Privacy Policy

Updated: August 13, 2026 Effective: August 13, 2026

Introduction

Welcome to our services. We value your privacy and personal information rights and take appropriate measures to protect them in accordance with applicable laws and regulations.

This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use features such as scanning, code creation, history, product information, AI product authenticity analysis, Sign in with Apple, and cloud synchronization, as well as how you may exercise your rights.

Please read this Privacy Policy carefully before using the App. Where separate consent is required by law for a particular processing activity, we will provide a separate notice and obtain your consent. You may refuse to provide non-essential information, but the corresponding feature may then be unavailable.

1. How We Collect and Use Personal Information

We process personal information only to the extent necessary for specific and reasonable purposes. The information actually processed depends on the features you use.

1.1 Scanning, Recognition, and Code Creation

Basic scanning, code creation, and history features may preferentially be processed and stored locally on your device. If you actively enable cloud synchronization, the relevant records will be uploaded as described in the “Cloud Synchronization” section of this Privacy Policy.

1.2 Contact Features

When you actively select “Import from Contacts” or add a vCard contact identified through a scan to your system contacts, the App requests contacts permission and processes only the contact information necessary to complete that operation. We do not read or upload your entire address book without an action initiated by you.

1.3 Product Search, Nutrition, and Rating Information

To retrieve product, food-ingredient, nutrition, and rating information associated with a barcode, we may send necessary data—such as barcode content, search terms, and network-request information—to Open Food Facts, search engines, e-commerce platforms, or other data-service providers. If you select a third-party entry, you may be taken directly to a third-party website or application, where information processing is governed by that third party’s privacy policy.

1.4 AI Product Authenticity Analysis

When you actively submit an authenticity-check request, we may process and transmit the following information to our servers and AI or data-service providers:

We use this information to perform AI image analysis, compare information with publicly available data, return a reference result, and save your authenticity-check history. Do not include identity documents, facial characteristics, bank-card information, home addresses, or other sensitive personal information unrelated to the authenticity check in an image or input. Do not upload another person’s information without authorization.

AI authenticity results are for reference only and do not constitute professional authentication, official brand certification, or a transaction guarantee.

1.5 Image Processing

When you actively use an image-processing tool, we process the image you select and the corresponding output. Some processing may be performed through third-party APIs, in which case the relevant image, recognized text, technical parameters, and processing result may be transmitted to the applicable service provider. Before the official release, we will identify the actual providers, processing purposes, and privacy-policy links in this Privacy Policy or a third-party service list, and obtain your separate consent where required by law.

1.6 Sign in with Apple, Accounts, and Cloud Synchronization

When you choose Sign in with Apple, we may receive the unique user identifier provided by Apple and the name, actual email address, or Apple private relay email address that you choose to share. Apple generally provides the name only upon the first authorization. We use this information to create or identify your account, maintain your signed-in state, and protect account security.

When you actively enable history synchronization, we upload account-associated scan records, creation records, favorites, authenticity-check records, and similar information to the cloud so that you can restore and synchronize them across devices. Before synchronization is enabled for the first time, we will explain its scope and obtain your consent. Disabling synchronization stops future synchronization. The retention or deletion of previously synchronized data is governed by the notice displayed when synchronization is disabled and by this Privacy Policy.

1.7 Operations, Security, Analytics, and Crash Diagnostics

To maintain service security and stability, understand feature usage, and improve the product, we may use Firebase Analytics, Firebase Crashlytics, or similar tools actually integrated into the final version to process:

We do not intentionally require analytics or crash logs to contain the substantive content you scan, create, or upload. If technical logs might inadvertently contain such data, we will take measures such as filtering, access controls, and shorter retention periods.

1.8 Customer Support and Rights Requests

When you contact us, submit a complaint, or exercise a personal information right, we may process your email address, communications, screenshots relating to the issue, account identifier, and other information necessary to verify and address your request.

To the extent permitted by applicable law, we may process relevant information without obtaining separate consent where the processing is necessary to enter into or perform a contract to which you are a party, comply with a legal obligation, respond to a public-health emergency, urgently protect a natural person’s life, health, or property, process personal information that you have made public or that has otherwise been lawfully made public, or in other circumstances provided by law.

2. Device Permissions

The App may request the following system permissions. Permissions are not enabled by default. Actual use is subject to the system prompt and the features implemented in the App.

PermissionPurposeEffect of Refusal
CameraScan QR codes or barcodes in real time; capture images needed for authenticity checks and similar featuresCamera capture and live scanning will be unavailable; features that do not require the camera remain available
Photos/Photo LibrarySelect images for recognition or processing; save QR-code imagesSelecting images from or saving results to the photo library will be unavailable; other features are generally unaffected
ContactsImport a contact you actively select; write vCard information to ContactsContact import and add-to-Contacts features will be unavailable

If we add location, notification, or other permissions in the future, we will explain the specific purpose when requesting them and update this Privacy Policy. You may manage permissions at any time in iOS Settings.

3. Cookies and Similar Technologies

Embedded webpages or third-party webpages within the App may use cookies, local storage, or similar technologies to maintain sessions, remember preferences, measure visits, and protect security. When these technologies are used by a third-party webpage, they are governed by that third party’s privacy policy. You may manage them through your system or browser settings, but disabling them may prevent certain webpage features from functioning properly.

4. Entrusted Processing, Sharing, Transfer, and Public Disclosure

4.1 Entrusted Processing and Sharing

We provide information to service providers only to the minimum extent necessary for the purposes described in this Privacy Policy. We require providers to process information lawfully through contractual terms, security measures, and access controls. Based on the current product plan, the following providers may be involved:

Service/ProviderInformation That May Be ProcessedPurposePrivacy Policy
Google Gemini / Google LLCAuthenticity-check images, product category, barcode, QR code, SKU, task parameters, and analysis resultsAI product authenticity analysisGoogle Privacy Policy
Firebase Analytics / Google LLCDevice and App information, anonymous or pseudonymous identifiers, and usage eventsProduct analyticsFirebase Privacy and Security
Firebase Crashlytics / Google LLCCrash, performance, device, and error-log informationTroubleshooting and diagnosticsFirebase Privacy and Security
Apple Inc.Sign in with Apple identifier and related authentication informationSign-in and account authenticationApple Privacy Policy
Open Food FactsBarcode and query-request informationRetrieve food, ingredient, nutrition, and rating informationOpen Food Facts Privacy Policy

If the final released version does not integrate a service listed above, the corresponding entry should be removed. If a new SDK, API, or service provider is added, it should be disclosed before release. We do not sell your personal information to third parties.

4.2 Transfer

As a general rule, we do not transfer your personal information. If a transfer becomes necessary as a result of a merger, division, dissolution, bankruptcy, asset transfer, or similar transaction, we will notify you as required by law of the recipient’s name and contact details and require the recipient to remain bound by this Privacy Policy. If the recipient changes the original purpose or method of processing, it must obtain your consent again as required by law.

4.3 Public Disclosure

We do not publicly disclose your personal information unless we have obtained your separate consent or disclosure is otherwise permitted or required by law.

5. Cross-Border Transfers

Google, Apple, Firebase, and other overseas or global service providers may process data outside your country or region. Whether a cross-border transfer actually occurs depends on the final technical architecture, service region, and server configuration.

If personal information is transferred outside the People’s Republic of China, we will fulfill the applicable legal obligations. These may include informing you of the overseas recipient’s name or identity, contact details, processing purposes and methods, categories of information, and the procedures through which you may exercise your rights against that recipient; obtaining your separate consent where applicable; completing a personal information protection impact assessment; and using a legally required cross-border transfer mechanism.

6. Retention and Deletion

  1. Data stored locally on your device: Scan, creation, and favorite records and certain processing results may remain on your device until you delete them within the App, clear the App’s data, or uninstall the App. Files saved to the system photo library must be deleted through the system photo library.
  2. Cloud-synchronized data: This data is retained while synchronization is enabled. If you delete the relevant record, request deletion of cloud data, or delete your account, we will delete or anonymize the data within the shortest period necessary for synchronization, backup rotation, dispute resolution, and compliance with legal obligations.
  3. AI and image-processing data: This data is retained only for the shortest period necessary to complete processing, return results, protect security, and troubleshoot issues. Unless we separately notify you and obtain lawful authorization, it will not be used to train general-purpose AI models.
  4. Account information: This information is retained while your account exists and for the period necessary to provide account, sign-in, and cloud-synchronization services. After account deletion, it will be processed in accordance with applicable law and this Privacy Policy.
  5. Analytics, crash, and security logs: These are retained for the shortest period necessary for statistics, troubleshooting, and security.
  6. After the applicable retention period expires, we will delete or anonymize the relevant information. If continued retention is required by law, we will retain it only for the required period and scope and restrict further processing.

7. How We Protect Personal Information

We take security measures appropriate to the relevant risks, including encryption in transit, access controls, permission management, log auditing, data minimization, de-identification, backups, and security-incident response, to prevent unauthorized access, disclosure, alteration, loss, or misuse of personal information.

No internet service can guarantee absolute security. If a personal information security incident occurs that may harm your rights and interests, we will take remedial measures in accordance with law and notify you of the basic circumstances, possible impact, measures taken or planned, protective steps available to you, and our contact information. Where applicable, we will also report the incident to the competent authorities.

8. Your Personal Information Rights

To the extent provided by applicable law, you have the right to:

  1. Access and obtain a copy of your personal information;
  2. Correct or supplement inaccurate or incomplete information;
  3. Delete personal information;
  4. Withdraw consent where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal;
  5. Restrict or object to specified processing activities;
  6. Delete your account and request deletion of cloud data;
  7. Request an explanation of this Privacy Policy and our personal information processing rules;
  8. Request the transfer of personal information to a processor designated by you where the legal requirements are met; and
  9. Submit a complaint or report concerning our processing activities.

You may exercise these rights through in-App settings, system permission settings, deletion of history records, disabling cloud synchronization, account deletion, or the contact information at the end of this Privacy Policy. To protect security, we may verify your identity. We will respond within the period required by law. If we cannot fulfill a request, we will explain the reason and any available complaint channel.

After you disable a permission or withdraw consent, we will stop the corresponding processing, but a feature that depends on that information may no longer be available. Local and cloud data are stored separately, so deleting data from one location may not automatically delete it from the other. Please manage each location through the relevant in-App function or contact us using the information below to request deletion.

9. Protection of Minors’ Personal Information

The App is primarily intended for adults. Users under 18 years of age should use the App under the guidance of a parent or other guardian. A child under 14 years of age may use a feature involving personal information only after a guardian has read and agreed to the applicable specific personal information processing rules.

We do not intentionally collect personal information that we know belongs to a child. If we discover that we have processed a child’s personal information without guardian consent, we will delete it or take other measures as soon as reasonably practicable in accordance with law. Guardians may contact us using the information below with any questions.

The App may contain links to third-party websites, applications, search results, product pages, or social platforms. After you leave the App or use a third-party service, that third party will process information under its own rules. We recommend reviewing the third party’s privacy policy before providing information. Except where otherwise required by law or where damage is caused by our fault, we are not responsible for a third party’s independent information-processing activities.

11. Updates to This Privacy Policy

We may update this Privacy Policy to reflect changes in features, service providers, processing purposes, laws and regulations, or security measures. If a change materially affects processing purposes, categories of information, sharing recipients, or your rights, we will notify you through an in-App pop-up, page notice, notification, or another reasonable method and obtain your consent again where required by law.

The updated Privacy Policy will take effect on the stated effective date. We will not reduce the rights you have under this Privacy Policy without your express consent.

12. Contact Us

If you have any questions, comments, complaints, or requests regarding this Privacy Policy, our personal information processing activities, or your personal information rights, please contact us at: