Privacy Policy
Version: 2026-09-15.1 · Effective: September 15, 2026
This Privacy Policy explains how V7 Check collects, uses, and stores information when you use the app and related services.
Controller and contact
Dovanos magija MB, Liusiu g. 12, Valu k., LT-21423, Lithuania, is the controller responsible for the personal data described in this Privacy Policy. For questions, complaints or privacy requests, email info@white-bear.co.
Information we collect
We currently collect the following categories of data:
- Account information: your account identifier, email address and authentication-provider information for sign-in, including an Apple relay address if you choose Hide My Email.
- Apple authorization: if you sign in with Apple, we process a short-lived authorization code and securely retain a server-only refresh token and provider identifier to revoke Apple access when you delete your account.
- Basket profiles: the product rules you create, share or follow.
- Product interaction data: barcode lookups, scan allowance counters, product reports, and related request data.
- Images you submit: photos uploaded for product analysis features, and the product information read from them.
- Subscription status: if you buy V7 Check Pro, whether your subscription is active and when it expires.
- Legal acknowledgement records: the terms and privacy versions acknowledged, the server-recorded acceptance time and app version, associated with your account.
- Support correspondence: your contact details, messages and information needed to investigate a problem or fulfil a rights request. Never send passwords or authorization codes.
- Technical and diagnostic data: device and app information, error logs, account identifiers, and sampled performance traces and profiles used to investigate reliability and performance problems. Service providers also process connection and security data needed to receive and protect requests.
- Local app cache: recent scans, cached product data, your shopping list and photo drafts, stored on your device.
How we use data and legal bases
- Requested services — contract necessity (GDPR Article 6(1)(b)): to create and manage your account, provide requested barcode lookup, product analysis and basket profile features, verify subscription access, answer service-related support requests, and close your account, including revoking Apple authorization. This basis covers only processing objectively necessary to provide the service you request.
- Security and reliability — legitimate interests (Article 6(1)(f)): to prevent abuse, enforce usage limits, investigate errors and performance problems, and maintain reliable product data. Our interests are protecting users and the service and correcting inaccurate information; these interests must be balanced against your rights and reasonable expectations.
- Agreement records and disputes — legitimate interests (Article 6(1)(f)): to record the terms you accepted and establish, exercise or defend legal claims where necessary. The retention limits below still apply.
- Legal duties — legal obligation (Article 6(1)(c)): to fulfil applicable data-protection duties, including responding to rights requests, and comply with binding legal requirements. We do not treat every operational use as a legal obligation.
Account and authentication data are required for authenticated features; without them we cannot provide those features. Subscription verification data are required for paid access. You can choose not to upload photos, send reports, share profiles or contact support, but we cannot perform the corresponding request without the necessary information.
Sensitive information and shared profiles
Profiles and rules concerning allergies, health conditions or religious dietary requirements may reveal health information or religious beliefs when linked to your account. Creating or following such a profile does not necessarily mean that you have that condition or belief. Nevertheless, these choices may be special-category personal data under GDPR Article 9 and require an additional lawful condition, not just a contract or legitimate interest.
Accepting the Terms or acknowledging this Privacy Policy is not explicit consent to special-category processing. Do not include diagnoses, medical records, information about another person's health or beliefs, or other unnecessary personal details in profile names, reports, photos or support messages.
When you share a profile, its name and rules can be seen by people who access or follow it. Do not share a profile if you do not want those choices disclosed. You can edit or delete profiles you own and unfollow profiles you no longer want associated with your account; account deletion is also available. Deleting a shared profile cannot recall copies another person has already made.
Third-party services
If you choose Sign in with Apple, Apple authenticates you and supplies an account identifier and your shared or relay email address. Our backend exchanges authorization codes and requests token revocation directly with Apple. Authorization credentials are not exposed to other users.
V7 Check uses Firebase services provided by Google, including Firebase Authentication, Cloud Firestore, Cloud Functions, Cloud Storage, App Check and Firebase Hosting. These services may process technical and device-related data required to operate the app.
V7 Check uses RevenueCat to process V7 Check Pro purchases made through the App Store or Google Play. RevenueCat receives your account ID and your store purchase and subscription information so we can tell whether your subscription is active. When you delete your account, we ask RevenueCat to delete your customer record.
V7 Check also uses the Open Food Facts API as a third-party data source. When you scan a barcode, the backend may send the scanned barcode to Open Food Facts to retrieve product details. We may cache retrieved provider results in Firestore to reduce repeat lookups and improve performance.
V7 Check also uses OpenRouter for AI-powered product analysis and ingredient normalization. For these features, submitted product images and/or ingredient text extracted from product data may be sent to OpenRouter and processed by one of its routed AI model providers to return structured product, nutrition, ingredient, and allergen information. Routing and fallback models mean the receiving model provider can vary. The internal V7 Check admin assistant also sends admin chat messages and information retrieved by its tools to routed models. This can include product reports, report descriptions and associated reporter identifiers, not only product-label text. Avoid putting personal information in product submissions. Provider retention and use of inputs depend on the applicable service settings and agreements; this notice does not promise zero retention or that every routed provider excludes training on inputs.
V7 Check uses Sentry for crash reporting, diagnostics and sampled performance monitoring, which may process crash logs, device and app information, performance traces and profiles, and your account ID to help us identify and fix bugs and performance problems.
V7 Check does not currently use advertising SDKs such as AdMob, and does not currently use Firebase Analytics or Crashlytics.
Apple and Google also process purchases under their store privacy notices and retain their own transaction records. Deleting V7 Check data does not delete records the stores must keep. We may disclose information when required by law or when necessary and lawful to protect rights, investigate abuse or respond to a legal claim.
International processing
Our backend is configured to run Cloud Functions in the United States. The service providers described above and OpenRouter's routed model providers may also process information outside your country, including outside the European Economic Area. Those countries may not provide the same protections as your home country.
For transfers subject to GDPR, we are responsible for establishing a valid transfer mechanism and any necessary supplementary measures; a provider's privacy policy alone is not a transfer safeguard. Depending on the recipient and arrangement, the law permits mechanisms such as an applicable adequacy decision or European Commission standard contractual clauses. Contact us for information about the safeguards applicable to your data and how to obtain a copy. Acknowledging this notice is not consent to an otherwise unlawful international transfer.
Account deletion and your choices
You can request deletion directly in the app via Settings > Account > Delete account. Apple-linked accounts may require a fresh Apple authorization during deletion. If authorization is unavailable or deletion fails, you can still request assistance. If you no longer have the app installed, you can request deletion by email at info@white-bear.co with subject Account Deletion Request. If you use an Apple relay address, mention this so we can help verify account ownership.
The deletion workflow removes your account, profile, basket profiles, legal acknowledgement records, subscription and allowance records, your reports and uploaded photos, requests deletion of your RevenueCat customer record, and clears the app's data on the device you delete from. Product facts read from your photos, such as ingredients and nutrition values, stay in the shared catalogue without your photos or direct account attribution. Some product-history and variation identifiers generated from your account ID remain to preserve product lineage. These identifiers are not guaranteed anonymous and may remain linkable to information held elsewhere.
In-app deletion normally completes within minutes; our operational target is to finish cleanup within 30 days, including provider follow-up. Failures may require support and are not silently treated as completed deletion. For rights requests, we respond without undue delay and normally within one month of receipt. Where legally permitted because of the complexity or number of requests, we may extend the response period by up to two further months, explaining the reason within the first month. We may ask for proportionate identity verification; this does not create an automatic new 30-day deadline. We explain any lawful reason for retaining information or not fulfilling a request and your complaint options. Deleting your account does not cancel an app-store subscription. See the Account deletion page for details.
Data retention
We keep data only as long as reasonably necessary to provide and operate the service, comply with legal obligations, and resolve disputes. After you delete your account:
- We delete photos from V7 Check when deletion completes. The storage bucket's documented soft-delete setting retains recoverable copies for 7 days; those copies are not used to serve product photos during that period.
- Server logs, which can include your account ID, are deleted after 30 days.
- A token-free record that deletion finished is scheduled to expire 7 days after completion, and the record associated with the random completion code the app checks is scheduled to expire 30 days after completion. Automatic expiry cleanup can occur after the scheduled time.
- Apple refresh tokens are removed when deletion is accepted. Unresolved Apple revocation records are deleted after 30 days. If Apple authorization cannot be revoked programmatically, we explain how to remove it in your Apple Account settings while assisting with deletion.
- Crash and performance reports expire under the configured Sentry retention period. Contact us to request removal of reports linked to your account; we investigate and act on applicable requests, including with the provider where needed.
- Emails about a deletion request are deleted within 30 days after the deletion is confirmed.
- Images or text already processed by OpenRouter and its routed providers are subject to those providers' retention settings and policies.
- We do not currently keep database backups. If we introduce them, deletions are reapplied before any restored data is used.
Product facts and the remaining product-lineage identifiers are kept while needed to maintain the shared catalogue and its history; this is not a promise that all remaining identifiers are anonymous. Account data and legal acknowledgement records normally remain until account deletion. Service-support correspondence is kept while necessary to resolve the request and associated disputes; the specific deletion-request email limit above applies to deletion correspondence. If a legal obligation or claim requires specific information to be kept longer, we limit it to what is necessary for that purpose and explain the exception where legally permitted.
Your privacy choices and rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, or a copy of your personal data, or to restrict certain processing. Under GDPR, you may object to processing based on legitimate interests on grounds relating to your particular situation, and request portability of data you provided where processing is automated and based on contract or consent. If we rely on consent for a particular use, you may withdraw it at any time without affecting the lawfulness of earlier processing; contact us if a withdrawal control is not available. Withdrawal can mean the optional feature concerned can no longer be provided. These rights are subject to applicable legal conditions, not a waiver in our Terms.
You can use the in-app deletion route for account deletion. To make another privacy request, email info@white-bear.co. The response and verification rules above apply. Product-rule matching is automated information to help you compare labels; it is not a medical assessment or a decision about your legal rights.
You may complain to a competent data-protection authority, including in the country where you live or work or where you believe an infringement occurred. In Lithuania, the authority is the State Data Protection Inspectorate (VDAI). You do not have to contact us before complaining to an authority.
Children's privacy
V7 Check is not intended for children under 13, and we do not knowingly collect personal data from children under 13.
That minimum is not a statement that every person aged 13 or above can independently consent to every use of data. Where local law requires a higher age or parental authorization for consent-based processing, that requirement applies. If you believe a child has provided information without the authorization required by law, contact us so we can investigate and remove it where appropriate.
Changes to this notice
We may update this notice when our processing or legal requirements change. The version and effective date identify the text you are reading. We will provide notice of material changes as required by law. Updating the notice does not substitute for obtaining separate consent where required.
Contact
For questions, complaints or privacy requests, contact Dovanos magija MB at Liusiu g. 12, Valu k., LT-21423, Lithuania, or email info@white-bear.co.