Last updated: August 19, 2026
The data controller is Iván Muñoz Ruiz, owner of ScanCal. You can contact us at support@scancal.app. We collect the information necessary to provide our services, including profile data (such as your name, email address and preferences) and eating habits. We only collect the minimum information required for the service to operate. Our collection methods include information you provide directly during registration and use of the application, as well as data generated automatically while you interact with our services.
Our application collects health and nutrition-related data solely to provide you with personalized nutritional information. Specifically, we collect: (1) Food images you upload for analysis, (2) Nutritional data about food consumed (calories, macronutrients, etc.), (3) Food consumption history, (4) Nutritional goals you set, and (5) Calories burned and step-count data from your device.
ScanCal uses third-party artificial intelligence services to provide features such as food recognition, recipe generation, meal suggestions and nutrition coaching. The AI providers we use are Google (Gemini) and OpenAI. Data that may be sent to these providers includes food images, nutritional goals and preferences, and the context of meals consumed during the day. Requests are designed not to include account data such as your name, email address, password or payment details; an image may nevertheless contain visual information you choose to capture. These requests are routed through our servers. You can review our providers' privacy policies at Google (https://policies.google.com/privacy) and OpenAI (https://openai.com/privacy).
On Android, only for production accounts whose account holder is at least 18 years old and only after you give express consent in the app, ScanCal may measure whether an installation is related to a ScanCal advertising campaign on Meta. This measurement is optional: you can use ScanCal without agreeing, and we do not access the Android advertising ID or send the event before your consent is saved. The legal basis is your consent, which you may withdraw at any time. If you agree, the app sends to the ScanCal API the Android advertising ID (AAID), when available and not limited; the advertising-limitation status; a random identifier for that installation; a technical event identifier; the installation date and time; the app and Android versions; and the version and date of your consent. The request uses your session so our servers can verify that the choice belongs to your account, that the person is an adult, and that the profile is a production profile. The ScanCal API sends to Meta Platforms Ireland Limited, through Meta’s Conversions API, only the AAID, random installation identifier, technical identifier and installation event date and time, app package and app and Android versions, and technical signals indicating that measurement was authorized. Meta may use these signals to attribute and measure ScanCal campaigns and to optimize, personalize, and deliver advertising under its Privacy Policy (https://www.facebook.com/privacy/policy/) and Meta Business Tools Terms (https://www.facebook.com/legal/terms/businesstools). ScanCal does not send Meta your IP address, name, email address, date of birth, ScanCal account identifier, profile, images, meals, or nutrition or health data.
We keep the current state of your choice, the text version and language, and the date of the change in your account while the account remains active. To demonstrate that consent was properly granted or withdrawn, we also retain a minimal history of those choices containing the account identifier, grant or withdrawal action, text version and language, server date and time, and authenticated request source. This history contains no AAID, IP address, device data, images, meals, or nutrition or health data. We retain evidence while consent is active and, after the latest withdrawal, for five calendar years for the establishment, exercise, or defence of legal claims. Deleting the account immediately removes the current state and this entire history. To prevent duplicates and allow safe retries, we retain a domain-separated SHA-256 digest of the event identifier, attempt count, timestamps, and a temporary random token: rows for sent events are deleted within no more than 90 days and unsent attempts within no more than 8 days from their first collection. This table contains no AAID, random installation identifier, account identifier, IP address, or content sent to Meta. The connection IP address is used transiently by the ScanCal API to prevent abuse: our code does not retain the raw IP address or include it in the event sent to Meta, and keeps a pseudonymous HMAC-derived value for no more than 24 hours to enforce request limits. Railway, our hosting provider, creates technical HTTP logs that may contain the IP address and user agent and retains them for up to 90 days depending on the contracted plan. Meta may retain Event Data for up to two years under its terms. You can decline or withdraw this permission under Profile > Privacy > Ad measurement with Meta. Withdrawal applies to your account, stops future sends, and does not limit any ScanCal feature; it does not erase data Meta has already received or aggregate reports already created. You can also reset or delete the AAID in Android privacy settings and manage your activity off Meta technologies in Meta Accounts Center (https://www.facebook.com/help/1224342157705160).
On iOS, only for production accounts whose account holder is at least 18 years old, ScanCal may optionally measure whether an installation is related to a ScanCal advertising campaign on Meta. The legal basis is your consent, expressed through Apple’s official AppTrackingTransparency (ATT) prompt without a custom ScanCal pre-prompt; versions that also support TikTok measurement use that one ATT prompt to identify both purposes, although ScanCal keeps each provider’s authorization separate. To evidence the Meta choice and apply a later withdrawal, ScanCal stores an authorization receipt in your account under version meta_ads_ios_idfa.v1. Before accessing Apple’s Identifier for Advertisers (IDFA), ATT must be authorized. Not authorizing it does not limit any feature. ScanCal checks ATT status immediately before reading the IDFA and sending the signal to our API; if the status is not authorized or the IDFA is missing, invalid, or all zeros, the event is not sent. If ATT is authorized and you have not turned off measurement in ScanCal, the app sends over HTTPS exclusively to the dedicated host https://meta-events.scancal.app the IDFA, a random installation identifier, a technical event identifier derived from it, the installation date and time, the app build number and version, the iOS version, the version and date of the authorization receipt, and the signal that ATT is authorized. The request uses your session only so the ScanCal API can verify that the receipt belongs to your account, that the person is an adult, that the profile is a production profile, and that the exact authorization receipt matches. The ScanCal API sends to Meta Platforms Ireland Limited, through Meta’s Conversions API, only the IDFA as an advertising identifier, random installation identifier, technical identifier and event date and time, fixed app identifier, app build number and app and iOS versions, and technical signals indicating that measurement was authorized. ScanCal does not send Meta your IP address, ScanCal account identifier, name, email address, phone number, date of birth, profile, images, meals, or nutrition or health data. ScanCal does not integrate the Meta SDK for this flow, access or send Apple’s Identifier for Vendors (IDFV), or create a device fingerprint; it also does not send Meta your device’s user agent, URL, install referrer, device model, carrier, locale, time zone, screen, or device-storage information. Meta may use the event to attribute and measure ScanCal campaigns and to optimize, personalize, and deliver advertising under its Privacy Policy (https://www.facebook.com/privacy/policy/) and Meta Business Tools Terms (https://www.facebook.com/legal/terms/businesstools). The current state and minimal history of this iOS authorization are stored separately from Android and follow the same minimization, account-deletion, and retention rules described in the previous section: the history contains neither the IDFA nor event data and, after the latest withdrawal, may be retained for five calendar years. You can stop future sends under Profile > Privacy > Ad measurement with Meta or disable ATT in iOS privacy settings. Either action stops future iOS sends and does not erase events Meta has already received or aggregate reports already created. Attribution through Apple’s SKAdNetwork remains independent of ATT and this IDFA-based measurement: Apple may generate aggregated, privacy-preserving postbacks without disclosing the IDFA to ScanCal.
Only for production accounts whose account holder is at least 18 years old and only after a TikTok-specific authorization, ScanCal may use the TikTok Business SDK to measure ScanCal campaigns. This authorization is separate from Meta authorization and its legal basis is your consent. On Android, when the current Meta and TikTok contracts are both available after onboarding and neither choice has been resolved yet, ScanCal displays one joint choice for both providers but stores independent receipts. If the Meta choice was already resolved, TikTok is unavailable, or its receipt cannot be confirmed, TikTok remains disabled and can be expressly enabled only under Profile > Privacy > Ad measurement with TikTok. On iOS, ScanCal uses only Apple’s official AppTrackingTransparency (ATT) prompt without a custom pre-prompt. A pre-existing ATT authorization, or an older receipt that covered Meta only, does not authorize TikTok. When this version initiates a new ATT prompt whose text identifies Meta and TikTok and you tap Allow, ScanCal may store a separate TikTok receipt within that same flow. Declining measurement does not limit any feature. ScanCal does not request SDK initialization or provide it with business events before the TikTok-specific authorization is active; on iOS it also requires ATT to remain authorized, and on Android it respects an unavailable or restricted advertising identifier. On iOS, TikTok’s library is linked into the app and its load-time code may run when the process starts before initializeSdk: depending on the vendor version, it may intercept or temporarily store in UserDefaults the opening URL or source and metadata from a notification or shortcut launch. ScanCal does not add those values to InstallApp or Registration or request that they be sent as business-event properties. After the first authorized initialization, ScanCal manually records InstallApp and, only after a registration completes successfully and while authorization remains active, Registration. Those are the only business events manually added by ScanCal’s bridge. The configuration disables automatic install, launch, retention, purchase and subscription events, Enhanced Data Postback and TikTok SKAdNetwork support; ScanCal also does not invoke the SDK’s identify or advanced-matching functions. On iOS, both automatic tracking and payment tracking are disabled before SDK initialization. On Android, ScanCal uses the SDK’s public control to disable automatic purchase measurement, and this option must also remain disabled in TikTok Events Manager. Version 1.7.0 of the Android SDK treats that control as a preference coordinated with remote configuration: its billing code may inspect or temporarily cache Google Play metadata even though ScanCal does not intentionally request or emit Purchase events. This technical observation does not initiate, validate, cancel, restore or modify purchases or subscriptions. RevenueCat and the store remain the sole authorities for checkout and access rights. The official SDK may perform internal remote-configuration, diagnostics, monitoring, crash, security and lifecycle communications and temporarily retain technical data in its cache; those communications depend on TikTok and the SDK version and are not business events manually added by ScanCal. ScanCal does not manually invoke functions to provide the SDK with your account identifier, name, email address, phone number, date of birth, profile, images, meals, searches, free-form text, or nutrition or health data. Once initialized with permission, the SDK may transmit to TikTok InstallApp, Registration and their date and time; fixed app identifiers and its package or bundle; app version and build; operating-system platform and version; and technical device and connection context that may include device model, manufacturer on Android, language or locale, time zone, screen characteristics, user agent, the IP address visible to the server, IDFV on iOS, a technical identifier generated by the SDK, the Google Play install referrer or installer package on Android, and IDFA or AAID where the system permits it. TikTok may use these data for attribution, measurement, fraud prevention, reporting and advertising optimization under its Privacy Policy (https://www.tiktok.com/legal/page/eea/privacy-policy/en) and the applicable Business Products Terms (https://ads.tiktok.com/i18n/official/policy/business-products-terms?lang=en). ScanCal’s attribution module remains the only component authorized to write the SKAdNetwork conversion value.
ScanCal separately stores for TikTok the current state of your choice, platform, text version and language, and date of the change while your account remains active. We also keep a minimal history containing the account identifier, grant or withdrawal action, platform, text version and language, server date and time, and authenticated request source to evidence that choice. This history contains no IDFA, AAID, SDK identifiers, IP address, device context, events, images, meals, or nutrition or health data. We retain evidence while authorization is active and, after the latest withdrawal, for five calendar years for the establishment, exercise, or defence of legal claims; deleting your account removes the current state and this history from the server. On the device, ScanCal also retains an installation marker and an account-scoped Registration marker with the attempt date and status solely to prevent duplicate events. These local markers are not sent as properties to TikTok or the ScanCal API. The installation marker remains until the app’s data is cleared or it is uninstalled. After an account deletion initiated in this app is confirmed, ScanCal attempts to remove that account’s Registration marker and local consent barriers. Signing out does not remove the markers; withdrawing authorization clears its local consent barriers but preserves the Registration marker to prevent duplicate events after a later sign-in. If the account is deleted from another device or local cleanup fails, the markers may remain until the app’s data is cleared or it is uninstalled. You can decline or withdraw authorization under Profile > Privacy > Ad measurement with TikTok. Withdrawal immediately blocks new manual ScanCal calls to InstallApp or Registration and invokes the SDK’s public controls to disable tracking for that process, without limiting any feature. The official SDK does not provide a complete and immediate removal of every task or cache on every platform: until the app is fully closed and reopened, some internal telemetry or technical processing may continue, and data already observed or queued may remain temporarily in the SDK cache. Re-enabling measurement after withdrawal requires an app restart. Withdrawal does not cancel or modify purchases, subscriptions or rights managed through RevenueCat, and does not erase data TikTok has already received or aggregate reports already created. You can also prevent future access to the IDFA by disabling ATT for ScanCal in iOS settings, or reset, delete, or restrict the AAID in Android privacy settings.
We use your information to: (1) Personalize your experience and nutritional recommendations, (2) Improve our recognition and nutritional analysis algorithms, (3) Provide statistics and tracking of your eating habits, (4) Send you relevant notifications about your progress and goals, and (5) Improve the application's overall functionality.
We apply reasonable technical and organizational measures to reduce the risk of unauthorized access, alteration or disclosure. Communications with our services use HTTPS/TLS connections, we restrict operational access to the information required, and we review measures as the service changes. No Internet-connected system can guarantee absolute security.
We use infrastructure and service providers to host and process the data ScanCal needs. The location of processing may depend on the provider and service configuration; where applicable, international transfers use the mechanisms required by law. We retain data while you maintain an active account and for any additional period needed to meet legal obligations, resolve incidents or protect the service.
Under applicable law, you may request: (1) Access to personal and health data we store about you, (2) Correction of inaccurate information, (3) Deletion of your personal information, except where we must retain it for a legitimate obligation, (4) A portable copy of data where applicable, and (5) Withdrawal of consent to the processing of health data.
Our application offers automatically renewing premium subscriptions. Payments are processed securely through the Apple App Store or Google Play Store. We do not store credit-card information on our servers.
We will notify you of any significant changes to our privacy policy through in-app notifications and/or email.
We are committed to protecting your personal and health data and to being transparent about our practices.