Privacy Policy

Last updated: April 28, 2026

This Privacy Policy describes how Ask Nonna (“we,” “us,” or “our”) collects, uses, and protects information when you use our AI-powered food ingredient analyzer mobile application and website (“App” or “Service”). This Service is operated by Axiomic, LLC, a California limited liability company based in Mill Valley, California.

We do not sell, rent, or trade your personal information to third parties. We never have, and we never will.

This Privacy Policy should be read in conjunction with our Terms of Service, which governs your use of the App.

1. Definitions

  • “Personal Information” means any information that identifies, relates to, or could reasonably be linked to you or your household.
  • “Processing” means any operation performed on Personal Information, whether automated or manual.
  • “Community Knowledge Base” refers to the public database of food products, ingredients, producers, and verdicts.

2. Information We Collect

Information you provide:

  • Apple ID email address and display name (via Sign in with Apple)
  • Food label images (when you scan a product)
  • Votes on verdict accuracy
  • Comments, ingredient corrections, and alternative product suggestions

Information generated by the App:

  • A unique user identifier (UUID)
  • User profile (auto-created on sign-up)
  • Verdict records (product name, producer, verdict, ingredient analysis)
  • Scan history (which products you scanned and when)
  • Per-scan results: the raw output of each individual ingredient analysis (product name, producer, verdict, and ingredient list as identified that scan), used to improve the canonical product record over time as multiple users scan the same product.
  • Follow relationships and blocks (who you follow, who you've blocked from your feeds)
  • Reports you submit about other users' content or behavior

Information collected automatically:

  • Authentication session data (tokens, refresh timestamps)
  • Rate-limiting logs (scan count per day, for abuse prevention)
  • Edge Function request metadata (timestamp, response status)

3. Information We Do Not Collect

We do not use analytics SDKs, crash-reporting tools, advertising identifiers, or device fingerprinting. The App does not collect:

  • Device advertising identifier (IDFA)
  • Location data (GPS, IP-based geolocation, or otherwise)
  • Contacts, calendar, or health data
  • Browsing history
  • Data from other apps on your device
  • Biometric data
  • Payment or financial information

4. How We Use Your Information

Core functionality:

  • Authenticate your identity via Apple Sign In
  • Analyze food ingredient labels via AI (Google Gemini)
  • Display and store your scan history (server-side, so your pantry persists across reinstalls and devices)

Community Knowledge Base:

  • Build a public database of food products, ingredients, and producers
  • Display anonymized product data on the Ask Nonna website
  • Aggregate ingredient statistics (occurrence counts, rating distributions)

Anti-abuse:

  • Rate limiting (50 scans per day per user)
  • SafeSearch image moderation to prevent inappropriate uploads

We do not use your data for advertising, selling to data brokers, behavioral profiling, or training AI models.

5. AI Processing, Barcode Detection & Storage of Images

When you open the camera, the App passively detects product barcodes (UPC-A, UPC-E, EAN-8, EAN-13) visible in the camera feed using on-device processing (Apple AVFoundation). If a barcode is detected, it is sent to our backend along with the food label image. If a matching product already exists in our database, you receive an instant cached result without the image being sent to Google's AI.

When you scan a food label, the image is resized (max 768px), compressed to JPEG, and transmitted to our backend over HTTPS. Our backend:

  • Forwards the image to the Google Gemini API for ingredient analysis. Only the food label image is sent; no personal information is transmitted to Google's AI.
  • Runs Google Cloud Vision SafeSearch moderation to screen for inappropriate content. Images flagged as inappropriate are rejected and not stored.
  • Stores the label image in our file storage to display on product pages in the Community Knowledge Base.

Label images are associated with the product, not with your personal account. They remain in the Community Knowledge Base after account deletion.

We do not use your images or any submitted data for training artificial intelligence or machine learning models.

6. Data Storage & Security

Server storage (Supabase):

  • Authentication credentials, encrypted in transit and at rest.
  • User profile (display name, email).
  • Product data: product name, producer, ingredients, verdict, label image.
  • Your activity: votes, comments, corrections, scan history (your pantry).

Your scan history is stored on our servers, not on your device. This means your pantry persists across app reinstalls and is consistent across any devices signed into your account.

Security measures:

  • All data transmitted between the App and our servers is encrypted using TLS 1.2 or higher (HTTPS).
  • Authentication uses OAuth 2.0 with PKCE via Sign in with Apple.
  • Database access is restricted by Row Level Security (RLS) policies.
  • Service-role isolation ensures user requests cannot access other users' data.
  • JWT-based authentication on all API endpoints.

No sensitive data collected: We do not process payments, government IDs, social security numbers, biometric data, or precise location data.

No method of internet transmission or electronic storage is completely secure. While we strive to use commercially acceptable means to protect your Personal Information, we cannot guarantee its absolute security.

7. Sub-Processors

We only work with providers that meet industry-standard security and privacy practices. Each sub-processor is contractually obligated to protect your data and may only process it for the specific purposes described. We do not share your data with advertising networks, data brokers, or analytics providers.

ServicePurposeLocation
AppleAuthentication (Sign in with Apple)USA
SupabaseBackend infrastructure, database, auth, file storageUSA
Google Gemini APIAI ingredient analysis (food label images only)USA
VercelWebsite hosting, CDN, serverless renderingUSA
Google Cloud VisionImage content moderation (SafeSearch)USA

8. Data Retention

We retain information only as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce our Terms.

  • Active accounts: Retained for the duration of your account.
  • Deleted accounts: Personal data (profile, votes, comments, corrections, scan history) permanently removed immediately upon deletion.
  • Community Knowledge Base: Product data (product name, ingredients, verdict, label image) retained indefinitely in anonymized form. Your identity is removed and cannot be recovered.
  • Rate-limiting logs: Retained for approximately 90 days.
  • Edge Function logs: Retained per Supabase's standard retention (approximately 14 days).

9. Your Rights & Choices

Regardless of your location, you have the following rights:

  • Camera access: You may deny or revoke camera access at any time in device Settings.
  • Hide scans from your Pantry: Use the swipe action in your Pantry to hide a scan from your own view. The product itself remains in the public Community Knowledge Base — hiding only affects what you see in your own pantry, not what other users see, your scan-count attribution, or the product's data on the website. Once a product has been scanned by anyone, the product record cannot be removed from the Community Knowledge Base.
  • Delete your account: Use the “Delete Account” button in the App's Settings screen. This immediately and permanently deletes your profile, votes, comments, corrections, and personal scan history from our servers, and removes your authentication account. Product data you contributed remains in the Community Knowledge Base in anonymized form (see “What we keep after deletion” below).
  • Access and portability: Request a copy of all Personal Information we hold about you.
  • Correction: Request correction of inaccurate data.

What we keep after deletion: Product data you scanned (product name, ingredients, verdict, label image) remains in the Community Knowledge Base in anonymized form — your identity is removed and cannot be recovered.

To exercise any of these rights, use the in-app features or contact [email protected] with the subject line “Privacy Request.”

10. California Privacy Rights (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):

Categories of Personal Information collected:

  • Identifiers: name, email address, unique user ID
  • Internet activity: scan history, votes, comments

Your California rights:

  • Right to know: Request disclosure of categories and specific pieces of Personal Information collected.
  • Right to correct: Request correction of inaccurate Personal Information.
  • Right to delete: Request deletion of your Personal Information.
  • Right to opt-out of sale: We do not sell Personal Information.
  • Right to non-discrimination: We will not discriminate against you for exercising privacy rights.
  • Right to limit use of sensitive information: We do not collect sensitive Personal Information as defined by the CPRA.

You can exercise your right to delete via the in-app “Delete Account” button, which processes your request immediately. We will respond to other verified CCPA requests within 45 days. Email [email protected] with subject line “CCPA Request.”

11. Other U.S. State Privacy Rights

If you are a resident of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), or another state with applicable consumer privacy legislation, you may have similar rights including:

  • Right to access your Personal Information
  • Right to correct inaccuracies
  • Right to delete your Personal Information
  • Right to data portability
  • Right to opt out of the sale of Personal Information (we do not sell your data)
  • Right to opt out of targeted advertising (we do not engage in targeted advertising)

To exercise your rights, email [email protected] with subject line “State Privacy Request.” We will respond within the timeframe required by your state's law.

12. European & UK Privacy Rights (GDPR)

If you are located in the EEA or UK, the GDPR provides you with additional rights.

Legal basis for processing:

  • Contract performance: Processing necessary to provide the Service (authentication, scan analysis, scan history).
  • Legitimate interests: Operating and improving the Service, maintaining the Community Knowledge Base, preventing abuse. We retain anonymized product data under legitimate interest in maintaining a public food safety resource.
  • Consent: Where required (e.g., optional features).

Your GDPR rights:

  • Access: Request a copy of your Personal Information.
  • Rectification: Request correction of inaccurate data.
  • Erasure: Request deletion (“right to be forgotten”). Note: anonymized product data in the Community Knowledge Base is no longer Personal Information and is not subject to erasure.
  • Restriction: Request restriction of processing.
  • Portability: Receive your data in a structured format.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw consent: Withdraw consent at any time.
  • Lodge a complaint: File a complaint with your local data protection authority.

Ask Nonna is the data controller. Sub-processors in Section 7 act as data processors on our behalf.

We will respond to GDPR requests within 30 days. Email [email protected] with subject line “GDPR Request.”

13. International Data Transfers

If you access the App from outside the United States, your information will be transferred to and processed in the United States.

For transfers from the EEA/UK:

  • Standard Contractual Clauses (SCCs), where applicable through sub-processors.
  • EU-U.S. Data Privacy Framework (DPF), where sub-processors are certified.
  • Your explicit consent where no other mechanism applies.

All international data transfers are protected by TLS 1.2+ encryption in transit and encryption at rest.

14. Data Breach Notification

In the event of a data breach affecting your Personal Information:

  • We will notify affected users within 72 hours of becoming aware of the breach.
  • Notification will be sent via email to your account address and/or prominent notice in the App.
  • The notice will include: description of the breach, types of data involved, steps we are taking, steps you can take, and contact information.
  • We will notify relevant authorities as required by law, including under the GDPR (within 72 hours) and California Civil Code §1798.82.

15. Children's Privacy

The App is not intended for children under 13. We do not knowingly collect Personal Information from anyone under 13. If we become aware that we have collected data from a child under 13, we will delete it promptly. For users between 13 and 18, parental or guardian consent is required. If you believe we have inadvertently collected information from a minor, please contact us immediately.

16. Do Not Track

The App is a native iOS application and does not respond to web browser Do Not Track (DNT) signals. We do not use web-based tracking technologies, advertising cookies, cross-site tracking, or social media tracking pixels.

17. Third-Party Links

The App and website may display links to third-party websites, including producer websites extracted from product labels. This Privacy Policy does not apply to third-party sites. We are not responsible for the privacy practices, content, or security of any third-party websites. We encourage you to review the privacy policy of every site you visit.

18. Changes to This Policy

When we update this Privacy Policy:

  • We will update the “Last Updated” date.
  • For material changes, we will notify you through the App at least 30 days before changes take effect.

Your continued use of the App after the effective date constitutes acceptance. If you do not agree, you must stop using the App.

19. Contact Us

For privacy-related questions or to exercise your rights, contact us at: [email protected]

Recommended subject lines:

  • “CCPA Request” — California privacy rights
  • “GDPR Request” — European/UK privacy rights
  • “State Privacy Request” — Other U.S. state privacy rights
  • “Privacy Inquiry” — General privacy questions

Marin County, California, United States