Vani

Privacy Policy

Last updated: May 24, 2026

Stoica Diana-Cristina Persoana Fizica Autorizata (“we”, “us”, or “our”), based in Romania, operates the Vani iOS application (“the App”). This Privacy Policy explains what information we collect, how we use it, and what rights you have.

Your privacy is important to us. Vani is designed as a privacy-first application: all of your personal product data stays on your device. We do not operate user accounts, and we do not have servers that store your inventory, photos, or routines.

Contents
  1. Information We Collect
  2. How We Use Your Information
  3. How We Share Your Information
  4. Data Retention
  5. Permissions
  6. Cookies and Tracking
  7. Data Security
  8. Children’s Privacy
  9. Your Rights
  10. International Data Transfers
  11. Changes to This Policy
  12. App Store Privacy Label Summary
  13. Contact

1. Information We Collect

1.1 Information You Provide (Stored Locally)

Most data you save in the App is stored exclusively on your device using Apple’s SwiftData framework. This includes:

We never have access to this data.

1.2 Shared Product Database (Anonymous Contributions)

The App includes an ingredient scanning feature that lets you photograph product packaging to identify ingredients. When a product is scanned and its ingredients are resolved, the App may contribute the following to an anonymous shared product database:

What is not contributed: No user account, device identifier, personal information, or usage history is attached to contributed data. Your personal inventory — which products you own, your notes, photos, and routines — remains on your device only, as described in Section 1.1. When the optional AI scan feature is used (see Section 1.3), a compressed image is processed server-side, but neither that image nor the recognition result is linked to your identity or contributed to the shared database without your explicit action.

The contributed data is public-domain product information, equivalent to what is printed on a product label. It is used solely to provide faster ingredient lookup results to all App users. We do not sell or license this data to any third party.

1.3 Cloud AI Product Recognition

The App includes an optional AI scan feature that can identify a product’s name, brand, and category from a photo of its packaging. When you choose to use this feature:

Google Gemini processes images under Google’s AI terms. See ai.google.dev/terms and policies.google.com/privacy.

1.4 AI Scan Quota Tracking

To enforce fair use limits on the AI scan feature, we maintain a per-device scan count on our Firebase servers:

Quota is tracked using an anonymous device identifier generated at app launch, not linked to your name, email, or any personal information. This identifier is used solely to count scans and is not shared with any third party beyond Firebase infrastructure.

1.5 Information Collected Automatically

Firebase Analytics (Google)

We use Firebase Analytics to understand general usage patterns and improve the App. Firebase automatically collects:

This data is anonymous and aggregated. It cannot be used to identify you personally, and it does not include any product data, photos, or notes you enter.

Firebase Crashlytics (Google)

We use Crashlytics to detect and fix app crashes. When a crash or non-fatal error occurs, Crashlytics collects:

Crash reports do not contain your product data, photos, or personal information.

1.6 Subscription Data (RevenueCat)

We use RevenueCat to manage in-app subscriptions. RevenueCat processes:

RevenueCat does not receive any product data, photos, or preferences you enter into the App. Billing is handled entirely by Apple.


2. How We Use Your Information

DataPurposeLegal Basis (GDPR)
Product inventory, photos, routines, preferencesProvide the App’s core features (stored locally on your device)Performance of a contract
Anonymous product database contributions (brand, product name, INCI list)Populate shared ingredient database to improve scan results for all usersLegitimate interest
Compressed product photos (AI scan, opt-in)Identify product name, brand, and category via Gemini AILegitimate interest
Anonymous AI scan quota countEnforce usage limits for the AI scan featurePerformance of a contract
Firebase Analytics events and user propertiesUnderstand feature usage to improve the AppLegitimate interest
Firebase Crashlytics reportsDetect, diagnose, and fix crashes and errorsLegitimate interest
RevenueCat subscription dataVerify subscription status and deliver Pro featuresPerformance of a contract

We do not use your data for advertising, profiling, or automated decision-making.


3. How We Share Your Information

We do not sell, rent, or trade your personal information. The only data shared with third parties is the anonymous, non-personal data described below:

ServiceData SharedPurposePrivacy Policy
Shared ingredient database (operated by us)Brand name, product name, INCI ingredient list — no user identifier attachedProvide ingredient lookup results to all App usersThis policy
Firebase Cloud Functions (Google)Compressed product photo — no user identifier attached; not permanently retainedProcess AI product recognition requestsfirebase.google.com/support/privacy
Google Gemini AI (Google)Compressed product photoIdentify product name, brand, and categorypolicies.google.com/privacy
Firebase Analytics (Google)Anonymous usage events, device info, countryApp improvement analyticsfirebase.google.com/support/privacy
Firebase Crashlytics (Google)Crash reports, device infoCrash detection and resolutionfirebase.google.com/support/privacy
RevenueCatAnonymous customer ID, purchase historySubscription managementrevenuecat.com/privacy

All services process data on servers that may be located outside your country of residence. Google and RevenueCat maintain appropriate data protection safeguards, including Standard Contractual Clauses for international transfers where required.


4. Data Retention

DataRetention
On-device data (products, photos, routines, preferences)Until you delete it or uninstall the App
Shared ingredient database entries (brand, product name, INCI list)Retained indefinitely to serve lookup results; contains no personal data
Server-side image hash and OCR cache (AI scan)Purged automatically; contains no personal data
Anonymous AI scan quota countersReset monthly for Pro users; retained until you request deletion or uninstall
Firebase AnalyticsRetained by Google for 14 months, then automatically deleted
Firebase CrashlyticsRetained by Google for 90 days
RevenueCat subscription dataRetained per RevenueCat’s data retention policy; you may request deletion

5. Permissions

The App requests the following device permissions, all of which are optional:

You can revoke any permission at any time in iOS Settings.


6. Cookies and Tracking

The App does not use cookies. We do not participate in cross-app or cross-site tracking. Firebase Analytics uses a randomly generated app-instance identifier (not an advertising identifier) that is reset when you reinstall the App.

The App does not track you across other companies’ apps or websites.


7. Data Security

We take reasonable measures to protect the limited data we process:

Because all product data lives on your device, you are responsible for maintaining your own backups (e.g., via iCloud device backups).


8. Children’s Privacy

Vani is not directed at children under the age of 16 (or under the age of 13 in jurisdictions where 13 is the applicable age threshold, such as the United States under COPPA). We do not knowingly collect personal information from children.

If you believe a child has provided personal information through the App, please contact us and we will take steps to delete it.


9. Your Rights

9.1 European Economic Area, United Kingdom, and Switzerland (GDPR / UK GDPR)

As a Romania-based company, we comply with the General Data Protection Regulation (GDPR). If you are in the EEA, UK, or Switzerland, you have the right to:

For on-device data: All product data is stored locally. You have full control and can delete it at any time within the App (Settings > Delete All Data) or by uninstalling the App.

For Firebase data: You can opt out of analytics data collection by enabling “Limit Ad Tracking” in iOS Settings (Settings > Privacy & Security > Apple Advertising > Personalized Ads off). You may also contact us to request deletion.

For RevenueCat data: Contact us or submit a request directly through RevenueCat’s privacy policy.

Supervisory authority: You have the right to lodge a complaint with ANSPDCP (Romania’s Data Protection Authority) or the supervisory authority in your country of residence.

9.2 California, USA (CCPA / CPRA)

If you are a California resident, you have the right to:

We do not sell or share your personal information as defined by the CCPA/CPRA. The only data shared with third parties is the anonymous analytics and subscription data described in Section 3.

9.3 Brazil (LGPD)

If you are in Brazil, you have similar rights under the Lei Geral de Protecao de Dados, including access, correction, deletion, portability, and information about sharing. Contact us to exercise these rights.

9.4 Canada (PIPEDA)

If you are in Canada, you have the right to access and correct your personal information. Contact us to exercise these rights.

9.5 How to Exercise Your Rights

To exercise any of the rights described above, contact us at: stoicadianacristina@outlook.com

We will respond to verified requests within 30 days (or within the timeframe required by applicable law). We do not charge a fee for reasonable requests.


10. International Data Transfers

We are based in Romania (EU member state). Firebase and RevenueCat may process anonymous data on servers located outside the EEA. Where applicable, these transfers are protected by:


11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top. If changes are material, we will notify you through the App or the App Store update notes. Continued use of the App after changes are posted constitutes acceptance of the updated policy.


12. App Store Privacy Label Summary

CategoryDataLinked to IdentityUsed for Tracking
App Functionality — Photos or VideosCompressed packaging photos (AI scan only, opt-in)NoNo
Diagnostics — Crash DataCrashlytics crash reportsNoNo
Diagnostics — Performance DataFirebase performance metricsNoNo
Analytics — Usage DataFirebase Analytics eventsNoNo
PurchasesRevenueCat subscription status (via Apple)Yes (to Apple ID, by Apple)No

Data used to track you: None.
Data linked to you: None (all analytics and AI processing are anonymous; photos are not retained).
Data sold to third parties: None.


13. Contact

If you have questions about this Privacy Policy, want to exercise your data rights, or have a privacy concern, please contact:

Stoica Diana-Cristina Persoana Fizica Autorizata
Email: stoicadianacristina@outlook.com