1. Introduction
AI Calorie Scanner - NutriSnap ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App").
Please read this Privacy Policy carefully. By using the App, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use the App.
2. Information We Collect
2.1 Information You Provide
The App allows you to manually enter or edit the following health and fitness information. This data is stored locally on your device and is not transmitted to our servers unless otherwise stated:
- Profile Information: Gender, age, height (cm), weight (kg), activity level, fitness goal (e.g., lose weight, maintain, gain weight).
- Dietary Records: Food names, portion sizes (grams), calorie counts, and nutritional breakdown (protein, carbohydrates, fat, fiber, sugar, sodium, calcium, iron, purine) for meals you log.
- Food Images: Photographs of food that you capture using the in-app camera or upload from your device's gallery for AI analysis.
2.2 Information Collected Automatically
| Category | Data Collected | Purpose |
|---|---|---|
| Device & Usage | Device model, OS version, screen resolution, app version | App functionality, crash reporting, analytics |
| Advertising ID | Google Advertising ID (resettable) | Delivering personalized advertisements via AdMob |
| Anonymous Identifier | Firebase Anonymous Authentication UID | Rate limiting, service abuse prevention |
| Language Preference | Selected language code | Displaying the app in your preferred language |
3. How We Collect Your Information
We collect information through the following methods:
- Direct Input: When you enter your profile details, dietary records, or adjust settings within the App.
- Camera & Gallery: When you take a photo of your food using the in-app camera or select an image from your device's gallery. Images are processed by Google's Gemini AI service to analyze nutritional content.
- Automated SDKs: Third-party software development kits (SDKs) integrated into the App automatically collect certain data as described in Section 5.
4. Permissions
Our App requires the following permissions to function properly:
| Permission | Purpose | Required? |
|---|---|---|
Camera (CAMERA) |
Take photos of food for AI-powered nutritional analysis | Yes (core feature) |
Internet (INTERNET) |
Communicate with Firebase services, Gemini AI, and AdMob | Yes (required) |
Media Images (READ_MEDIA_IMAGES) |
Select food images from your device gallery (Android 13+) | Optional |
External Storage (READ_EXTERNAL_STORAGE) |
Select food images from your device gallery (Android 12 and below) | Optional |
You can manage these permissions through your device settings at any time. Disabling camera permission will prevent the core food scanning feature from working.
5. Third-Party Services & SDKs
We integrate several third-party services to provide core features. Each service processes data according to its own privacy policy:
| Service | Provider | Purpose | Data Shared | Privacy Policy |
|---|---|---|---|---|
| Firebase Authentication | Google LLC | Anonymous user identification for rate limiting | Anonymous UID (no email/password) | Firebase Privacy Policy |
| Firebase Firestore | Google LLC | Store rate-limiting metadata (scan counts, timestamps) | Anonymous UID, daily scan/advice counts, timestamps | Firebase Privacy Policy |
| Firebase Remote Config | Google LLC | Server-side configuration of rate-limit thresholds | Device app instance identifier | Firebase Privacy Policy |
| Firebase App Check | Google LLC | Protect backend resources from abuse | App integrity attestation data | Firebase Privacy Policy |
| Google Gemini AI (Vertex AI) | Google LLC | AI analysis of food images to identify food and estimate nutritional content; generate dietary advice | Food images (bitmaps), dietary record summaries | Gemini API Data Governance |
| Google AdMob | Google LLC | Serve advertisements (App Open, Interstitial, Banner, Native) | Advertising ID, device info, IP address | Google Privacy Policy |
| CameraX | Google LLC (AndroidX) | In-app camera functionality | None (all processing on-device) | — |
| Coil | Open-source (instacart) | Image loading and caching in the UI | None | — |
| Room Database | Google LLC (AndroidX) | Local storage of dietary records and scan history | None (all data stored on-device) | — |
6. Advertising
Our App displays advertisements through Google AdMob, which uses the following ad formats:
- App Open Ad: Shown when the app is opened or resumed.
- Interstitial Ad: Shown between sessions, with a minimum 60-second interval between displays and a cap of 3 displays per session.
- Banner Ad: Displayed at the bottom of the screen on certain pages.
- Native Ad: Displayed as in-content card ads on the home screen.
AdMob may use your device's Advertising ID to deliver personalized ads. You can opt out of personalized advertising in your device settings (Settings → Google → Ads → Opt out of Ads Personalization).
7. How We Use Your Information
We use the collected information for the following purposes:
- Provide Core Functionality: Analyze food images using AI to identify food items and estimate nutritional content. Track your daily calorie and nutrient intake. Generate personalized dietary advice based on your eating history.
- Improve Our Service: Monitor app performance, diagnose technical issues, and analyze usage patterns.
- Rate Limiting & Abuse Prevention: Track daily scan and advice request counts to prevent service abuse.
- Advertising: Display third-party advertisements.
8. Data Storage & Security
8.1 Local Storage
We use the following local storage mechanisms:
- Room Database (SQLite): Stores your dietary records, scan history, and nutritional data on your device.
- SharedPreferences: Stores your profile information (gender, age, height, weight, activity level, goal), authentication UID, and language preference.
8.2 Cloud Storage
Only rate-limiting metadata (daily scan counts and timestamps) is stored in Firebase Firestore. Your dietary records, profile information, and food images are not uploaded to cloud servers by us — they remain on your device.
8.3 Data Security
We implement appropriate technical and organizational measures to protect your information, including encrypted communications via HTTPS/TLS for all network requests. However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
8.4 Data Backup
Android automatic backup for this app is disabled (allowBackup="false"). Your data is not included in Android's system backup.
9. Data Retention & Deletion
We retain your data as follows:
- Locally stored data (dietary records, profile, images): Retained on your device until you delete it or uninstall the App. You can delete individual records within the App at any time.
- Firestore rate-limit data (scan counts): Retained for as long as your Firebase anonymous account exists. This data contains only timestamps and counters — no personal information.
- Food images sent to Gemini AI: Google's Gemini API processes images in real-time and does not retain them after analysis is complete.
To delete all locally stored data, uninstall the App. To request deletion of Firestore rate-limit data, contact us at the email below.
10. Your Rights & Choices
Depending on your jurisdiction, you may have the following rights regarding your information:
- Access: Request a copy of the information we hold about you.
- Correction: Request correction of inaccurate information.
- Deletion: Request deletion of your information, subject to legal requirements.
- Opt-out of Advertising: Disable personalized ads via your device settings or by resetting your Advertising ID.
- Withdraw Consent: Revoke camera permission or other permissions through your device settings.
- Data Portability: Receive your data in a structured, commonly used format.
To exercise any of these rights, please contact us at the email address in Section 14.
10.1 GDPR (European Economic Area)
If you are located in the EEA, you have the right to lodge a complaint with your local data protection authority. Our legal basis for processing your data is your consent (Article 6(1)(a) GDPR).
10.2 CCPA (California)
California residents have the right to request disclosure of the categories and specific pieces of personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell your personal information.
10.3 LGPD (Brazil)
If you are located in Brazil, you have additional rights under the Lei Geral de Proteção de Dados, including the right to confirm the existence of data processing and to request anonymization or deletion of unnecessary data.
11. Children's Privacy
Our App is not intended for children under the age of 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete it. If you believe a child has provided us with personal data, please contact us.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top. Material changes will be communicated via an in-app notice.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:
Email: shanghejunda@gmail.com
We will respond to your inquiry within a reasonable timeframe, typically within 30 days.
14. Data Controller
For the purposes of applicable data protection laws, the data controller is the developer and operator of the AI Calorie Scanner - NutriSnap App. If you are located in the European Economic Area (EEA) or the United Kingdom, Google Ireland Limited processes certain data on our behalf through Firebase and AdMob services.