Privacy Policy

Last updated: February 2026

Introduction

At SoyPre, your privacy is paramount. We believe you should have full control over your personal data. This Privacy Policy explains what information we collect through our mobile application, how we use it, and the rights you have regarding your data.

Key Principles: We collect only what's necessary, we never sell your data, and we're transparent about our practices.

Information We Collect

Account Information

  • Email Address: Used for account creation, authentication, and important app notifications
  • Display Name (Optional): If you choose to personalize your profile
  • Password: Stored as a hashed, salted value (we never store plaintext passwords)

Health & Dietary Information

  • Dietary Preferences: Allergies, intolerances, dietary restrictions you set in the app
  • Health Goals: Pregnancy tracking, fitness goals, or health conditions you choose to track
  • Product Scans: Barcode data and products you scan for analysis
  • Product Ratings: Your personal ratings and notes on products

Usage Data

  • App Interactions: Features you use, search queries, navigation patterns
  • Performance Data: Crash reports, loading times, errors (anonymized)
  • Device Information: OS version, app version, device model (for compatibility)

Camera Access

The app requires camera access to scan product barcodes. Images are processed locally on your device and are not stored or transmitted to our servers.

What We DON'T Collect

  • ❌ We don't use analytics trackers (Google Analytics, Facebook Pixel, etc.)
  • ❌ We don't track your location
  • ❌ We don't access your contacts, photos, or other personal files
  • ❌ We don't use advertising IDs or tracking pixels

How We Use Your Information

Essential Services

  • Product Analysis: Matching scanned products against your dietary preferences and health goals
  • Personalized Recommendations: Suggesting alternatives based on your preferences
  • Account Management: Authentication, password resets, account security

Service Improvement

  • Bug Fixes: Using anonymized error reports to fix issues
  • Feature Development: Understanding which features are most valuable to users
  • Database Updates: Adding new products based on scan requests (product data only, not user identity)

Communications

  • Essential Updates: Security alerts, policy changes, critical app updates
  • Optional Notifications: Feature announcements, product recalls (you can opt out)

Research (Anonymized Only)

We may use aggregated, fully anonymized data for research purposes (e.g., "30% of users filter for vegan products"). This data cannot be traced back to individual users.

Data Sharing & Disclosure

We NEVER sell, rent, or share your personal data with third parties for marketing purposes.

Service Providers (Data Processors)

We use a minimal number of trusted service providers to operate our app. All have GDPR-compliant Data Processing Agreements:

  • Cloud Infrastructure: Cloudflare Workers (global edge network) and database hosting (Asia region)
  • Email Delivery: Transactional emails (password resets, account notifications)
  • Crash Reporting: Anonymized error tracking for bug fixes

These providers can only process data according to our instructions and cannot use it for their own purposes.

Legal Obligations

We may disclose your information if required by law, such as in response to a valid court order or government request. We will notify you unless prohibited by law.

Business Transfers

If SoyPre is acquired or merged with another company, your data will remain subject to this Privacy Policy unless you consent to a new policy.

Your Rights (GDPR & CCPA)

You have the following rights regarding your personal data:

Right to Access

Request a copy of all personal data we hold about you in a machine-readable format (JSON or CSV).

Right to Rectification

Correct any inaccurate or incomplete personal data. Most data can be updated directly in the app settings.

Right to Erasure ("Right to be Forgotten")

Request deletion of your account and all associated personal data. We will comply within 30 days.

Right to Data Portability

Export your data in a structured, commonly used format (e.g., to transfer to another service).

Right to Object

Object to processing of your personal data for specific purposes (e.g., research, marketing).

Right to Restrict Processing

Temporarily limit how we use your data while we resolve a dispute or verify accuracy.

How to Exercise Your Rights

Send requests to privacy@soypre.com or use the "Data & Privacy" section in the app. We will respond within 30 days.

Data Protection Officer: For complex privacy matters, contact our DPO at dpo@soypre.com

Data Retention

  • Active Accounts: We retain your data while your account is active
  • Deleted Accounts: Personal data is permanently deleted within 30 days of account deletion
  • Legal Obligations: Some data may be retained longer if required by law (e.g., financial records)
  • Anonymized Data: Fully anonymized usage data may be retained indefinitely for research

Backup Retention: Deleted data is removed from backups within 90 days.

Data Security

We implement industry-standard security measures to protect your data:

  • Encryption: AES-256 encryption at rest, TLS 1.3 in transit
  • Access Controls: Multi-factor authentication and role-based access for our team
  • Regular Audits: Annual third-party security audits
  • Incident Response: 24/7 monitoring and rapid response to security events

For detailed security practices, see our Security page.

International Data Transfers

Global Infrastructure: We use Cloudflare Workers for edge computing (globally distributed) and our primary database is hosted in Asia. Your data may be processed and stored in multiple jurisdictions.

GDPR Compliance: For EU users, we comply with GDPR requirements through:

  • Standard Contractual Clauses (SCCs) with all data processors
  • Adequate safeguards for international data transfers
  • Full GDPR rights regardless of server location
  • Data Processing Agreements with all service providers

Children's Privacy

SoyPre is not intended for children under 13 (or 16 in the EU). We do not knowingly collect personal data from children. If we discover a child's account, we will delete it immediately. If you believe your child has created an account, contact us at privacy@soypre.com.

Cookies & Tracking

Mobile App

The mobile app does not use cookies or third-party tracking technologies.

Website (soypre.com)

Our website uses only essential session cookies. We do not use:

  • ❌ Google Analytics or similar analytics platforms
  • ❌ Advertising cookies or tracking pixels
  • ❌ Third-party cookies
  • ❌ Social media tracking (Facebook Pixel, Twitter analytics, etc.)

Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you via:

  • In-app notification
  • Email to your registered address
  • Prominent notice on this page

Continued use of the app after changes constitutes acceptance of the new policy.

Contact Us

For questions, concerns, or to exercise your privacy rights:

Supervisory Authority: If you're in the EU and believe we haven't addressed your concern, you have the right to lodge a complaint with your local data protection authority.