1. Controller
The Fino application and website are operated by Aleksandar Deskoski (sole proprietor), hereinafter referred to as "the Controller". For all privacy-related correspondence: [email protected].
2. Categories of Personal Data Collected and Purposes of Processing
2(a) Account Data
Data collected: email address; authentication identifiers issued by Supabase.
Purpose: account creation, authentication, and account recovery.
Storage: Supabase, hosted in the European Union (Frankfurt data centre).
Legal basis (GDPR): performance of a contract to which the data subject is a party — Article 6(1)(b) of Regulation (EU) 2016/679 ("GDPR").
2(b) Health Data (Special Category — GDPR Article 9)
Data collected: allergy and intolerance profiles, including severity settings, for the account holder and any family profiles the user creates within the application.
Purpose: comparison of food product ingredient lists against the user's saved avoid list in order to generate scan results.
Storage: stored server-side in Supabase (EU, Frankfurt) so that profiles follow the account across devices.
Legal basis (GDPR): explicit consent of the data subject — GDPR Article 9(2)(a). Consent is obtained in-app, prior to any processing of health data. Consent may be withdrawn at any time via Settings → Data & privacy within the application. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal. Upon withdrawal, the server-side profile data is deleted.
2(c) Scan Content
Data collected and processed: photographs of product labels are processed transiently on-device and via the Controller's infrastructure solely to recognise printed text. The recognised ingredient text, together with the active profile's avoid list, is transmitted to a Cloudflare Worker operated by the Controller and onward to OpenAI for analysis. No name, email address, or location data accompanies scan requests. OpenAI does not use data submitted via its API for the training of its models.
Storage: scan history is stored locally on the user's device. Original photographs are not stored on the Controller's servers.
Legal basis (GDPR): performance of a contract — Article 6(1)(b).
2(d) Purchase Data
Data processed: subscription entitlement status processed via Apple and RevenueCat. No payment card data or payment instrument details are received by the Controller.
Legal basis (GDPR): performance of a contract — Article 6(1)(b).
2(e) Optional iCloud Synchronisation
iCloud synchronisation is disabled by default. If the user elects to enable it, profile and history data sync via the user's private iCloud account, operated by Apple Inc. The Controller does not receive or store data transmitted via this pathway.
2(f) Website
The Fino website stores a single functional localStorage entry recording the
visitor's selected language preference. No tracking cookies are set and no advertising
identifiers are collected via the website.
2(g) Consent and Age-Verification Records
Data collected: date of birth or age confirmation, country/region, and consent records (the consent given, its version, and the time at which it was given or withdrawn).
Purpose: verification of the minimum-age requirements set out in Section 10, determination of the applicable consent regime, and documentation of consent as required by GDPR Article 7(1).
Legal basis (GDPR): compliance with legal obligations to which the Controller is subject — Article 6(1)(c) — and the Controller's legitimate interest in maintaining demonstrable records of consent — Article 6(1)(f).
2(h) Usage Analytics (Opt-In)
Data collected: anonymised in-app usage events (for example, that a scan was started or a screen was viewed). Usage events never include ingredient text, scan results, health data, names, or precise location.
Purpose: understanding aggregate feature usage in order to improve the application.
Legal basis (GDPR): consent — Article 6(1)(a). Analytics are processed only where the user has opted in, and the choice may be reversed at any time via Settings → Data & privacy.
3. Recipients and Sub-Processors
The Controller engages a limited set of sub-processors. A maintained list, including each processor's role, data location, and transfer mechanism, is published at /sub-processors. The current processors are:
- Supabase, Inc. — authentication and database infrastructure (EU, Frankfurt)
- Cloudflare, Inc. — edge network and Worker infrastructure
- OpenAI, LLC — AI analysis of recognised ingredient text
- Apple Inc. — App Store distribution, in-app purchase billing
- RevenueCat, Inc. — subscription entitlement management
The Controller does not sell personal data and does not share personal data for cross-context behavioural advertising.
4. International Transfers
Several sub-processors are established in the United States. Transfers of personal data to those processors are safeguarded by one or more of the following mechanisms: (i) the EU–U.S. Data Privacy Framework (and its UK and Swiss extensions) where the processor is certified thereunder; and/or (ii) Standard Contractual Clauses approved by the European Commission pursuant to Article 46(2)(c) GDPR. Supplementary technical measures, including encryption in transit (TLS 1.2 or higher) and at rest, are in place.
5. Retention
- Account data and server-side health profile data — retained until the user deletes their account or, in respect of health data, withdraws consent, whichever occurs first.
- Local scan history — retained on the user's device until deleted by the user or until the application is removed.
- Technical backups — maintained for short operational windows in accordance with the Controller's disaster-recovery procedures.
6. Rights of Data Subjects (GDPR)
Data subjects whose personal data is processed by the Controller have the following rights under GDPR, subject to applicable conditions and limitations:
- Right of access (Article 15) — to obtain confirmation of processing and a copy of personal data held.
- Right to rectification (Article 16) — to have inaccurate personal data corrected.
- Right to erasure (Article 17) — to request deletion of personal data where the grounds set out in Article 17 apply.
- Right to restriction of processing (Article 18) — to request that processing be restricted in the circumstances described in Article 18.
- Right to data portability (Article 20) — to receive personal data in a structured, commonly used, machine-readable format.
- Right to object (Article 21) — to object to processing based on legitimate interests or to profiling.
- Right to withdraw consent (Article 7(3)) — to withdraw consent at any time, without affecting the lawfulness of prior processing.
- Right to lodge a complaint (Article 77) — with the competent supervisory authority in the Member State of habitual residence, place of work, or place of the alleged infringement.
7. California Residents — CCPA/CPRA Disclosures
The Controller does not sell personal information as defined under the California Consumer Privacy Act (as amended by the California Privacy Rights Act) and does not share personal information for cross-context behavioural advertising. No personal information has been sold or shared for such purposes in the preceding twelve months.
California residents have the right to:
- Know — request disclosure of the categories and specific pieces of personal information collected, used, disclosed, and sold.
- Delete — request deletion of personal information, subject to legal exceptions.
- Correct — request correction of inaccurate personal information.
- Non-discrimination — not receive discriminatory treatment for exercising CCPA/CPRA rights.
To exercise these rights, see Section 9 of this Policy.
8. Washington Residents — My Health My Data Act
Allergy and intolerance profile data constitutes consumer health data within the meaning of the Washington My Health My Data Act ("MHMDA"). In respect of such data:
- It is collected only with the data subject's affirmative consent, obtained in-app prior to processing.
- It is never sold.
- Washington residents have the right to access such data, to withdraw consent (which results in deletion of the server-side profile), and to request deletion.
To exercise these rights, see Section 9 of this Policy.
9. Exercising Your Rights
The following procedures apply to the exercise of rights under this Policy:
- In-app (recommended): Settings → Data & privacy provides a full data export function (JSON format) and an account deletion function. Withdrawing consent for health data processing is also available at this location.
- By email: submit a request from the email address registered to your account to [email protected]. The Controller may request reasonable identity verification before fulfilling a request, in order to prevent unauthorised disclosure.
- Response time: the Controller will respond within one month of receipt of a verifiable request, as required by GDPR Article 12(3). For requests made under applicable U.S. state privacy laws, the Controller will respond within the period required by the relevant law.
- Appeals and escalation: if a request is refused, the data subject may appeal by replying to the Controller's response. If the Controller's decision is maintained, the data subject may escalate the matter to the competent supervisory authority (GDPR) or, where applicable, to the relevant state attorney general's office.
10. Children
The Fino application and website are not directed to children. The minimum age to create an account is 16 years in the European Economic Area, the United Kingdom, and Switzerland, and 13 years in all other jurisdictions, subject to any higher minimum age imposed by applicable local law. Age is confirmed at sign-up. If the Controller becomes aware that personal data has been collected from a person below the applicable minimum age, that data will be deleted without undue delay.
11. Automated Decision-Making
The Controller does not carry out automated decision-making, including profiling, that produces legal effects or similarly significantly affects the data subject. The Fino application is an informational label-reading aid; outputs generated by the application are informational only and do not constitute medical advice, diagnosis, or treatment.
12. Future Community Features
Should the Controller introduce community features that involve the sharing of user-contributed content, any such sharing will require a separate, explicit, opt-in consent from the user and will not be enabled by default.
13. Changes to This Policy
The Controller may update this Policy when data processing practices change. The revised version will be published at this URL with an updated "Last updated" date. For material changes, an in-app notification will be displayed no fewer than 30 days before the change takes effect. Continued use of the application following the effective date of a material change constitutes acknowledgement of the updated Policy.
Questions about this document?
Email [email protected] for privacy-related requests, or [email protected] for general questions. We reply within 2 business days.