NanoSpotter Privacy Policy
This Privacy Policy explains how FeatureBugg ("FeatureBugg," "we," "us," or "our") handles information when you use NanoSpotter: Ingredient Scan ("NanoSpotter"). NanoSpotter is an assistive ingredient-awareness tool that helps users identify and understand ingredients they choose to watch for.
1. Information stored on your device
NanoSpotter is designed to keep much of its user-specific information on the device. Depending on the features you use, local information may include:
- profiles and profile names;
- ingredients or concerns you choose to watch for, including custom watch terms;
- Profile Card colors, icons, messages, and other display preferences;
- scan history, favorites, and product information associated with saved scans;
- ingredient text read from package labels;
- saved package-label evidence images when a scan preserves an image for later review;
- app settings, accessibility preferences, appearance settings, and other local preferences; and
- local records used to support scan limits, trial state, and offline operation.
These local profile details, selected concerns, Profile Card messages, label images, and recognized ingredient text are not currently sent to FeatureBugg's backend as part of normal NanoSpotter operation.
2. Camera and package-label processing
NanoSpotter requests camera access so you can scan supported product barcodes and ingredient labels. Barcode recognition and ingredient-label text recognition are performed using on-device Android libraries. NanoSpotter may save a selected label image locally as evidence for a completed scan. Camera access is requested through Android's permission system.
3. Information transmitted off your device
NanoSpotter transmits limited information when a network connection is available and a feature requires it. Current categories include:
| Information | Why it is used | Where it goes |
|---|---|---|
| Product barcode number | Look up product and ingredient information | Open Food Facts |
| Anonymous installation identifier | Trial state, scan limits, purchase entitlements, abuse prevention, legal acceptance records, and related service operation | FeatureBugg backend hosted with Supabase |
| Integrity challenge data, request hashes, app/package information, and Play Integrity verdict information | Protect backend actions against automated abuse and unauthorized app/device states | FeatureBugg backend and Google Play Integrity |
| Free-scan usage/reconciliation records | Apply the free daily scan allowance and reconcile eligible offline activity | FeatureBugg backend |
| Trial and entitlement records | Activate and restore trial or paid access | FeatureBugg backend |
| Google Play purchase tokens, product identifiers, and purchase/subscription state | Verify purchases, restore access, and process subscription lifecycle changes | FeatureBugg backend and Google Play |
| Legal document versions, acceptance time, app version, and anonymous installation identifier | Document acceptance of the Terms of Use and acknowledgment of this Privacy Policy | FeatureBugg backend |
| Completed-scan product and quality telemetry: app version, scan source, product barcode when available, barcode lookup outcome, network/cache lookup source, result-status category, and a hashed anonymous installation identifier | Measure scan volume, identify frequently scanned products, detect incomplete product records and fallback patterns, troubleshoot scan-quality problems, and improve NanoSpotter | FeatureBugg backend hosted with Supabase |
Network providers and service providers may also process ordinary technical connection information, such as IP addresses and request timestamps, as part of operating and securing their services.
4. Scan-quality telemetry
NanoSpotter sends a small, best-effort telemetry event after a completed scan when network conditions allow. This event is designed to help FeatureBugg measure real scan volume and improve product and scanning quality without collecting the user's personal profile content.
The telemetry event may include the app version, whether the scan used a barcode, a physical ingredient label, or a barcode-to-label fallback; the product barcode when one is available; whether barcode product data was found and included ingredients; whether the lookup used the network or a local cache; and the final high-level result category (Concern found, Possible concern, or Nothing flagged in this scan).
The app supplies its anonymous installation identifier to the telemetry endpoint only so the server can create a one-way SHA-256 hash. The raw installation identifier is not stored in the scan-telemetry table, and the telemetry table is not linked by a database foreign key to NanoSpotter profiles, History, or operational installation records.
Telemetry is intentionally disposable. NanoSpotter does not retry failed telemetry, does not maintain a persistent telemetry upload queue, and cancels telemetry when new scanner or product-lookup work needs priority. A telemetry failure does not block or change a scan result.
Scan telemetry does not include profile names, Profile Card messages, user-selected concerns, custom concerns, recognized ingredient text, package-label images, camera frames, or personal notes.
5. Product information from Open Food Facts
When NanoSpotter performs an online barcode lookup, the barcode is sent to Open Food Facts to request available product information. Product records may be incomplete, outdated, or different from the physical package. NanoSpotter therefore treats barcode data as supplemental information and encourages users to verify the physical package label.
6. Google Play services
NanoSpotter uses Google Play Billing for eligible paid purchases and subscriptions and Google Play Integrity to help protect selected backend operations. Google processes information under its own terms and privacy practices. FeatureBugg may receive purchase tokens, product identifiers, subscription states, and integrity verdict information needed to verify access and protect the service.
7. Backend service provider
FeatureBugg uses Supabase-hosted services for NanoSpotter's backend database and server functions. Backend records are pseudonymous: NanoSpotter does not require a FeatureBugg account, email address, legal name, or street address to scan products.
8. What we do not currently do
- NanoSpotter does not require a user account.
- FeatureBugg does not sell personal or sensitive user data.
- NanoSpotter does not use advertising SDKs in the current 1.0 release plan.
- NanoSpotter does not request precise or approximate device location.
- NanoSpotter does not currently upload saved label evidence images or recognized ingredient-label text to FeatureBugg's backend during normal use.
- NanoSpotter does not transmit profile names, Profile Card personal messages, user-selected concerns, custom concerns, recognized ingredient text, package-label images, camera frames, or personal notes as part of scan telemetry.
9. Data security
FeatureBugg uses reasonable technical safeguards appropriate to the service, including encrypted HTTPS connections for network traffic and protected backend actions for sensitive entitlement, quota, billing, integrity, and legal-acceptance operations. No security method is perfect, and we cannot guarantee absolute security.
10. Retention and deletion
Local data. Scan history, favorites, profiles, selected concerns, saved evidence images, and local settings remain on the device until you delete them through available app controls, clear the app's storage, or uninstall the app, subject to Android backup or restore behavior outside FeatureBugg's control.
Backend operational records. FeatureBugg retains pseudonymous backend records for as long as reasonably necessary to operate NanoSpotter, verify purchases and entitlements, prevent abuse, resolve disputes, meet legal or accounting obligations, and document legal acceptance. Some records may therefore be retained longer than local app data.
Deletion requests. Because NanoSpotter does not require an account, FeatureBugg may need an anonymous installation/privacy identifier or other information sufficient to locate a backend record before it can process a backend deletion request. Contact featurebugg@gmail.com for privacy or deletion requests. FeatureBugg may retain records when retention is required by law or is necessary to establish, exercise, or defend legal claims.
11. Children
NanoSpotter is not designed as a service directed specifically to children. Parents, guardians, and caregivers may choose to use NanoSpotter for household or family ingredient-awareness needs. If we learn that information has been collected in a manner that requires deletion under applicable children's privacy law, we will take appropriate steps.
12. Changes to this Privacy Policy
We may update this Privacy Policy as NanoSpotter changes. The policy will identify its version and effective date. When a change requires renewed acknowledgment or consent, NanoSpotter may present the updated policy before continued use. Routine app updates do not by themselves cause re-consent when the legal document version has not changed.
13. Contact
Developer: FeatureBugg
App: NanoSpotter: Ingredient Scan
Privacy contact: featurebugg@gmail.com
Support: featurebugg@gmail.com