Last updated 8 September 2026
Vegan Lens is a food app, so almost everything it knows about you is something you told it on purpose: what you ate, what’s in your cupboard, a photo of a label. This page says exactly what happens to all of it. It is written to be read, not to be survived.
The short version.
On this page
Vegan Lens (“the app”, “we”) is operated by Boris Nandi, Level 1, Suite 1.01/222 Pitt St, Sydney NSW 2000, Australia. For the purposes of the UK and EU GDPR we are the data controller for the information described here, and in Australia we handle personal information in line with the Australian Privacy Principles.
Privacy questions, data requests and complaints: privacy@veganlens.app. We answer every request within 30 days, and usually within a few days.
We collect five kinds of thing, and nothing else.
Purpose: to give you an account that follows you between devices. Legal basis: performance of a contract.
Purpose: to make the targets and recommendations yours rather than generic. Legal basis: consent (see §4 on health data). You can change or clear all of it.
Purpose: it is the app. Legal basis: performance of a contract.
Every time the AI is asked something, we write one row noting that it happened: the kind of scan, the verdict, a confidence number, which model answered, how many tokens it used, what it cost us, how long it took, and any error. This is how we keep the app affordable, catch a model that has started answering badly, and count your free scans for the day.
Legal basis: legitimate interest in running and paying for the service.
Purpose: to email you once when the app is released, or to add you to the Google Play closed test if that is the form you filled in. Legal basis: consent, which you can withdraw at any moment by replying to any email from us or writing to privacy@veganlens.app. Joining the list does not create an account, and is not linked to one if you make one later.
The app contains no advertising SDK, no analytics SDK and no tracking of any kind. That has not changed and is not going to. The paragraphs below are about the website only, which is a different thing with a different job: we pay for advertising to bring people here, and we need to know which of those adverts actually leads to someone installing the app.
To measure that, veganlens.app can load advertising tags from Google, Meta (Facebook and Instagram) and TikTok. When one of these loads, it may set cookies or similar storage in your browser and send your IP address, the page you are on and which of our buttons you pressed to that company, which uses it to attribute an advert to a visit. These companies are outside the EU, and transfers rely on the relevant standard contractual clauses and adequacy decisions.
Region is determined from your browser’s time zone and language settings, because a site made of static files has no other way to tell. It is accurate for almost everyone and it is not perfect — if you are in the EU or UK and were not asked, tell us at privacy@veganlens.app and we will fix it.
We never send your email address, or anything else you type, to any of these companies. They see that a visit happened and what was clicked. Legal basis: consent where consent is required, and legitimate interest in measuring our own advertising elsewhere.
What the app does not collect. No advertising identifier. No contacts, calendar, microphone, or health-app data. No third-party analytics or attribution SDK. No location history. No browsing behaviour, in this app or any other. The advertising tags described above exist only on the website, and never inside the app.
When you photograph a meal, a label or a menu, the picture is resized on your phone and sent over an encrypted connection to our server, which forwards it to OpenAI to be analysed. OpenAI returns a verdict and an ingredient read; we return that to your phone.
The app asks for your permission before the first such scan, and will not run one until you agree. Barcode scanning does not involve AI and works whether you agree or not.
The photo is not kept. It exists in memory long enough to be analysed and is then discarded — it is never written to our database or our file storage. What we keep is the result: the verdict, the ingredients the model read, and the nutrition estimate, attached to the meal in your log.
We may add an opt-in one day that lets you keep the photo alongside the meal. If we do, it will be off by default, it will be a switch you turn on yourself, and this page will say so before it ships.
OpenAI processes the image on our behalf as a data processor under their API terms. API inputs are not used to train OpenAI’s models. OpenAI may retain the request briefly for abuse monitoring before deleting it; see openai.com/policies.
Please don’t photograph other people, documents, or anything you would mind a third party processing. The app only needs to see food.
Your height, weight, age and food log are, taken together, information about your health. Under GDPR Article 9 that is a special category of personal data, and we rely on your explicit consent to process it — given when you complete onboarding, and withdrawable at any time by deleting your account or clearing those answers.
We do not share this data with anyone. It is not sold, not used for advertising, and not passed to any insurer, employer, or data broker — there is no arrangement of that kind, and there will not be one.
Vegan Lens is not a medical service. Its nutrition figures are estimates for general wellness. It does not diagnose, treat or prevent anything, and it is not a substitute for advice from a doctor or a registered dietitian.
If you use nearby places, the app asks for your location while you are using it. Your coordinates are sent to the public Overpass API to ask OpenStreetMap “what vegan-friendly places are within this radius”.
veganlens+ is sold through the App Store and Google Play. We never see or handle your payment details — Apple and Google take the payment, and we are told only whether a subscription is active.
We use RevenueCat to keep track of that. RevenueCat receives your account’s user id, the store’s purchase receipt, the product bought, and its renewal or expiry date, and tells our server when your subscription starts, renews or lapses. We store the resulting entitlement — active or not, which product, when it expires, and whether it is a sandbox purchase — against your account, because a subscription that only your phone knew about would be trivial to fake.
These are every third party involved, and exactly what each one gets.
| Who | What they receive | Why |
|---|---|---|
| Supabase | Everything in your account: profile, food log, pantry, saved recipes and places | They host our database, authentication and file storage (Frankfurt, Germany) |
| Vercel | Only what any web request carries: your IP address, your browser, and the page you asked for. No account data — the app itself never talks to them | They host the veganlens.app website, including this page |
| OpenAI | The photo or menu text you scan, and the question asked about it | The scan itself. Not used to train their models |
| RevenueCat | Your user id, store receipt, product and renewal date | To know whether veganlens+ is active |
| Apple / Google | Payment details, which we never see; and your identifier if you use their sign-in | Distribution, payment, and optional sign-in |
| Open Food Facts | The barcode number you scanned. No account information | To look up the product and its ingredients |
| OpenStreetMap / Overpass | A latitude and longitude and a search radius, from your phone. No account information | To find vegan-friendly places near you |
| Sentry | Crash and error reports: the error, where in the code it happened, your app version and device model | To find and fix crashes. Configured to send no message contents, no photos and no food log |
That is the complete list. We do not sell personal information, and we do not “share” it for cross-context behavioural advertising as California’s CPRA uses those words.
Your account data is stored by Supabase in the EU (Frankfurt, eu-central-1) region. Some of our processors — OpenAI, RevenueCat, Sentry — process data in the United States. Those transfers are covered by the European Commission’s Standard Contractual Clauses in each provider’s data processing agreement.
The website is served from Vercel’s global edge network, so the machine that hands you this page may be anywhere. Waitlist addresses collected by the website are written to the same Supabase database in Frankfurt as everything else.
| What | Kept for |
|---|---|
| Account, profile, food log, pantry, saved items | Until you delete your account |
| Scan photos | Not kept at all — discarded as soon as the scan returns |
| Scan records (verdict, cost, timing) | Until you delete your account |
| Subscription state | Until you delete your account; Apple, Google and RevenueCat keep their own billing records for their own legal reasons |
| Crash reports | 90 days |
| Waitlist email addresses | Until the launch email has been sent, or until you ask to be removed — whichever comes first |
| Cached barcode product data | Indefinitely — it describes a product, not a person, and is shared by everyone |
In the app: You → Settings → Delete account. You will be asked to type the word delete, and then it happens immediately.
Without the app, or if you can no longer sign in, use veganlens.app/delete-account.
Deletion removes your login, your profile and quiz answers, every meal you logged, your pantry and shopping list, your saved recipes and places, your scan records, your entitlement row, and every photo in your storage folder. It cannot be undone, and we keep no shadow copy. Encrypted backups roll off within 30 days.
Deleting your account does not cancel a subscription — only Apple or Google can do that. Cancel it in your device’s subscription settings first, or you will keep being billed for an app you no longer have.
If you also joined the waitlist on this website, that is a separate list and deleting your account does not remove you from it. Ask us at privacy@veganlens.app and we will delete that too.
If you are in the UK, the EU or the EEA you have the right to access your data, to correct it, to delete it, to restrict or object to how we use it, and to receive a copy in a portable format. Where we rely on consent, you can withdraw it at any time without affecting what came before.
If you are in California you have the right to know what we collect, to delete it, to correct it, and not to be discriminated against for asking. We do not sell or share personal information, so there is nothing to opt out of.
Email privacy@veganlens.app for any of these. You may also complain to your local data protection authority; in the UK that is the ICO.
Vegan Lens is not intended for children under 13, and we do not knowingly collect their data. If you believe a child has created an account, write to privacy@veganlens.app and we will delete it.
All traffic is encrypted in transit (TLS), and data is encrypted at rest by Supabase. Every table enforces row-level security in the database itself, so one account physically cannot read another’s rows even if the app were tampered with. Photos live in per-account folders under the same rule. Our OpenAI key exists only on the server and is never present in the app.
No system is perfect. If a breach ever affects your data, we will tell you and the relevant regulator, and we will tell you what actually happened.
If we change this policy we will update the date at the top, and if the change is significant we will tell you in the app before it takes effect. We will not retroactively reduce your rights over data you have already given us.