FoodClear
English · Dansk

Updated 5 October 2026

Privacy notice

Your local choices, reviewed evidence and the technical processing behind them.

Current scope: FoodClear is in private development and is not available as a public app. A narrowly enrolled development installation can send reviewed structured package facts to a separate FoodClear development service. Public contributions, contributor sign-in, remote product reports and paid store purchases are not active. This notice also covers this public information website and emails you choose to send.

Controller and contact

Dennis Kakar, trading as EventConnect (PMV), CVR 46455231, is responsible for FoodClear’s processing. The postal address and email are below. Ordinary scanning does not require an account; this does not mean that no personal data are processed.

What stays on your device

Myself/Child choices, focus areas, selected allergens, language, market, private History, quota and cached results remain local. History and factual cache each hold at most 100 records. Review drafts are local to their flow. Preferences and usage remain until changed/reset; cache eviction and freshness rules limit reuse. History reopening preserves its saved version and does not create an upload or another free-scan charge.

Selected allergens and saved results can suggest health concerns. These choices stay on your device and do not become shared product data. FoodClear does not ask for a diagnosis, child name, birth date or a child’s health record. Do not enter sensitive or unrelated personal details into package text.

The local information is used to provide your requested overview and preserve continuity. Local preference processing is not permission for remote health profiling. The required legal assessment and safeguards for any public consumer activation, including potentially health-revealing local choices, remain a launch prerequisite; no public consumer collection is being offered here.

Camera and OCR

Raw label photos remain on the device. Apple Vision (iOS) or Google ML Kit (Android) reads them locally. FoodClear does not upload them or attach them to contributions. The native reader owns temporary images and deletes them after its readers finish or release them on cancellation. Cleanup is retried at supported lifecycle points; deletion failure remains a recoverable error. A crash or an unfinished native read may delay cleanup, so this is not a promise of instantaneous deletion in every OS state.

Google’s retained ML Kit libraries can process technical app/device, installation-identifier and usage/performance information under Google’s ML Kit terms. This is separate from FoodClear product payloads and local image processing. We do not describe the app as having no provider technical processing.

Private development contributions

Explicit review intent can queue minimum structured package information: a validated barcode, confirmed ingredient/warning text, supported nutrition/package fields, known market and source language, original review/observation time, and retry identity. A random installation secret is held in secure device storage. The server retains a purpose-separated pseudonymous hash and restricted receipt/support references for independence, retries and deletion; these never become product facts, profiles, analytics or entitlement.

The limited development purpose is validating the factual service and protecting it against duplicate or abusive requests. Legitimate interests under GDPR Article 6(1)(f) must be assessed for necessity, proportionality and your ability to object. A contribution action is not automatically valid GDPR consent, and building a shared database is not automatically necessary to deliver a local result under Article 6(1)(b). Public contribution remains inactive until that separate review and required controls are complete.

No raw photos, photo metadata, local image paths, personal allergen choices, child context, private History or support messages belong in a contribution. Schema and review checks reduce unintended input but cannot guarantee that arbitrary text is free of personal data.

Retention and deletion

Stopping contribution fences future uploads and uses retained deletion access for applicable server erasure. Required deletion handles survive History clearing and ordinary content reset. A secure installation identity is retained for this limited continuity, not rotated to make new “people”. On iOS secure storage may survive reinstall; Android uninstall can lose it. Uninstalling may lose deletion access; contact us if that happens.

Clearing local History is not erasing server data or refunding quota. Offline/server erasure remains pending until acknowledged. Erasure retracts unsupported confirmation and removes facts supported only by the erased contribution; independently lawfully supported facts may remain. Provider logs and backups have separate lifecycles. We do not guarantee immediate deletion from all provider backups/logs; their actual handling remains a public-activation prerequisite.

Providers and technical requests

The private development database is hosted by Supabase in Frankfurt. Supabase processes hosted records for FoodClear under its applicable service/DPA arrangements and technical operations under its own terms. This is a separate development service, not an active production database. See Supabase’s DPA and privacy information. Product lookups contact Open Food Facts directly and, when enabled for the enrolled installation, the FoodClear dev service. Requests reveal a barcode, relevant technical request data and IP address to the receiving service; provider logs are distinct from FoodClear analytics.

This static site uses Cloudflare Pages for HTTPS delivery and security. Cloudflare can process IP addresses, requested paths, timestamps, request/device information and routing/security logs. Necessary delivery/security is based on legitimate interests, Article 6(1)(f). We add no analytics, advertising trackers, remote fonts, cookies, local storage or forms. Cloudflare has processor duties for customer content/logs and its own controller purposes for some network/security data. Its retention uses necessity and legal-obligation criteria, rather than a FoodClear-guaranteed fixed deletion deadline. See Cloudflare’s privacy policy.

EU database location does not guarantee that every provider log, support operation or subprocessor stays in the EU. Providers may process outside the EEA under their applicable transfer safeguards, such as adequacy arrangements or standard contractual clauses. Ask us for relevant information; this notice does not claim verified EU-only processing or zero provider logs.

Email support

The app and site hand off only our recipient and an empty body after your press. Sending is your choice. If you email us, we receive your sender address, message, timestamps and any attachments you choose. We use them to answer the request and manage necessary follow-up, based on legitimate interests, Article 6(1)(f); handling statutory rights requests uses Article 6(1)(c).

The approved mailbox is Gmail, provided by Google. Its technical processing and retention are governed by Google’s privacy policy; we do not claim a separately qualified Google Workspace processor contract or immediate backup deletion. We retain correspondence only while necessary to answer and follow up; closed cases must be reviewed to remove unnecessary details. Minimal records needed for a legal obligation or dispute remain only for the applicable obligation/claim period. Please avoid health information and details about children.

Inactive functions

PostHog analytics, Sentry hosted error collection, Crisp chat and external language-model calls are OFF. No public contributor Apple sign-in or remote report collection is activated. Local StoreKit test fixtures are not actual purchases. Future Apple purchasing would require limited product/transaction/expiry data to verify entitlement; it would not receive your allergy choices or product History. Any material activation requires updated information and qualified safeguards first.

Your rights

Where applicable, you may request access, correction, erasure, restriction and data portability, object to legitimate-interest processing, or withdraw any applicable consent without affecting earlier lawful processing. Email Dennis using the address below. We respond within GDPR’s applicable deadlines, normally one month; necessary identity/record verification and lawful extensions will be explained. We do not collect extra identifying information solely to put a name on records, but may need information you can provide to locate them or verify a request.

You can complain to Datatilsynet or your competent supervisory authority. FoodClear makes no automated decision with legal or similarly significant effects and does not sell personal History or use it for advertising. Material changes to purposes or providers require an updated dated notice and any necessary additional controls.