Privacy Policy
Last Updated: August 15, 2026
Privacy-First Commitment
- No required user account: Purova does not require signup or a cloud profile to scan.
- History on your device: Scan history, bookmarks, country, language, and dietary preferences stay in on-device storage.
- No advertising tracking: We do not sell personal data or use ad networks.
- You control deletion: Export or wipe local data anytime in Settings.
1. Introduction
This Privacy Policy explains how Purova (operated by Sadh Inc.) ("Purova," "we," "us," or "our") handles information when you use the Purova mobile application (the "App") and this website (https://purova.app) (together, the "Services").
Purova is an independent food and cosmetics barcode scanner. We designed the App so your personal scan history stays on your device whenever possible. Please read this policy carefully. By using the Services, you acknowledge the practices described here.
Related documents: Terms of Use.
2. Information We Collect
2.1 Information We Do Not Collect as Account Data
Purova does not require or collect as an App account:
- Name, email address, phone number, or postal address to create a Purova login
- Social media profiles or contact lists
- Precise location for advertising
- Photos of you (the camera is used to read product barcodes; we do not operate a Purova photo gallery of your scans on our servers)
2.2 Information Stored Locally on Your Device
Depending on how you use the App, Purova may store locally (SQLite / preferences), and this information is not uploaded as a synced Purova user account:
- Scan history: barcodes, product names, categories, scores, images URLs, and cached product JSON you opened or saved
- Preferences: language, selected country/region, dietary and skin-profile answers from onboarding or Settings
- App state: favorites/bookmarks and similar UI flags
Local data is generally deleted when you use "Delete All Data" in Settings or uninstall the App (subject to your device's backup behavior).
2.3 Product Lookups (Barcode Queries)
When you scan or open a product, the barcode and your selected country are sent to our product API (hosted on Cloudflare Workers / D1) and, if needed, to public product databases:
- Purova catalog: country-scoped product records so Explore and lookups match your region
- Open Food Facts and Open Beauty Facts: public community databases for nutrition, ingredients, cosmetics, and scores
These requests identify a product, not a named user. We use them to return the product sheet, alternatives, and related catalog results.
2.4 Translations
If your app language is missing on a product, the App may send product text (ingredients, packaging, origins, display tags — not the official product name) to an AI translation pathway (currently via OpenRouter) so a translation can be generated on your device session.
- Purpose: show ingredients and tags in your language — not to build an advertising profile
- Shared product maps: if translation succeeds, we may save that language map onto the product record in our catalog so later users do not wait. This is product copy, not your identity
- Failure: if translation fails, we show the original text and do not store a fake translation
2.5 Camera
Scanning requires camera permission. Frames are processed on-device to detect barcodes. We do not operate a Purova cloud that stores your camera roll or live video.
2.6 Subscriptions and Payments
If you purchase Purova Premium, payments are processed by Google Play. We may use RevenueCat (or the store APIs) to validate entitlement status. We do not receive your full payment card number. We may receive pseudonymous subscription status needed to unlock paid features.
2.7 Notifications
If you opt in, the App may use device notification services to deliver reminders you configure. Tokens and delivery metadata may be processed by those platform providers solely to deliver notifications you requested.
2.8 Diagnostics
We may collect limited crash or error diagnostics (device type, OS version, App version, stack traces) to keep the App stable. We configure diagnostics to avoid collecting unnecessary personal content from your history.
2.9 Website Information
When you visit https://purova.app, standard hosting logs (IP address, user agent, pages requested) may be processed by our hosting provider (for example, Vercel) for security, reliability, and basic analytics. If you email us, we receive the content of your message and your email address.
Optional cookie consent on this marketing site may store a local preference (purova-cookie-consent) in your browser.
3. How We Use Information
- Look up products, scores, ingredients, and alternatives you request
- Detect food versus cosmetics and localize product text
- Improve a shared product catalog (including successful translation maps)
- Validate Premium entitlements
- Deliver optional reminders you enable
- Diagnose crashes and improve reliability
- Respond to support or privacy requests you send by email
- Comply with law and protect the integrity of the Services
We do not sell your personal information.
4. Legal Bases (GDPR / UK GDPR)
Where applicable (EEA/UK), we rely on:
- Contract / requested service: barcode lookups, translations you trigger, subscription validation
- Legitimate interests: security, abuse prevention, catalog quality, crash diagnostics — balanced against your rights
- Consent: optional notifications and non-essential website cookies/analytics, where required
- Legal obligation: when we must retain or disclose information to comply with law
5. Sharing and Processors
We share information only with service providers needed to run the Services, including:
- Cloudflare (Workers / D1 product API and catalog)
- Open Food Facts / Open Beauty Facts (public product data)
- OpenRouter / AI model providers (optional product-text translation)
- Google Play (app distribution and payments)
- RevenueCat (subscription entitlement, if enabled)
- Hosting providers for this website (for example, Vercel)
- Email providers when you contact us
We do not share your data with advertising networks for behavioral advertising. We may disclose information if required by law or to protect vital interests to the extent we actually possess relevant information (we typically do not hold your on-device history on a Purova account server).
6. International Transfers
Service providers may process data in the United States or other countries. Where required, we rely on appropriate transfer mechanisms used by those providers. Cross-border processing primarily relates to product APIs, public databases, optional translation, subscriptions, diagnostics, and website hosting.
7. Data Retention
- On-device data: until you delete it in-app, clear App storage, or uninstall (device backups may retain copies)
- Product catalog: barcodes, public product fields, and shared translation maps are retained as product records, not as a user profile
- Translation requests: processed to generate a response; provider retention is governed by provider policies
- Subscription records: kept as needed for entitlement, accounting, and compliance via store systems
- Support emails: retained as reasonably needed to resolve your request
8. Your Rights and Choices
8.1 Access, Export, Delete (App)
You can view history in the App, export local data from Settings, or delete all local data. Uninstalling removes the App's local store subject to OS behavior.
8.2 GDPR / CCPA-style Requests
Depending on your location, you may have rights to access, correct, delete, restrict, or object to certain processing, and to data portability. For information we actually control (for example, support email correspondence), contact privacy@purova.app. We will respond within the timeframe required by applicable law (typically within 30 days where GDPR applies).
8.3 California (CCPA/CPRA)
We do not sell personal information and do not share personal information for cross-context behavioral advertising as those terms are commonly defined. California residents may contact us to exercise applicable rights regarding personal information we hold.
8.4 Do Not Track
This marketing site does not respond to DNT signals in a specialized way beyond our general minimal-tracking approach.
9. Children's Privacy
Purova is not directed to children under 13 (or under 16 where stricter rules apply). We do not knowingly collect personal information from children under these ages to create accounts. If you believe a child has provided personal information to us via email, contact us and we will take appropriate steps to delete it.
10. Security
We use reasonable technical and organizational measures: on-device storage for history, HTTPS for network calls, and limited collection of personal identifiers. No method of transmission or storage is 100% secure. You are responsible for securing your device with a passcode/biometrics and OS updates.
11. Third-Party Product Data
Product facts may come from public community databases and may be incomplete or outdated. Purova is not a substitute for the physical label. Third-party sites and databases have their own privacy practices.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will revise the "Last Updated" date above. Material changes may also be highlighted in the App or on this website. Continued use after an update constitutes acceptance where permitted by law.
13. Contact Us
For privacy questions or requests:
- Privacy: privacy@purova.app
- General: contact@purova.app
- Website: https://purova.app
Your Trust Matters
Purova's product principle is simple: honest product information without selling your shopping habits to brands. Premium features fund the product — not advertising against your scans.