We rely on a small number of companies to keep KindScan running. Here's who they are and why they see your data — each receives only the minimum needed to do its job:
•
Firebase (Google) — handles your sign-in. They verify your password so we don't have to store it ourselves.
•
Railway — runs our servers and database in the US. Your profiles and scan history live here.
•
Cloudflare R2 — file storage for the ingredient photos you upload, in the US.
•
Google Vision — reads the text from ingredient photos you take. We delete your uploaded photos when you delete your account.
•
Anthropic and OpenAI — power our AI safety analysis. They receive ingredient information, the per-person context needed to explain why something is flagged (life stage, allergies, and sensitivities you've entered), and — for the Ask KindScan feature — the question you type. They do not receive family member names or your contact information.
•
TruLayer — monitors the performance of our AI features — how fast they respond and how much they cost to run. It receives a scrambled partial account identifier (never your full ID), the type of scan you ran (barcode, photo, or web link), the overall safety result (Safe/Caution/Avoid), and AI response times. For web-link scans it also receives the public product page text we're processing. It never receives ingredient names, health profiles, or the text of anything you type. TruLayer doesn't yet offer a way for us to delete an individual record on request, so this technical data is kept under TruLayer's standard retention period even after you delete your KindScan account. We're working with TruLayer to add a deletion option and will update this policy when we do.
•
RevenueCat — processes your subscription. They handle the payment; we never see your card number. When you delete your account, we also delete your subscription record from RevenueCat.
•
Mixpanel — tells us which app features are used, in anonymized form. No personal content. When you delete your account, we also delete your usage profile from Mixpanel.
•
Resend — sends the emails we send you — like recall alerts and account confirmations — and keeps a short-term delivery log to troubleshoot bounced or failed messages. That log follows Resend's standard retention period and isn't something we can delete early on a per-account basis.
•
Sentry — receives crash reports when the app breaks. No personal content is included. Crash reports are automatically deleted after 90 days, whether or not you've deleted your account.