Privacy Policy
Last updated: August 24, 2026
This policy explains, plainly and accurately, what Jaini ("we", "us") collects when you use the app or website, why, how long we keep it, who else processes it, and the rights you have. It is written to describe what the software actually does. The data controller is the operator of Jaini; contact hello@swapncore.com.
The most important thing to know. Your selected dietary mode (for example Everyday, Temple, or Paryushan) reflects religious dietary observance. Under the EU/UK GDPR this is special-category data (Article 9). We ask for your explicit consent before processing it, and you can withdraw that consent at any time. If you do not consent, you can still browse the site, but the scan-to-verdict feature will not run, because judging a product against your dietary mode is the whole purpose of that feature.
Camera access and video frames
Camera frames are processed entirely on your device. When you use the camera scanner, the video stream is decoded locally in your browser using the ZXing barcode library. No camera images, video frames, or screenshots are ever sent to our servers. The camera feed is used only to detect barcode numbers, and is never stored or transmitted. Camera access is only requested after you tap "Scan with camera."
What we collect when you scan or look up a product
When a barcode is detected or entered, we send the barcode number, your selected dietary mode, and an anonymous device ID (below) to our API to return a verdict. Our server then records a scan event that includes:
- the barcode, the dietary mode, and the verdict returned;
- your IP address, and the coarse country and city derived from it;
- your browser's user-agent string and the response time;
- the anonymous device ID; and
- if you are signed in, your account ID, which links that scan to your identity.
We use scan events to operate and protect the service (rate-limiting and abuse prevention) and to understand aggregate usage. Search queries you type are recorded the same way. These records are retained for 90 days and then deleted automatically. This is a correction to earlier versions of this policy, which incorrectly stated that IP addresses were not stored and that scans were never linked to an identified person.
Account and sign-in
Sign-in is optional and unlocks saved favorites and scan history. We offer sign-in with Google, with Apple, and by email link, using Google Firebase Authentication. When you sign in we store your name, email address, and (for Google) profile photo URL, and we use them to identify your account across devices and to display your name in the app. While you are signed in, the scans and searches you make are associated with your account, as described above. You can sign out at any time and delete your account at any time (see "Your rights").
Cookies and on-device storage
The core app stores small values in your browser's localStorage, not in cookies: an anonymous device ID (JAIN_CLIENT_ID, a random UUID used only for rate-limiting), your selected dietary mode, a short cache of recent verdicts, and free-scan counters. You can clear these by clearing site data for this domain.
Cookies are set by Google when you use Google Sign-In (Google Identity Services), and Firebase Authentication stores your sign-in session in browser storage. These load only after you have accepted our consent prompt or chosen a sign-in method; they are not loaded on your first visit.
Third parties that process your data
| Provider | What they receive | Purpose |
|---|---|---|
| Google (Firebase Authentication & Identity Services) | Your email, name, photo URL; your IP when their scripts load | Account sign-in |
| ipwho.is | Your IP address, per scan | Resolve coarse country/city; the full IP is not retained by the provider on our behalf beyond the lookup |
| Resend | Your email address and message content | Send sign-in links and, if you opt in, a weekly digest |
| Sentry | Error diagnostics, which may include a barcode or dietary mode | Diagnose crashes and errors (enabled only if configured) |
| Amazon | A click, if you choose to open an affiliate link | Suggested alternatives on non-compliant products (see below) |
Product ingredient data is retrieved from third-party food databases; we display their data and do not control how those databases collect it. Several processors above are located in the United States, so using Jaini involves an international transfer of your data.
Suggested alternatives and affiliate links
When a product is not compliant with your dietary mode, we may show links to compliant alternatives, some of which are Amazon affiliate links from which we may earn a commission. Commerce never appears on a compliant or "unknown" verdict, and a product's verdict is never influenced by whether we can earn from it. Affiliate links do not send your barcode or personal data to the retailer.
Voluntary reports and submissions
If a product is missing, you may submit a photo of its ingredient list and, optionally, an email address to be notified. Submissions are stored to expand our database, reviewed by administrators, and associated with your account (or the email you provide) to prevent abuse.
Legal bases (EU/UK GDPR)
- Explicit consent (Art. 9(2)(a)) for processing your dietary mode, which reflects religious observance. You give it through our consent prompt and can withdraw it at any time.
- Contract / your request for delivering a verdict and operating your account.
- Legitimate interests for security, rate-limiting, abuse prevention, and aggregate analytics, balanced against your rights and limited by the 90-day retention above.
- Consent for optional email (the weekly digest), which is off by default and which you can turn off at any time.
How long we keep data
- Scan and search events (including IP, country/city, and any linked account ID): 90 days.
- Ad/commerce and app-diagnostic events: 7 days.
- Account data (name, email, favorites, history): until you delete your account.
- Photo submissions: until reviewed and processed.
Your rights
Depending on where you live (EU/UK GDPR, California CCPA/CPRA, and similar laws) you have the right to access, correct, delete, and export your data, to object to or restrict processing, and to withdraw consent. Account deletion is built into the app and also available by email; it removes your account and de-links your event history. To exercise any right, or to complain, contact hello@swapncore.com; we respond within 30 days. EU/UK users may also complain to their local data protection authority.
Children
Jaini is not directed at children under 13 (or under 16 where that is the local age of consent), and we do not knowingly collect their data.
Changes to this policy
If we make material changes, we will update the "Last updated" date above and, where the change concerns special-category data, ask for your consent again.
Contact
For privacy questions or data requests: hello@swapncore.com