and email infrastructure. Test builds are distributed through Google Play Internal Testing and Apple TestFlight; those platforms may process tester device data, crash diagnostics, and feedback under their own terms and privacy policies. Feedback you submit through those platforms (including text and screenshots) and crash diagnostics may be provided to us; we process them under this policy for service maintenance and improvement. Each platform is an independent controller for the personal data it processes in its platform services. We do not sell, rent, or trade your personal data. Google Sign-In and Apple Sign-In are currently available only to invited test accounts, and platform availability depends on activation notices. The Apple Sign-In backend and both the Android and iOS clients have been implemented, and the production host rollout was completed on 2026-09-18, but this remains invite-only validation — device and operational acceptance are still pending, and it is not a public service. When these sign-in methods are used, their data handling is also governed by the providers’ terms and privacy policies. VegiSearch never requests extraneous permissions like Gmail or Google Drive. The service does not provide OCR capabilities and does not engage external image OCR processors.

5. Retention & Deletion

Data is retained only as long as necessary to fulfill services, maintain security, and satisfy legal requirements. Upon account deletion, identifiable user data is deleted or de-identified within 30 days; encrypted backups are rotated out within 90 days.

For opted-in app telemetry, Layer 3 UX events are retained for at most 90 days and Layer 1 aggregated scan statistics for at most 365 days. The primary database runs the fixed-floor batch purge functions from the daily vegisearch-auth-maintenance.timer; the maintenance job fails closed if its post-purge overdue-data assertion fails. These telemetry records are not automatically erased by the in-app consent switch and remain subject to the retention and deletion policy; the standby host keeps this maintenance timer disabled.

Security-audit exception: Login, logout, token-revocation, and account-status events are written to append-only audit records. The current maintenance job sets an audit row's session_id to NULL before an expired or revoked session is removed, which breaks the session link; it does not currently purge the audit row itself. We retain only the minimum fields for security operations, disputes, and legal obligations for the necessary period. These audit records are not covered by the 90-day Layer 3, 365-day Layer 1, or 30-day account-linked scan-history purge windows.

You may submit requests per our Account Deletion Instructions.

6. Security

We implement technical and organizational measures appropriate to risk levels, including HTTPS, least privilege, password hashing, opaque session tokens, security audits, and backups.

7. Your Rights

You may request access to, correction of, or deletion of your personal data, or revoke non-essential consent at any time. Some requests may require reasonable identity verification to protect your account.

8. Children

VegiSearch is not intended for children. We do not knowingly collect personal data from minors below the legally required age.

9. Updates

We update this policy when features, providers, or laws change. Material changes will be notified reasonably.

10. Contact Us

For privacy inquiries, please write to support@vegisearch.com. Please do not send passwords, one-time codes, access tokens, or full payment details by email.

葉VegiSearchvegisearch

Let every choice come with a little more understanding.

About FounderPrivacy PolicyTerms of ServiceAccount Deletionsupport@vegisearch.com
© 2026 VegiSearch. Site information currently reflects the invited dual-platform testing phase.