Product Decoded (“we”, “us”) helps you scan and understand packaged food products. This policy explains what we collect, why, and your rights.
You give us:
Created as you use the app:
Collected automatically:
We do not sell your personal data, and we do not use it for advertising.
We share the minimum needed with providers acting on our behalf. None of them may use your data for their own purposes.
| Provider | What they receive | Why | Where |
|---|---|---|---|
| Amazon Web Services (AWS) | Everything stored by the service: the database (RDS) and product photos (S3) | Hosting and storage | EU — eu-west-1 (Ireland) |
| Anthropic | The label photos you submit and the text extracted from them, when you add a product. No account identifier is sent. | Reading the label (ingredients, nutrition, serving) with an AI model | US. Anthropic does not train its models on API data; inputs are retained per Anthropic's API data policy. |
| Resend | Your email address and the content of transactional emails (password-reset codes, security notices) | Sending email | US |
| Expo (push service) | Your device push token and the content of each alert | Delivering push notifications you enabled | US |
| Sentry | Error reports and technical context (app version, device model, OS). Configured not to send personal identifiers. | Crash/error diagnostics | US |
| Only if you choose Sign in with Google: Google learns that you signed in to Product Decoded; we receive your Google email, identifier and name | Sign-in | US | |
| RevenueCat | Your Product Decoded user number and purchase/entitlement state from the app stores | Subscription status | US |
| Apple App Store / Google Play | Purchase and payment details (handled entirely by the store; we never see your card) | Subscription purchases | Per store |
| Open Food Facts | The barcode you scan — no account identity | Public product data lookup | France |
Push notifications go through Expo's push service (which in turn uses Apple's and Google's device notification channels).
Some providers process data outside the EEA (United States). Where they do, transfers rely on Standard Contractual Clauses or the EU-US Data Privacy Framework, as applicable per provider.
We keep account data while your account exists. Sign-in sessions and password-reset codes expire and are removed automatically. Photos uploaded to a product that is already published are held as pending and not shown publicly until an administrator approves them. Diagnostics are retained for a limited period by Sentry. Anthropic retains label inputs per its API data policy.
Use Account → Delete account in the app, or email us. Because deletion is irreversible, the app asks you to re-authenticate first: your password for email accounts, or a fresh Google sign-in for Google accounts.
Deleted permanently: your account and email, password hash, sessions, scan history, saved products, ingredient/additive flags, alert preferences and alert history, push tokens, AI-usage counts tied to you, and every photo you uploaded (the stored file and its record).
Kept, but de-linked from you: product data you submitted stays in the shared catalog with no link to your account (it is a contribution to a public catalog); product reports you filed are kept for catalog quality with the link to you and your free-text note removed.
Copies held by processors (e.g. an email already delivered, an error report already sent to Sentry, label inputs held by Anthropic) expire on those providers' retention schedules.
Under the GDPR you can access, correct, delete, restrict, or port your data, and object to certain processing.
You may also complain to the Spanish DPA (AEPD, www.aepd.es) or your local supervisory authority.
If you live in California, Virginia, Colorado, Connecticut, Utah or another US state with a consumer-privacy law, you have the following rights, which we extend to every US user:
How to exercise these rights: use the in-app controls above, or email privacy@productdecoded.app from the address on your account (we verify requests by matching that address, or by a code sent to it). An authorised agent may submit a request on your behalf with your written permission. We respond within 45 days (extendable once by a further 45 days where permitted, with notice).
Non-discrimination: we will not deny service, charge a different price or provide a different level of quality because you exercised any of these rights.
Appeals: if we decline a request, reply to our decision and we will review it within 45 days; if you are still unsatisfied you may contact your state attorney general.
Passwords are hashed with bcrypt; traffic is encrypted in transit (TLS); stored data and photos are encrypted at rest; every administrative action is logged. No system is perfectly secure, but we take reasonable measures to protect your data.
Product Decoded is not directed to children under 16 in the EEA or under 13 in the United States, and we do not knowingly collect their data. If you believe a child has given us personal data, email us and we will delete it.
We may update this policy; material changes will be notified in-app or by email.
Product Decoded provides label-based information and is not medical or dietary advice. The ingredient alert feature is not an allergen or medical safety tool. See the Terms of Service.