Privacy Policy
Effective date: July 29, 2025
This Privacy Policy ("Policy") describes how ScanFood.AI ("Data Controller", "we", "us") collects, processes, stores, and protects personal data when you use the ScanFood.AI service ("the Service").
1. Definitions
- Personal Data — any information relating to a directly or indirectly identified or identifiable individual.
- Processing — any operation performed on personal data, including collection, recording, systematization, accumulation, storage, modification, extraction, use, transfer, anonymization, blocking, deletion, and destruction.
- Data Subject — the individual whose personal data is being processed.
- Service — the ScanFood.AI platform for nutrition tracking and calorie analysis, accessible via the Telegram bot at @ScanFoodAI_bot.
- Website — the web pages at https://scanfood.ai and its subdomains.
2. General Provisions
This Policy defines the Data Controller's actions regarding the processing of personal data, the procedures for such processing, and the measures taken to ensure data security and prevent unauthorized access.
By using the Service — including launching the Telegram bot, submitting information, or making a payment — you consent to the collection and processing of your personal data as described in this Policy.
3. Information We Collect
We collect and process the following categories of personal data:
3.1 Data provided directly by you
- Telegram username and user ID (chat_id)
- Name (first name as provided by Telegram)
- Age, gender, height, weight, activity level — for calculating personalized calorie and macronutrient targets
- Goal (weight loss, maintenance, or gain) — for personalization
- Food photos submitted for analysis
3.2 Data generated through your use of the Service
- Food analysis history and diary entries
- Saved meal plans, recipes, and preferences
- Interaction history with the Telegram bot
3.3 Data collected automatically
- Browser type and version (on the Website)
- Device information
- Language preference
- Anonymized page views and interactions via privacy-respecting analytics
4. Purposes of Data Processing
We process your personal data for the following purposes:
- Service delivery — providing AI-powered calorie and nutrition analysis, maintaining your food diary, generating meal plans and recipes
- Contract fulfillment — processing orders, managing subscriptions, and providing customer support
- Personalization — tailoring recommendations based on your goals, preferences, and dietary profile
- Service improvement — analyzing usage patterns and collecting statistics to improve the accuracy and quality of the Service
- Communications — sending service-related notifications and, with your consent, promotional materials
5. How We Obtain Your Data
Personal data is obtained through:
- Information you enter in the Telegram bot or on the Website
- Data transferred as part of the contractual relationship
- Automatic data collection during your use of the Service
Consent to data processing is given through actions such as launching the bot, pressing buttons (e.g., "START", "Submit"), or making a payment.
6. Data Storage and Retention
- Food photos are processed in real-time for nutritional analysis and are not stored permanently after processing is complete.
- Diary data, preferences, and usage history are retained for up to 1 year after the completion of the contractual relationship, or until you withdraw consent.
- Data is stored on secure servers with appropriate technical and organizational safeguards.
7. Your Rights
As a Data Subject, you have the right to:
- Obtain information about what personal data we hold about you
- Request correction, blocking, or deletion of your personal data
- Withdraw your consent to data processing at any time
- Export your food diary data
- Lodge a complaint with a supervisory authority regarding our data processing activities
To exercise any of these rights, contact us at [email protected] or through the Telegram bot.
8. Third-Party Services
We use the following third-party services:
- Telegram Bot API — for bot communication and user interaction
- AI providers — for food image recognition and nutritional analysis
- Paddle.com (Merchant of Record) — Paddle acts as our online reseller and processes all payment transactions. Paddle collects your financial and payment information (credit card details, billing address, payment method) directly on their secure checkout page. ScanFood.AI does not receive or store your credit card numbers. From Paddle, we receive only your email address, country of purchase, and transaction details. Paddle is fully PCI DSS and GDPR compliant. For more information, see Paddle's Privacy Policy.
- Analytics services — for anonymized website usage statistics
Personal data is shared with Paddle for order processing, product fulfillment, fraud prevention, and customer support under legitimate interest. Otherwise, personal data is not shared with third parties without your consent, except as required for Service delivery or by applicable law.
9. Data Security
We implement appropriate legal, organizational, and technical measures to protect your personal data against unauthorized access, loss, alteration, or destruction.
In the event of a security incident that may affect your rights:
- The relevant regulatory authority will be notified within 24 hours
- Investigation results will be reported within 72 hours
10. Cessation of Processing and Data Destruction
Processing of personal data ceases and data is destroyed in the following cases:
- The purpose of processing has been achieved — within 30 days
- Consent has expired — within 30 days
- Unlawful processing is identified — within 3 business days
- You withdraw your consent — within 30 days of receiving the request
To withdraw consent, submit a written request to [email protected].
11. Cookies
Our Website uses only essential cookies required for functionality. We do not use tracking cookies or sell data to advertisers.
12. Children's Privacy
ScanFood.AI is not intended for children under 13. We do not knowingly collect personal data from children under 13 years of age.
13. Changes to This Policy
We may update this Policy at any time. Changes take effect upon publication on the Website and in the Telegram bot. Your continued use of the Service after changes constitutes acceptance of the updated Policy.
14. Contact
For privacy-related questions or requests regarding your personal data, contact us at [email protected] or via our Telegram bot.