Privacy policy
SafeFood has no accounts and collects almost nothing. Here is all of it.
Last updated: 2026-09-08
14Past3 d.o.o. operates SafeFood and is responsible for the processing described here. This policy covers the SafeFood iPhone app and this website.
The short version
- No account is needed. The app does not ask for your name, email address or health condition. If you contact support, we receive what you send us.
- Label photos go to our server and a third-party AI service to be read. We do not save scan photos or label text on our servers. The AI provider's separate retention is explained below.
- Your scan history stays on your phone. We store installation and subscription records, and limited operational figures about scans.
- No advertising or tracking across apps. The app has no advertising, attribution or analytics SDK. This website uses cookieless measurement.
- We do not sell personal data.
Label photographs and readings
When you request a scan, your selected photographs pass through our server, which is hosted by Vercel, to Google Ireland Limited / Google LLC (Gemini API). The AI transcribes the printed text and identifies declared ingredients. The photographs, label text and result are processed to return the reading to your phone; we do not save them in our database or include them in our scan logs.
Google's applicable Gemini API data terms state that inputs and outputs are not used to train its models. Google retains prompts and generated outputs for 55 days for abuse monitoring, security and required legal or regulatory disclosures. Authorised Google personnel may review content flagged by its safety systems. This includes the photographs and text sent for a reading. See Google's data terms and abuse-monitoring policy.
A label photograph or a gluten or milk reading, in context, may reveal health information. We therefore handle it as potentially special category data and rely on your explicit consent under Articles 6(1)(a) and 9(2)(a) GDPR. The app asks before scanning. You can withdraw consent in Settings; scanning stops until you consent again. Withdrawal does not undo earlier lawful processing or automatically delete your local history.
We do not ask for a health condition, create a dietary profile or personalise the reading to your health. The same reading rules apply to everyone. Please photograph the label only, avoiding faces, addresses and other personal details.
Installation, usage and security records
The app creates a random installation identifier and stores it in the iOS Keychain. It is not derived from your Apple Account or advertising identifier. It is pseudonymous, not anonymous: it connects the installation's scan allowance, security credentials and subscription status. You can find it in Settings and provide it when asking us for help or deletion.
The identifier can survive deleting and reinstalling the app. Reinstalling does not necessarily create a new identity or reset your allowance.
We store monthly and lifetime scan counts, counts of unresolved readings, creation and last-use times, app version and cached Pro entitlement. App Attest public keys and verification counters help us check that requests come from the genuine app. Short-lived challenges prevent replay. Our rate limiter briefly stores the installation identifier or IP address with request times so automated abuse does not prevent others from scanning.
These records support the service and subscription you request (Article 6(1)(b) GDPR). Security and abuse prevention also serve our legitimate interests in protecting the service (Article 6(1)(f)). They are not used for advertising or to infer a health condition.
Scan quality and error records
For each scan, we keep technical information such as the app, model and prompt versions, requested language, photo count and size, duration, list completeness, legibility, finding states and issue or error codes. These records contain no photographs, ingredient text, product names or installation identifiers. We use them to diagnose failures and assess how the reader performs.
A random reference identifies that request. If you send the reference to support, we can connect your message to that record. It is not reused across scans. Records expire automatically after 90 days. Our basis for operational diagnostics is our legitimate interest in maintaining the service; where information is treated as health data, the explicit consent described above also applies.
Purchases
Apple handles App Store payments. We do not receive your payment card details. RevenueCat receives the installation identifier, purchase and subscription history, and technical information needed to operate its SDK, and tells our server whether Pro is active. Apple and RevenueCat can therefore associate purchase records with the installation. We use this to provide, restore and manage subscription access, on the basis of our contract with you. RevenueCat also provides reports on trials, renewals and subscription performance, which we use to understand the business based on our legitimate interests.
Support
If you email us, we receive your email address, message and any attachments, installation identifier or error reference you choose to include. We use these to answer you and investigate the issue. Sending a photograph to support is separate from scanning: that attachment is retained with your correspondence. We request permission before adding an identifiable support photograph to a reusable test set. We handle support on the basis of our legitimate interest in helping users, and use consent where health information requires it.
Service providers and international processing
- Google Ireland Limited / Google LLC (Gemini API): processes scan photographs and text as described above, under the applicable Gemini API and data-processing terms.
- Vercel Inc.: hosts the API and website; processes request data, including scan uploads in transit through the API, network metadata and service logs. It also provides the website measurement described below.
- MongoDB Atlas: stores installation, quota, security and scan-quality records. It does not store scan photographs, label text or product names.
- RevenueCat, Inc.: manages subscription records and access checks.
- Apple: distributes the app, processes purchases and provides App Attest under Apple's terms and privacy information.
Providers may process data outside the EEA, including in the United States. Where required, transfers rely on applicable adequacy decisions or standard contractual clauses in the providers' data-processing terms. You can contact us for information about the safeguards that apply. We do not promise that Gemini API processing remains within the EU.
Retention and deletion
- Scan photos and text: not saved on our servers. Google's 55-day monitoring retention is described above. Copies you send to support are handled as support correspondence.
- Local history: the app keeps your most recent readings and photos on your phone and prunes older ones. Use Clear history in Settings to delete them. Deleting the app removes its local history, but not necessarily its Keychain identifier or any backup you control.
- Scan-quality records: 90 days, with automatic expiry.
- Rate-limit records: expire about two minutes after the latest request; database expiry runs periodically. App Attest challenges are short-lived and are deleted on use or expiry.
- Installation, quota and App Attest key records: remain until deleted; resetting a monthly allowance does not erase the installation record. Deleting the app does not notify our server. Contact us with the identifier in Settings to request deletion of the associated records.
- Purchase records: Apple and RevenueCat retain records under their respective terms for subscriptions, restoration and legal obligations. We help direct or carry out applicable deletion requests.
- Support correspondence: retained while needed to resolve your request and any related dispute or legal obligation. You may request deletion.
Deleting data or the app does not cancel an Apple subscription. Manage or cancel it in your Apple Account subscription settings.
This website
This public site has no account login, advertising trackers or social-media trackers. Vercel Web Analytics and Speed Insights measure page visits and performance without analytics cookies. Measurements can include the page, referrer, browser/device characteristics, approximate country and timing. Vercel processes request metadata to produce these measurements; cookieless does not mean that no data is processed. We use this information to understand and maintain the website, based on our legitimate interests.
Your rights
Depending on the applicable law, you can request access, correction, erasure, restriction or portability, object to processing based on legitimate interests, and withdraw consent. Email support@safefoodscanner.com. Include the installation identifier from Settings when your request concerns app records; we do not need your Apple password or payment card details.
We respond to GDPR requests within one month, subject to the extensions the law permits. If a record cannot be identified, we will explain the limitation. You can complain to the Slovenian Information Commissioner or your local supervisory authority. Our separate Consumer Health Data Privacy Policy explains additional rights where those laws apply.
Age and regional access
SafeFood is available only to adults aged 18 and over. We do not offer the app to anyone under 18, including with parental permission. The age check runs before AI consent, scanning or subscription access.
On supported devices, the app asks Apple for a declared age range. It uses that information on the phone to check adult eligibility. Where Apple's age service is unavailable and not required, the app checks a date of birth on the phone instead. A refusal to share with Apple or an age range that does not confirm adulthood does not offer this alternative. We do not receive a birth date or the age range. The app remembers the successful check locally and sends only an adult-access confirmation with a scan request; we do not store that confirmation in the database or send it to the AI provider. For a birth date entered as under 18, the phone retains the date on which access becomes eligible to prevent immediate repeated attempts. No birth date is retained after a successful check. These are declarations, not identity verification.
Our hosting service infers a country from your connection's IP address to check regional availability before processing a scan or starting a purchase. We do not request GPS or location permission, and we do not store a country history in the SafeFood database or send the country to the AI provider. These checks support our contract with you and our legitimate interest in enforcing the service's access requirements.
Changes
We update the date above when this policy changes. If a change to processing requires new consent, we will obtain that consent before applying it. The current provider list is always available on this page.
Contact
14PAST3 računalniške storitve d.o.o. Cesta na Bokalce 20E, 1000 Ljubljana, Slovenia Company registration number 9959513000 · VAT SI85358975 Email: support@safefoodscanner.com
Last updated 2026-09-08. This page is the canonical version; the app ships a copy of the same text.