01Plain-language summary
We take pictures of product labels with your camera, extract the text on your device, and match the ingredients against public databases. Your profile (skin type, allergens, diet, avoid list) stays on your device. We don't sell your data, we don't share it with brands, and we don't tie analytics back to your identity. If you want it gone, we delete it on request.
This Privacy Policy explains what data Ingreview ("we", "us") collects when you use our mobile apps and website ("the Service"), why we collect it, and what you can do about it. It is written to satisfy the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act / CPRA, the UK Data Protection Act, and similar frameworks worldwide.
02Who we are
The data controller for the Service is Ingreview Labs Ltd., a private company registered in the United Kingdom. Our registered office, EU representative (per GDPR Art. 27), and Data Protection Officer can be reached at privacy@ingreview.app.
03What we collect
We try to collect as little as possible. Below is the complete list.
Information you give us
| Category | Examples | Where stored |
|---|---|---|
| Profile | Skin type, food allergens, diet, avoid-list, life-stage modes | On your device (encrypted) |
| Account | Email, display name (only if you create an account) | Our servers (encrypted at rest) |
| Scans | Photos of product labels, OCR text, your edits | On your device by default. Optional cloud sync. |
| Ratings & reports | Star ratings, sensitivity tags, optional review text | Our servers — your user ID is replaced with a rotating anonymous token before aggregation |
Information collected automatically
- Device data: OS version, app version, language, time-zone — used to keep the app working and route the right content.
- Crash & performance: Anonymous crash reports via on-device aggregation. No PII attached.
- Aggregate scan counts: "Product X was scanned 412 times this week" — never tied to a user.
What we do not collect
- Contacts, photos from your camera roll (except ones you explicitly pick), microphone, location, calendar, health records.
- Third-party tracking IDs, advertising identifiers, fingerprints.
- Behavior outside the app.
04Why we use it
We use each category of data only for the purpose listed below, on the lawful basis stated.
| Purpose | Lawful basis (GDPR) |
|---|---|
| Read your label photos and return ingredient analysis | Contract performance |
| Personalize results against your profile | Contract performance |
| Improve our ingredient dictionary (aggregated only) | Legitimate interest |
| Fix crashes and bugs | Legitimate interest |
| Send the optional weekly digest | Consent (you can revoke any time) |
| Bill Premium subscriptions | Contract performance · legal obligation |
05Who we share with
We don't sell your data and we don't share it with brands or advertisers. Period. We do share with the following processors, each bound by a Data Processing Agreement (GDPR Art. 28):
- Apple & Google — to deliver the app via the App Store and Play Store, and to bill subscriptions.
- Supabase (United States, EU servers) — encrypted database hosting for accounts and aggregate signals.
- Crash-reporting (Sentry) — anonymous crash traces.
We also disclose data when legally required (subpoena, court order). We publish a transparency report annually.
06Where it lives & how long
- On your device. Profile, scan photos, and history live on your phone until you delete them or uninstall the app.
- On our servers. Account email and Premium status are retained while your account is active, then deleted within 30 days of cancellation. Aggregated, anonymous ratings persist indefinitely.
- Backups. Encrypted backups expire after 90 days.
07Your rights
You can exercise any of the rights below by emailing privacy@ingreview.app or via Settings → Privacy & data in the app.
- Access — receive a copy of everything we hold tied to your account.
- Rectification — fix anything that's wrong.
- Erasure — delete your account and all associated data.
- Portability — export your scan history as JSON.
- Object — tell us to stop processing for any legitimate-interest purpose.
- Restriction — freeze processing pending a dispute.
- Withdraw consent — turn off the digest or revoke any consent at any time.
- Lodge a complaint — with your local data protection authority. EU residents can reach the ICO (UK) or any EU supervisory authority.
California residents: under the CCPA / CPRA, you also have the right to know, delete, correct, and opt out of "sharing" — which we do not do, but the right exists anyway.
08Children
Ingreview is rated 4+ on the App Store and PEGI 3 on Google Play. We do not knowingly collect data from children under 13 (or under 16 in the EU). Baby and Toddler safety modes in our app are designed for parents and caregivers to use — not for children to operate directly. If you believe a child has created an account, email privacy@ingreview.app and we will delete it.
09International transfers
If you are in the EU/EEA or UK, your data is processed in the EU. Aggregated, anonymous data may be processed in the United States via Standard Contractual Clauses (SCCs) and supplementary measures per the EDPB's recommendations.
10Changes to this policy
If we make a material change, we'll notify you in-app and by email (if you have an account) at least 14 days before it takes effect. Older versions are archived and available on request.
11Contact
Ingreview Labs Ltd.
Privacy team: privacy@ingreview.app
Legal team: legal@ingreview.app
Postal address & EU representative on request.