Legal

Consumer Health Data Privacy Policy

Last updated: July 13, 2026

Scope

This nationwide U.S. policy explains Aurascan’s consumer health data practices and provides disclosures for Washington’s My Health My Data Act, Nevada consumer health data law, and Connecticut consumer health data law. We offer its baseline controls to U.S. users where practicable, while particular statutory rights apply when the relevant law covers you. It supplements our general Privacy Policy. Consumer health data is information linked or reasonably linkable to a consumer that identifies or permits an inference about physical or mental health. Aurascan provides educational food-ingredient information, not medical diagnosis or treatment.

Consumer health data we collect and why

  • Profile, physiology, and household information: date of birth for 18+ verification, age bracket, biological sex, activity level, and optional household profile display names, demographics, and health conditions. We use it to confirm eligibility and tailor requested ingredient education to the selected profile.
  • Dietary rules and preferences: allergens, ingredients and additive classes to avoid, ingredients and nutrients to limit, and dietary preset identifiers. We use them to evaluate products and create requested personalized results and alerts.
  • Product, scan, and submitted-label activity: decoded barcodes, product and ingredient information, scan timestamps and history, the selected profile, and ingredient-label or nutrition-label photos you explicitly submit. We use them to look up and analyze a requested product, read label text, display results, maintain history, and moderate contributed product data.
  • Health journal and goals: journal severity from 1 to 5, selected symptoms, a free-form note, timestamp, optional linked scan, and goals with their type, target, period, and status. We use this information to provide the journal and goal-tracking features you request.
  • Watchlists and saved-product organization: watched product barcodes or ingredients, likes, notes, tags, shelf, and safe-or-avoid list labels. This content can reveal a dietary or health preference. We use it to maintain the library, organization, monitoring, and alert features you request.
  • Health-related results and inferences: tailored ingredient analysis, per-organ impact summaries, evidence tiers, dietary-rule match counts, redacted alert verdicts, and related educational results generated from product ingredients and profile context. We use them to provide requested results and generic product-alert notifications and to cache ingredient analyses not linked to an account so repeated lookups can be served efficiently.
  • Account linkage: an opaque internal account identifier associated with profile data, scan history, and results. We use it only to return your data to you, keep accounts separated, support deletion, secure the service, and maintain your history across devices.

We collect and use these categories only as needed to provide features you request, maintain your feature content and history, send requested alerts, secure and support the service, comply with law, and carry out the purposes described above. We do not use consumer health data for advertising, data-broker profiling, or analytics.

Fresh-scan location is handled separately. With foreground permission, a fresh mobile scan may include precise latitude and longitude and an on-device reverse-geocoded place label so ItemDex can show where the product was discovered. We treat this as general personal information because we use it only for that product discovery feature, not to infer health status or identify a healthcare visit. We do not send it to analytics or advertising providers. See the general Privacy Policy for full details.

Sources of consumer health data

  • You: profile and household choices, dietary rules, journal and goal entries, saved-product organization, notification choices, and the products and label photos you choose to submit.
  • Your device interactions: decoded barcodes and use of requested scan, history, journal, library, watchlist, and alert features. Continuous barcode-camera frames stay on your device. Only label photos you explicitly submit are uploaded.
  • Public product sources: product, brand, category, and ingredient information returned for the barcode you supplied.
  • Aurascan’s analysis: educational results and health-related inferences derived from product ingredients, research evidence, and the profile context you provided.

How we process consumer health data

Our AWS-hosted first-party backend authenticates the opaque account identifier and feature request, retrieves or writes the needed account-linked records in Supabase, sends a barcode to Go-UPC for public product data when needed, and sends limited product and profile context to Google Vertex AI / Gemini to produce requested analysis. For an explicitly submitted label photo, the backend sends the image bytes to Gemini for optical character recognition. A submitted photo awaiting product-data moderation is stored in Supabase Storage until approval or rejection, when it is deleted; it may be deleted earlier if automatically rejected, failed, or duplicate. We currently apply no fixed maximum period while a submission remains pending.

Results are returned to the requesting account and may be saved for history, journal, library, goal, watchlist, or alert features. Authorized administration can review a pending product-data submission. Generic notifications may then be delivered through Expo or Resend without stating the underlying dietary rule. Access controls keep account-linked records separated from other users.

Sharing and named processors

We disclose only the consumer health data needed for a requested feature to the following service providers acting for Aurascan:

  • Supabase: stores account linkage, profile and household information, dietary rules, scans, journals, goals, watchlists, saved-product organization, notification preferences, alerts, and results in our application database, plus submitted label photos awaiting moderation.
  • Amazon Web Services (AWS): hosts the backend that securely transmits and processes requested scans, profile context, and results.
  • Google Cloud Vertex AI / Gemini: processes product name, brand, category, ingredient names, biological sex, and explicitly submitted label-image bytes as needed for optical character recognition and ingredient analysis. We do not include your name, email, account ID, or IP address in model content.
  • Go-UPC: receives only the decoded barcode needed to return public product information.
  • Expo: receives a device push token and generic notification content to deliver a requested mobile product alert.
  • Resend: receives the email address and generic notification content needed to deliver a requested product-alert email.

We have no affiliates with which we share consumer health data. We do not send consumer health data to PostHog, Google Analytics 4, Grafana Faro, Sentry, advertisers, or data brokers. If you request access, we will provide the names and contact details of the third parties and affiliates, if any, with which your consumer health data was shared or sold as required by law.

We do not collect consumer health data across unaffiliated websites, apps, or services over time, and we do not use it for cross-context behavioral advertising.

No sale of consumer health data

Aurascan does not sell consumer health data. We do not exchange it for money or other valuable consideration, and we do not permit our processors to sell it.

Your consumer health data rights

You may ask us to:

  • Confirm whether we collect, share, or sell your consumer health data and access the data we hold.
  • Review and correct inaccurate consumer health data where applicable.
  • Receive a list of third parties and affiliates with which we shared or sold your consumer health data, including contact information where required.
  • Withdraw consent to collect or share your consumer health data.
  • Delete consumer health data from our records. We will also notify the processors and third parties that received it so they can delete it from their records.

When processing relies on your consent, you may revoke it. For Connecticut consumers, we stop consent-based processing as soon as practicable and no later than 15 days after receiving the revocation. Connecticut law may permit processing that is necessary and proportionate to provide a product or service you specifically requested; that does not authorize unrelated use. Exercising a right will not result in discrimination or a degraded service beyond what is necessary when deleted or withdrawn data is required to provide a requested feature.

Deidentified counters after account deletion

After account deletion, Aurascan does not retain consumer health data linked or reasonably linkable to the erased account for analytics. For consumer-health or service-usage analytics derived from the erased account’s scans, the only retained data is an aggregate or deidentified scan-volume counter. A separate aggregate or deidentified signup-volume counter contains no health or scan content. These counters do not include individual identity, raw account scans, or product, ingredient, health, profile, location, device, or free-text dimensions. Each erased account can contribute no more than 10 scans to a UTC-day counter. Private admin time buckets are published only after at least five erased accounts contribute. Displayed counts are released in five-account batches, rounded down to multiples of five, and remain unchanged between those batch boundaries. Monthly counts sum only already published protected daily batches. An unpublished daily batch contributes nothing until it reaches its next five-account boundary; it does not remove or otherwise change a published month. We do not publish the number of suppressed buckets. Suppressed or unpublished is not zero, and the displayed lower bounds are not exact totals.

These protected counters begin with erasures processed after activation; accounts erased earlier are not backfilled, although a later erasure can contribute an older signup or scan date. If a counter write fails but its durable failure signal succeeds, deletion continues and the admin history becomes partial rather than zero. If neither can be recorded, the deletion transaction rolls back so the deletion can be retried instead of losing unreported data. Our general Privacy Policy also describes identifier-free, count-only transactional-email event counters retained internally and non-identifying subscription or revenue evidence retained for limited operational or legal purposes. The erased-recipient email counters contain no consumer health data and are not published in admin reports until a distinct-recipient cohort protection is available. Identifier-free erased-waitlist signup counters are also kept out of admin reports pending a safe cohort contract.

We take reasonable measures designed to prevent retained aggregate or deidentified data from being associated with a person or household. We publicly commit to maintain and use that data only in aggregate or deidentified form and not to attempt to reidentify it, except to test whether our deidentification measures work. We do not sell or share the retained counters or other deidentified records. Any contract under which a service provider or other recipient receives aggregate or deidentified retained data must require the recipient to honor the same use and reidentification restrictions.

Deletion timing by state

  • Washington: after authentication, we delete covered records and notify processors and other recipients as required. Data stored only in backups or archives is deleted within six months.
  • Nevada: after authentication, we delete covered data from our main records and network within 30 days and notify processors and other recipients that received it. Those recipients must delete it within 30 days after our notice. Data in backups may be retained for up to two years only as necessary to restore operations.
  • Other covered jurisdictions, including Connecticut: we delete and direct our processors to delete as required by the applicable law and the response timing below.

How to submit a request

Email privacy@aurascan.fit with the subject “Consumer Health Data Request” and state whether you want access, recipient details, review or correction, withdrawal, or deletion. You may also start account deletion in the mobile app or web dashboard under Profile → Delete account. You do not need to create a new account to submit a request. We use reasonable authentication steps appropriate to the request and respond within 45 days. If the applicable law permits and an extension is reasonably necessary, we may extend once by another 45 days and explain the extension during the initial period.

Appeal a decision

If we deny your request, email privacy@aurascan.fit with the subject “Consumer Health Data Appeal” and identify the request and decision you want reviewed. We will respond in writing within 45 days. If the appeal is denied, we will explain the reasons. Depending on where you live, you may also contact the Washington State Attorney General, the Nevada Attorney General, or the Connecticut Attorney General.

Changes to health-data practices

Before collecting a new category of consumer health data, using a category for a new purpose, or disclosing it to a new category of recipient, we will update this policy, provide prominent notice through the site or app and by email where appropriate and available, and obtain the affirmative consent or other authorization required by law before the materially changed practice begins.

Effective date

This policy is effective July 13, 2026. The “Last updated” date above identifies its latest revision.

Contact

Consumer health data questions and requests: privacy@aurascan.fit.