1. Introduction
Welcome to IngreAI! We are committed to protecting your privacy and personal information. This Privacy Policy explains how we collect, use, store, and protect your information when you use our mobile application.
By using our app, you agree to the information collection and use practices described in this Privacy Policy.
2. Information We Collect
2.1 Information You Provide
- Account Information: Email address and username when you create an account
- Profile Information: Dietary preferences, allergen information, and other personal details you choose to provide
- Photo Content: Food ingredient label photos you upload for analysis
2.2 Automatically Collected Information
- Device Information: Device model, operating system version, app version, device identifiers (IDFA/GAID)
- Usage Data: App usage frequency, feature usage, session duration, crash reports, error logs
- Network Information: IP address, network type, carrier information
- Cookies and Similar Technologies: We use cookies and similar tracking technologies to enhance user experience
2.3 Information from Third Parties
- Social Media: If you connect social media accounts, we may receive profile information
- App Store Data: Purchase history and subscription information from Apple App Store or Google Play
3. How We Use Your Information
We use the collected information for the following purposes:
- Service Provision: Provide ingredient label recognition and analysis functionality
- Account Management: Create and manage your user account
- Subscription Services: Process paid subscriptions and billing
- Product Improvement: Analyze usage data to improve app features
- Customer Support: Respond to your inquiries and provide technical support
- Security Protection: Detect and prevent fraudulent activities
4. Information Sharing
We do not sell, trade, or transfer your personal information to third parties, except in the following circumstances:
- With your explicit consent
- When necessary to provide services (e.g., cloud storage providers)
- When required by law or court order
- To protect our rights, property, or safety
We may share information with the following types of third parties:
- Service Providers: Technical service providers who help us operate the app
- Analytics Services: Third-party analytics tools to understand app usage
- Payment Processors: Payment service providers for subscription billing
5. Data Security
We implement appropriate technical and organizational measures to protect your personal information:
- SSL/TLS encryption for data transmission
- Encrypted storage of sensitive information
- Regular security audits and vulnerability assessments
- Limited employee access to personal information
- Data breach response procedures
6. Your Rights
Under applicable data protection laws (GDPR for EU/UK, CCPA for California, PIPEDA for Canada), you have the following rights:
- Access Right: Request access to personal information we hold about you and information about our processing activities
- Correction Right: Request correction of inaccurate or incomplete personal information
- Deletion Right ("Right to be Forgotten"): Request deletion of your personal information, subject to certain exceptions
- Restriction Right: Request restriction of processing of your personal information in certain circumstances
- Data Portability: Request your data in a structured, commonly used, machine-readable format
- Objection Right: Object to processing based on legitimate interests or for direct marketing purposes
- Withdraw Consent: Withdraw consent where processing is based on consent
- Non-Discrimination: We will not discriminate against you for exercising your privacy rights
- Complaint Right: Lodge a complaint with your local data protection authority
How to Exercise Your Rights: Contact us at contact@youanlab.com or through the app's privacy settings. We will respond within 30 days (or as required by local law). Identity verification may be required.
7. Data Retention
We retain your personal information only for as long as necessary:
- Account Information: During your account existence and 30 days after deletion
- Analysis Data: Up to 2 years, unless you request deletion
- Usage Logs: Up to 1 year
- Legal Requirements: Some information may be retained longer due to legal obligations
8. Children's Privacy
Our services are not directed to children under the age of digital consent in their jurisdiction:
- United States: Under 13 years (COPPA compliance)
- EU/UK: Under 16 years (GDPR compliance, or lower age set by member state)
- Canada: Under 13 years (PIPEDA compliance)
We do not knowingly collect personal information from children below these ages. If we discover we have collected such information, we will delete it immediately and suspend the associated account. Parents/guardians can contact us to request deletion of their child's information.
9. Legal Basis for Processing (EU/UK Users)
Under GDPR, we process your personal data based on the following legal grounds:
- Contract Performance: To provide app services and manage your account
- Consent: For marketing communications and optional features
- Legitimate Interests: For analytics, security, and service improvement
- Legal Obligation: To comply with applicable laws and regulations
- Vital Interests: To protect health and safety in emergency situations
10. International Data Transfers
Your information may be transferred to and processed in countries outside your jurisdiction, including the United States. We ensure appropriate safeguards are in place:
- Adequacy Decisions: Transfers to countries deemed adequate by your local authorities
- Standard Contractual Clauses: EU-approved contractual safeguards for data transfers
- Binding Corporate Rules: Internal data transfer agreements with strong privacy protections
- Certification Programs: Participation in recognized privacy certification frameworks
For EU/UK residents: We comply with GDPR requirements for international transfers. For Canadian residents: We ensure adequate protection as required by PIPEDA.
11. Privacy Policy Updates
We may update this Privacy Policy from time to time. Significant changes will be communicated through in-app notifications or email. Continued use of our services constitutes acceptance of the updated Privacy Policy.
We will provide at least 30 days' notice for material changes affecting your rights under GDPR, CCPA, or PIPEDA.
12. Regional Specific Information
12.1 California Residents (CCPA/CPRA)
California residents have additional rights under the California Consumer Privacy Act:
- Right to know what personal information is collected and how it's used
- Right to delete personal information
- Right to opt-out of sale (we do not sell personal information)
- Right to non-discrimination for exercising CCPA rights
12.2 EU/UK Residents (GDPR)
EU and UK residents have enhanced rights under GDPR, including data portability and the right to object to processing.
12.3 Canadian Residents (PIPEDA)
Canadian residents have rights under PIPEDA to access and challenge the accuracy of their personal information.
Last Updated: July 2025 | Version 2.0