Legal

Privacy Policy

Effective Date: September 5, 2026

Applies to: SafaScan iOS and Android mobile applications — US · UK · Canada

1. Introduction

SafaScan ("we," "us," or "our") is a halal food scanner application developed and operated by Sothes LLC. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, share, and safeguard information when you use our iOS and Android applications in the United States, United Kingdom, and Canada.

By downloading, installing, or using SafaScan, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree, please do not use the app.

SafaScan handles religious preference data (madhab selection), dietary information, and product scan data that are meaningful to you. We treat this data with the highest level of care and do not share it with advertisers or analytics platforms.

2. Information We Collect

2.1 Information You Provide Directly

  • Account registration details (email address, or linked Apple/Google account identifier). Account creation occurs after the paywall decision in the onboarding flow.
  • Madhab preference — your Islamic school of jurisprudence, stored client-side only and used solely to apply Mushbooh boundary adjustments to scan results
  • Optional custom sensitivities (dairy, gluten, nuts, etc.) used for client-side filtering
  • Scanning depth preference (standard or thorough)
  • Barcode scan history, saved product verdicts, and My Halal Pantry items (subscribers only)
  • Community product submissions — ingredient lists and barcode data you submit for products not found in our database
  • Feature request submissions — title (max 120 characters) and optional description (max 500 characters) submitted via Profile → Help & Support

2.2 Information Collected Automatically

  • Device identifiers for debugging (internal UUID only; never transmitted as PII to any analytics or advertising platform)
  • App usage events via Firebase Analytics and Google Analytics (e.g., scan initiated, verdict received, paywall viewed) — structured parameters only, no raw ingredient text or personal data
  • Product analytics via PostHog (e.g., scan funnels, subscription lifecycle events, in-app review banner interactions) — tied to hashed anonymous user identifiers
  • Attribution and advertising measurement events via AppsFlyer, Meta Ads (Meta Developer / Facebook SDK), Google Ads, TikTok Ads (TikTok SDK), and SKAdNetwork (iOS) — no PII in any payload; only structured event names and campaign identifiers
  • Crash reports and performance diagnostics via Sentry — personal identifiers are scrubbed before transmission; last 20 breadcrumb actions attached to each error report
  • Subscription status and tier (never_subscribed, free_trial, paid_monthly, paid_annual, trial_expired, subscription_expired) — managed via RevenueCat
  • Push notification delivery, open, deep-link status, and FCM token
  • In-app review banner interactions — tracked in PostHog only, not sent to analytics or advertising SDKs
  • Time zone (IANA string) for daily duʿa and scheduled notification delivery

2.3 Barcode and Label Scan Data

  • Barcode values are queried against multiple third-party product databases (Open Food Facts, UPC Item DB, Nutritionix, and our Firestore cache) using a parallel multi-source lookup with a 400ms timeout
  • Label images submitted for AI vision analysis are processed transiently by OpenAI's GPT-5.4 Nano vision model and are not stored permanently by SafaScan
  • Ingredient lists are classified through our 5-stage offline-first classifier pipeline; AI results are cached in Firestore to prevent repeated AI calls for the same ingredient
  • Raw ingredient text is never forwarded to Firebase Analytics, Google Analytics, Google Ads, Meta Ads, AppsFlyer, TikTok Ads, or any other analytics or advertising SDK — only structured category and risk-level parameters are used

2.4 AI-Generated Content and Classification

  • Stage-5 AI fallback uses OpenAI's GPT-5 Nano for text and GPT-5.4 Nano for vision label analysis. All AI results are cached in Firestore; the same ingredient is never classified twice by AI.
  • AI-generated halal alternatives, ingredient explanations, and confidence scores are stored per product in Firestore and returned to you as part of scan results
  • The daily AI duʿa is generated each day with Islamic calendar context (e.g., Ramadan, Dhul Hijjah) and delivered to all opted-in users via Firebase Cloud Messaging at 8:00 AM in your local time zone. No individual user data is used in duʿa generation.
  • Community product submissions are pre-screened by GPT-5 Nano to validate ingredient list authenticity before entering the classification pipeline

2.5 Feature Request Submissions

  • Stored in our Supabase backend with: your internal user UUID (not email or name), feature title, optional description, app version, device OS, and submission timestamp
  • Never forwarded to Firebase Analytics, Google Analytics, Google Ads, Meta Ads, AppsFlyer, TikTok Ads, or any other analytics or advertising SDK
  • Enter a moderation queue (is_visible = false by default) and reviewed by Sothes LLC before any public surfacing
  • Rate-limited to 5 per user per 24-hour period

2.6 Retention Engine Data

  • Halal Confidence Score: a weekly score computed from your scan history; stored in your private Firestore user profile
  • Halal Streak: day-by-day scan activity used to display your streak and send streak nudges
  • My Halal Pantry: verified HALAL products you save; used to power reclassification alerts and pantry insights
  • Weekly Haram-Found Summary: aggregated counts of flagged ingredients and products from your weekly scan history, used to generate the Sunday summary
  • Ramadan Mode: seasonal preference and Iftar reminder timing derived from your device time zone and prayer-time API

3. How We Use Your Information

3.1 Core App Functionality

  • Classify food product ingredients (Halal, Mushbooh, Haram, or Pending) using our 5-stage offline-first classifier pipeline
  • Apply your madhab preference as a client-side modifier to Mushbooh verdict boundaries — never shared with third parties
  • Provide AI-powered ingredient explanations, confidence scores, and halal alternative suggestions for Mushbooh and Haram verdicts
  • Perform AI label scan analysis when a product barcode is not found
  • Manage and display your personal scan history, My Halal Pantry, and Safe List (subscribers only)
  • Compute your Halal Confidence Score, Halal Streak, and Weekly Haram-Found Summary (subscribers only)
  • Send the daily AI duʿa notification to all opted-in users, including free-tier users
  • Notify you via push when a community-submitted product you scanned is verified by 3+ independent scanners
  • Notify active subscribers when an ingredient in a previously scanned product or Safe List item is reclassified

3.2 Analytics and Product Improvement

  • Firebase Analytics and Google Analytics: structured parameters only (e.g., scan_type, ingredient_category, risk_level, subscription_tier). No PII, no raw ingredient text, no madhab preference.
  • PostHog: primary product analytics. Tracks scan funnels, subscription lifecycle, review banner interactions, and Day 1/3/30 retention. Session recording is disabled.
  • Sentry: crash reports and performance diagnostics with PII scrubbed.

3.3 Advertising Measurement and Attribution

  • AppsFlyer: mobile attribution and marketing analytics; events include app install, onboarding_completed, first_scan, trial_started, subscription_started, and subscription_expired. No PII in any payload.
  • Meta Ads / Meta Developer (Facebook SDK): app events for advertising optimisation, including onboarding_completed, first_scan, paywall_viewed, trial_started, subscription_started, and scan_completed. No PII in any payload.
  • Google Ads: conversion tracking for app install campaigns and in-app events (e.g., first_scan, subscription_started). No PII in any payload.
  • TikTok Ads (TikTok SDK): onboarding_completed, first_scan, paywall_viewed, trial_started, subscription_started, ingredient_flagged (category only), and scan_completed. No PII in any payload.
  • Subscription conversion events fire only after backend confirmation from RevenueCat — never on a client-side tap. Prevents attribution fraud.
  • On iOS, we use SKAdNetwork (SKAN) for privacy-preserving attribution. SKAN postbacks contain no individual user identifiers.
  • Raw ingredient text, madhab preference, feature request content, and free-text user input are never sent to any advertising or analytics SDK.

3.4 Push Notifications

  • Daily AI Duʿa — every day at 8:00 AM in your local time zone to all users who have not disabled it. Free-tier users tapping it land on the paywall; subscribers see the full duʿa.
  • Halal Tip of the Week — scheduled Sunday educational notification
  • Weekly Haram-Found Summary — Sunday summary for paid subscribers based on that week's scan history
  • Halal Confidence Score — Sunday score update for paid subscribers
  • Halal Streak Nudge — daily evening reminder for paid subscribers who have not scanned that day
  • Product Verified Callback — transactional FCM push when a community-submitted product reaches 3 confirmations
  • Ingredient Reclassification Alert — transactional alert when an ingredient in your scan history or Safe List changes verdict (subscribers only)
  • Trial and Lifecycle Notifications — trial nurture, expiry warning, trial lapsed, win-back, renewal reminder, and payment failure alerts
  • Ramadan Seasonal — pre-Ramadan and daily Iftar reminders (cap-exempt)
  • Inactivity Re-engagement — behaviour-triggered notification after 2 days without a scan or app open
  • Disable any optional notification type at any time in the app's Notification Settings. Transactional lifecycle notifications cannot be opted out because they are account-management communications.

4. Religious and Dietary Data

SafaScan collects your madhab preference (Islamic school of jurisprudence) to personalise halal classification. This is sensitive religious preference data. We treat it with the strictest privacy controls.

  • Madhab preference is stored client-side only — never written to Firestore or sent to any analytics SDK, advertising SDK, paywall SDK, or third-party service
  • Custom sensitivities and scanning depth preferences are stored client-side only
  • Never included in Firebase Analytics, Google Analytics, Google Ads, Meta Ads, AppsFlyer, TikTok Ads, PostHog, or Sentry payloads
  • Not shared with any third party
  • Permanently deleted when you delete your account or uninstall the app

IMPORTANT: SafaScan is an informational tool. Halal verdicts do not constitute a scholarly halal certification. Always verify with a certified halal authority if in doubt.

5. Analytics and Attribution Data — What We Do and Do Not Send

  • PostHog receives: app lifecycle events, onboarding, scan funnels, subscription events, in-app review interactions, ingredient change alerts. Includes hashed user UUID, subscription tier, and structured scan parameters.
  • Firebase Analytics and Google Analytics receive: scan events, ingredient category and risk level (never raw text), paywall and subscription conversion events, feature usage events. Used for Google Ads Smart Bidding signals.
  • AppsFlyer receives: install attribution, onboarding completion, first scan, trial start, subscription start, subscription expiry, and re-engagement events. No PII.
  • Meta Ads / Meta Developer (Facebook SDK) receives: onboarding completion, first scan, paywall view, trial start (backend-confirmed), subscription start (backend-confirmed), scan completed. No PII.
  • Google Ads receives: app install attribution, first scan, subscription start, and remarketing signals. No PII.
  • TikTok Ads (TikTok SDK) receives: onboarding completion, first scan, paywall view, trial start (backend-confirmed), subscription start (backend-confirmed), ingredient flagged (category only), scan completed (scan type only). No PII.
  • No platform receives: email, phone number, name, raw ingredient text, madhab preference, feature request text, free-text user input, full ingredient lists, or scan history contents.

6. Data Sharing and Third-Party Services

We do not sell your personal data. We share data with third parties only as described below.

6.1 Service Providers

  • Firebase (Google LLC) — authentication, Firestore, Cloud Functions, Analytics, FCM
  • Google Analytics and Google Ads (Google LLC) — app analytics and advertising conversion / remarketing measurement
  • OpenAI — AI ingredient classification (GPT-5 Nano), vision label analysis (GPT-5.4 Nano), daily duʿa, community submission moderation. Not used to train OpenAI models per our API agreement.
  • RevenueCat — subscription paywall, trial and billing lifecycle, webhook-based subscription confirmation
  • Sentry — crash reporting and performance monitoring (PII scrubbed)
  • PostHog — primary product analytics (session recording disabled)
  • AppsFlyer — mobile attribution, marketing analytics, and re-engagement measurement (no PII)
  • Meta Platforms, Inc. (Meta Developer / Meta Ads / Facebook SDK) — advertising optimisation and app event measurement (no PII)
  • TikTok (TikTok SDK / TikTok Ads) — advertising attribution SDK (no PII; structured events only)
  • Supabase — feature request submission backend
  • Open Food Facts, UPC Item DB, Nutritionix — product barcode lookup (queries contain barcode values only)

6.2 Legal Requirements

We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of SafaScan, our users, or others.

7. Data Retention

  • Scan history and saved verdicts: retained until you delete items, clear history, or delete your account
  • My Halal Pantry and Safe List: retained until you remove items or delete your account
  • Community product submissions: retained indefinitely for classification integrity; your user ID is associated with your submission but not publicly displayed
  • Firestore ingredient and product cache: 30-day TTL, renewed on cache hit
  • AI-generated content: retained in Firestore cache; duʿa overwritten daily
  • Push notification delivery history: retained for 90 days
  • Feature request submissions: retained in Supabase until manually deleted by Sothes LLC moderation
  • Account data: retained until deletion is requested; permanent deletion confirmed within 30 days

8. Analytics and Advertising Consent and Controls

You can opt out of analytics and advertising measurement data collection at any time via the app's Settings. When you opt out:

  • Firebase Analytics, Google Analytics, Google Ads, Meta Ads, AppsFlyer, and TikTok Ads collection is disabled immediately on your device
  • Your analytics consent preference is stored on your account and respected across devices
  • Opting out does not affect core functionality, halal classification, AI explanations, daily duʿa, or transactional push notifications

PostHog uses only anonymous hashed identifiers. AppsFlyer, Meta Ads, Google Ads, and TikTok Ads receive only the structured attribution events described in Section 3.3.

9. Children's Privacy

SafaScan is not directed to children under 13 (or under 16 in the European Economic Area). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

10. International Data Transfers

SafaScan is operated from the United States and serves users in the US, UK, and Canada. Your information may be transferred to and processed in the United States or other countries where our service providers (including Google, OpenAI, TikTok, Meta Platforms, AppsFlyer, and Supabase) operate. By using the app, you consent to this transfer.

11. Security

We implement administrative, technical, and physical safeguards including encrypted data transmission (TLS), Firestore server-side access controls, PII scrubbing in all analytics and advertising payloads, a CI/PR lint rule that blocks any Firebase Analytics, Google Analytics, Google Ads, Meta Ads, AppsFlyer, or TikTok event parameter containing email, name, phone, or raw ingredient text, and row-level security on our Supabase feature request table. No method of transmission over the internet is 100% secure.

12. Your Rights

  • Access — request a copy of the data we hold about you
  • Correction — update inaccurate or incomplete data
  • Deletion — request deletion of your account and all associated data
  • Portability — receive a machine-readable export of your scan history and My Halal Pantry
  • Withdrawal of analytics consent — disable Firebase Analytics at any time (see Section 8)

UK users have additional rights under the UK GDPR. Canadian users have rights under PIPEDA. To exercise any of these rights, contact us at the address in Section 14.

13. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the Effective Date at the top of this document and, where the changes are material, notify you via in-app notification or email. Your continued use of SafaScan after any change constitutes your acceptance of the updated policy.

14. Contact Us

For questions, concerns, or requests regarding this Privacy Policy, please contact:

Sothes LLC
Privacy enquiries: privacy@sothesllc.com
General support: support@sothesllc.com

Frequently asked questions

What data does SafaScan collect?
SafaScan collects account details, scan history, and app usage and attribution data used to operate and improve the service. Full detail is in the privacy policy on this page.
Does SafaScan share data with third parties?
SafaScan uses service providers such as AppsFlyer, Google Analytics, Firebase Analytics, Meta, TikTok, and Google Ads for analytics and marketing attribution. Personal data is not sold.
How do I delete my SafaScan account and data?
Email support@sothesllc.com from your account email to request deletion of your account and associated data.