CarbSight

Privacy Policy

Last updated: September 29, 2026

JCW Digital ("we", "us", or "our") operates CarbSight, a mobile application that uses AI to estimate carbohydrate content from food photos. This Privacy Policy explains how we collect, use, and protect your information.

1. Information We Collect

Account Information: When you create an account, we collect your email address and authentication provider (Apple ID or email). If you sign in with Apple, we receive only the information you choose to share.

Food Photos: When you use the scan feature, your food photos are sent to our backend server for AI analysis. Photos are transmitted securely via HTTPS and are processed by OpenAI's Vision API. Photos sent to OpenAI are automatically deleted within one hour. Photos are also stored in our database to enable meal history and sync features.

Meal Estimates: We store the AI-generated carbohydrate estimates, food item names, portion sizes, and confidence scores associated with your scans. This data is linked to your user account.

Subscription Data: If you subscribe, we store your Apple transaction identifiers and entitlement status to manage your subscription. We do not have access to your payment method or billing details — those are handled entirely by Apple.

Usage Data: We track scan counts, successful scan operations, and free-allowance usage to enforce access limits. You can scan and purchase without registering; the app uses an anonymous backend identifier until you choose to add sign-in.

Free Scan Protection: We use Apple DeviceCheck to record whether a device has received its free-scan allowance. This state can survive app reinstallation. A random recovery key stored in the device Keychain can reconnect a reinstalled app to its remaining allowance; our server stores a hash of that key. These records do not contain food photos or meal estimates.

Local Data: The app stores meal history, preferences (appearance, disclaimers acknowledged), and cached data locally on your device using CoreData and UserDefaults.

2. How We Use Your Information

3. Third-Party Services

We use the following third-party services:

4. Data Retention

Your account data and meal history are retained for as long as your account is active. Food photos sent to OpenAI are automatically deleted within one hour of processing. When you delete your account, all associated data is permanently removed from our servers, including meal estimates, transaction records, entitlements, and identity-linked usage data. The device-level free-allowance marker and recovery-key hash with its aggregate allowance count may remain to prevent repeated redemption; deleting an account does not reset the free offer.

5. Data Security

All data transmission between the app and our servers uses HTTPS encryption. User authentication is managed through Supabase with industry-standard JWT tokens. We use row-level security policies to ensure users can only access their own data.

6. Your Rights

You have the right to:

7. Children's Use and Parental Responsibility

CarbSight is designed to support individuals managing carbohydrate intake, including parents and caregivers assisting minors with dietary needs such as diabetes management.

Accounts within CarbSight are intended to be created and managed by individuals aged 13 or older. Parents or legal guardians may use the app on behalf of minors under their supervision.

We do not knowingly permit children under the age of 13 to create independent accounts or to provide personal information without verified parental involvement. Any carbohydrate estimates, meal history, or related data associated with minors are expected to be entered and managed by a parent or guardian.

Parents or guardians who believe their child has provided personal information without their consent may contact us to request review or deletion of the data.

8. Tracking & Analytics

We use TelemetryDeck to understand onboarding, scans, paywall views, purchases, and return usage. Signals include event names and coarse categories or counts. Free-scan experiment events do not include photos, correction text, or nutrition values. Existing scan analytics include item counts and broad carbohydrate ranges, rather than exact amounts. We do not use advertising SDKs, track you across other apps or websites, or share your data with advertisers.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes through the app or by updating the "Last updated" date above.

10. Contact Us

If you have questions about this Privacy Policy or your data, please contact us at:

Email: support@carbsight.app