Your data and privacy
Privacy Policy
Version 2026-08-31.
A closer look at how your data is handled.
1. Who we are
Ingredence is operated by AI Servise LLP, BIN 260340008494, registered at microdistrict Aksay-4, building 123, apt. 49, Almaty, Kazakhstan (“Ingredence”, “we”, “us”). For data-protection purposes, AI Servise LLP is the controller (operator under the Personal Data Law of Kazakhstan).
Ingredence is an information resource: a mobile application that decodes the information printed on a product's label — food, cosmetic or household-chemical — and presents information from published government regulations of the selected jurisdiction.
Contact: support@ingredence.com. The app itself also routes contact through the in-app feedback form, which reaches the same person.
2. Scope
This policy covers the Ingredence iOS application and the website at ingredence.com. Android and HarmonyOS builds do not exist yet; when they ship, this policy is updated before they are published.
3. The short version
- You can use the app without an account. A scan needs an anonymous session, and nothing else.
- Your allergens, your diet, your household members and your avoidances never leave your phone. They are matched against a scan result on the device, after the result comes back.
- Photographs of a label are cropped on your phone, stripped of metadata, and refused entirely if a face or a personal document is detected in them and cannot be masked.
- A label photo is deleted from our servers within an hour — unless the product was not in the catalogue yet, in which case the photo becomes part of the shared product catalogue, which the consent screen tells you before the first upload.
- We show no advertising, we sell no placement, and there is nothing in the app for an advertising network to profile.
- The website sets no cookies and runs no analytics.
4. Data inventory
This is the complete list of what exists. Each row was checked against the code, not against a template.
4.1 On our servers
| Datum | Why | Retention | Processor |
|---|---|---|---|
| Anonymous session id | Ties a scan to the device that made it, without an account | The session expires 24 hours after creation; the record remains until the scan or account it belongs to is deleted | Hosting provider |
| Scan record: state, product category, jurisdiction, barcode, ruleset schema version, correlation id, timestamps | Produce and re-serve the verdict; support requests | Until you delete the scan or your account | Hosting provider |
| Verdict: outcome, ruleset id and version, confidence, full result | Show the result and make it reproducible | With the scan | Hosting provider |
| Evidence and provenance of each fact used | Every field on the result screen can name its source | With the scan | Hosting provider |
| Scan audit events | Append-only audit trail. Stores hashes of payloads, never the payloads | With the scan | Hosting provider |
| AI cost ledger: model alias, token counts, latency, outcome | Cost control. Contains no prompts and no user text | Indefinite; not linked to any person once the scan is deleted | Hosting provider |
| Label photographs | The AI extractor reads the label from them | Deleted after 1 hour. A sweep every 15 minutes also removes uploads that were never attached to a scan | Hosting provider (storage), Google Cloud (reading) |
| A photograph of a product that was new to the catalogue, and the fact you contributed it | The product becomes recognisable instantly for everyone; you earn free scans | Kept as part of the catalogue. Disclosed on the consent screen before the first upload | Hosting provider |
| Consent receipts: type, version, granted or declined, locale, time, pseudonymous Support ID | Proof of what you were shown and what you answered | Terms-acceptance and score-publication receipts are retained after account deletion, linked only to the pseudonymous Support ID, as evidence of acceptance for legal claims; other receipts are erased with the account | Hosting provider |
| Account identity: provider (Apple or Google), the provider's subject id, e-mail as the provider returned it, verified flag, first and last seen | Sign you back into the same account | Until account deletion | Hosting provider; Apple or Google as identity provider |
| Account e-mail | Sign-in by e-mail code; welcome and deletion-receipt letters. Taken from the sign-in session, never typed into a profile field | Until account deletion, when it is erased | Hosting provider; Resend (delivery) |
| E-mail sign-in codes (hashed) | One-time sign-in | Short-lived, single use | Hosting provider; Resend |
| Nickname, its confusable-folded form, display name | Identify you in Community; prevent look-alike impersonation | Until account deletion | Hosting provider |
| Avatar: a generated seed, and — if you upload one — a 512×512 JPEG | Your picture in Community. Uploads are decoded and re-encoded on the server, which strips EXIF including location | Until you remove it or delete the account | Hosting provider |
| Attribution choice | Whether your nickname and scan history are shown to other people | Until account deletion | Hosting provider |
| Selected jurisdiction (two-letter country code) | Which country's rules to evaluate against | Until account deletion | Hosting provider |
| Subscription state: plan, period, expiry, Apple original transaction id, revocation time | Server-side proof of Premium, so the badge is true on every device | Until account deletion | Hosting provider; Apple |
| Personal score of a scan: value 0–100 and band (red/yellow/green) | Show your own result in your public history when attribution is ON. Computed on the device; the profile inputs and reasons behind it are never sent | With the scan | Hosting provider |
| Saved products | Your saved list | Until removed or account deletion | Hosting provider |
| Push device token, platform, locale, and which products this device watches | Tell you when the composition of a product you scanned yourself changes; at most one notification per device per week | Until notifications are turned off (the token is revoked, not deleted) or the account is deleted | Hosting provider; Apple (APNs) |
| Content reports and blocks: who reported what, reason, free-text note | Moderation | Erased within 30 days of account deletion; resolved reports kept no longer than needed for moderation | Hosting provider |
| Error reports you send from the app | Fixing wrong data. Free text, truncated to 4000 characters | Erased within 30 days of account deletion | Hosting provider |
| Cached external reference data about chemical compounds (ALETHEIA) | Avoid re-querying the source | 30 days. A cache of substance data, not of anyone's personal data | Hosting provider |
4.2 On your phone only
The following is stored by the app on the device and is never sent to our servers, never included in a scan request, and never published to Community. A score derived from these fields (the personal score value and band, section 4.1) may be transmitted and, with separate opt-in consent, published as described in section 7 — the underlying fields themselves remain on your device:
- your allergens;
- your diet, including religiously determined diets (halal, kosher, Jain, Buddhist vegetarian) — data about religious belief in the sense of GDPR Article 9, which is precisely why it stays on the device;
- ingredients you personally avoid;
- household member profiles (label, allergens, diet, avoidances);
- an elimination-protocol selection, if you use one;
- interface preferences, the free-scan counter, and which contributions were already credited.
The privacy export screen shows these profiles as counts, and says in as many words that they are not part of the server export.
4.3 What we never collect
- No precise location and no location history. The app may ask the system for a single location fix, and only when you tap the "use my location" row on the country step or in travel mode: those coordinates go to your phone's own geocoding service — Apple's on an iPhone, the one built into the device on Android — to be turned into a country name, are never stored and never sent to us — the only value that reaches us is the two-letter country code you then see and can change. Photograph metadata — including GPS — is stripped on the device before upload.
- No contacts, no calendar, no health data, no advertising identifier.
- No third-party analytics or advertising SDK in the app, and none on the website.
- No card numbers or payment credentials. Subscriptions are billed by Apple; we receive a transaction identifier and an expiry date, never a payment instrument.
5. Photographs of labels
- You are shown a consent screen before the first upload that names what is sent (cropped photographs of the label and the text recognised from them), why, who processes it, and for how long. Declining leaves everything on the device.
- The photograph is cropped to the packaging on the device, and re-encoded so that all metadata — EXIF, GPS, maker notes — is discarded.
- The device looks for faces and personal documents in the frame. If something is found and can be covered, it is painted over before upload; if it cannot be located precisely, the photograph is discarded and you are asked to retake it rather than uploaded as it is.
- The upload goes to a transient bucket and is deleted within an hour, unless the product was new to the catalogue, in which case the photograph becomes catalogue content as described above.
6. Accounts
An account is optional. It exists for Community, for a nickname, and for a subscription badge that other people can see.
- Identity is the provider's subject identifier, never the e-mail address. Signing in with Apple and signing in with Google on the same address creates two separate accounts; Apple relay addresses are treated as display data.
- The e-mail address shown in your account comes from the sign-in session and cannot be edited by hand.
- On the first sign-in for an account, one welcome e-mail is sent. Not on every sign-in.
- Anonymous work is not lost when you sign in: the same session is attached to the new account, so history, quota and a pending contribution survive.
7. Community
Community is opt-in and has no social graph: there are no followers, no people search, and no outbound links from a profile.
- The app calculates a personal score on your device and sends the score value (0–100) and its band (red/yellow/green) to our server. With attribution ON, those two fields are published with your nickname and scan in your public history. We do not receive the profile inputs or the reasons behind the score. Turning attribution OFF removes the score from public view. Publication of the personal score requires a separate opt-in consent.
- We do not display any personal score, Nutri-Score-derived number, or other score on the public Community showcase. A personal score may appear only in the relevant member's public scan history when that member has enabled attribution.
- With attribution on, your nickname appears on products you were first to bring into the catalogue, on the leaderboard and in the feed, and your scan history with verdicts is visible to other members. With it off, your contributions remain but your name is shown nowhere and your history is not published.
- Your avatar, if you upload one, is publicly readable by id — the same as in any messenger.
- Verdicts shown in another member's public history are shown as that person's result in their jurisdiction, not recomputed for yours.
- A report hides the reported content immediately, before any human has looked at it. Review is manual; there are no automatic account sanctions.
- A deleted account disappears from every public surface: the feed, the leaderboard, discovery attribution, public history, ambassador listings and avatar serving all exclude deleted users.
8. Who processes data for us
| Processor | What they do |
|---|---|
| Hosting provider (EU, Germany) | Application servers, database, object storage |
| Google Cloud | All AI models used for reading a label: Gemini directly, and Claude through Vertex AI. One processor for all models, by design |
| Resend | Transactional e-mail: sign-in codes, welcome letter, deletion receipt |
| Apple | Sign in with Apple; subscription billing and receipt validation; push delivery through APNs |
| Holistic Quality LLC (ALETHEIA) | Supplies reference data about chemical compounds shown in the “Risks” section. We send a substance identifier, not anything about you |
We do not sell personal data, and we do not share it for advertising.
9. International transfers
The operator is based in Kazakhstan. Personal data is processed on servers located in the European Union (Germany); AI label reading runs on Google Cloud; users may be in any of the countries the app supports. By creating a session or an account you consent to the cross-border transfer of your data to these servers, including transfer out of the Republic of Kazakhstan. Where GDPR/UK GDPR applies, transfers to processors outside the EEA/UK rely on the European Commission's Standard Contractual Clauses or an adequacy decision.
10. Legal bases
Where GDPR/UK GDPR applies, we rely on: performance of a contract (Art. 6(1)(b)) for analysing a scan, serving its result and operating your account and subscription; consent (Art. 6(1)(a)) for label-photograph upload (recorded as a receipt), composition-change notifications, Community participation and publication of your personal score; and legitimate interests (Art. 6(1)(f)) for security, abuse prevention and service diagnostics. Special-category data in the sense of Article 9 — your diet and allergens — is never processed by us, because it never leaves the device. Under the Personal Data Law of Kazakhstan, processing rests on your consent and on the performance of the service you requested, including consent to cross-border transfer (section 9).
11. Your rights, and what already works
Whatever the final legal analysis says, the following is already implemented and available to everyone, with or without an account:
- Export. Settings → Privacy → Export data returns everything the server holds for your session: every scan with its verdict, and every consent receipt. The same screen lists the profiles that live on the device, so nothing is silently omitted.
- Deletion. Settings → Delete account works from inside the app, with no e-mail link to click. Your account becomes inaccessible immediately: sessions are revoked, your e-mail address is erased, and the account vanishes from every public surface. Remaining production records are erased within 30 days; backup copies expire within 90 days and are not restored except for disaster recovery. A receipt e-mail follows; the deletion does not wait for it. A photograph you contributed to the product catalogue stays in the catalogue after your account is deleted — the product would otherwise stop being recognisable for everyone else — but it is de-identified: nothing links it to you or your account any more.
- Withdrawing publication. The attribution switch removes your name from Community without removing your contributions.
- Blocking and reporting are available on user content.
- Turning off notifications revokes the device token.
Depending on applicable law, you may additionally request access, correction, erasure, restriction, portability, or object to processing, and may withdraw consent at any time. Send requests to support@ingredence.com. GDPR/UK GDPR requests are answered without undue delay and normally within one month. You may complain to the supervisory authority in your country; Kazakhstan residents may also contact the competent personal-data authority of Kazakhstan.
11.1 U.S. state privacy rights
If you reside in California (CCPA/CPRA) or another U.S. state with a comprehensive privacy law (Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others), you have the rights those laws grant — to know, access, correct, delete, and obtain a portable copy of your personal information, and the right to non-discrimination for exercising them. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use it for targeted advertising or profiling — there is nothing to opt out of. We also do not knowingly sell or share the personal information of consumers under 16. To exercise any right, e-mail support@ingredence.com; we will verify your identity and respond within the period the applicable law sets (45 days under the CCPA, extendable once).
12. Retention summary
| Data | Kept |
|---|---|
| Label photographs (transient) | 1 hour |
| Photographs of a product new to the catalogue | Part of the catalogue, kept |
| Anonymous session | 24 hours, then expired |
| Scans, verdicts, evidence | Until you delete them or your account; after a deletion request, production records are erased within 30 days |
| Account fields | Until deletion; e-mail erased at deletion; residual records erased within 30 days |
| Backups | Isolated copies expire within 90 days; not restored except for disaster recovery |
| ALETHEIA compound cache | 30 days |
| Push delivery log | Until the account or the device registration is deleted |
13. Children
Ingredence is not designed for children and has no feature aimed at them. The App Store age rating is 12+ international, with regional exceptions set by Apple's rating system.
You must be at least 13 years old to use any networked feature of Ingredence — including anonymous scanning, uploading a photograph of a label, an account, or Community. Functionality that transmits no personal information may be used without an account, but a person under 13 may not use the Service. Where local law sets a higher age of digital consent (13–16 in EEA member states under GDPR Article 8) and we rely on consent, an account requires authorization by a parent or guardian.
We do not knowingly collect personal data from children under 13. If we obtain actual knowledge that we collected personal information from a child under 13 without valid parental consent, we stop processing it and delete it; if you believe a child has provided us personal data, contact support@ingredence.com. The sensitive on-device profile never reaches us regardless of age.
14. Security
Sessions are signed and expire. Access to a scan is checked against the session that owns it. Label uploads use pre-signed, time-limited URLs. Avatars are re-encoded rather than stored as received. Audit events store hashes, not payloads. AI provider keys exist only on the backend and are never present in the app.
No system is perfect; we describe what is built, not a guarantee.
15. The website
ingredence.com is a static site. It sets no cookies, embeds no analytics, no tracking pixels and no third-party scripts, and stores nothing in your browser. There is consequently no cookie banner and no consent to manage. If that ever changes, this section changes first.
16. Changes to this policy
The version date at the top changes whenever the text changes. Material changes will be announced in the app before they take effect.
17. Contact
support@ingredence.com. Inside the app, Settings → Community rules → Write to us reaches the same person.