Privacy Policy
Last updated: February 2026
Introduction
GlutenScan is a mobile application that uses artificial intelligence to detect gluten-containing ingredients from photos of product labels. This privacy policy explains how we collect, use, store, and protect your personal information when you use our service.
We are committed to protecting your privacy and being transparent about our data practices. This policy describes the minimal data we collect and how it is used to provide you with gluten detection services.
Data Controller: Delpha Labs, France
Contact: delphalabs@gmail.com
Legal Basis for Processing
We process your personal data under the following legal bases (as required by GDPR):
- Contractual necessity: Processing your photos for gluten detection and managing your account are necessary to provide the service you signed up for.
- Legitimate interest: We use anonymized analytics to improve the app's functionality and user experience.
- Consent: You consent to data processing when you sign in and use the service.
Data Collection
GlutenScan collects the following types of data:
- Photos: When you upload a photo of an ingredient label, we process the image using our AI service. Original full-resolution images are not stored on our servers. Only a compressed thumbnail may be saved for your scan history.
- User Account: If you choose to sign in, we collect your email address for account management purposes. This is stored securely using Firebase Authentication.
- Scan History: We may store information about your scans, including the thumbnail image, detected ingredients, and gluten verdict. This allows you to access your scan history within the app.
- Subscription Data: If you subscribe to GlutenScan Pro, your purchase is processed through Google Play or the Apple App Store. We do not directly collect or store your payment information.
- Analytics: We use anonymized analytics to understand how the app is used. We use Google Analytics on our website to understand traffic and usage patterns. This data is aggregated and cannot be used to identify individual users.
What we do NOT collect:
- Original full-resolution images
- EXIF metadata from photos (location, camera settings, etc.)
- IP addresses (beyond what is needed for rate limiting)
- Payment card details
- Health or medical records
- Personal information beyond what is necessary for the service
Data Usage
We use the data we collect for the following purposes:
- Gluten Detection: Your photos are sent to an AI service (OpenAI API) to read ingredient labels and detect gluten-containing ingredients. This is the core functionality of our service.
- Scan History: We store your scan history so you can access previously scanned products within the app.
- Service Improvement: We use anonymized analytics data to improve the app's accuracy and user experience.
- Account Management: Your email address is used to manage your account, enforce scan quotas, and provide customer support if needed.
Data Storage
All data is stored using Firebase (Google Cloud Platform) services:
- Location: Our Firebase project is deployed in the EU region (europe-west1) to ensure GDPR compliance and data residency requirements.
- Thumbnails: Small thumbnail images are stored in Firebase Storage and associated with your account.
- Scan Data: Scan results, timestamps, and metadata are stored in Firestore.
- Authentication: User account information is managed by Firebase Authentication.
All data is encrypted in transit and at rest using Firebase's built-in security measures.
Data Retention
- Scan data and thumbnails are retained until you delete them individually or delete your account.
- Account data is deleted immediately upon account deletion request.
- Analytics data is aggregated and anonymized and cannot be traced back to you.
We do not retain your data after account deletion. When you delete your account, all associated scans, thumbnails, and account information are permanently removed from our servers.
Data Sharing
We share data only with the following third-party services that are necessary to provide our functionality:
- OpenAI: Photos are sent to OpenAI's API for ingredient label reading and gluten detection. OpenAI's API terms state that data submitted via the API is not used for model training. We do not send any personal information beyond the image itself. OpenAI Privacy Policy
- Google (Firebase & Analytics): We use Google's Firebase services for data storage and authentication, and Google Analytics on our website to measure traffic. Google Privacy Policy
We do not sell your data to third parties. We do not share your personal information with advertisers, data brokers, or any other parties for marketing purposes.
Your Rights
You have the following rights regarding your personal data:
- Access: You can access all your personal data, including your scan history, through the app.
- Deletion: You can delete individual scans from your history at any time within the app.
- Account Deletion: You can delete your account and all associated data at any time.
- Rectification: You can request correction of any inaccurate personal data.
- Restriction: You can request that we restrict processing of your data in certain circumstances.
- Complaint: You have the right to lodge a complaint with a supervisory authority (in France, this is the CNIL — cnil.fr).
To exercise any of these rights, please contact us at delphalabs@gmail.com.
Children's Privacy
GlutenScan is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected data from a child under 13, please contact us at delphalabs@gmail.com and we will promptly delete it.
Security
We take security seriously and implement the following measures to protect your data:
- Authentication: All user accounts are protected by Firebase Authentication with industry-standard security practices.
- Secure API Endpoints: All API endpoints use HTTPS encryption to protect data in transit.
- Data Encryption: All data stored in Firebase is encrypted at rest using Google Cloud's encryption standards.
- Access Controls: Data access is restricted to authenticated users and scoped to their own account data only.
Medical Disclaimer
GlutenScan is an informational tool and is not a medical device. It should not be used as a substitute for professional medical advice, diagnosis, or treatment. The gluten detection results are generated by AI and may not be 100% accurate. Always consult your doctor or dietitian for medical decisions related to celiac disease or gluten intolerance.
Contact
If you have any questions, concerns, or requests regarding this privacy policy or how we handle your data, please contact us at:
Email: delphalabs@gmail.com
We will respond to your inquiry within 7 business days.
Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the new privacy policy on this page and updating the "Last updated" date.
Your continued use of GlutenScan after any changes to this privacy policy constitutes your acceptance of the updated policy.