← Back to SnackScore

Privacy Policy

Last updated: 17 July 2026

This policy covers the SnackScore iOS app and the snackscore.app website. SnackScore tells you how healthy a packaged food really is: you give it a photo, a barcode or a product name, and it returns a 1-100 health score built on source-backed nutrition data when available, or a clearly labelled photo estimate when exact source data cannot be found. This page explains what data is used, why, and who processes it.

The short version

What we use, and why

Stored on your device only

Your scan history, saved (starred) products and settings are stored on your device (encrypted at rest), and are removed when you delete the app. There is no account and we keep no copy of your history. If you use Apple's iCloud or a local device backup, your history and any saved scan photos are included in that backup - those backups belong to you and Apple and we never see them. The anonymous install identifier is kept in the keychain and deliberately excluded from backups. When available, free allowances use the salted server pseudonym derived from Apple's signed, app-scoped AppTransaction. Older versions and temporary proof omissions keep a compatibility allowance under a server-HMAC pseudonym of the same random install identifier.

Photos are not shared with other users

When you scan a product photo or a barcode photo, that image is processed only to return your own SnackScore result. It is not published, sold, used in marketing, added to a shared database, or made visible to other people using SnackScore. When a product has no stock picture, your photo is kept locally on your device so it can stand in as that item's picture on your History screen; otherwise it is not kept. If you choose to share or export a result yourself, that is your action.

Who processes data on our behalf

Web search

When a product is not found in Open Food Facts, SnackScore asks its AI provider to search the public web (for example, the manufacturer's site or a retailer) for that product's real ingredients and nutrition, and shows you the sources it used. Most web lookups send the product name and brand. If those fail and you uploaded a photo, a last-resort photo rescue may also send the product photo so the provider can confirm the exact visible product. Your scan history and personal identity are not sent for this lookup.

Retention

Photo handling. SnackScore does not write a scanned photo to its own database, cache or logs. The photo is transmitted to OpenAI to answer the request. SnackScore requests no Responses API application-state storage (store: false), but OpenAI's standard API controls may retain request content in abuse-monitoring logs for up to 30 days, unless shorter-retention or Zero Data Retention controls apply. OpenAI may retain content longer when legally required or for the limited safety-review cases described in its API data-controls policy.

Product results are cached; you are not. To make scans faster and cheaper for everyone, the scored result for a product - its product name, score, cleaned-up ingredient list and nutrition summary - may be kept in a server-side cache for up to 30 days. That shared cache is keyed to the product itself (its barcode or identity), not to you or your device. It does not contain request quota data, uploaded photos, visible OCR text, the anonymous install identifier or other information about who scanned the product. Our service logs do not retain what products you scanned.

Lost-response retry record. To prevent a cancelled or interrupted retry from being processed and counted twice, our service may retain the exact completed response for up to 15 minutes. Its key is scoped to the anonymous install identifier, a random request identifier and the normalized request facts, so only the same logical request can replay it. It is transient retry state, not a browsable or persistent scan history, and it does not contain the uploaded photo.

Anonymous scan counts on our service expire automatically. Paid monthly allowance records use the random install identifier and expire after about 35 days; per-install daily web, provider and rescue controls use it for up to about 2 days. Free monthly allowances instead use the pseudonyms described next and also expire after about 35 days. When Apple proof is available, the service first validates the signed AppTransaction and its device challenge, discards the raw signed transaction and app-specific device-verification UUID, and stores only a salted, non-reversible pseudonym derived from signed appTransactionId. For compatibility when proof is unavailable, it stores the allowance under a server-HMAC pseudonym derived from the random install identifier. After an install has supplied valid Apple proof, a separate HMAC-keyed mapping keeps that install on the same Apple-derived allowance during later proof omissions; the mapping expires 400 days after the install's last free-tier request that uses it. Separate daily abuse counters retain only a salted, non-reversible network-source hash, not the raw address. Apple's DeviceCheck service separately confirms the request comes from a genuine Apple device - SnackScore does not read or write either DeviceCheck bit. To limit subscription-identifier sharing, our service may keep salted, non-reversible hashes derived from the anonymous install identifier and a RevenueCat alias. Those alias anti-replay bindings expire on a rolling 35-day schedule; raw aliases are not stored in those binding records. A direct positive paid-tier cache, keyed by the random install identifier, may be kept for up to 15 minutes. A restored-alias verdict may also be copied once to the current anonymous install for up to 5 additional minutes, so paid behavior may persist for about 20 minutes after server-side access is switched off; copied verdicts cannot be transferred again. Your on-device history is kept until you delete it or delete the app; the separate retry record above expires automatically.

Your choices

Who is responsible (data controller)

SnackScore is operated by its developer under the name Tactical Code Works, based in Luxembourg, who acts as the data controller for the limited processing described here. For anything in this policy, including data requests, contact tacticalcodeworks@hotmail.com.

Legal basis (EU/EEA users)

Where the GDPR applies, we process the data described above on these bases: performance of a contract (Art. 6(1)(b)) - identifying and scoring the food you ask us to score, and metering the free and paid scan allowances; and legitimate interest (Art. 6(1)(f)) - preventing abuse of the free tier and keeping the service secure. We do not use your data for advertising, tracking or profiling, and we do not sell it.

International transfers

Cloudflare, OpenAI and RevenueCat are US companies, so the limited data described above - for example a food photo sent for identification or an anonymous subscription identifier sent to RevenueCat - may be processed in the United States. Transfers are protected through the providers' applicable transfer mechanisms, such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses. Requests are encrypted in transit. OpenAI's processor retention and the pseudonymous server-side caches, counters and anti-replay bindings are described under Retention.

Your rights (EU/EEA users)

You have the rights of access, rectification, erasure, restriction, portability and objection over personal data we hold. In practice almost everything lives on your device, under your direct control: your scan history and saved products never leave it, and most settings remain local. Your selected goal is sent with a scoring request as described above. You can view, export or delete your local history in the app at any time. Server-side data is limited to anonymous, expiring scan counters, product-keyed result caches, the request-scoped 15-minute retry record, a short paid-tier cache and the salted anti-replay hashes described above. If you contact us with a data request we will help with whatever is technically possible. You can also lodge a complaint with your supervisory authority - in Luxembourg, the CNPD (cnpd.public.lu).

Security

Data in transit is protected with TLS. On-device data is protected with iOS file protection. Secret keys (AI provider) are held only on our secure service, never in the app.

Not medical advice

SnackScore explains food quality, not your health. Scores are guidance, not a medical or dietary diagnosis. If you have a medical condition or allergy, check the actual packaging and a qualified professional.

Children

SnackScore is not directed at children and does not knowingly collect data from children.

Changes

We may update this policy; the date at the top reflects the latest version.


Contact: tacticalcodeworks@hotmail.com · See also Terms and Support.