Privacy Policy
Last updated: April 6, 2026
1. Information We Collect
Account information: Email address, display name, and avatar when you create an account. If you sign in via Google or Apple, we receive your name and email from those providers.
Report data: Photos of spoiled food products, receipt images, product names, brand names, store locations, prices, descriptions, and category selections.
Location data: With your permission, we collect approximate location to sort nearby stores. We do not track your location in the background.
Usage data: Pages visited, features used, report submissions, and interaction patterns via Google Analytics.
2. How We Use Your Information
We use your data to: operate and improve the Service; route spoiled food claims to brand quality teams on your behalf; generate aggregated spoilage trend data (heat maps, trending products); operate the leaderboard and XP system; send you notifications about claim status updates; and analyze platform performance.
3. Information Sharing
We share limited report information with brand quality teams to process your refund claims. This includes the product name, store, photos, and description — but not your email address or personal identity unless required for claim resolution.
Aggregated, anonymized spoilage trend data may be shared publicly through the feed and leaderboard features. Your display name and avatar are visible to other users on the leaderboard and feed.
4. Data Storage & Security
Your data is stored securely using Supabase infrastructure with row-level security policies. Photos are stored in encrypted cloud storage. We use HTTPS for all data transmission. While we take reasonable measures to protect your data, no system is 100% secure.
5. AI Processing
When you upload a photo, our AI system analyzes the image to automatically detect the product, brand, category, and condition. This processing happens on our servers and the image data is not used to train AI models. The AI analysis results are stored with your report.
6. Third-Party Services
We use the following third-party services: Google Analytics (usage analytics), Supabase (authentication and database), Anthropic (AI photo analysis), Google OAuth and Apple Sign-In (authentication), and Vercel (hosting). Each has its own privacy policy governing data handling.
7. Your Rights
You may: request a copy of your data; request deletion of your account and associated data; update your profile information at any time; opt out of optional location sharing; delete individual reports. To exercise these rights, contact us or use the in-app settings.
8. Cookies & Tracking
We use essential cookies for authentication and session management. Google Analytics uses cookies to collect anonymous usage data. You can disable analytics cookies in your browser settings.
9. Children's Privacy
rotten.food is not intended for children under 13. We do not knowingly collect data from children. If you believe a child has provided us with personal information, contact us for removal.
10. Changes & Contact
We may update this policy as needed. Material changes will be communicated via the app or email. For privacy-related questions, contact us at privacy@rotten.food.