Back to home

Privacy Policy

Last updated: February 1, 2026

This Privacy Policy describes how ScanPal ("we", "us" or "our"), operated by XPROFIT OÜ, a company registered in Estonia (Registry code: 16919521), located at Pae tn 21, 11415 Tallinn, Estonia, collects, uses, stores, and shares your personal information when you use our website, mobile applications, or related services (collectively, the "Service").

By using the Service you consent to the collection and use of your information in accordance with this Privacy Policy and any consents you provide during registration, in-app prompts, payment flows, or other interactions with the Service.

1. Information We Collect

We collect the following information in order to provide the Service, deliver features, maintain security, and comply with legal obligations.

A. Account Information

B. Usage Information

C. Technical Information

D. Health-Related and Special Categories

When you choose to provide it, we may collect:

This data may qualify as "special category data" under GDPR (see Section 3).

E. Payment Information

We do not collect sensitive payment card data. Your payment information is processed directly by our payment providers (Stripe and EveryPay). We may receive transactional metadata (e.g., subscription tier, payment timestamps).

2. How We Use Your Information

We use your information for the following purposes, based on legal grounds described in Section 3:

3. Legal Basis for Processing (GDPR)

We process personal data based on the following GDPR legal bases:

Contractual necessity (Art. 6(1)(b))
Account creation, scan history, subscription management, security.

Consent (Art. 6(1)(a))
Email marketing, AI analysis of photos, profiling personalization.

Legitimate interests (Art. 6(1)(f))
Fraud detection, security, service improvement.

Legal obligation (Art. 6(1)(c))
Compliance with applicable laws and legal requests.

Special category data (GDPR Art. 9)
Health-related and dietary data are processed only with your explicit consent.

4. Retention of Your Data

We retain user data only as long as necessary to fulfill Service functions and legal obligations. Specific retention periods include:

Data Type Retention Period
Account profileUntil account deletion + 30 days
Scan history90 days
Premium analysis cache30 days
Session logs90 days
"Remember me" tokens365 days
Transactional metadataAs required by law
Email marketing consentsUntil withdrawal

After the retention period expires, we delete or anonymize data.

5. Third-Party Services and Transfers

We use third-party services to operate the Service. These providers may process data on our behalf or as independent controllers. They include:

A. OpenAI

AI analysis of product photos is processed by OpenAI on servers outside the European Economic Area (EEA). Transfers are safeguarded under Standard Contractual Clauses and limited to necessary data for analysis.

B. Stripe & EveryPay

Payment processing is handled by Stripe and EveryPay. They may be independent data controllers for payment metadata, and data transfers outside the EEA may occur under appropriate safeguards.

C. Telegram

If you use Telegram login, basic profile information is shared through Telegram's systems. Telegram operates as a separate controller for login data.

D. Nutrition Databases

We use public nutrition data sources (Open Food Facts, USDA, FatSecret). Your use of these features may involve requests to external sites, governed by their respective privacy policies.

6. Cookies

We use cookies and similar technologies to operate the Service and improve your experience.

Essential Cookies — Required to enable core service functions (e.g., session cookies, language setting).

Analytics Cookies — Used to understand usage patterns and improve features.

We do not use advertising or tracking cookies without your consent.

You may configure or reject cookies via browser or device settings. See our Cookie Policy for details.

7. Your Rights (Under GDPR)

Under the GDPR, you have the right to:

To exercise these rights, contact us at support@scanpal.app.

If you believe your rights have been violated, you may lodge a complaint with the Estonian Data Protection Inspectorate.

8. Data Security

We implement industry-standard security measures, including:

However, no system is completely secure; we cannot guarantee absolute protection.

9. Children's Privacy

ScanPal is not directed at children under 16. We do not knowingly collect data from individuals under 16. If we discover such data, it will be deleted promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect legal or operational changes. We will notify you of significant changes via the Service or email.

Your continued use of the Service constitutes acceptance of the updated policy.

11. Contact Information

XPROFIT OÜ

Pae tn 21, 11415 Tallinn, Estonia

Registry code: 16919521

Email: support@scanpal.app