Privacy Policy

Effective Date: September 12, 2026

Ingredio ("the App") is developed by Yingying Zhu ("we", "us", or "our"). This Privacy Policy explains the information processed when you use Ingredio, why it is processed, and the choices available to you.

1. Information We Process

Account Information

Ingredio uses Sign in with Apple. We receive a stable, app-specific Apple account identifier and, if you choose to share it, an email address that may be an Apple private relay address. We also process authentication tokens. We do not receive your Apple password or your Apple ID credentials.

Device and Service Information

The App sends an app-scoped device identifier (Apple's identifier for vendor) and platform value when creating or refreshing a session. We use these for session management, service security, and abuse prevention. Operational server logs may include an IP address, the app-scoped device identifier, request path, response status, and timing information.

Ingredient-Label Content

The App first performs optical character recognition (OCR) on your device. To structure the result and provide ingredient references, it sends the recognized label text and your selected display language to our server. For barcode scans, the App may also send product name, ingredient-list, nutrition, and reference fields returned by Open Food Facts. When on-device OCR confidence is very low, the App may send a compressed copy of the label image for image-assisted processing. Your personal watchlist keywords are not included in this processing request; watchlist matching occurs in the App.

Scan History and Preferences

Scan history, saved product labels, scan images, watchlist choices, and results are stored locally on your device. Scan content is transmitted only when you initiate processing as described above.

Usage Counters

We retain per-account request and token-usage counters, including daily and short-window totals, to operate quotas, prevent abuse, and protect service capacity. These counters do not contain the label text or image.

Purchase Information

Subscriptions are processed by Apple through StoreKit. The App receives verified entitlement and transaction status needed to unlock features. We do not receive your payment-card number or billing address.

2. How We Use Information

Ingredio does not determine whether a product is safe, healthy, or suitable for an individual. OCR and reference data may contain errors; always verify the complete product label yourself.

3. Service Providers

Apple — Apple provides Sign in with Apple, StoreKit subscriptions, and App Store distribution. See Apple's Privacy Policy.

Microsoft Azure and Azure OpenAI — Our application service is hosted on Microsoft Azure. The recognized label text, optional barcode context, and a compressed label image only when OCR confidence is very low are processed through Azure OpenAI to produce a structured result. We do not send your personal watchlist to Azure OpenAI. Microsoft processes this content on our behalf under our service configuration and its applicable terms. See the Microsoft Privacy Statement.

Open Food Facts — When a barcode is detected, the App may query the Open Food Facts public database. The barcode and standard network information needed to make the request are sent to that service. See the Open Food Facts privacy information.

4. Advertising, Analytics, and Tracking

We do not use advertising SDKs, cross-app tracking, or third-party product-analytics SDKs. We do not sell personal information or share scan content for advertising. The App's internal analytics facade currently records privacy-safe event names only in local diagnostic logs and does not transmit those events to an analytics service.

5. Storage and Retention

Your scan history, images, watchlist, and preferences remain on your device until you delete them or uninstall the App. Our application database does not persist the OCR text, barcode context, or label image submitted for a scan after the processing request completes. Processing providers and network operators may handle request content and technical metadata under their applicable terms and our service configuration.

Account identifiers, an optional email address, authentication records, device/session information, subscription state where applicable, and usage counters are retained while the account is active. Operational security logs are kept only as reasonably necessary to operate, secure, and troubleshoot the service.

6. Security

We use transport encryption, authenticated API requests, access controls, and service rate limits. No system can guarantee absolute security, and you should avoid scanning information that is not needed to use the ingredient-label feature.

7. Children's Privacy

Ingredio is not directed to children under 13, and we do not knowingly collect personal information from children under 13.

8. Your Choices and Account Deletion

You can delete local scan history from Settings. Uninstalling the App removes locally stored App data, subject to Apple's device and backup behavior.

You can request account deletion in Settings → Delete Account. We immediately sign you out, revoke active App sessions, and mark the account for deletion. The account identifier, identity binding, optional email, Apple authorization token where available, subscription state, and usage counters may be retained for up to 30 days to prevent quota abuse and permit account restoration if you sign in again during that period. After the period expires, the account and associated server database records are deleted and we attempt to revoke the Sign in with Apple authorization. You may also contact us using the address below.

9. International Processing

Our service providers may process information in the United States or other locations where they operate. Their privacy and security obligations are governed by our service configuration, applicable agreements, and applicable law.

10. Changes to This Policy

We may update this Privacy Policy as the App or its data practices change. We will post the revised policy here with a new effective date.

11. Contact Us

For privacy questions or requests, contact:
ericopcalvin@outlook.com