SahihScan Privacy Policy
Last updated: 2026-09-08
SahihScan ("the app") is built by deepfai. We collect the minimum data needed to provide halal ingredient analysis.
What we collect
- Scans: barcodes you scan, ingredient text, and the resulting verdicts. Stored on your device; synced to our servers only if you sign in with a Pro subscription.
- Label photos: processed transiently for analysis and never stored — neither on your device beyond the analysis nor on our servers.
- Halal profile: your strictness preferences and personal watchlist. Stored on device; synced to your account when signed in.
- Saved restaurants (Pro): the restaurant names and notes you save in Restaurant Mode. Stored on our servers and tied to your account; removed on account deletion.
- Account data: email (or Apple/Google identity) when you choose to sign in. Signing in is never required to scan.
- Usage analytics: anonymized events (PostHog) with a random identifier until you sign in. We never sell data.
- Crash and diagnostic reports: when the app crashes or hits an unexpected error we send a report to Google Firebase Crashlytics containing the error, a stack trace, and basic device and app state (device model, OS version, app version). We also use Firebase Analytics for aggregate usage counts. Neither is used for advertising, and neither carries your email or your scan contents.
- Advertising (free tier only): free users are shown banner ads via Google AdMob. We request non-personalized ads, so AdMob does not use a cross-app advertising identifier to profile you; it may still collect a device identifier, coarse location (from IP), and ad-interaction data to serve and measure ads, per Google's policies (https://policies.google.com/technologies/partner-sites). Pro removes all ads. We do not perform App Tracking Transparency tracking. If you are in the EEA or the UK, Google's consent form is shown before any ad is requested, and you can change that choice later from Settings → "Ad privacy options".
- Purchases: handled by Apple/Google via RevenueCat; we receive entitlement status, never payment details.
Where data goes
- Product lookups query Open Food Facts (the barcode is sent).
- AI analysis requests go from our server functions to OpenAI, which is our sole AI processor. Ingredient text, chat messages, restaurant dish and menu content, and transient label or menu photos are sent to OpenAI to produce the verdict or reply, and are returned to you through our servers. OpenAI processes this under its API terms, which do not use API data to train its models. We send no account identifier, email or device identifier with these requests. Label and menu photos are never stored — not by us and not beyond OpenAI's own limited abuse-monitoring retention.
- You decide whether AI analysis happens. The first time you use a feature that sends content to OpenAI — a label photo, typed ingredients, a restaurant menu or dish, or the Halal Assistant — we ask your permission and name OpenAI before anything is sent. You can withdraw it at any time in Settings → "AI processing". With it off, barcode scanning and the app's built-in ingredient database keep working; only the AI-backed features stop.
- Processors we use: Supabase (our backend and database), OpenAI (the AI that analyses ingredients, label and menu photos, and powers the Halal Assistant chat), Google Firebase (Crashlytics crash reporting and Analytics), PostHog (product analytics), RevenueCat (subscription entitlement status) and Google AdMob (ads on the free tier only).
Your rights
- Export your scan history and halal profile from Settings → "Export my data".
- Delete your account and synced data from Settings → "Delete account" (immediate, irreversible).
- Contact: haris.sidd786@gmail.com
Retention
Device data stays until you delete the app or use in-app deletion. Server data is removed on account deletion; error reports and aggregate usage metering are anonymized (unlinked from your account) rather than deleted.