Privacy Policy
Last updated: 30 September 2026Helal Scan (“we,” “us”) helps you check whether a product's ingredients are permissible. We built the app to need as little of your data as possible. This policy explains exactly what we do and don't collect.
What we collect
| A random device identifier | Created on first launch and stored securely on your device (the iOS Keychain or the Android Keystore), and sent to our server with each request. Your scan history is kept on our server against this identifier, which is what lets the history work across launches, and it also lets us prevent abuse. It is not linked to your name, email, Apple ID or Google account. |
|---|---|
| Barcodes you scan | Sent to our server over HTTPS to look up the product and return an answer. Scans may be recorded to measure coverage and improve accuracy. |
| Searches | When you search by product name or brand, the search text is sent to our server over HTTPS to find matching products. We do not store searches. If a search fails, its text may appear in our error logs so we can fix the problem. |
| Ingredient text you submit | If you use “Add a missing product” or suggest a correction, the text you type or confirm is sent to us and stored to improve the shared database. While you edit that text, the app also sends it to us so it can point out words our checker does not recognise yet; that check stores nothing. |
| Which screens you open | If Share anonymous usage is on in Settings, the app tells us the name of the screen you opened — and, for the E‑number directory, which E‑number you looked at. It is how we learn which parts of the app are worth improving. It is tied to the same random device identifier, never to you, and it is not sent at all while that switch is off. In the EU, the EEA and the UK the switch starts OFF, so nothing is collected unless you turn it on; elsewhere it starts on and you can turn it off. We never receive what you type into a search box. |
| Notifications | Only if you allow notifications. A push token for your device, the app’s language (so the notification is written in it), which of the two switches in Settings are on, and a record of the notifications we sent you and whether you opened one. We use them only to tell you when a product you asked the maker about, or scanned while it read “Mushbooh”, gets an answer — at most one a day, and never at night. No location or time zone is collected. Turn them off in Settings at any time; Clear Scan History deletes the record and the token. |
| IP address | Transiently, for rate limiting and in server logs, to prevent abuse and keep the service running. We do not use it to identify you. |
What we do not collect
| Accounts or personal identity | Never No sign-up, name, email, phone, Apple ID or Google account is required or collected. |
|---|---|
| Photos or images | Never Text recognition (OCR) runs entirely on your device. Images are processed on-device and are never uploaded. |
| Location | Never The app does not request or use your location, and we do not derive an approximate one from your IP address either. Whether the usage switch starts off is decided by your device’s own region setting, read on the device and never sent to us. |
| Tracking IDs | Never No cross-app or cross-site tracking, and no profile built about you. |
| Analytics or advertising SDKs | Never The app bundles no analytics, attribution, advertising or tracking libraries, and no third party receives your usage. The screen names described above go to our own servers, and nowhere else. The one Google component the app uses, ML Kit, is described under Third parties. |
Third parties
To return answers, a scanned barcode may be looked up against Open Food Facts, a public, open ingredient database. Our servers are hosted by our infrastructure provider solely to run the service. We do not sell or share your data with advertisers or data brokers.
Notifications, if you allow them, are delivered through Expo’s push service and then Apple’s or Google’s own push service, which is how any app on your phone receives a notification. They receive your push token and the notification’s text (a product name and its answer) — nothing else about you.
Text recognition, and barcode scanning on Android, use Google ML Kit, which runs on your device. ML Kit may send Google diagnostic data about how it performs: device model and operating system version, app version, a per-installation identifier that is not intended to identify you, and performance and error data. It does not send your photos, the text it reads or the barcodes you scan. See Google's ML Kit data disclosure.
This website (helalscan.com, not the app) uses no analytics, no cookies and no tracking scripts. It is served through Cloudflare, a US company, which necessarily receives your IP address and browser details with each request in order to deliver the page; we do not receive or keep them. Product pages show the pack photo from Open Food Facts, a non-profit in France, so your browser fetches that image from them and they see your IP address.
How we use the data
Only to operate and improve Helal Scan: to return an answer for a scan, to keep your local scan history, to grow and correct the ingredient database from submissions, and to prevent abuse of the service. We do not use it for advertising or profiling.
Retention
Scan and submission records are retained to maintain and improve accuracy. Your scan history is stored on our server against your random device identifier, not only on your phone. You can erase it at any time with “Clear Scan History” in the app, which deletes those server records as well as the local copy. Deleting the app removes the identifier and the local copy from your phone, but it cannot reach our server, so clear your history first if you want those records gone. You can also ask us to delete submissions associated with your device identifier (see Support).
Security
Data in transit is protected with HTTPS/TLS. The device identifier is held in the operating system's secure storage. See our Privacy & Security page for a plain-English walkthrough.
Children
Helal Scan is a general-audience utility and is not directed at children under 13. We do not knowingly collect personal information from children.
Your choices
- Delete the app to remove the device identifier and local scan history from your phone.
- Contact us to request deletion of ingredient submissions tied to your device identifier.
Changes
If this policy changes, we will update this page and revise the date above.
Contact
Questions or requests: [email protected].