Privacy Policy

Effective Date: August 23, 2025

VeganKey helps you scan restaurant menus and make informed choices about vegan and modifiable dishes. This Privacy Policy explains what we collect, how we use it, and the choices you have. We do not sell your personal information, we do not run third‑party advertising, and we do not track your activity across other companies' apps or websites.

1) Summary

We process menu images you submit and generate classifications (e.g., Vegan, Modifiable, Not Vegan) and suggestions. We collect device/app information and purchase data necessary to operate the app, improve quality, and support subscriptions. You can delete scans and request a copy or deletion of your data.

2) What We Collect

Provided by You

  • Menu Photos (user‑initiated): Images you capture or upload for analysis.
  • Favorites & History (optional): Saved dishes, restaurants, and past results.
  • Account & Support: Email and any message content if you create an account or contact support.

Collected Automatically

  • Device & App Info: Device identifier (e.g., IDFV), device model, operating system version, app version, language, and IP address.
  • Events & Usage Analytics (aggregate or pseudonymous): App launches, scan starts/completions, paywall views, purchases, quota violations, settings access, feature taps.
  • Performance Metrics: App launch time, processing duration, image file size, memory pressure levels.
  • Diagnostics & Crash Logs: Stability data and crash traces.
  • Subscription & Purchase Data: Transaction identifiers, purchase timestamps, receipt/verification data, product identifiers, offer/trial eligibility, and localization context (currency/region) required for StoreKit and fraud prevention.

Not Collected by Default

  • Precise Geolocation (off by default).
  • Sensitive categories not required to operate the app (e.g., health records, financial account numbers).

3) How We Use Data

  • Core Functionality: Analyze menu photos (and where applicable extracted text) to return classifications and suggestions.
  • Performance & Quality: Measure reliability, speed, and accuracy; tune models and prompts; detect abuse or anomalous usage.
  • Purchases & Entitlements: Validate receipts, manage subscriptions, apply free‑trial/intro offers, and localize pricing.
  • Support & Safety: Respond to requests, debug issues, prevent fraud/abuse, and comply with legal obligations.
  • No Automated Decisions With Legal Effects: We use AI classification to label menu items, but not to make decisions producing legal or similarly significant effects about you.

4) Processing & Storage

  • On‑device: Camera capture; optional on‑device OCR (Apple Vision) where available.
  • Cloud processing: Images are uploaded securely to AWS S3. We may send the image and/or extracted text to OpenAI to classify items.
  • Application services:
    • AWS Lambda (including orchestration functions) to handle classification and move files.
    • AWS AppSync/GraphQL to route structured results.
    • Amazon DynamoDB (via Amplify DataStore) to persist results/history/favorites.
    • Amazon CloudWatch for operational logs.
    • Amazon Pinpoint/Analytics (if enabled) for aggregate usage metrics.
    • Apple for in‑app purchases, analytics, and crash diagnostics.

5) Third‑Party Service Providers

We use vetted processors solely to provide and improve the app: Amazon Web Services (S3, DynamoDB, Lambda, AppSync, CloudWatch), OpenAI (menu understanding and classification), and Apple (IAP, analytics, crash logs). We do not allow providers to use your data for their own marketing.

6) Data Retention

  • Menu Photos: Retained only as long as needed to generate results and ensure reliability (short‑term caching or troubleshooting); routine purges are applied.
  • Results (JSON): Retained to power history and favorites until you delete them or request deletion.
  • Rejects/Low‑Confidence Images: Retained briefly (typically ≤ 30 days) for review/quality and then purged.
  • Purchase/Entitlement Records & Logs: Retained as needed for compliance, fraud prevention, and accounting.

You can delete scans and favorites in the app, or request deletion/export via support@vegankey.xyz. We will delete associated data unless retention is required by law or needed for abuse prevention.

7) Your Choices & Rights

  • Access/Deletion/Export: Email support@vegankey.xyz to request a copy or deletion of your data.
  • Opt‑outs: Where offered, you can disable analytics and delete history/favorites.
  • Permissions: Revoke camera/photo permissions in iOS Settings.

EEA/UK: Legal bases include Contract (core app functions), Legitimate Interests (security, quality, analytics), and Legal Obligation (billing/records). You may have rights to access, correct, delete, restrict, object, and data portability. Contact us to exercise rights.

California (CPRA): We do not "sell" or "share" personal information for cross‑context behavioral advertising. Categories collected can include identifiers (IDFV/IP/email), device & internet activity, purchase info, and in‑app content you submit. You may request access/correction/deletion and limit use of sensitive info (we don't process sensitive categories for inferring characteristics).

8) Children's Privacy

The app is not directed to children under 13. If you believe a child provided data, contact us and we will delete it.

9) Security

We use industry‑standard safeguards, including TLS in transit and server‑side encryption at rest (e.g., S3 & DynamoDB), least‑privilege access, and monitoring. No method is 100% secure, but we work continuously to protect your data.

10) International Transfers

Data may be processed in the United States and other locations where we and our providers operate. When transferring personal data internationally, we apply appropriate safeguards consistent with this Policy (e.g., standard contractual clauses where applicable).

11) Changes to This Policy

We may update this Policy from time to time. We will post the new version and update the Effective Date. Material changes may be announced in‑app.

12) Contact

Questions, privacy requests, or complaints: support@vegankey.xyz