Last updated: 2026-05-29
This Privacy Policy explains what data the Lafai mobile application ("Lafai", "the app", "we") processes, why, and your choices. Lafai is currently distributed as a limited external beta.
The app developer is the data controller for this beta. For privacy requests or support, contact: support@lafai.app.
| Data | Purpose | Where it is stored | Shared with |
|---|---|---|---|
| Food label images you capture/upload | To extract and analyze nutrition information | Processed transiently in the backend; sent to Google Gemini for analysis; the scan record (and thumbnails) is stored locally on your device | Google (Gemini API) |
| Custom prompts & Lifestyle profile (free-text: e.g. custom questions, allergies, dietary preferences) โ optional | To personalize the nutritional evaluation | Stored locally on your device; sent to Google Gemini as analysis context only when provided | Google (Gemini API) |
| Follow-up chat messages | To answer your questions about a product | Conversation stored locally; messages sent to Google Gemini | Google (Gemini API) |
| Anonymous account identifier (Firebase Anonymous Auth UID) | To authenticate requests and apply fair-use rate limits | Firebase Authentication | Google (Firebase) |
| Pseudonymized request metadata (a salted, daily-rotating hash of your IP address; usage counters) | Abuse prevention, rate limiting, and cost control | Firebase / Cloud Logging | Google (Firebase) |
We do not intentionally collect your name, email, precise location, or advertising identifiers.
If you choose to create a custom prompt or enter a lifestyle profile, that information may include dietary, lifestyle-related details, or other personal text. It is transmitted over an encrypted (HTTPS) connection to our backend and then to Google's Gemini API to generate your analysis. Providing a custom prompt or lifestyle profile is optional โ you can use the app without them, and you can clear them at any time in Settings. Lafai provides nutritional information only and is not a medical device or a substitute for professional medical advice.
To provide our core scanning and analysis features, Lafai uses the Gemini API from Google LLC. When you scan a product or send text within the app, the image and accompanying text are transmitted to Google's servers for processing.
We prioritize your privacy: we do not use your data to train any AI models. Furthermore, under Google's standard privacy terms for the Gemini API, the data sent for analysis (your images and text) is not used by Google to train their foundational models. We encourage you to review Google's privacy documentation regarding its handling of API data. Lafai is not affiliated with, endorsed by, or sponsored by Google LLC.
These providers process data under Google's terms; see Google's privacy documentation for details.
Depending on your region, you may have rights under the GDPR (EU/EEA/UK) or CCPA (California), including access, correction, deletion, and objection.
Network traffic uses HTTPS. The backend enforces authentication, input validation, rate limiting, and (for production builds) Firebase App Check. No method of transmission or storage is 100% secure.
Lafai is not directed to children under 13 (or the minimum age in your jurisdiction) and we do not knowingly collect their data.
We may update this policy. Material changes will be reflected by the "Last updated" date and, where appropriate, in-app notice.
Questions or requests: support@lafai.app.