ScanSafe

Privacy Policy

Privacy First

Your Privacy is Our Priority

ScanSafe is built on a simple principle: your data belongs to you. We scan products so you can stay safe — not to build profiles or sell your information.

Effective Date March 24, 2026
Last Updated March 24, 2026
Developer Craftura / Carlos Filipe
Website scansafe.pro

What We Collect

  • Camera access (scanning only, never stored)
  • Scanned product history (local device)
  • Email address (if you create an account)
  • Anonymous usage analytics

What We Never Collect

  • Location / GPS data
  • Contacts or address book
  • Microphone access
  • Photos or camera roll
  • Advertising identifiers
  • Financial data (handled by Stripe)
🇪🇺

GDPR Compliant — EU Users Protected

ScanSafe fully complies with the General Data Protection Regulation (GDPR). EU and EEA users have the right to access, rectify, erase, and port their data. We never engage in automated profiling or sell personal data to third parties.

Section 01

Introduction

This Privacy Policy explains how ScanSafe ("the App," "we," "us," or "our") — developed by Carlos Filipe / Craftura — collects, uses, and protects your information when you use the ScanSafe mobile application and related services.

By using ScanSafe, you agree to the data practices described in this Privacy Policy. If you do not agree, please discontinue use of the App.

ScanSafe is a product safety scanner. Its sole purpose is to help you identify harmful ingredients, allergens, and substances in everyday products. We are not in the data business — we are in the safety business.
Section 02

Information We Collect

We collect only the minimum information necessary to provide ScanSafe's core features.

Data Type Purpose Stored? Location
Camera feed Real-time barcode scanning Never stored Device only, in-memory
Scanned products Build your scan history Local device On-device storage (SQLite)
Email address Account creation & login Cloud (optional) Encrypted cloud database
Subscription status Premium feature access Stripe-managed Stripe secure servers
App usage analytics Improve app performance Anonymous Aggregated, non-identifiable

We do not collect device fingerprints, advertising IDs (IDFA/GAID), location coordinates, microphone recordings, photo library contents, or contacts.

Section 03

How We Use Your Information

Your data is used solely to power ScanSafe's features:

Section 04

Third-Party Services

ScanSafe integrates with the following trusted third-party services. Each operates under its own privacy policy:

🥫

Open Food Facts

Open-source food product database used to retrieve ingredient and nutritional data. No personal data is shared — only the scanned barcode number is queried.

View Open Food Facts Privacy Policy
🤖

Anthropic / Claude AI

AI-powered ingredient analysis. When you request an AI analysis, the product's ingredient list is sent to Claude. No personal information, account data, or device identifiers are included in these requests.

View Anthropic Privacy Policy
💳

Stripe

All subscription payments are processed by Stripe, a PCI DSS Level 1 certified payment processor. ScanSafe does not store payment card details. Stripe may collect billing name, address, and payment method information subject to its own privacy policy.

View Stripe Privacy Policy

We do not integrate with advertising networks, social media trackers, or data brokers. No personal data is sold to or shared with any third party for commercial purposes.

Section 05

Data Storage and Security

Primary storage is on-device. Your scan history, preferences, and cached product data are stored locally on your device using encrypted storage. This data does not leave your device unless you explicitly enable cloud sync.

Cloud sync (optional): If enabled, your scan history is encrypted end-to-end before being transmitted to our secure cloud infrastructure. We use industry-standard AES-256 encryption in transit (TLS 1.3) and at rest.

Account data: If you create an account, your email and hashed password are stored on our servers in the European Union. We never store plaintext passwords.

Data minimization: We automatically delete inactive account data after 24 months of inactivity. Scan history older than 12 months may be pruned from cloud sync while remaining on-device unless you delete it.

Security practices: Our infrastructure undergoes regular security audits, penetration testing, and automated vulnerability scanning. All servers are hardened with encrypted storage, VPN-only administrative access, and intrusion detection systems.

Section 06

Your Rights (GDPR — EU/EEA Users)

If you are located in the European Union or European Economic Area, you have the following rights under the General Data Protection Regulation (GDPR):

Right to Access

Request a copy of all personal data we hold about you.

Right to Rectification

Correct any inaccurate or incomplete personal data.

Right to Erasure

Request deletion of your personal data ("right to be forgotten").

Right to Portability

Receive your data in a structured, machine-readable format.

Right to Object

Object to processing of your data for specific purposes.

Right to Restrict

Limit how we process your personal data in certain circumstances.

Right to Withdraw Consent

Withdraw consent at any time for consent-based processing.

Right to Complain

Lodge a complaint with your local Data Protection Authority (DPA).

To exercise any of these rights, contact us at hello@craftura.net. We will respond within 30 days. No fees apply for standard requests.

The legal basis for processing your personal data is:

Section 07

Children's Privacy

ScanSafe is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us immediately at hello@craftura.net and we will promptly delete such information.

Users between 13 and 16 in the EU require parental consent under GDPR Article 8 before creating an account.

Section 08

Cookies and Tracking

The ScanSafe mobile app does not use tracking cookies. The ScanSafe website (scansafe.pro) may use essential cookies for session management and optional analytics cookies, subject to your consent via our cookie banner.

We do not use:

Section 09

International Data Transfers

ScanSafe is developed by Carlos Filipe / Craftura, based in Malta, European Union. Our primary infrastructure is located within the EU.

When product data is sent to Claude AI (Anthropic, US-based) for analysis, this represents a transfer outside the EU. This transfer occurs under Anthropic's Standard Contractual Clauses and Binding Corporate Rules, which provide adequate safeguards under GDPR Article 46.

Payment data handled by Stripe may be processed in the United States. Stripe operates under the EU-US Data Privacy Framework and Standard Contractual Clauses.

Section 10

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

Continued use of ScanSafe after any changes constitutes acceptance of the updated Privacy Policy. We encourage you to review this page periodically.

Section 11

Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out:

Carlos Filipe — Craftura

Data Controller & Developer

Email: hello@craftura.net

Website: scansafe.pro

We aim to respond to all privacy inquiries within 5 business days, and GDPR requests within 30 calendar days.