Privacy policy
This policy covers the ismyfoodgood.app website and the IsMyFoodGood apps for iPhone and Android. It describes data processing known as of September 27, 2026, and identifies retention periods that still need to be confirmed before public launch.
Controller and contact
The person responsible for the service is Otourou Da Costa. For questions about your data or to exercise your rights, email [email protected].
Data we process
- Account: Keycloak identifier, username, email address and, if provided, first and last name. Sign-in tokens are protected on the device by Keychain or Android Keystore.
- Food profile: questionnaire answers, preferences, goals, ingredients to avoid, allergies and any medical reason provided. The latter answers may reveal health data.
- App use: barcodes viewed, scan history for signed-in accounts, lists, food log, conversations with the assistant, label photos submitted for analysis and extracted text. Scans made without an account are not added to a personal history on the server.
- Subscriptions: transaction identifiers, plan, status and validity dates used to check access rights. Apple and Google handle payment; IsMyFoodGood does not receive card numbers.
- Operations and security: IP address, requests, errors and technical logs needed to deliver the site, operate the API and protect the service. The website code contains no advertising tracker or audience analytics tool. Your language choice is stored locally in your browser. Its fonts load from Google Fonts, which receives connection data as a result.
Why we use this data
The account, profile, history, lists, log and assistant provide the features you request. Purchase references are used to check access to paid features. This processing is necessary to provide the service you choose. Technical data supports operations, diagnostics and security on the basis of the operator's legitimate interests. Data that must be retained by law is processed to comply with that obligation.
Allergies, intolerances and medical reasons may be health data. Processing them requires explicit, separate consent that you can withdraw. The apps' flow to collect and record this consent is not yet complete: this feature should not be considered ready for public launch.
Recipients
People operating IsMyFoodGood and necessary technical service providers may access data according to their roles. The API, Keycloak, database, image storage and Ollama models used by the assistant and image analysis are hosted within the service infrastructure. The public website is delivered by Cloudflare Pages. Apple and Google verify purchases made in their stores. Google supplies the website's fonts. Public product data may come from Open Food Facts; searching for a missing product may send a server request to that service.
The current code has no advertising network and does not share personal data for targeted advertising. The location and retention terms of individual providers still need to be checked before public launch.
Retention
- The profile, history, lists, log, conversations and subscription references are kept while the account is active, then deleted when the account is deleted, subject to any specific legal obligation.
- Private label photos expire from object storage after 30 days and are also included in account deletion.
- An account deletion request in progress is retained until processed. After the verification pass, the anonymized technical record is deleted after 7 days.
- The repository configuration specifies 7 days for Loki logs and Tempo traces. Actual enforcement of this period in production, and retention periods for website and content delivery network logs, still need to be verified.
- The retention period for backups containing account data has not yet been set or verified. A copy may therefore remain temporarily after deletion. A purge policy and a tested restore are needed before public launch.
Account deletion
In the app, open the account menu and choose “Delete my account.” You can also request deletion on the web by signing in to the relevant account. The request covers your Keycloak identity, profile, history, lists, log, conversations, subscription references and private images. If a step fails temporarily, it is retried automatically. Deleting your account does not cancel billing for an Apple or Google subscription: cancel it in the relevant store.
Your rights
You can request access to your data, correction, deletion, restriction of processing, objection where applicable and portability of eligible data. Email [email protected] with your request. You can also lodge a complaint with the CNIL.
Updates to this policy
This page will be updated when the outstanding retention periods are verified and whenever features, providers or processing activities change. The update date appears at the top of the page.