Legal
Last updated: 31 August 2026 · Effective date: 31 August 2026
This Privacy Policy explains how Arovya ("we", "us", "the app") handles your information. We've written it in plain English. If anything is unclear, contact us at the address at the bottom of this page.
Arovya is an indie app developed by Anand Basavaraj Muddi, based in the United Kingdom. We are the data controller for any information you provide.
Correspondence address:
Anand Muddi
Unit 166188
PO Box 7169
Poole, BH15 9EL
United Kingdom
For privacy questions, contact: support@arovya.uk
The following information is stored exclusively in your device's local storage (UserDefaults). It is not intentionally sent to us or to any third party as part of normal app operation:
Your supplement routine is handled a little differently. The dose amounts you enter never leave your device. However, when you add or remove a supplement, mark one as taken, or change its timing, we send an anonymous analytics signal to TelemetryDeck (see Section 4.8): the add and remove signals together let the set of supplements you track be reconstructed, while the timing and your adherence (whether you marked a supplement as taken) are transmitted with the relevant signal. Each signal is tagged with a catalogue code for the supplement type (for example, vitamin_d3) — never its display name — and anything you type in yourself is sent as custom.
This health information is 'special category' data under UK/EU law; our legal basis is your explicit consent, given when you add it and withdrawable at any time by removing it in the app or deleting the app.
If you delete the app, this information is removed with it.
When you scan a barcode, we send the barcode number to Open Food Facts (openfoodfacts.org) to retrieve product information. Open Food Facts is a free, open product database. We send only the barcode — no information about you. See Open Food Facts' privacy policy at openfoodfacts.org/privacy.
When you choose to scan a product's label with AI — either because the product isn't in Open Food Facts, or because the available data is too sparse to score reliably — the photos you take are sent through our Cloudflare Worker (a security and rate-limiting proxy we operate) to OpenAI for ingredient and nutrition extraction.
What we send:
What we do not intentionally send:
OpenAI processes the photos to extract text and structured data, then returns the result. We use OpenAI's API service. Under OpenAI's API data handling terms, data submitted via the API is not used to train OpenAI's models by default. Only the first photo you took is ever written to our storage, and only when the AI confirms a food product (see Section 4.3). The remaining photos are never written to our storage — they exist only in transit for extraction and are discarded immediately afterwards. For current details on OpenAI's data handling, review their privacy and API documentation.
When AI label scanning successfully identifies a food product, we retain the first photo you took. The image is stored in Cloudflare R2 (Western Europe region) alongside the extracted product data described in Section 4.4, so that we can improve product recognition over time and reduce repeat processing of the same labels. We may use it to serve faster results to other users in future.
We write at most one image to storage per scan, and only when the AI confirms a food product: the first photo you took. Any other photos (such as the ingredients list and nutrition panel) are never written to storage at all — not stored and later deleted, simply never saved. The stored image is not linked to your name, identity, or account; it sits alongside the anonymised data described in Section 4.4.
After a successful AI label scan, we save the extracted result to our database, paired with a hashed device identifier. We keep this so that we can improve product recognition over time, and improve coverage in regions where Open Food Facts has gaps. We may use it to serve faster results to other users in future.
What's stored:
What's not intentionally stored:
The device identifier is a random UUID generated when you first use AI label scanning and stored only on your device. Your device sends this raw identifier with each AI scan; our Worker salts and hashes it on receipt and stores only the hash — the raw value is never written to our storage. This lets us count how many distinct devices use the service for rate-limiting and abuse prevention, without being able to identify any individual.
If a previously-scanned product looks wrong, you can report it as such from within the app; this clears the cached entry and triggers a fresh AI scan. The new result replaces the previous record under the same barcode. AI label scanning is subject to fair-use limits that prevent automated or abusive use and may vary by tier and region. Free users receive a limited allowance; Pro subscribers have no monthly limit, subject to the same short-term burst limits. Corrections are processed using the same flow described in Section 4.2 and produce a new entry as described in this section.
To prevent abuse of the AI scanning service, our Cloudflare Worker enforces rate limits keyed on two values: the hashed device identifier, and your device's IP address. IP-keyed entries are held for up to 24 hours and then automatically expire; device-hash counters are kept for short rolling windows and expire the same way. Your IP address is used only for rate limiting and abuse prevention — it is not stored alongside scan results (Section 4.4) and is not linked to your identity or the contents of a scan. The separate ingredient reports described in Section 4.10 do not use the IP address at all — they are rate-limited on a salted hash of it.
We use Mixpanel to understand which features are used. Events are tied to an anonymous Mixpanel-generated identifier, not to your name or any account.
Events we track:
screen_viewed (with a screen name like "scan_home")scan_started, scan_completed (with score and data source)upgrade_screen_viewed, upgrade_completedpurchase_marked_bought, purchase_marked_didnt_buy, purchase_decision_cleared — fired when you mark a scanned product as bought, not bought, or clear that status. We record only the score range (low / medium / high) — no product names, brands, or barcodes.correction_initiated, correction_completed, correction_failed, correction_limit_reached — fired when you report a scanned product as wrong and trigger a fresh AI scan. We record only the original data source ("OFF" / "Cache" / "AI"), the score range, and (for failures) a categorical reason such as "non_food" or "network_error". No product names, brands, or barcodes are included.data_gap_fill_initiated, data_gap_fill_completed, data_gap_fill_failed — fired when you add photos to improve a product with sparse data. We record only the original data source ("OFF" / "Cache"), the original and new score ranges, and (for failures) a categorical reason. No product names, brands, or barcodes are included.We do not intentionally attach your name, supplement list, adherence data, goals, or diet to any analytics event. Mixpanel is hosted on its EU server (api-eu.mixpanel.com) for GDPR compliance.
We use Sentry to receive crash reports so we can fix bugs. Sentry crashes contain device model, operating system version, and a stack trace. We have explicitly disabled the collection of personal identifying information (sendDefaultPii = false) — Sentry is configured not to collect your IP address, cookies, or user identifiers.
We use TelemetryDeck (privacy-first analytics, hosted in the EU) to understand how Arovya is used in aggregate. TelemetryDeck collects anonymous device and usage information including device type, operating system version, country (approximate, derived from network), language preference, and counts of in-app events (such as scans started, tabs viewed, and Pro features explored).
Events we track include: app launches, onboarding progress, tab navigation, scan flow stages, paywall views, Pro purchase events, and four supplement-routine signals — when a supplement is added, removed, marked taken (toggled), or has its timing changed. Together these convey which supplements you track (add and remove signals reconstruct the set), their timing, and your adherence; each carries a catalogue code for the supplement type (for example, vitamin_d3), never its display name, with anything you type in yourself sent as custom. The dose amounts you set are not included and never leave your device. Other event parameters use anonymous identifiers or bucketed values (e.g., score ranges) — never your name, scan content, or other personally identifying information.
TelemetryDeck does not assign persistent user identifiers. The data is anonymous and cannot be linked back to individual users. You can read TelemetryDeck's privacy policy at telemetrydeck.com/privacy.
When you subscribe to Arovya Pro:
Arovya colour-codes each ingredient on a product's label. When it cannot recognise a word — often because the label is in a language we don't yet cover well — it marks that ingredient as unread rather than guessing. If more than 40% of a label comes back unread, the app sends us a short report so we can improve recognition.
What's sent:
What's not sent: no device identifier of any kind — not your device ID, not a hash of it, not a session or install identifier. Unlike the scan results described in Section 4.4, these reports carry nothing that links them to a device or a person. They are notes about a product label, not a record of anything you did.
Reports are stored one row per barcode. Sending the same report again increases a counter on that row rather than adding a new one, so the data cannot show when, or how often, any individual scanned a product. Your IP address is not stored with these reports. It is used only to limit abuse of this endpoint, and only as a salted, irreversible hash — not as the address itself. This differs from the rate-limit counters in Section 4.5, which are keyed on the IP address.
Each product is reported at most once per device, and only when the app genuinely could not read most of the label.
We do not collect:
The health details you choose to enter yourself — such as medications, conditions, pregnancy status or smoking status — are stored on your device (see section 3); we simply never read them from Apple Health.
| What | Where | How long |
|---|---|---|
| Your supplement logs, profile and settings on your device | Your iPhone | Until you delete the app |
| Your scan history on your device | Your iPhone | Kept to your most recent 500 scans — older scans are deleted automatically; only your most recent 60 keep their full details |
| AI scan results in our database | Cloudflare D1 | Retained for as long as reasonably necessary to improve product recognition and operate the service. Wrong-product corrections replace previous records under the same barcode. |
| Unreadable ingredient reports | Cloudflare D1 | Retained for as long as reasonably necessary to improve ingredient recognition. One row per barcode, with no device identifier. |
| Product images (the first photo of each scan) | Cloudflare R2 | Retained for as long as reasonably necessary to improve product recognition; we may remove or replace images as coverage improves |
| Rate-limit counters | Cloudflare KV | Device-hash counters auto-expire after short rolling windows; IP-based rate-limit entries auto-expire within 24 hours |
| Mixpanel events | Mixpanel (EU) | Per Mixpanel default retention (currently up to 5 years) |
| Sentry crashes | Sentry (EU) | Per Sentry default retention (currently 90 days) |
| TelemetryDeck events | TelemetryDeck (EU) | Per TelemetryDeck default retention |
| Subscription receipts | Apple | Per Apple policy |
Because almost all your personal information stays on your device, most data-subject requests are handled by you simply using the app:
For the small amount of data on our servers (anonymous scan results and product images), we do not hold information that directly identifies you. If you would like us to locate and delete records associated with your device, contact support@arovya.uk and include your device identifier, which the app displays at Profile → Privacy. This identifier and any server-side records are created only when you run your first AI label scan — if you have never run one, we hold no scan records for your device and there is nothing to delete. We will make reasonable efforts to locate matching records and remove them.
Legal basis for processing. Where we process your personal data, we rely on the following legal bases under UK GDPR: legitimate interests for operational data such as rate limiting, abuse prevention, crash diagnostics, and anonymised product records used to improve the service; contract performance for subscription management; and consent where required by applicable law.
You also have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) if you believe your privacy rights have been infringed.
Arovya is not directed to children under 13. We do not knowingly collect personal information from children under 13. If we become aware that we have received personal information directly from a child under 13, we will take reasonable steps to delete it. If you are a parent or guardian and believe a child has provided information to us, please contact support@arovya.uk.
Some of our service providers process data outside the UK and EU:
Where data is transferred outside the UK, we rely on safeguards offered by our providers, such as Standard Contractual Clauses or equivalent transfer mechanisms where applicable.
We may update this policy. Material changes will be communicated via the app or by updating the "Last updated" date at the top. Continued use after changes constitutes acceptance.
Anand Basavaraj Muddi
Unit 166188
PO Box 7169
Poole, BH15 9EL
United Kingdom
Email: support@arovya.uk
For UK GDPR matters, our supervisory authority is the Information Commissioner's Office (ico.org.uk).