Legal
Privacy Policy
Last updated: July 13, 2026
Overview
Aurascan (“we,” “us”) operates the website at www.aurascan.fit and the Aurascan mobile apps for iOS and Android. This policy explains what personal information we collect across all of our products, how we use it, and your rights. If you do not agree with this policy, please do not use our services.
Our separate Consumer Health Data Privacy Policy provides the disclosures and rights specific to consumer health data, including data categories, sources, purposes, processors, deletion, withdrawal, and appeals.
Information we collect
- Account information. When you create an account, our authentication provider Clerk collects your email address and (if you sign up via Apple or Google) the basic profile information those providers return, typically your name and avatar image. You can also sign up with email and password. If you choose a profile photo, the photo is uploaded to and stored by Clerk.
- Profile, household, and dietary data.We store your full name if provided, date of birth for 18+ age verification, age bracket, biological sex (male or female), and activity level. You may create household profiles with a display name, sex, age bracket, activity level, and health conditions. Per-profile dietary rules may include allergens, ingredients or additive classes to avoid, ingredients or nutrients to limit, and preset identifiers. We use this information to tailor ingredient analysis and alerts to the selected profile’s physiology, lifestyle, and stated preferences. Some of this information may be consumer health data; see our Consumer Health Data Privacy Policy linked above.
- Scan and product history. When you scan a product, we store the barcode, resulting product information, timestamp, and selected household profile, when applicable, linked to your account so you can revisit past scans. A copy of recent scans is also cached on your device for offline access.
- Camera and submitted label photos (mobile apps). Continuous camera frames used to decode a barcode remain on your device; only the decoded barcode is sent for a normal barcode scan. If you explicitly submit ingredient-label or nutrition-label photos, however, those image bytes are uploaded to our backend and sent to Google Vertex AI / Gemini for optical character recognition. Photos awaiting product-data moderation are stored in Supabase Storage until the submission is approved or rejected, when the photo is deleted. A photo may be deleted sooner if a submission is automatically rejected, fails, or is a duplicate. We currently do not apply a fixed maximum retention period while a submission remains pending.
- Fresh-scan location (mobile apps). If you grant foreground location permission, the app makes a best-effort, time-limited request for precise latitude and longitude only when you perform a fresh scan. It reverse-geocodes a readable place label on your device, sends the coordinates and place label to our first-party backend, and stores them with that scan so ItemDex can show where products were discovered. Reopening a past scan does not collect fresh location. We do not send this location to analytics, advertising, or telemetry providers.
- Journal, goals, watchlists, and saved products. Health-journal entries can include severity from 1 to 5, selected symptoms, a free-form note, timestamp, and an optional linked scan. We also store goals and their target, period, and status; watched product barcodes or ingredients; and saved-product organization such as likes, notes, tags, shelf, and safe-or-avoid list labels.
- Notifications. We store notification preferences, alert read state, and device push tokens with platform and last-seen details. Product alerts retain a redacted verdict and match counts. Generic dietary-preference notifications may be delivered through Expo push notifications or Resend email without including the underlying dietary rule in the message.
- Waitlist signups. When you join our waitlist, we collect your email address and the time of signup.
- Billing data. If you purchase a subscription, payment card details are collected and processed by Stripe, Apple, or Google, as applicable. We do not see or store your full card number. Our records may include provider identifiers, platform, tier, billing period and status, transaction dates, amount and currency, and an append-only subscription-event ledger used for entitlement, support, fraud, and accounting purposes.
- Analytics.Basic website analytics run by default unless you turn them off through Privacy choices or send a Global Privacy Control (GPC) signal. Google Analytics 4 records aggregate page, referral-domain, device, and country information; PostHog creates a pseudonymous profile using a random browser identifier and records only the aggregate interaction events we intentionally define; and Grafana Faro records Web Vitals and navigation performance on public marketing pages. We exclude names, email addresses, health data, text you enter, URL query strings and fragments, full referrers, and free-form campaign term or content values. Faro and PostHog receive only allowlisted or templated page paths. Scan contents, ingredient names or results, health conditions, biological sex, and other health-related content are never used for analytics or advertising. Account association and website session replay are off until you explicitly choose “Allow enhanced.” After that choice, signing in can associate the pseudonymous browser profile, including its earlier aggregate events, with your account using an opaque internal account identifier only — never your name or email. When replay is also enabled by us, it runs only on allowlisted public marketing pages, masks all rendered text and input values, and blocks elements marked as private. It never records sign-in, account, dashboard, admin, onboarding, product, or health-result pages. We do not enable PostHog autocapture, surveys, automatic exception capture, or page-leave capture. Closing the notice does not change your current analytics setting. On a first visit, closing leaves basic pseudonymous analytics on while account association and replay stay off. Opting out or sending GPC stops analytics, replay, and account association. In our mobile apps, PostHog helps us understand intentionally defined product-usage events such as screens viewed and scans completed. Production mobile replay is disabled; a separately controlled preview beta may use masked replay only for an opted-in signed-in user, with sensitive screens excluded.
- Cookies and local storage.On the website we use essential storage for session continuity and your privacy choice. Unless you opt out (via Privacy choices or a GPC browser signal), GA4 and PostHog may also use first-party cookies or local storage holding random pseudonymous identifiers for basic analytics. An explicit “Allow enhanced” choice is required before PostHog may associate that profile with an opaque account identifier or start eligible masked replay. No advertising cookies are set.
- Operational error monitoring. We use Sentry to diagnose website, backend, and mobile crashes and performance failures. For website and backend events, default personal-information collection is disabled and our outbound filter removes request bodies, cookies, authorization and IP headers, free text, and URL query strings or fragments before a report is sent. Mobile monitoring is configured without account identity and sanitizes crash and performance events before transmission. Sentry Session Replay is disabled.
- Server logs. Our backend records request paths, status codes, and IP addresses for security and debugging, retained for 30 days.
How we use your information
- To create and authenticate your account
- To run ingredient analysis tailored to your biological sex and return per-organ impact summaries
- To save your scan history so you can review past results
- To maintain household profiles, dietary rules, journals, goals, watchlists, saved products, and personalized product alerts
- To associate a fresh scan with its discovery location for ItemDex when you grant foreground location permission
- To extract ingredient and nutrition text from label photos you explicitly submit and moderate contributed product data
- To process subscription payments and manage your plan
- To send you launch updates if you joined the waitlist
- To send transactional emails such as account, billing, and security notifications
- To understand aggregate usage patterns and improve the product
- To detect and prevent abuse, fraud, or security incidents
- To comply with legal obligations
We do not sell or rent your personal information. We do not use your personal data to train AI models, and we do not allow our AI processor (Google Gemini, via Google Cloud Vertex AI) to use your data to train their general-purpose models. Vertex AI’s terms prohibit such training by default.
How AI processing works
Aurascan uses Google Gemini (via Google Cloud Vertex AI) to analyse food ingredients, infer ingredient lists for products that are missing them, and read ingredient or nutrition text from label photos you explicitly submit. Depending on the feature, our backend sends the following to Gemini:
- The product’s name, brand, and category (from a public barcode database)
- The image bytes of an ingredient-label or nutrition-label photo you explicitly submit for optical character recognition
- Each ingredient name being analysed
- Your biological sex (male or female), so analysis can reflect sex-specific physiology
We do not send your name, email, account ID, IP address, or any other identifier you can be recognised by to Gemini. Analyses are cached in our database keyed by ingredient and sex, so the same ingredient is rarely re-analysed. Gemini returns an evidence tier (strong, moderate, limited, or mechanistic) for each impact so you can see the strength of the underlying research.
Third-party services
We share limited data with these processors, each bound by their own terms:
- Clerk: authentication, account management, profile-photo storage, and (via Apple and Google) social sign-in
- Supabase: database hosting for account-linked profiles, scans, journals, dietary rules, goals, watchlists, saved products, notifications, subscriptions, and analysis results; plus temporary storage of submitted label photos awaiting moderation
- Google Cloud (Vertex AI / Gemini): ingredient and nutrition-label optical character recognition and ingredient analysis (no name, email, account ID, or IP address transmitted in model content)
- Go-UPC: barcode-to-product lookup (only the barcode number is sent)
- Stripe: payment processing and subscription management
- RevenueCat: subscription entitlement management across web and mobile purchases
- Resend: transactional email, including welcome, account, billing, and generic dietary-preference alert notifications
- Expo: delivery of mobile push notifications using the device push token and generic notification content
- Google Analytics 4: website analytics
- PostHog: product analytics for the website and mobile apps, plus masked replay on allowlisted public website pages after an explicit enhanced choice and when separately enabled
- Grafana Labs (Faro): Web Vitals and navigation performance for allowlisted public website marketing pages while analytics are enabled
- Sentry: operational website and backend error monitoring, plus mobile crash and performance monitoring configured without account identity
- Amazon Web Services (AWS): application hosting (Amplify Hosting and CloudFront for the website; ECS Fargate for the backend API)
- Apple App Store / Google Play: distribution and in-app purchase processing for the mobile apps (subject to their own privacy policies)
International data transfers
Several of our processors, including Clerk, Supabase, Stripe, Google Cloud, Expo, Resend, Sentry, Grafana Labs, and our analytics providers, may process data in the United States and other countries where they operate. We rely on the safeguards each provider offers (such as Standard Contractual Clauses) for cross-border transfers where required.
Your rights
Depending on your location (GDPR, UK GDPR, CCPA, and similar laws), you may have the right to access, correct, delete, or export your personal data, restrict or object to certain processing, withdraw consent, and lodge a complaint with your local supervisory authority.
United States state privacy rights. Depending on the law that applies where you live, you may ask us to confirm whether we process your personal information; access, correct, or delete it; and receive a portable copy. Where applicable, you may also opt out of a sale, targeted advertising, or profiling used to make decisions with legal or similarly significant effects, and withdraw consent to processing sensitive personal information. We do not sell personal information or use it for targeted advertising. We will not discriminate against you for exercising a privacy right. You may use an authorized agent where applicable law permits, subject to reasonable identity and authority verification.
Account deletion.You can delete your account directly from the mobile app (Profile → Delete account) or web dashboard (Profile → Delete account). Doing so initiates deletion of your authentication record, account row, and associated account-linked records from our application database. Provider-side deletion jobs may be retried until they complete, so durable deletion is not necessarily instantaneous. We and our processors may retain limited billing or other records where required for security, legal, tax, accounting, fraud prevention, or dispute handling. You may also email privacy@aurascan.fit to exercise any of your other rights and we will respond within the timeframes required by applicable law (within 30 days under GDPR; within 45 days under CCPA).
If we deny your request and your state law gives you a right to appeal, email privacy@aurascan.fit with the subject “Privacy appeal” and identify the request and decision you want reviewed. We will review and respond as required by applicable law.
Do Not Sell or Share My Personal Information (California)
Aurascan does not sell or share your personal information.Under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), “sale” and “sharing” have specific meanings, including transfers for cross-context behavioural advertising. We do not engage in either: we do not transfer your personal information to third parties for advertising purposes, we do not share it with data brokers, and we do not use it to power ad networks.
California residents have the right to opt out of the sale or sharing of personal information. Because we do not engage in either, there is nothing to opt out of, but exercising the right is still available to you. We also treat the Global Privacy Control (GPC) browser signal as a valid opt-out of website analytics. To submit a request, email privacy@aurascan.fit with the subject line “Do Not Sell or Share” and we will confirm receipt and disposition within 15 business days as required by CCPA.
You also have the right to correct, access, and delete your personal information (see “Your rights” above), and the right not to be discriminated against for exercising any of these rights.
Data retention
Account-linked profiles, scans, journals, household and dietary settings, goals, watchlists, saved-product organization, and notification settings are generally kept while your account or the relevant feature item exists. When you delete an available item or your account, or make a verified deletion request, we delete covered records subject to processor limitations and records we must retain for security, legal, tax, accounting, fraud-prevention, or dispute purposes. Non-identifying subscription and purchase evidence, with account and provider-customer identity removed, is kept only as needed for those operational and legal purposes; payment providers control retention of their own payment records.
After account deletion, first-party analytics derived from account signups or scans retain only privacy-protected aggregate or deidentified lower-bound signup-volume and scan-volume counters. We delete the individual identity and raw account scans, together with product, ingredient, health, profile, location, device, and free-text dimensions associated with the account; those fields are not carried into the retained counters. Each erased account can contribute no more than 10 scans to a UTC-day counter. A private admin time bucket is published only after at least five erased accounts contribute. Its displayed count is released in five-account batches, rounded down to a multiple of five, and remains unchanged between those batch boundaries. A monthly count is the sum of only the already published protected daily batches. An unpublished daily batch contributes nothing until it reaches its next five-account boundary; it does not remove or otherwise change a published month. We do not publish the number of suppressed buckets. Suppressed or unpublished is not zero, and these displayed lower bounds are not exact event or signup totals.
Capture begins when the protected erasure counters are activated. Accounts erased before activation are not backfilled, although an account erased later can contribute an older signup or scan date. If a counter write fails but its durable failure signal succeeds, account deletion continues and the admin report identifies the preserved history as partial rather than silently treating the missing data as zero. If neither the counter nor its failure signal can be recorded, the deletion transaction rolls back so the deletion can be retried instead of losing the unreported data.
Separately, after recipient identifiers are removed, we may retain identifier-free, count-only transactional-email delivery event counters internally. We do not publish those erased-recipient counters in admin reports until a distinct-recipient cohort protection is available, and we do not use them in live rates, unique-recipient, campaign, template, subject, or link analytics. Identifier-free erased-waitlist signup counters likewise remain internal and are not published until a safe cohort contract is available. We may also retain non-identifying subscription or revenue evidence needed for entitlement, support, security, fraud prevention, tax, accounting, or disputes. None of these categories contains raw account scans or food-product, ingredient, health, profile, location, device, or free-text dimensions.
We take reasonable measures designed to prevent retained aggregate or deidentified data from being associated with a person or household. We publicly commit to maintain and use that data only in aggregate or deidentified form and not to attempt to reidentify it, except to test whether our deidentification measures work. We do not sell or share the retained counters, identifier-free email counters, or non-identifying revenue evidence. If we disclose aggregate, deidentified, or non-identifying retained data to a service provider or other recipient, our contract requires the recipient to honor the same use and reidentification restrictions.
Submitted label photos awaiting moderation are kept until the submission is approved or rejected and the photo is deleted; they may be deleted earlier after an automatic rejection, failed submission, or duplicate. There is currently no fixed maximum period for a submission that remains pending. Device push tokens are maintained while the device remains registered and may be pruned when invalid. Waitlist emails are kept until you unsubscribe or request deletion. Server logs are retained for 30 days.
Analytics data is retained according to the settings configured for each provider and may vary by analytics data type. When enabled, masked replay in our primary PostHog website project is retained for no more than 30 days. Production mobile replay is disabled. A separately controlled preview beta, if replay is enabled there, follows that preview project’s own configured retention rather than a period stated here. Cached AI ingredient analyses are keyed by ingredient and sex, are not linked to an account identifier, and are retained as part of our reference dataset.
Security
Authentication tokens are issued and verified by Clerk. Account data is stored in Supabase using row-level security so users can only read their own records. Our API requires a valid bearer token on every request. No system is perfectly secure, but we work to apply reasonable administrative and technical safeguards. If we ever discover a personal data breach that affects you, we will notify you and the relevant authorities as required by applicable law.
Children
Aurascan is intended only for users who are 18 or older. We verify age during onboarding and do not knowingly allow users under 18 to use the service. If you believe someone under 18 has given us data, contact us at privacy@aurascan.fit and we will delete it.
Health information disclaimer
Aurascan provides educational information about food ingredients. It is not a medical device, does not provide medical advice, and the data we collect about you (including biological sex) is used only to tailor ingredient education, not to diagnose or treat any condition. See our Terms of Service for the full medical disclaimer.
Changes to this policy
We may update this policy as our services evolve. Material changes will be announced via the site, in-app, or by email to account holders and waitlist subscribers. The “Last updated” date above reflects the most recent revision.
Contact
Privacy questions: privacy@aurascan.fit