Legal

Privacy Policy

Last updated: June 2026

Operator: Filanostic, LLC ("Olua," "we," "us," "our")

Contact: privacy@olua.ai

1. Overview

This Policy explains what information Olua collects, how we use it, and your choices. We designed Olua to need as little personal data as possible. Olua has no user accounts and no login.

2. Information we collect

a. Information you provide

  • Messages you send us (support requests, feedback).

b. Information generated by using the app

  • Barcodes you scan and search prompts you type, which we send to third-party services to look up product and research information (see §4).
  • Camera input for scanning / label reading. Barcode scanning is processed on your device and is not uploaded. Label "photograph" reading (OCR) sends the captured image to our backend and our AI provider to extract the ingredient text; the image is not retained beyond processing that request.
  • Scan/search history, stored only on your device (local); it is never uploaded, and it is cleared when you clear history or uninstall the app.

c. Information collected automatically

  • Basic device and app information (device type, OS version, app version, crash/diagnostic data) and privacy-friendly usage analytics. We use a cookieless, IP-anonymizing analytics approach with no cross-app tracking.
  • When the app encounters an ingredient it does not yet recognize, the unrecognized ingredient name (with no personal identifiers) may be sent to our backend so we can expand coverage.

We do not intentionally collect health records, and we ask that you not send us sensitive personal information.

3. How we use information

  • To provide core features: look up products, match ingredients, and show research and regulatory information.
  • To maintain, secure, debug, and improve the Service.
  • To respond to your requests and communicate service updates.
  • To comply with law.

We do not sell your personal information, and we do not use your scans or prompts to target advertising. There are no third-party advertising SDKs in the app, no in-app cookies, and no cross-app tracking.

4. Third parties we share data with

To function, Olua transmits limited data to service providers:

  • Product/ingredient database (Open Food Facts): the scanned barcode and typed search text are sent to retrieve product data.
  • AI provider (Anthropic — Claude): for the prompt-based and OCR features, your typed query (and relevant product context) or the captured label image is processed by our AI provider under their data-processing terms. Per Anthropic's commercial API terms, your inputs are not used to train models and are retained only transiently for abuse monitoring before deletion.
  • Scientific literature (PubMed/NCBI): citations are pre-compiled into the app's knowledge base. The app does not send your queries to PubMed/NCBI at runtime — PubMed/NCBI is a data source used to build the knowledge base, not a recipient of your data.
  • Hosting / infrastructure (Cloudflare): our backend runs on Cloudflare (Workers and D1).

We share data with these providers only as needed to operate the Service, and we require them to protect it. We may also disclose information to comply with law or protect rights and safety.

5. Your choices and rights

Depending on where you live (e.g., under GDPR or CCPA/CPRA), you may have rights to access, correct, delete, or port your data, to opt out of certain processing or "sale"/"sharing" (we do neither), and to withdraw consent. To exercise rights, contact privacy@olua.ai. You can also:

  • clear your local scan/search history in the app;
  • disable camera permission in your device settings (scanning will not work).

We will not discriminate against you for exercising your rights.

6. Data retention

We keep personal data only as long as needed for the purposes above or as required by law. Device-local history stays on your device until you clear it or uninstall the app. Label images sent for OCR are not retained beyond processing the request, and inputs to our AI provider are retained only transiently for abuse monitoring before deletion.

7. Security

We use reasonable technical and organizational measures to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Children's privacy

The Service is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us data, contact us and we will delete it.

9. International users and transfers

If you use the Service outside the United States, your information may be processed in the United States or other countries where our providers operate, which may have different data-protection laws. Where required, we use appropriate safeguards for international transfers.

10. Changes to this Policy

We may update this Policy and will revise the "Last updated" date. Material changes will be communicated in the app or by other reasonable means.

11. Contact

Privacy questions or requests: privacy@olua.ai, [registered mailing address].