Privacy Policy
Last updated: 17 July 2026
This policy covers the SnackScore iOS app and the snackscore.app website. SnackScore tells you how healthy a packaged food really is: you give it a photo, a barcode or a product name, and it returns a 1-100 health score built on source-backed nutrition data when available, or a clearly labelled photo estimate when exact source data cannot be found. This page explains what data is used, why, and who processes it.
The short version
- We do not sell your data, show ads, or use third-party advertising or tracking.
- There are no accounts. Your scan history stays on your device.
- The photo, barcode or name you scan is used only to identify and score that product. SnackScore does not write photos to its own database, cache or logs. A photo is sent to OpenAI for processing, where it may be retained in abuse-monitoring logs for up to 30 days under OpenAI's API data controls. A product's scored result may be cached for a short time so scans are faster, but that cache belongs to the product, not to you.
- Scanned photos are not published in SnackScore, added to a shared product catalog, or shown to other users.
What we use, and why
- The photo, barcode or name you scan - sent through our secure service to identify the product and look up its ingredients and nutrition. A product photo is sent to our AI provider to read the product name and brand off the front of pack. If database and text-web lookup fail, the same product photo may also be sent in a last-resort photo-and-web lookup to confirm the exact visible product and source-backed facts. If exact source data still is not available, SnackScore may return a clearly labelled low-confidence photo estimate instead. SnackScore does not write photos to its own database, cache or logs; OpenAI's processor retention is described below. Photos are not used to create public listings, not added to SnackScore's shared Explore catalog, and not shown to other users.
- Your selected goal - sent with the request so the score and the explanation are tuned to your goal. The reply language is currently English.
- Anonymous app and device verification - a random install identifier is stored in your keychain and used for subscriptions and compatibility. When StoreKit makes them available, the app also sends our service an Apple-signed AppTransaction and Apple's app-specific device-verification UUID over TLS for free-scan allowances. Our service uses the UUID only to recompute and validate Apple's signed device challenge, then discards it. The salted, non-reversible free-quota pseudonym derives from the signed
appTransactionId, not from the UUID; the raw UUID and signed transaction are not stored, returned or logged. If proof is unavailable, including for an older app version, the same monthly allowance uses a separate server-HMAC pseudonym derived from the random install identifier. A partial or invalid supplied proof is rejected. Separate salted network-source counters limit abuse but do not replace the install's monthly allowance. None of these values is your name, email or Apple ID, and they are not used for tracking. - Subscription status - SnackScore Pro and Pro Max purchases are billed by Apple and managed through RevenueCat under the anonymous install identifier. The app sends RevenueCat that identifier and App Store purchase status. Our service asks RevenueCat whether it has an active SnackScore entitlement. When available, the Apple-signed AppTransaction sent to our service is used only for free-quota identity and never grants paid access. We never receive your name, Apple ID, email or payment details.
Stored on your device only
Your scan history, saved (starred) products and settings are stored on your device (encrypted at rest), and are removed when you delete the app. There is no account and we keep no copy of your history. If you use Apple's iCloud or a local device backup, your history and any saved scan photos are included in that backup - those backups belong to you and Apple and we never see them. The anonymous install identifier is kept in the keychain and deliberately excluded from backups. When available, free allowances use the salted server pseudonym derived from Apple's signed, app-scoped AppTransaction. Older versions and temporary proof omissions keep a compatibility allowance under a server-HMAC pseudonym of the same random install identifier.
Photos are not shared with other users
When you scan a product photo or a barcode photo, that image is processed only to return your own SnackScore result. It is not published, sold, used in marketing, added to a shared database, or made visible to other people using SnackScore. When a product has no stock picture, your photo is kept locally on your device so it can stand in as that item's picture on your History screen; otherwise it is not kept. If you choose to share or export a result yourself, that is your action.
Who processes data on our behalf
- Cloudflare - hosts the secure service the app talks to. Our API keys live only on this service, never in the app. Like any web host, Cloudflare processes standard request metadata (including your IP address and general network/device technical details) to route, secure and rate-limit the service. SnackScore disables persistent Worker invocation logging; Cloudflare may still process limited security and routing metadata under its own service controls. We do not use that metadata to identify or track you.
- OpenAI - identifies the product from your photo, scores it from source-backed nutrition data when available, helps create clearly labelled estimates when exact source data is unavailable, and - when a product is not in the food database - researches it on the live web. Last-resort photo rescue may include the product photo in that web-research request. SnackScore sends
store: falsefor Responses API requests so it does not request separate response-state storage. OpenAI states that API data is not used to train its models unless a customer opts in, but may retain request content in abuse-monitoring logs for up to 30 days unless approved shorter-retention or Zero Data Retention controls apply. - Open Food Facts - the open food database we read real ingredients and nutrition from.
- USDA FoodData Central, Chomp and UPCitemdb - additional food databases queried when Open Food Facts does not have the product. They receive only the barcode or product name being looked up, never your photo or identity.
- RevenueCat - manages SnackScore subscriptions. The app transfers the anonymous install identifier and App Store purchase status to RevenueCat so paid features unlock. RevenueCat does not receive your name, email or payment-card details from SnackScore.
- Apple - the App Store and subscription billing. Apple's DeviceCheck confirms a free scan comes from a genuine device. When StoreKit supplies it, the signed AppTransaction's
appTransactionIdestablishes the app-scoped free-quota principal. The device-verification UUID is used only to validate Apple's signed challenge and is then discarded. These signals are used for app functionality and abuse prevention, not tracking.
Web search
When a product is not found in Open Food Facts, SnackScore asks its AI provider to search the public web (for example, the manufacturer's site or a retailer) for that product's real ingredients and nutrition, and shows you the sources it used. Most web lookups send the product name and brand. If those fail and you uploaded a photo, a last-resort photo rescue may also send the product photo so the provider can confirm the exact visible product. Your scan history and personal identity are not sent for this lookup.
Retention
Photo handling. SnackScore does not write a scanned photo to its own database, cache or logs. The photo is transmitted to OpenAI to answer the request. SnackScore requests no Responses API application-state storage (store: false), but OpenAI's standard API controls may retain request content in abuse-monitoring logs for up to 30 days, unless shorter-retention or Zero Data Retention controls apply. OpenAI may retain content longer when legally required or for the limited safety-review cases described in its API data-controls policy.
Product results are cached; you are not. To make scans faster and cheaper for everyone, the scored result for a product - its product name, score, cleaned-up ingredient list and nutrition summary - may be kept in a server-side cache for up to 30 days. That shared cache is keyed to the product itself (its barcode or identity), not to you or your device. It does not contain request quota data, uploaded photos, visible OCR text, the anonymous install identifier or other information about who scanned the product. Our service logs do not retain what products you scanned.
Lost-response retry record. To prevent a cancelled or interrupted retry from being processed and counted twice, our service may retain the exact completed response for up to 15 minutes. Its key is scoped to the anonymous install identifier, a random request identifier and the normalized request facts, so only the same logical request can replay it. It is transient retry state, not a browsable or persistent scan history, and it does not contain the uploaded photo.
Anonymous scan counts on our service expire automatically. Paid monthly allowance records use the random install identifier and expire after about 35 days; per-install daily web, provider and rescue controls use it for up to about 2 days. Free monthly allowances instead use the pseudonyms described next and also expire after about 35 days. When Apple proof is available, the service first validates the signed AppTransaction and its device challenge, discards the raw signed transaction and app-specific device-verification UUID, and stores only a salted, non-reversible pseudonym derived from signed appTransactionId. For compatibility when proof is unavailable, it stores the allowance under a server-HMAC pseudonym derived from the random install identifier. After an install has supplied valid Apple proof, a separate HMAC-keyed mapping keeps that install on the same Apple-derived allowance during later proof omissions; the mapping expires 400 days after the install's last free-tier request that uses it. Separate daily abuse counters retain only a salted, non-reversible network-source hash, not the raw address. Apple's DeviceCheck service separately confirms the request comes from a genuine Apple device - SnackScore does not read or write either DeviceCheck bit. To limit subscription-identifier sharing, our service may keep salted, non-reversible hashes derived from the anonymous install identifier and a RevenueCat alias. Those alias anti-replay bindings expire on a rolling 35-day schedule; raw aliases are not stored in those binding records. A direct positive paid-tier cache, keyed by the random install identifier, may be kept for up to 15 minutes. A restored-alias verdict may also be copied once to the current anonymous install for up to 5 additional minutes, so paid behavior may persist for about 20 minutes after server-side access is switched off; copied verdicts cannot be transferred again. Your on-device history is kept until you delete it or delete the app; the separate retry record above expires automatically.
Your choices
- You choose what to scan; you can use a typed name or a barcode instead of a photo at any time.
- Deleting the app removes your on-device data (history, saved products, settings). The keychain install identifier may persist for subscription continuity. When Apple proof is available, free limits remain tied to its app-scoped, server-pseudonymized AppTransaction principal; older versions and temporary proof omissions use the install-based compatibility pseudonym described above.
- You can clear your scan history in the app's Settings at any time, and export it as a JSON file from there.
- For any question or a data request, contact us at the address below.
Who is responsible (data controller)
SnackScore is operated by its developer under the name Tactical Code Works, based in Luxembourg, who acts as the data controller for the limited processing described here. For anything in this policy, including data requests, contact tacticalcodeworks@hotmail.com.
Legal basis (EU/EEA users)
Where the GDPR applies, we process the data described above on these bases: performance of a contract (Art. 6(1)(b)) - identifying and scoring the food you ask us to score, and metering the free and paid scan allowances; and legitimate interest (Art. 6(1)(f)) - preventing abuse of the free tier and keeping the service secure. We do not use your data for advertising, tracking or profiling, and we do not sell it.
International transfers
Cloudflare, OpenAI and RevenueCat are US companies, so the limited data described above - for example a food photo sent for identification or an anonymous subscription identifier sent to RevenueCat - may be processed in the United States. Transfers are protected through the providers' applicable transfer mechanisms, such as the EU-U.S. Data Privacy Framework or Standard Contractual Clauses. Requests are encrypted in transit. OpenAI's processor retention and the pseudonymous server-side caches, counters and anti-replay bindings are described under Retention.
Your rights (EU/EEA users)
You have the rights of access, rectification, erasure, restriction, portability and objection over personal data we hold. In practice almost everything lives on your device, under your direct control: your scan history and saved products never leave it, and most settings remain local. Your selected goal is sent with a scoring request as described above. You can view, export or delete your local history in the app at any time. Server-side data is limited to anonymous, expiring scan counters, product-keyed result caches, the request-scoped 15-minute retry record, a short paid-tier cache and the salted anti-replay hashes described above. If you contact us with a data request we will help with whatever is technically possible. You can also lodge a complaint with your supervisory authority - in Luxembourg, the CNPD (cnpd.public.lu).
Security
Data in transit is protected with TLS. On-device data is protected with iOS file protection. Secret keys (AI provider) are held only on our secure service, never in the app.
Not medical advice
SnackScore explains food quality, not your health. Scores are guidance, not a medical or dietary diagnosis. If you have a medical condition or allergy, check the actual packaging and a qualified professional.
Children
SnackScore is not directed at children and does not knowingly collect data from children.
Changes
We may update this policy; the date at the top reflects the latest version.
Contact: tacticalcodeworks@hotmail.com · See also Terms and Support.