Legal
Privacy Policy
Effective Date: May 14, 2026
Applies to: SafaScan iOS and Android mobile applications — US · UK · Canada
1. Introduction
SafaScan ("we," "us," or "our") is a halal food scanner application developed and operated by Sothes LLC. We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, share, and safeguard information when you use our iOS and Android applications in the United States, United Kingdom, and Canada.
By downloading, installing, or using SafaScan, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree, please do not use the app.
SafaScan handles religious preference data (madhab selection) and dietary information that are meaningful to you. We treat this data with the highest level of care and do not share it with advertisers or analytics platforms.
2. Information We Collect
2.1 Information You Provide Directly
- Account registration details (email address, or linked Apple/Google account identifier)
- Madhab preference — your Islamic school of jurisprudence, used solely to apply client-side Mushbooh boundary adjustments to scan results
- Barcode scan history and saved product verdicts (subscribers only)
- Community product submissions — ingredient lists and barcode data you submit for products not found in our database
- Feature request submissions — title (max 120 characters) and optional description (max 500 characters) submitted via Profile → Help & Support
2.2 Information Collected Automatically
- Device identifiers for debugging (internal UUID only; never transmitted as PII to any analytics platform)
- App usage events via Firebase Analytics (e.g., scan initiated, verdict received, paywall viewed) — structured parameters only, no raw ingredient text or personal data
- Product analytics via PostHog (e.g., scan funnels, subscription lifecycle events, in-app review banner interactions) — tied to hashed anonymous user identifiers
- Attribution and advertising measurement events via TikTok SDK (e.g., onboarding completed, first scan, trial started, subscription started) — no PII in any TikTok event payload
- Crash reports and performance diagnostics via Sentry — personal identifiers are scrubbed before transmission; last 20 breadcrumb actions attached to each error report
- Subscription status and tier (never_subscribed, trial, active, subscription_expired) — managed via RevenueCat
- Push notification delivery, open, and deep-link status
- In-app review banner interactions — tracked in PostHog only, not sent to Firebase or TikTok
2.3 Barcode and Label Scan Data
- Barcode values are queried against multiple third-party product databases (Open Food Facts, UPC Item DB, Nutritionix, and our Firestore cache) using a parallel multi-source lookup with a 400ms timeout
- Label images submitted for AI vision analysis are processed transiently by OpenAI's GPT-5.4 Nano vision model and are not stored permanently by SafaScan
- Ingredient lists are classified through our 5-stage offline-first classifier pipeline; AI results are cached in Firestore to prevent repeated AI calls for the same ingredient
- Raw ingredient text is never forwarded to Firebase Analytics or TikTok SDK — only structured category and risk-level parameters are used
2.4 AI-Generated Content and Classification
- Stage-5 AI fallback uses OpenAI's GPT-5 Nano for text and GPT-5.4 Nano for vision label analysis. All AI results are cached in Firestore; the same ingredient is never classified twice by AI.
- AI-generated halal alternatives, ingredient explanations, and confidence scores are stored per product in Firestore and returned to you as part of scan results
- The weekly AI duʿa is generated once per week with Islamic calendar context (e.g., Ramadan, Dhul Hijjah) and broadcast to all opted-in users via Firebase Cloud Messaging. No individual user data is used in duʿa generation.
- Community product submissions are pre-screened by GPT-5 Nano to validate ingredient list authenticity before entering the classification pipeline
2.5 Feature Request Submissions
- Stored in our Supabase backend with: your internal user UUID (not email or name), feature title, optional description, app version, device OS, and submission timestamp
- Never forwarded to Firebase Analytics or TikTok SDK
- Enter a moderation queue (is_visible = false by default) and reviewed by Sothes LLC before any public surfacing
- Rate-limited to 5 per user per 24-hour period
3. How We Use Your Information
3.1 Core App Functionality
- Classify food product ingredients (Halal, Mushbooh, Haram, or Pending) using our 5-stage offline-first classifier pipeline
- Apply your madhab preference as a client-side modifier to Mushbooh verdict boundaries — never shared with third parties
- Provide AI-powered ingredient explanations, confidence scores, and halal alternative suggestions for Mushbooh and Haram verdicts
- Perform AI label scan analysis when a product barcode is not found
- Manage and display your personal scan history and Safe List (subscribers only)
- Send the weekly AI duʿa notification to all opted-in users, including free-tier users
- Notify you via push when a community-submitted product you scanned is verified by 3+ independent scanners
3.2 Analytics and Product Improvement
- Firebase Analytics (15 events): structured parameters only (e.g., scan_type, ingredient_category, risk_level, subscription_tier). No PII, no raw ingredient text, no madhab preference.
- PostHog (18 events): primary product analytics. Tracks scan funnels, subscription lifecycle, review banner interactions, and Day 1/3/30 retention. Session recording is disabled.
- Sentry: crash reports and performance diagnostics with PII scrubbed.
3.3 Advertising Measurement
- TikTok SDK (7 events): onboarding_completed, first_scan, paywall_viewed, trial_started, subscription_started, ingredient_flagged (category only), and scan_completed. No PII in any payload.
- Subscription conversion events fire only after backend confirmation from RevenueCat — never on a client-side tap. Prevents attribution fraud.
- On iOS, we use SKAN (SKAdNetwork) for privacy-preserving attribution. SKAN postbacks contain no individual user identifiers.
- Raw ingredient text, madhab preference, feature request content, and free-text user input are never sent to TikTok.
3.4 Push Notifications
- Weekly AI Duʿa — every Friday to all users who have not disabled it. Free-tier users tapping it land on the paywall; subscribers see the full duʿa.
- Product Verified Callback — transactional FCM push when a community-submitted product reaches 3 confirmations.
- Disable any notification type at any time in the app's Notification Settings.
4. Religious and Dietary Data
SafaScan collects your madhab preference (Islamic school of jurisprudence) to personalise halal classification. This is sensitive religious preference data. We treat it with the strictest privacy controls.
- Madhab preference is stored in your private Firestore user account and applied client-side only — never used to alter the underlying ingredient database classification
- Never included in Firebase Analytics, TikTok, PostHog, or Sentry payloads
- Not shared with any third party
- Permanently deleted when you delete your account
IMPORTANT: SafaScan is an informational tool. Halal verdicts do not constitute a scholarly halal certification. Always verify with a certified halal authority if in doubt.
5. Analytics Data — What We Do and Do Not Send
- PostHog receives: app lifecycle events, onboarding, scan funnels, subscription events, in-app review interactions. Includes hashed user UUID, subscription tier, and structured scan parameters.
- Firebase Analytics receives: scan events, ingredient category and risk level (never raw text), paywall and subscription conversion events, feature usage events. Used for Google Ads Smart Bidding signals.
- TikTok SDK receives: onboarding completion, first scan, paywall view, trial start (backend-confirmed), subscription start (backend-confirmed), ingredient flagged (category only), scan completed (scan type only).
- No platform receives: email, phone number, name, raw ingredient text, madhab preference, feature request text, free-text user input, or full ingredient lists.
6. Data Sharing and Third-Party Services
We do not sell your personal data. We share data with third parties only as described below.
6.1 Service Providers
- Firebase (Google LLC) — authentication, Firestore, Cloud Functions, Analytics, FCM
- OpenAI — AI ingredient classification (GPT-5 Nano), vision label analysis (GPT-5.4 Nano), weekly duʿa, community submission moderation. Not used to train OpenAI models per our API agreement.
- RevenueCat — subscription paywall, trial and billing lifecycle, webhook-based subscription confirmation
- Sentry — crash reporting and performance monitoring (PII scrubbed)
- PostHog — primary product analytics (session recording disabled)
- TikTok — advertising attribution SDK (no PII; 7 structured events only)
- Supabase — feature request submission backend
- Open Food Facts, UPC Item DB, Nutritionix — product barcode lookup (queries contain barcode values only)
6.2 Legal Requirements
We may disclose your information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of SafaScan, our users, or others.
7. Data Retention
- Scan history and saved verdicts: retained until you delete items, clear history, or delete your account
- Community product submissions: retained indefinitely for classification integrity; your user ID is associated with your submission but not publicly displayed
- Firestore ingredient and product cache: 30-day TTL, renewed on cache hit
- AI-generated content: retained in Firestore cache; duʿa overwritten weekly
- Push notification delivery history: retained for 90 days
- Feature request submissions: retained in Supabase until manually deleted by Sothes LLC moderation
- Account data: retained until deletion is requested; permanent deletion confirmed within 30 days
8. Analytics Consent and Controls
You can opt out of Firebase Analytics data collection at any time via the app's Settings. When you opt out:
- Firebase Analytics collection is disabled immediately on your device
- Your analytics consent preference is stored on your account and respected across devices
- Opting out does not affect core functionality, halal classification, AI explanations, weekly duʿa, or push notifications
PostHog uses only anonymous hashed identifiers. TikTok receives only the structured attribution events described in Section 3.3.
9. Children's Privacy
10. International Data Transfers
11. Security
12. Your Rights
- Access — request a copy of the data we hold about you
- Correction — update inaccurate or incomplete data
- Deletion — request deletion of your account and all associated data
- Portability — receive a machine-readable export of your scan history
- Withdrawal of analytics consent — disable Firebase Analytics at any time (see Section 8)
UK users have additional rights under the UK GDPR. Canadian users have rights under PIPEDA. To exercise any of these rights, contact us at the address in Section 14.
13. Changes to This Policy
14. Contact Us
For questions, concerns, or requests regarding this Privacy Policy, please contact:
Sothes LLC
Privacy enquiries: privacy@sothesllc.com
General support: support@sothesllc.com
