Privacy Policy — Halal Scanner
Effective date: September 2026
Last updated: September 2026
1. Introduction
Halal Scanner ("we", "us", "our") is an iOS app that analyses packaged food products to indicate whether they are halal, along with a health score, diabetic suitability, and allergen information. This policy explains what data the app handles, why, and what control you have over it.
There is no sign-up. Halal Scanner has no user accounts, so we never ask for your name, email address, or date of birth, and nothing you scan is tied to a personal profile.
By using Halal Scanner, you agree to the practices described here.
2. Information we handle
2.1 Device identifier
The app generates a per-installation device identifier and sends it to our backend so we can track how many free scans that installation has left and whether it has an active subscription. It is not your advertising identifier, it is not linked to your name or email, and it is reset when you delete and reinstall the app.
2.2 Photos you scan
- What is sent: the photo you take of a product's ingredient list, or of the product itself.
- Where it goes: to our backend, which forwards it to a third-party AI model provider (OpenRouter) that reads the ingredient text and returns the analysis.
- What it is used for: producing the analysis you requested — nothing else. Your photos are not used for advertising or profiling.
- Retention: photos are processed for the request and are not kept as a photo library on our servers afterwards. The AI provider processes them transiently under its own retention policy.
- No face processing. The app does not detect, scan, map, or recognise faces, and creates no biometric identifier of any kind. Photograph a product label, not a person.
The app requests camera access to scan barcodes and labels, and photo library access only if you choose an existing image instead of taking a new one. Both permissions are asked for at the moment you first use the corresponding feature, and both can be revoked in iOS Settings.
2.3 Barcodes you scan
When you scan a barcode, the number is looked up in Open Food Facts, a public open-data product database, to retrieve the product name, brand, ingredient text, and nutrition data. Only the barcode number is sent — no device identifier and no photo.
2.4 Scan results and history
Your scanned products, their analyses, and your favourites are stored on your device. Scan records are also written to our backend database so we can count usage against your free-scan allowance and diagnose failures; these records are keyed to the device identifier, not to you.
2.5 Preferences you set
During onboarding the app asks whether you are diabetic and whether you have allergies, so results can be tailored. These answers are stored on your device and included in the analysis request so the AI can flag what is relevant to you. They are not sold, shared for advertising, or used to build a health profile.
2.6 Usage analytics
We use Firebase Analytics and Mixpanel to understand how the app is used — which screens are opened, which scan type is chosen, where people drop off. Events are associated with the device identifier, never with a name or email address. We do not log the contents of your scans into analytics.
2.7 Advertising attribution
The app includes the TikTok Business SDK, which reports install and purchase events so we can measure whether an advertising campaign worked. It receives event data and device-level advertising signals permitted by iOS. If you decline App Tracking Transparency when prompted, tracking identifiers are not shared.
2.8 Purchases
Subscriptions are sold by Apple and managed through RevenueCat, which receives the device identifier, product identifiers, and transaction identifiers so PRO can be unlocked and restored. We never see or store your card or billing details — Apple handles all payment processing.
2.9 Technical data
Our backend logs standard request data — IP address, timestamp, endpoint, app version, and device model — for security, rate limiting, and debugging.
3. Why we use it
| Purpose | Legal basis |
|---|---|
| Analysing the products you scan | Contract performance |
| Counting free scans and unlocking PRO | Contract performance |
| Tailoring results to diabetic or allergy preferences | Consent |
| Preventing abuse and rate-limiting the API | Legitimate interest |
| Analytics to improve the app | Legitimate interest |
| Advertising attribution | Consent (App Tracking Transparency) |
| Responding to support requests | Legitimate interest |
| Legal compliance | Legal obligation |
4. Who we share it with
We share data only as needed to operate the service:
| Recipient | What is shared | Why |
|---|---|---|
| OpenRouter (openrouter.ai) | Scanned photo or ingredient text, language, dietary preferences | AI ingredient analysis |
| Open Food Facts (openfoodfacts.org) | The barcode number only | Product lookup |
| Google Cloud | API request data, backend hosting | Infrastructure |
| Firebase (Google) | Device identifier, scan records, analytics events | Database and analytics |
| Mixpanel (mixpanel.com) | Anonymous usage events | Product analytics |
| RevenueCat (revenuecat.com) | Device identifier, purchases | Subscription management |
| TikTok (business SDK) | Install and purchase events, permitted ad identifiers | Advertising attribution |
We do not sell your personal information to any third party.
We may disclose information where required by law, court order, or to protect the rights and safety of our users.
5. How long we keep it
| Data | Retention |
|---|---|
| Scan history and favourites on your device | Until you delete them or remove the app |
| Scanned photos | Not retained after the analysis request completes |
| Scan records on our backend | Kept while the installation is active, for scan accounting |
| Device and subscription records | Until the installation is removed or you request deletion |
| API request logs | 30 days |
| Analytics data | Up to 2 years, per Firebase and Mixpanel defaults |
| Purchase records | As required for financial and tax record-keeping |
6. Your rights
- Deletion on device: delete individual products, several at once, or the whole app — everything stored locally goes with it.
- Deletion on our side: email us and we will delete the backend records associated with your device identifier. Because there is no account, please send the request from the app (Profile → Contact Developer) or tell us the approximate install date and last scan so we can locate the right record.
- Access and portability: request a copy of the data we hold against your device identifier.
- Withdraw consent: revoke camera or photo access in iOS Settings, and disable ad tracking under Settings → Privacy & Security → Tracking.
- Object: ask us to stop processing your data for analytics.
To exercise any of these, contact [email protected].
7. Children's privacy
Halal Scanner is not directed at children under 13 and we do not knowingly collect personal information from them. If you believe a child has provided us with personal information, contact us and we will delete it.
8. International transfers
Our providers (Google Cloud, Firebase, OpenRouter, Mixpanel, RevenueCat, TikTok) may process data outside your country. Where required, we rely on Standard Contractual Clauses or equivalent safeguards.
9. Security
- HTTPS/TLS for all data in transit
- API key authentication and rate limiting on all backend endpoints
- Secrets held in Google Secret Manager, never in source code
- No passwords to steal — the app has no accounts
No method of transmission over the internet is completely secure, and we cannot guarantee absolute security.
10. Changes to this policy
We may update this policy from time to time. Material changes will be signalled by an in-app notice or by updating the "Last updated" date above. Continued use after a change constitutes acceptance.
11. Contact
Email: [email protected]
App: Halal Scanner — available on the Apple App Store
This Privacy Policy covers the Halal Scanner iOS app as of the effective date above.