ToxScan Privacy Policy
Last updated: July 2026
In short: ToxScan has no accounts, so we never ask for your name or email address. The app creates a random ID on your device and uses it to run the scanning service, understand how the app is used, and measure our advertising. Photos you take are analyzed and then discarded, and we never sell your data.
1. Who we are
ToxScan is operated by Jonas Westh Creative, a sole proprietorship registered in Denmark (CVR-registered).
Address: Bjørnø 12, 5603 Bjørnø, Denmark
Email: support@toxscanapp.com (you can also reach us at jonas@jonaswesth.com)
Jonas Westh Creative is the "data controller" for the personal data described in this policy. That means we decide how and why this data is used, and we are the ones responsible for it.
2. What we collect
A random device identifier. When you first open ToxScan, the app generates a random identifier (a UUID) and stores it on your device. This ID is not derived from your name, email, phone number, or any Apple or Google account. It is how we recognize your install without knowing who you are. It is sent with requests to our server and is used as your subscription identifier with RevenueCat.
Scan and usage data. When you scan a barcode, our server logs the barcode, the product lookup result, the AI analysis result, and the outcome of the scan, linked to your device identifier. We also log app events such as screens viewed, scan outcomes, and subscription funnel steps (for example, that a trial was started), along with your platform (iOS or Android).
Photos, briefly. If you photograph a product or its ingredient label, the photo is sent through our server to Anthropic (the AI provider) to read the text or identify the product. Photos are processed transiently and are not stored on ToxScan's servers. Camera snapshots used to display the product on your result screen stay on your device.
Purchase state. If you subscribe, we receive subscription lifecycle events (for example trial started, renewed, cancelled) including the price and country, linked to your device identifier. We never see your card number or payment details. Apple and Google handle payment.
Crash reports. If the app crashes or hits an error, a technical error report is sent to Sentry. We have configured Sentry not to collect personal information.
What we do NOT collect: your name, your email address (unless you choose to email us), any account or login, your precise location, your contacts, or your payment card details. ToxScan has no user accounts at all.
3. Why we use this data
- To provide the service. Looking up products, generating AI analyses, remembering your free scans, and managing your subscription.
- To improve the app. Understanding which scans succeed or fail, which screens people use, and where the app breaks, so we can fix and improve it.
- To make results faster for everyone. Analyzed products are cached anonymously (barcode to result, with no device identifier) so the next person who scans the same product gets an instant answer.
- To measure advertising. We run ads (currently on Meta platforms) and need to know whether they lead to installs and subscriptions.
- To fix crashes. Error reports tell us when and why the app fails.
4. Legal bases under GDPR
If you are in the EU, UK, or a similar jurisdiction, each use of your data needs a legal basis. Ours are:
| Purpose | Legal basis |
|---|---|
| Providing the scanning service and AI analysis | Performance of a contract (the service you asked for) |
| Managing subscriptions and free-scan limits | Performance of a contract |
| First-party analytics and app improvement | Legitimate interest (understanding and improving our own app) |
| Crash reporting | Legitimate interest (keeping the app working) |
| Anonymous product result caching | Legitimate interest (faster results for all users) |
| Advertising measurement with Meta | Consent, where required. On iOS we ask through Apple's App Tracking Transparency prompt before your device's advertising data is used for cross-app ad measurement. If you decline, events sent to Meta do not include the cross-app advertising identifier. |
Where we rely on legitimate interest, you have the right to object (see section 8). Where we rely on consent, you can withdraw it at any time (on iOS: Settings, Privacy & Security, Tracking).
5. Who we share data with
We never sell your data. We share data with the service providers below, each for a specific job:
| Service | What it does for ToxScan | What it receives |
|---|---|---|
| Anthropic (Claude AI, USA) | Reads ingredient labels from photos, identifies products, and generates the health analysis | Product photos (transiently, not stored by us), barcodes, product names and ingredient text. No device identifier is sent to Anthropic. |
| Cloudflare (global network, including the EU) | Runs our server, product cache, and analytics database | Barcodes, scan results, app events, and your device identifier |
| Meta (Facebook) (USA) | Ad measurement and attribution | App events such as install, trial start, purchase, and funnel steps, with device identifiers and a shared event ID, sent both from the app (Meta SDK) and from our server (Conversions API) so Meta can de-duplicate them. Subject to your ATT choice on iOS. |
| RevenueCat (USA) | Manages subscription state across devices and platforms | Your device identifier and subscription events (trial, purchase, renewal, cancellation, price, country) |
| Apple App Store / Google Play | Process payment and distribute the app | Your payment, handled entirely under Apple's or Google's own terms. We never see card details. |
| Sentry (EU-hosted) | Crash and error reporting | Technical error reports only. Configured to not send personal information. |
| Product databases: Publicly available product databases and search services (they receive only the barcode or product name, never any information about you) | Look up product names and ingredients | Only the barcode or product name. No device identifier, ever. |
6. How long we keep data
- Anonymous product cache: 30 days per product result.
- Scan logs and analytics events: up to 24 months, then deleted or anonymized.
- Crash reports: retained by Sentry for around 90 days.
- Subscription records: as long as needed for the subscription and for accounting and tax obligations under Danish law.
- On your device: the device identifier, scan history, and snapshots stay on your device until you delete the app.
7. International transfers
ToxScan is operated from Denmark and our crash reporting is EU-hosted. Some providers (for example Anthropic, Meta and RevenueCat) are based in the United States, and Cloudflare operates a global network. Where your data leaves the EU, the transfer is protected by European Commission Standard Contractual Clauses or by the provider's certification under the EU-US Data Privacy Framework. You can ask us for details about a specific provider at any time.
8. Your rights
If you are in the EU, UK, or Switzerland, you have the right to:
- Access: ask for a copy of the data we hold that relates to your device.
- Rectification: ask us to correct inaccurate data.
- Erasure: ask us to delete your data.
- Restriction: ask us to limit how we process your data.
- Portability: receive your data in a portable format, where applicable.
- Objection: object to processing based on legitimate interest, and to any automated processing that significantly affects you.
- Withdraw consent: at any time, without affecting past processing.
- Complain: lodge a complaint with your data protection authority. In Denmark this is Datatilsynet (www.datatilsynet.dk). You can also complain to the authority in your own EU country.
How to exercise these rights: email support@toxscanapp.com. Because ToxScan has no accounts, your data is linked only to the random device identifier, not to your name or email. To find and delete your data we will work with you to identify your device identifier. Deleting the app removes the identifier and all ToxScan data from your device, and permanently breaks any link between you and the server-side scan logs.
We respond to requests within one month.
9. Children
ToxScan is not directed at children under 16, and we do not knowingly collect data from children under 16. If you believe a child under 16 has used ToxScan and you want the related data deleted, contact us.
10. Security
Data travels encrypted (HTTPS) between the app, our server, and our providers. Access to our databases is restricted. No system is 100% secure, but the small amount of personal data we hold, with no names or emails, limits what could ever be exposed.
11. Changes to this policy
When we change this policy we will update the date at the top. If a change is significant, we will let you know in the app.
12. Contact
Questions, requests, or complaints:
Jonas Westh Creative
Bjørnø 12, 5603 Bjørnø, Denmark
support@toxscanapp.com (fallback: jonas@jonaswesth.com)