Privacy Policy

Last updated: September 12, 2026

SafePlate is published by Finn Digital LLC. This policy covers the SafePlate iOS and Android apps and finndigital.net/safeplate. Features and storage differ by platform as described below. Contact [email protected] about privacy, access, correction or deletion.

Accounts and service identifiers

You can start without a personal sign-in. The app uses a Firebase anonymous account identifier for cloud requests, usage limits and service security. If you choose Google or Apple sign-in, Firebase also processes the provider identifier and any name or email the provider supplies. We do not receive your provider password. Service requests expose ordinary network information, including your IP address, to the services handling them.

Family profiles and scan history

Family profiles can contain names, birth dates, allergies, severity, custom allergens, selected health conditions, photos, preferred foods and emergency contact details. These are sensitive data. Only enter information you are authorized to manage, including information about a child in your care.

Android stores profiles in an app-private local database. Optional family backup requires personal sign-in and a separate “Enable backup” action. It uploads the profile fields, including an optional profile photo and emergency contact details, to your account in Google Firebase Firestore. Turning backup off stops future synchronization; it does not delete the existing cloud copy. Signing out leaves local family data on that device. Android does not use iCloud or Android automatic app backup. The iOS app uses local SwiftData storage; Apple device backup settings may apply.

Completed scans are saved locally. When personally signed in, scan history is automatically synchronized with Firebase; it is not conditional on a separate Save button. Records include the product, barcode, ingredient text, profile name, allergen findings, time and result. Android records may also include health-condition flags. Raw camera photos are not part of scan-history synchronization.

Android reaction-journal photos, EpiPen records, reminders, restaurant notes and cached menus are stored locally. Reminder notifications can be disabled in system settings. Recall notifications use Firebase Cloud Messaging and a device registration token associated with the app account.

Camera, photos and optional AI

Barcode detection and normal label text recognition run on the device. Product lookup sends the barcode to Open Food Facts and, through our authenticated server, USDA FoodData Central. Product-name search sends the words you enter to Open Food Facts. Food-name corrections send the food name to USDA through our server. These requests do not include the family profile or camera frames.

Optional cloud scanning sends the selected photo through our authenticated Google Cloud service to Gemini on Vertex AI to identify foods or read label text. The app asks for consent before cloud analysis. You can change consent in Profile. On Android, declining cloud analysis leaves barcode and local label scanning available; there is no offline food-photo recognition fallback.

The cloud scan request includes the app’s authentication token. Photos are processed for the requested analysis; SafePlate does not add these scan images to a photo library on our server. Google Cloud processing, security and abuse-monitoring retention may apply. We do not train models on your scans or profiles. See Google Cloud’s privacy notice. Profile photos uploaded with family backup are a separate, persistent use of photos.

Locations, recipes and shared cards

Restaurant search uses a city you enter or foreground location you authorize. Approximate or precise coordinates and restaurant queries are processed by Google Places through our server; Android map display uses Google Maps. System geocoding services may also process a city query. Location is optional; the app does not request background location. Recipe searches and recipe images use TheMealDB. Recall feeds use FDA and USDA FSIS sources.

Sharing a card or report sends the information you select to the recipient or app you choose. Allergy-card links contain the profile name, listed allergens, severity and optional emergency contacts. Anyone with the link can read that snapshot; links are not password protected and cannot recall copies already shared. New Android card links keep the payload in the URL fragment, which is decoded in the recipient’s browser. Older path-based links may include the payload in hosting logs. The card page does not fetch a profile photo or add analytics.

Purchases, diagnostics and analytics

Apple processes iOS payments and Google Play processes Android payments. We receive product, transaction and subscription-status information needed to verify access and restore purchases. We do not receive payment-card numbers or store-account passwords. Android verification binds purchases to a SafePlate account and retains hashed ownership records to limit purchase-token replay.

Android uses Firebase Crashlytics for crash reports, stack traces, device/app information and installation identifiers, and Firebase Analytics for app interactions and purchase events. These are pseudonymous identifiers, not a promise of anonymity. Android’s custom analytics excludes names, barcode values, ingredient text, allergy results, health-condition selections and free-text errors. iOS analytics may include feature interactions and selected health-rule categories. Firebase may process standard device and usage metadata. See Firebase privacy information.

SafePlate does not sell personal data, use third-party advertising SDKs, or use your family profiles and photos for advertising. Android does not request the advertising-ID permission.

Support and AI-result reports

If you contact us, we receive the message and contact details you provide. Android’s in-app AI reporting sends only the text you enter, the app account identifier, app version and submission time to Firebase for our review. No photo or family profile is automatically attached. Reports are not an emergency service; avoid including private details that are unnecessary to explain the issue.

Retention and deletion

Local data remains until you remove it, delete the account through the app, or clear/uninstall the Android app. Cloud profiles and history remain until deleted. Turning off backup or signing out does not erase stored cloud data. Deletion markers may remain to stop a removed profile from reappearing during synchronization. Shared exports and copies held by recipients are outside the app’s control.

Use Profile → Account → Delete account on Android, or the account-deletion control in the iOS Profile settings. You may need to sign in again. You can also request deletion without the app at Delete your SafePlate account and data. We verify ownership before acting on a request and aim to respond within 30 days. Request deletion of anonymous-account data by contacting us with available app/account details; do not send passwords or purchase tokens.

Limited transaction, fraud-prevention, security, backup and legally required records may remain where necessary. Provider-controlled diagnostic retention follows the provider’s settings and terms. Ask us which records apply to your request. Deleting SafePlate does not cancel a store subscription; cancel it through Apple or Google Play separately.

Children and changes

SafePlate is intended for adults managing their own or their family’s information, not for unsupervised use by children. Parents and guardians can request access, correction or deletion of information they manage. We update the date on this page when the policy changes.

SafePlate is an informational tool. It is not a medical device or a substitute for checking the manufacturer’s label and consulting a qualified medical professional. In an emergency, call local emergency services.