Privacy

Privacy Policy

This Policy explains how Addi processes information when you scan ingredient labels, look up barcodes, use an anonymous or Apple account, manage Pro access, send feedback, or request account deletion.

Effective date: 09.07.2026

Addi is operated by Kovacs Software Solutions. The official service is addi.kovacssoftware.com. This Policy and our Terms of Use apply to the app, website, and API.

1. Information we process

  • Ingredient-label images and extracted ingredient text, selected additive categories, custom watchlists, language, country, barcode, and product information needed for a scan.
  • An anonymous account or, if you choose Sign in with Apple, Apple’s stable account identifier and any name or relay email Apple provides.
  • A random installation identifier that we store as a keyed hash, session and token records, scan usage, IP address, user agent, request times, and security or error logs.
  • RevenueCat customer identifiers, App Store product and entitlement status, renewal or expiry information, and webhook events. We do not receive your full payment-card details.
  • Feedback you submit, including your message, rating, scan context, ingredient or product details, additive identifiers, and technical metadata.

2. Ingredient images and AI processing

When you request a label scan, the selected image is validated and sent through our API to an artificial-intelligence provider (currently OpenAI, with Gemini available as a service fallback) to transcribe the ingredient list. The backend does not save the uploaded image or completed AI result in its application database. Providers may process requests under their own terms and retention controls.

AI output can be incomplete or incorrect. Always compare the result with the physical package, especially for allergies, intolerances, pregnancy, medication, or other health decisions.

3. Barcode data and Open Food Facts

Barcode lookups use a periodically imported local copy of selected fields from Open Food Facts, a community-maintained database. Ordinary barcode lookups do not send the scanned barcode to Open Food Facts. Product names, images, and ingredient lists can be outdated or incomplete, so verify the package.

4. Accounts and authentication

You may use an anonymous account or Sign in with Apple. We use access and refresh tokens to maintain sessions and a hashed installation identifier to enforce free-scan limits and reduce abuse. Apple controls the Apple sign-in service and information it supplies.

5. Subscriptions

Apple processes App Store purchases and billing. RevenueCat helps us verify and restore Pro entitlements. Deleting your Addi account does not cancel an App Store subscription; cancellation and refund requests must be managed through Apple.

6. How we use and share information

We use information to provide scans and barcode results, authenticate accounts, enforce allowances, reconcile Pro access, receive feedback, troubleshoot, secure the service, prevent abuse, comply with law, and protect users and our rights. We share only what is reasonably necessary with Apple, RevenueCat, AI providers, infrastructure or support providers, professional advisers, and authorities where legally required. We do not sell personal information or use third-party advertising SDKs.

7. Retention

  • Uploaded scan files and AI results are not stored in the Addi application database after the response is produced.
  • The imported Open Food Facts product catalog is retained until it is replaced by a newer catalog import.
  • Expired Sanctum access tokens and expired or revoked mobile refresh tokens are scheduled for deletion after a 24-hour operational window.
  • Account, entitlement, quota, feedback, and security records remain while the account or service need exists, then are deleted or de-identified unless a longer period is necessary for fraud prevention, disputes, security, or law.
  • Apple, RevenueCat, Open Food Facts, and AI providers apply their own retention policies to information they control.

8. Account deletion and your choices

You can start account deletion from Addi Settings. The backend revokes local sessions, deletes the local account and related feedback, and requests deletion of the associated RevenueCat customer where supported. Apple billing history and any active App Store subscription remain controlled by Apple. If Apple reauthorization is required, you may be asked to sign in again before deletion.

You may request access, correction, or deletion by emailing info@kovacssoftware.com. Technical help is available at support@kovacssoftware.com.

9. Security, international processing, and children

We use encrypted transport, access controls, hashed device identifiers, short-lived credentials, and production configuration checks, but no service is completely secure. Providers may process data outside your country. Addi is not directed to children who cannot consent under applicable law.

10. Changes

We may update this Policy when features, providers, or laws change. We will update the effective date and provide additional notice where required.