Privacy Policy
Last updated: May 24, 2026
Stoica Diana-Cristina Persoana Fizica Autorizata (“we”, “us”, or “our”), based in Romania, operates the Vani iOS application (“the App”). This Privacy Policy explains what information we collect, how we use it, and what rights you have.
Your privacy is important to us. Vani is designed as a privacy-first application: all of your personal product data stays on your device. We do not operate user accounts, and we do not have servers that store your inventory, photos, or routines.
1. Information We Collect
1.1 Information You Provide (Stored Locally)
Most data you save in the App is stored exclusively on your device using Apple’s SwiftData framework. This includes:
- Product entries (name, brand, category, color, cost, rating, notes, batch codes, barcodes, expiration dates)
- Product photos you capture with your camera (stored locally; when you use the optional AI scan, a compressed version is also transmitted to our cloud service — see Section 1.3)
- Ingredient lists identified from product packaging — whether entered manually, recognized via on-device OCR, or returned from the optional AI scan — stored locally on your device (see Section 1.2 for anonymous database contributions; see Section 1.3 for the optional cloud AI scan)
- Your skin profile (skin type and skin concerns) used to personalize ingredient analysis — stored locally on your device and never transmitted
- Usage logs and product status changes
- Skincare routines and routine completion history
- Custom lists and collections
- App preferences (currency, measurement system, appearance, notification settings)
We never have access to this data.
1.2 Shared Product Database (Anonymous Contributions)
The App includes an ingredient scanning feature that lets you photograph product packaging to identify ingredients. When a product is scanned and its ingredients are resolved, the App may contribute the following to an anonymous shared product database:
- Brand name (e.g., “The Ordinary”)
- Product name (e.g., “Niacinamide 10% + Zinc 1%”)
- Ingredient list in INCI format (the standardised cosmetic ingredient names printed on packaging)
What is not contributed: No user account, device identifier, personal information, or usage history is attached to contributed data. Your personal inventory — which products you own, your notes, photos, and routines — remains on your device only, as described in Section 1.1. When the optional AI scan feature is used (see Section 1.3), a compressed image is processed server-side, but neither that image nor the recognition result is linked to your identity or contributed to the shared database without your explicit action.
The contributed data is public-domain product information, equivalent to what is printed on a product label. It is used solely to provide faster ingredient lookup results to all App users. We do not sell or license this data to any third party.
1.3 Cloud AI Product Recognition
The App includes an optional AI scan feature that can identify a product’s name, brand, and category from a photo of its packaging. When you choose to use this feature:
- A compressed version of your product photo is transmitted over TLS to a Firebase Cloud Function operated by us on Google Cloud infrastructure.
- The Cloud Function sends the image to Google Gemini AI (operated by Google), which analyzes it to identify the product.
- The recognized result (product name, brand, category) is returned to the App. You remain in full control of whether to save it.
- Image retention: We do not permanently store the raw or compressed image. A hash of the image and any extracted OCR text may be cached server-side to avoid redundant API calls for identical scans; this cache contains no personal data and is not linked to your identity.
- Your choice: AI scanning is opt-in. You can always add products manually without using this feature.
Google Gemini processes images under Google’s AI terms. See ai.google.dev/terms and policies.google.com/privacy.
1.4 AI Scan Quota Tracking
To enforce fair use limits on the AI scan feature, we maintain a per-device scan count on our Firebase servers:
- Free tier: Up to 10 lifetime AI scans.
- Pro tier: A monthly quota that resets each billing period.
Quota is tracked using an anonymous device identifier generated at app launch, not linked to your name, email, or any personal information. This identifier is used solely to count scans and is not shared with any third party beyond Firebase infrastructure.
1.5 Information Collected Automatically
Firebase Analytics (Google)
We use Firebase Analytics to understand general usage patterns and improve the App. Firebase automatically collects:
- App events: screens viewed, features used (e.g., “barcode scanned”, “routine created”), session duration and frequency
- Device information: device model, operating system version, app version
- General location: country-level, derived from IP address (IP addresses are not stored by Firebase)
- User properties (anonymous, non-identifying): subscription tier (free/pro), item count range (bucketed, e.g., “6-20”), whether a routine has been created, preferred appearance setting
This data is anonymous and aggregated. It cannot be used to identify you personally, and it does not include any product data, photos, or notes you enter.
Firebase Crashlytics (Google)
We use Crashlytics to detect and fix app crashes. When a crash or non-fatal error occurs, Crashlytics collects:
- Crash stack traces and error logs
- Device model, operating system version, and app version
- Free disk space and RAM at the time of the crash
Crash reports do not contain your product data, photos, or personal information.
1.6 Subscription Data (RevenueCat)
We use RevenueCat to manage in-app subscriptions. RevenueCat processes:
- An anonymous customer ID (generated by RevenueCat, not linked to your name or email)
- Purchase and subscription history (processed through the Apple App Store)
- Entitlement status (whether you have an active Pro subscription)
RevenueCat does not receive any product data, photos, or preferences you enter into the App. Billing is handled entirely by Apple.
2. How We Use Your Information
| Data | Purpose | Legal Basis (GDPR) |
|---|---|---|
| Product inventory, photos, routines, preferences | Provide the App’s core features (stored locally on your device) | Performance of a contract |
| Anonymous product database contributions (brand, product name, INCI list) | Populate shared ingredient database to improve scan results for all users | Legitimate interest |
| Compressed product photos (AI scan, opt-in) | Identify product name, brand, and category via Gemini AI | Legitimate interest |
| Anonymous AI scan quota count | Enforce usage limits for the AI scan feature | Performance of a contract |
| Firebase Analytics events and user properties | Understand feature usage to improve the App | Legitimate interest |
| Firebase Crashlytics reports | Detect, diagnose, and fix crashes and errors | Legitimate interest |
| RevenueCat subscription data | Verify subscription status and deliver Pro features | Performance of a contract |
We do not use your data for advertising, profiling, or automated decision-making.
3. How We Share Your Information
We do not sell, rent, or trade your personal information. The only data shared with third parties is the anonymous, non-personal data described below:
| Service | Data Shared | Purpose | Privacy Policy |
|---|---|---|---|
| Shared ingredient database (operated by us) | Brand name, product name, INCI ingredient list — no user identifier attached | Provide ingredient lookup results to all App users | This policy |
| Firebase Cloud Functions (Google) | Compressed product photo — no user identifier attached; not permanently retained | Process AI product recognition requests | firebase.google.com/support/privacy |
| Google Gemini AI (Google) | Compressed product photo | Identify product name, brand, and category | policies.google.com/privacy |
| Firebase Analytics (Google) | Anonymous usage events, device info, country | App improvement analytics | firebase.google.com/support/privacy |
| Firebase Crashlytics (Google) | Crash reports, device info | Crash detection and resolution | firebase.google.com/support/privacy |
| RevenueCat | Anonymous customer ID, purchase history | Subscription management | revenuecat.com/privacy |
All services process data on servers that may be located outside your country of residence. Google and RevenueCat maintain appropriate data protection safeguards, including Standard Contractual Clauses for international transfers where required.
4. Data Retention
| Data | Retention |
|---|---|
| On-device data (products, photos, routines, preferences) | Until you delete it or uninstall the App |
| Shared ingredient database entries (brand, product name, INCI list) | Retained indefinitely to serve lookup results; contains no personal data |
| Server-side image hash and OCR cache (AI scan) | Purged automatically; contains no personal data |
| Anonymous AI scan quota counters | Reset monthly for Pro users; retained until you request deletion or uninstall |
| Firebase Analytics | Retained by Google for 14 months, then automatically deleted |
| Firebase Crashlytics | Retained by Google for 90 days |
| RevenueCat subscription data | Retained per RevenueCat’s data retention policy; you may request deletion |
5. Permissions
The App requests the following device permissions, all of which are optional:
- Camera (
NSCameraUsageDescription): Used to scan product barcodes, take product photos, and photograph product packaging. When you use the optional AI scan feature, a compressed version of your packaging photo is transmitted to our cloud service for recognition (see Section 1.3). All other photos are stored locally on your device only and are never uploaded. - Photo Library — Write Only (
NSPhotoLibraryAddUsageDescription): Used to export images to your photo library. The App does not read from or access your existing photo library. - Notifications: Used for local skincare routine reminders and expiration alerts. Notifications are scheduled and delivered entirely on your device. No notification data is sent to any server. Notifications are never used for marketing.
You can revoke any permission at any time in iOS Settings.
6. Cookies and Tracking
The App does not use cookies. We do not participate in cross-app or cross-site tracking. Firebase Analytics uses a randomly generated app-instance identifier (not an advertising identifier) that is reset when you reinstall the App.
The App does not track you across other companies’ apps or websites.
7. Data Security
We take reasonable measures to protect the limited data we process:
- All product data is stored on-device using Apple’s encrypted storage (protected by your device passcode/biometrics)
- Widget data is stored in an encrypted App Group container on your device
- Network communications with Firebase and RevenueCat use TLS encryption
- We do not store passwords, payment information, or personal identifiers on any server we operate
Because all product data lives on your device, you are responsible for maintaining your own backups (e.g., via iCloud device backups).
8. Children’s Privacy
Vani is not directed at children under the age of 16 (or under the age of 13 in jurisdictions where 13 is the applicable age threshold, such as the United States under COPPA). We do not knowingly collect personal information from children.
If you believe a child has provided personal information through the App, please contact us and we will take steps to delete it.
9. Your Rights
9.1 European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR)
As a Romania-based company, we comply with the General Data Protection Regulation (GDPR). If you are in the EEA, UK, or Switzerland, you have the right to:
- Access: Request a copy of data held about you
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your data (“right to be forgotten”)
- Data portability: Request your data in a structured, machine-readable format
- Restriction: Request restriction of processing
- Objection: Object to processing based on legitimate interest
- Withdraw consent: Where processing is based on consent, withdraw it at any time
For on-device data: All product data is stored locally. You have full control and can delete it at any time within the App (Settings > Delete All Data) or by uninstalling the App.
For Firebase data: You can opt out of analytics data collection by enabling “Limit Ad Tracking” in iOS Settings (Settings > Privacy & Security > Apple Advertising > Personalized Ads off). You may also contact us to request deletion.
For RevenueCat data: Contact us or submit a request directly through RevenueCat’s privacy policy.
Supervisory authority: You have the right to lodge a complaint with ANSPDCP (Romania’s Data Protection Authority) or the supervisory authority in your country of residence.
9.2 California, USA (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what personal information is collected and how it is used
- Delete personal information held about you
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information
- Non-discrimination for exercising your privacy rights
We do not sell or share your personal information as defined by the CCPA/CPRA. The only data shared with third parties is the anonymous analytics and subscription data described in Section 3.
9.3 Brazil (LGPD)
If you are in Brazil, you have similar rights under the Lei Geral de Protecao de Dados, including access, correction, deletion, portability, and information about sharing. Contact us to exercise these rights.
9.4 Canada (PIPEDA)
If you are in Canada, you have the right to access and correct your personal information. Contact us to exercise these rights.
9.5 How to Exercise Your Rights
To exercise any of the rights described above, contact us at: stoicadianacristina@outlook.com
We will respond to verified requests within 30 days (or within the timeframe required by applicable law). We do not charge a fee for reasonable requests.
10. International Data Transfers
We are based in Romania (EU member state). Firebase and RevenueCat may process anonymous data on servers located outside the EEA. Where applicable, these transfers are protected by:
- The European Commission’s adequacy decisions
- Standard Contractual Clauses (SCCs)
- Other appropriate safeguards as required by applicable law
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top. If changes are material, we will notify you through the App or the App Store update notes. Continued use of the App after changes are posted constitutes acceptance of the updated policy.
12. App Store Privacy Label Summary
| Category | Data | Linked to Identity | Used for Tracking |
|---|---|---|---|
| App Functionality — Photos or Videos | Compressed packaging photos (AI scan only, opt-in) | No | No |
| Diagnostics — Crash Data | Crashlytics crash reports | No | No |
| Diagnostics — Performance Data | Firebase performance metrics | No | No |
| Analytics — Usage Data | Firebase Analytics events | No | No |
| Purchases | RevenueCat subscription status (via Apple) | Yes (to Apple ID, by Apple) | No |
Data used to track you: None.
Data linked to you: None (all analytics and AI processing are anonymous; photos are not retained).
Data sold to third parties: None.
13. Contact
If you have questions about this Privacy Policy, want to exercise your data rights, or have a privacy concern, please contact:
Stoica Diana-Cristina Persoana Fizica Autorizata
Email: stoicadianacristina@outlook.com