The short version
- You do not create an account. The app identifies your device with a random ID generated on first launch. We never ask for your name, email or phone number.
- Label photos are processed, not kept. A photo you scan is sent to our server, read once to extract the ingredient text, and discarded. We do not store your photos.
- Your dietary profile stays on your device and is sent with a scan only so the result can be tailored. It is not saved on our servers.
- We never see your payment details. Apple handles the payment.
- We do not sell your data and we do not use it for advertising or cross-app tracking.
1. Who we are
Protein Grade (the “app”) is provided by Tetiana Sarancha, an individual developer based in Kharkiv, Ukraine (“we”, “us”, “our”). We are the data controller for the personal data described in this policy.
Questions, requests or complaints: costori.app@gmail.com. We aim to reply within 5 working days and, for formal data-protection requests, within one month.
2. What this policy covers
This policy covers the Protein Grade mobile app and the server that powers it. It does not cover the app stores you download the app from, or any website or product you reach by following a link from the app — those are governed by their own policies.
3. What we collect, why, and for how long
| Data | Why we process it | How long we keep it |
|---|---|---|
| Anonymous app ID (a random UUID created on your device at first launch) | To count your free scans, to know whether you have an active subscription, and to link your purchase to your installation. It is not linked to your name or email. | Until you delete the app and ask us to erase the record. See §9. |
| Photos of product labels | To read the ingredient list and protein content printed on the label so the product can be graded. | Not stored. The image exists in memory only for the seconds it takes to process the request. See §4. |
| Extracted label text (ingredients, protein grams) and a fingerprint (SHA-256 hash) of the photo | Caching: if the same label is scanned again, we reuse the extracted text instead of re-processing it. This makes scans faster and cheaper. The cache is shared and not tied to you. | 30 days, then automatically deleted. |
| Dietary profile (diet type, allergies, ingredients you have blocked) | To flag ingredients that matter to you. Stored on your device; sent with a scan request so the result can be tailored, then discarded once the response is returned. | On your device, until you change it or delete the app. Not retained on our servers. |
| Subscription status and free-scan count | To enforce the free-scan allowance and to unlock Pro features. | For as long as your installation record exists. See §9. |
| Usage analytics (see §6) | To understand which screens and features are used, and to find and fix crashes and failures. | Up to 14 months in Google Analytics for Firebase, then automatically deleted. |
| Technical request data (IP address, device and OS version, app version, timestamps) | Security, abuse prevention, and diagnosing errors. Handled automatically by our hosting provider. | Server logs are retained for a short rolling period. |
We do not collect your name, email address, postal address, phone number, contacts, precise location, or any advertising identifier. We do not ask for App Tracking Transparency permission because we do not track you across other companies’ apps or websites.
4. Label photos in detail
When you scan a product, the app captures a photo (or you choose one from your photo library) and sends it to our server, which runs on Cloudflare’s infrastructure. There, an AI model reads the text on the label and returns the ingredient list and protein content. The image itself is not written to any database or file store and is not retained after the request completes. What is retained is the extracted text, stored for up to 30 days against a one-way fingerprint of the image so that repeat scans of the same label are instant.
Only send us photos of product labels. Anything else in the frame is processed the same way and discarded the same way, but there is no reason to include it.
The app requests camera access to take label photos and photo-library access if you choose an existing photo. You can refuse or withdraw either permission in your device settings; the corresponding way of starting a scan will then be unavailable.
5. Health-related information
If you record allergies or a diet in your profile, that is information about your health under EU and UK data-protection law (a “special category” of personal data). We process it only on the basis of your explicit consent, given when you enter it, and only to produce your scan results. It is stored on your device, transmitted to us over an encrypted connection for the duration of a scan, and not retained by us afterwards. You can withdraw consent at any time by clearing your profile in the app.
6. Analytics
We use Google Analytics for Firebase to see how the app is used in aggregate. It records events such as: completing onboarding, seeing the paywall, selecting a plan, starting or completing a purchase, restoring a purchase, submitting a scan, and the outcome of a scan (the grade letter, the number of flags raised, and whether it failed or was unreadable). Alongside those events, Firebase automatically collects a randomly generated app-instance ID, your device model, operating-system version, app version and approximate country, derived from your IP address.
We do not send your dietary profile, your photos, your purchase identifiers or the names of products you scan to analytics. Firebase data is not used for advertising or audience-building.
7. Purchases and subscriptions
Purchases are made through Apple’s in-app purchase system and managed for us by RevenueCat, Inc. Apple processes your payment and charges your Apple account; we never receive your card number or billing details. RevenueCat receives your anonymous app ID and the purchase receipt data from the app store so it can tell us whether your subscription is active. Apple then notifies our server of renewals and cancellations so that Pro access stays in sync.
Apple’s handling of your purchase is governed by Apple’s Privacy Policy. RevenueCat’s is governed by RevenueCat’s Privacy Policy.
8. Who we share data with
We do not sell your personal data, we do not share it for cross-context behavioural advertising, and we do not disclose it to third parties for their own purposes. We use the following service providers, who process data on our instructions:
- Cloudflare, Inc. — hosting, the AI model that reads labels, the extraction cache and the entitlement database.
- Google LLC (Firebase) — usage analytics.
- RevenueCat, Inc. — subscription management.
- Apple Inc. — app distribution and payment processing.
We may also disclose data where we are legally required to, or where it is necessary to establish, exercise or defend legal claims, or to protect the rights and safety of our users. If the app is ever transferred to another owner, the data described here may transfer with it; you would be told before that happened.
9. International transfers
We are based in Ukraine and our providers are based in the United States and operate globally, so your data is processed outside your country and may be processed outside the European Economic Area and the United Kingdom. Where data is transferred out of the EEA or UK, the transfer is covered by the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), which each of the providers above has incorporated into its terms, together with the technical protections described in §11. Ukraine is not currently the subject of an EU adequacy decision, so transfers to us likewise rely on those clauses.
10. Your rights
Depending on where you live, you have some or all of the following rights: to access the personal data we hold about you; to have it corrected; to have it deleted; to restrict or object to our processing; to receive it in a portable format; and to withdraw consent at any time without affecting processing already carried out.
How to exercise them. Email costori.app@gmail.com.
Because the app has no accounts, we hold nothing that connects a server-side record to your name or email. To locate your record we need your anonymous app ID; write to us and we will tell you how to retrieve it from your installation. If you cannot supply it, we cannot single out your record, and we will tell you so plainly rather than guess — but that record holds only a random ID, a scan count and a subscription expiry date, and nothing in it identifies you.
Deleting the app erases everything held on your device, including your dietary profile and your app ID. It does not by itself delete the server-side record of your scan count and subscription status, which is why the email matters if you want that gone too.
You will not be charged for exercising these rights, and we will not treat you differently for doing so.
If you are in the EEA or the UK
Our legal bases are: performance of a contract (running scans, enforcing the free allowance, delivering Pro features); explicit consent (your dietary profile — §5); consent (analytics, where required in your jurisdiction); and legitimate interests (security, abuse prevention, and understanding how the app is used, balanced against your privacy — the data involved is minimal and never used to target you). You may lodge a complaint with your national supervisory authority.
If you are in California
We have not sold or shared personal information in the preceding twelve months, and we do not knowingly collect personal information from anyone under 16. The categories we collect are identifiers (the anonymous app ID), commercial information (subscription status), health information you volunteer (§5), and internet activity (usage analytics) — all as described in §3. You have the right to know, delete, correct, and to opt out of sale or sharing (there is nothing to opt out of), and to be free from discrimination for exercising those rights.
11. Security
All traffic between the app and our server travels over HTTPS. Access to our infrastructure is restricted and protected by multi-factor authentication. We minimise what we hold in the first place: no accounts, no photos, no contact details. No system is perfectly secure, but if a breach affecting your data occurs we will notify you and the relevant authorities where the law requires it.
12. Children
The app is not directed at children and is not intended for anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.
13. Changes to this policy
We may update this policy as the app changes. The “last updated” date at the top always reflects the current version. If a change materially affects your rights, we will tell you in the app before it takes effect.
14. Contact
Tetiana Sarancha
Individual developer, Kharkiv, Ukraine
costori.app@gmail.com
A postal address for formal correspondence is available on request by email.