Privacy Policy · Last updated: September 5, 2026
LuckyhanStudio ("we", "us", or "our") operates the Food Scanner application (the "App"). Food Scanner reads the ingredients, additives and nutrition information printed on food packaging through your camera, and explains what it finds. This Privacy Policy explains what happens to your information when you use the App.
By using the App, you agree to the practices described in this Privacy Policy.
Food Scanner is local-first. When you scan a label, the image is analysed on your phone. Text recognition, ingredient matching and the explanations you read all run on the device, from data shipped inside the App.
We never upload the picture. There is no account and no login. Scanning itself works with the device in airplane mode, and scanning history, if you keep it, is stored only on your device.
One feature is different, and it is the only one: if you turn on AI explanations and agree when asked, the text read from the ingredients panel is sent to our server to be explained. The photograph is still never sent. Section 3 sets out exactly what that feature sends, where it goes and what is kept; until you turn it on, nothing about your scans leaves the device.
We are aware that what a person scans can reveal a great deal — an allergy, a medical condition, a religious dietary rule, a pregnancy. The design answer to that is to receive as little as possible: everything the App can do without a server, it does without one, and the one feature that needs a server asks first and is given only the words printed on the packet.
The App can ask a language model to explain an ingredients list in plain words. This is the only feature that uses the internet, it is off until you agree to it, and you are asked before anything is sent for the first time. You can switch it off again at any time in Settings → AI explanations.
What is sent when you use it:
What is not sent: your photograph, your name, your email address, your account (there is none), your advertising identifier, and no hardware identifier of any kind. We do not ask for or store anything that identifies you as a person.
Where it goes. The request goes to our own service running on Cloudflare Workers, which passes the text to Google's Vertex AI to produce the explanation. Google processes it as our service provider and, under the Google Cloud terms that apply to Vertex AI, does not use it to train its models.
What we keep. We store the number of requests your installation made, the number of words processed, and the resulting cost, so we can keep the service running and within budget. We keep a short technical log of each request for up to 30 days for debugging. If you report an answer as wrong or offensive, we keep your report so we can look into it and improve the wording.
Daily limit. Use of this feature is capped per installation each day. The count is kept on our server, not in the App.
We do not collect anything that personally identifies you. Because the App has no account system and no backend server, there is no user profile, email address, photo, or scan history for us to receive.
Third-party SDKs used for advertising do collect limited technical data — see Section 5 below.
We do not use any information to build a profile of you, and we have no server-side database of users to build one from.
Google AdMob: The App displays banner, native, interstitial and app-open advertisements through Google AdMob. AdMob and its partners may collect device identifiers and other advertising-related data to serve and measure ads. See Google's Privacy Policy at policies.google.com/privacy and the list of AdMob ad technology partners at support.google.com/admob/answer/6128543.
Google User Messaging Platform (UMP): We use Google's UMP to obtain your consent for personalized advertising where required by law, including in the EEA/UK and other applicable regions. You can review or change your advertising-consent choice at any time from Settings → Privacy options inside the App.
Advertising is the only reason the App uses the network at all. The scanning feature itself never does.
Everything the App creates — your scan history and the settings you choose — lives on your device and is removed when you clear your history or uninstall the App. Because we do not operate a server that stores your content, we hold nothing on our side to retain or delete.
The App is an information tool, not a medical device, and it does not provide medical, dietary or nutritional advice. It reports what is printed on a label and what recognised public bodies have published about an ingredient, together with the source and the date that information was reviewed. It does not diagnose, treat or make recommendations, and it deliberately does not score foods as good or bad. If you have an allergy, an intolerance, or any medical condition affected by diet, rely on the packaging itself and on a qualified professional.
The App is not directed to children under 13, and we do not knowingly collect personal information from children.
EEA/UK (GDPR): Because we do not hold your photos, your scans, or a personal account on any server, most data-subject requests (access, correction, deletion, objection) have nothing on our side to act on — your content already lives entirely on your device, where you have full control. For advertising data processed by Google AdMob/UMP, you may exercise applicable rights directly via the consent tools in Settings → Privacy options, or by contacting Google.
California (CCPA/CPRA): We do not sell or share personal information, and we do not maintain a database of personal information to disclose, correct, or delete. You may still contact us with any privacy question or request at the email below.
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this page.
For any questions about this Privacy Policy, contact us at luckyhan1013@gmail.com.