Privacy Policy
Last updated: 31 August 2026
The short version. Halal Trace has no accounts and no sign-in. Your photos are read on your phone and are never uploaded. Your scan history, favourites, settings and personal rulings stay on your device. There is no analytics, no advertising, and no tracking of any kind. The only things that ever leave your phone are a barcode or a line of ingredients text, and only when they are needed to look a product up.
1. Who is responsible
Halal Trace ("we", "us") is operated by A2I Studio AB, a company registered in Sweden with its registered office in Stockholm. For anything in this policy, including any request about your data, write to privacy@halal-trace.com, and we will answer you there.
For users in the EU/EEA and the UK, we are the data controller for the limited processing described below.
2. What stays on your device
The following never leaves your phone. We cannot see any of it:
- Photographs and camera frames. Barcode detection and ingredient-label text recognition (OCR) run entirely on your device. The image is never uploaded, and we never receive it.
- Your scan history and favourites, including the products you scanned and the verdicts you were shown.
- Your settings — strictness profile, label languages, and any personal rulings you record for individual ingredients.
- The ingredient knowledge base, which is stored on your device so scans work offline.
All of this lives in the app's own private storage. Deleting the app, or clearing its data, permanently deletes it. There is no server-side copy to request or erase.
3. What leaves your device, and when
Looking a barcode up
When you scan a barcode, we send that barcode to Open Food Facts to fetch the product's name, image and ingredients. If Open Food Facts does not know the product, we may then query the U.S. Department of Agriculture's FoodData Central. These services receive the barcode and, as with any internet request, your IP address. They are independent controllers of that request and handle it under their own privacy policies. We send no identifier of you or your device to either of them.
Products nobody has resolved yet
If neither the on-device knowledge base nor our shared verdict cache can resolve a product, the app asks our own server (a Supabase Edge Function) to assess it. That request contains:
| Data | Why |
|---|---|
| The product's barcode, or the recognised ingredients text — never the photo | It is what has to be assessed |
| A randomly generated device identifier (a UUID created on first launch and stored only in the app) | Enforcing a per-device daily limit, so one device cannot exhaust the service for everyone |
| Your IP address, as seen by the server | A second abuse limit, in case the device identifier is spoofed |
The device identifier is not derived from your phone's hardware, is not linked to your name, email, Apple ID or Google account, and is not shared with anyone. Clearing the app's data replaces it with a new one.
To assess a product it has not seen before, that server sends only the ingredients text (or the ingredients it retrieved for the barcode) to Anthropic's Claude API. No device identifier, IP address or other user data is included. Anthropic processes it as our sub-processor and does not use it to train models.
The resulting verdict is stored in a shared cache keyed by a hash of the barcode or the ingredients text, so the next person to scan that product is served the stored answer instead. That cache holds product assessments only — no device identifiers, no IP addresses, nothing about who scanned what.
Reporting a wrong verdict, or emailing us
These open your own email app with a message pre-filled. Nothing is sent until you send it, and we then hold whatever you chose to write, plus your email address, for as long as it takes to deal with your message.
Purchases
If you buy the one-time Pro unlock, the payment is handled entirely by Apple or Google. We never see your card details, billing address or Apple/Google account. We use RevenueCat to verify the purchase receipt and tell the app whether Pro is active; RevenueCat receives the store receipt and an anonymous app user identifier, and acts as our sub-processor.
4. What we never do
- No accounts, sign-in, email collection or user profiles.
- No analytics or crash-reporting SDKs, and no advertising SDKs.
- No tracking across apps or websites, and nothing shared with data brokers.
- We do not sell or rent personal data, and never have.
- This website loads no fonts, scripts or images from third parties, sets no cookies, and runs no analytics.
5. Legal bases (EU/EEA and UK users)
- Legitimate interests (Article 6(1)(f) GDPR) for looking products up and for the rate-limiting described above — providing the service you asked for and keeping it available and affordable to everyone. The data involved is minimal and is not used to profile you.
- Performance of a contract (Article 6(1)(b)) for verifying a purchase and unlocking Pro.
- Legitimate interests (Article 6(1)(f)) for answering support emails you send us.
6. How long we keep things
- Rate-limit counters (device identifier or IP address, plus that day's call count) record a single day's activity, and are never used for anything other than enforcing the limits described above. A scheduled job deletes them daily, once the day they count is more than a week old.
- Cached product verdicts are kept indefinitely — they describe products, not people, and the whole point is that they are reused.
- Support emails are kept until the matter is resolved.
- Everything on your device is kept until you delete it or uninstall the app.
7. Where data is processed
Our server and database are operated on Supabase's infrastructure. Requests to Open Food Facts, FoodData Central, Anthropic and RevenueCat may be processed outside the EU/EEA, including in the United States. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard in the relevant provider's terms.
8. Your rights
If you are in the EU/EEA or the UK, you have the right to access, correct, erase, restrict or object to the processing of your personal data, and to data portability. Because we hold no account and no identifiers linked to you, we usually cannot tell which — if any — of our minimal records relate to you, so in practice:
- To erase everything the app holds about your use, delete the app or clear its data from your device settings. This also removes the random device identifier.
- To ask about anything else, or to exercise a right, email privacy@halal-trace.com. We will respond within one month.
You may also lodge a complaint with your data protection authority. In Sweden this is Integritetsskyddsmyndigheten (IMY).
If you are a California resident: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use it for cross-context behavioural advertising.
9. Children
Halal Trace is not directed at children and we do not knowingly collect personal data from anyone under 13. Since the app has no accounts and collects no personal details, there is nothing for a child to submit.
10. Changes to this policy
If this policy changes in substance, we will update the date at the top and, where the change is significant, note it in the app. Continued use after a change means you accept the updated policy.
11. Contact
privacy@halal-trace.com — or support@halal-trace.com for anything that isn't about privacy.