Effective September 1, 2026

Privacy policy

ScanHalal AI is designed to inspect ingredient labels with as little personal-data collection as possible. This notice describes the mobile app, website and supporting ScanHalal API operated by VentraM Tech.

What we collect

  • Account data: email address, a one-way password hash, account role and session tokens when you create an account. Guest use does not require an account.
  • Ingredient analysis data: ingredient text you enter, verdict metadata, selected school of jurisprudence and minimal diagnostic information needed to return the result.
  • Label images: a photo you choose or capture is sent over HTTPS to our self-hosted OCR service only when you request extraction. The image is processed transiently and is not saved as a scan record.
  • Reports and review submissions: the ingredient/product context and description you deliberately submit for correction or scholar review.
  • Device-local data: scan history, settings and queued reviews may remain in AsyncStorage on your device until you clear them or remove the app.

How we use data

We use data to authenticate accounts, extract ingredient text, run deterministic halal-safety rules, display sources and explanations, prevent abuse, investigate errors, and maintain the scholar-review workflow. OCR and explanatory AI do not independently issue or upgrade a religious verdict.

Sharing and sale

We do not sell personal data, run behavioral advertising, or share label images with a paid OCR provider. Infrastructure processors may handle encrypted traffic or stored database records only to operate ScanHalal AI. The production API and OCR stack are self-hosted on our isolated server environment.

Retention and deletion

Account credentials and active sessions are kept while your account exists. Deleting an ordinary user account removes the account and refresh sessions immediately. Reports, scholar-review submissions and aggregate safety records may be retained in de-identified form so corrections and religious-safety evidence are not lost. Encrypted operational backups age out within 14 days and deleted account data is not restored into active systems. Local scan history remains on your device until you clear app data or uninstall.

You can delete your account in the mobile app under Profile → Delete account, or use the public account deletion page. Staff accounts are removed through a controlled process that preserves mandatory ruling provenance.

Security

We use HTTPS, hashed passwords and refresh tokens, short-lived access tokens, role-based authorization, rate limits, isolated database access and tested backups. No system can promise absolute security; report a suspected issue through the support page.

Your choices and rights

Depending on your location, you may have rights to access, correct, delete, restrict or object to processing of personal data. You may use ScanHalal AI as a guest, decline camera/photo access and enter ingredients manually. Account deletion is available without contacting support.

Children

ScanHalal AI is not directed to children under 13 and we do not knowingly collect their personal data. A parent or guardian who believes a child created an account should use the deletion flow or contact the developer through the Google Play listing.

International processing and changes

Data may be processed where our infrastructure operates. We will update the effective date when this notice materially changes. Store review and qualified legal review may require further wording for particular launch countries.

This policy describes current product behavior and is not legal advice. VentraM Tech should obtain qualified legal review before broad public distribution in additional jurisdictions.