Privacy Policy
Effective Date: January 1, 2025
Secure
Your data is encrypted
Never Sold
We don't sell your data
Your Control
Delete anytime
1. Introduction and Data Controller
NoWaste.ai ("Company," "we," "us," or "our") operates the NoWaste.ai mobile application (the "Service"). This Privacy Policy informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service.
Data Controller Contact:
Email: [email protected]
Address: Ruunaoja tn 3, Lasnamäe linnaosa Tallinn, Harju maakond, 11415
2. Legal Basis for Processing (GDPR)
We process your personal data under the following legal bases:
- Consent: For marketing communications and optional features
- Contract: To provide the Service you requested
- Legitimate Interests: For improving our Service and ensuring security
- Legal Obligation: When required by law
3. Information We Collect
3.1 Information You Provide Directly
- Account Information: Name, email address, profile picture (via Google Sign-In)
- User Content: Pantry items, expiration dates, dietary preferences, allergies
- Receipt Images: Temporarily processed for data extraction (deleted within 24 hours)
- Communications: Support requests, feedback
3.2 Information Collected Automatically
- Device Information: Device model, OS version, app version, crash logs
- Usage Information: Features used, time spent, interaction patterns
- Analytics Data: Aggregated usage statistics
3.3 Information We DO NOT Collect
- Precise location data
- Contact lists
- Phone numbers
- Payment information
- Health or medical data
- Biometric data
4. How We Use Your Information
4.1 Primary Purposes
- Provide and maintain the Service
- Manage your account and authenticate users
- Send expiration notifications (with consent)
- Generate AI-powered recipes based on your ingredients
- Process receipt scans
- Sync data across devices
4.2 Secondary Purposes
- Improve Service functionality
- Analyze usage patterns
- Prevent fraud and ensure security
- Comply with legal obligations
- Respond to support requests
5. Data Sharing and Disclosure
5.1 Service Providers
Provider | Purpose | Data Shared |
---|---|---|
Firebase (Google) | Auth, Database, Analytics | User ID, email, usage |
OpenAI | Recipe generation, OCR | Ingredients (anonymized) |
Open Food Facts | Product information | Barcode numbers |
5.2 We Will NOT
- Sell your personal information
- Share data with advertisers
- Use your data for marketing without consent
- Share data beyond what's necessary for the Service
6. Data Retention
Data Type | Retention Period | Reason |
---|---|---|
Account data | Until account deletion | Service provision |
Pantry items | Until manually deleted | Core functionality |
Receipt images | 24 hours maximum | Processing only |
Analytics data | 14 months | Service improvement |
Crash logs | 90 days | Debugging |
7. Data Security
We implement appropriate technical and organizational measures:
- Encryption in transit (TLS/SSL)
- Encryption at rest for sensitive data
- Access controls and authentication
- Regular security assessments
- Incident response procedures
However, no method is 100% secure. We cannot guarantee absolute security.
8. Your Rights and Choices
8.1 Under GDPR (EU Users)
- Access: Request a copy of your data
- Rectification: Correct inaccurate data
- Erasure: Delete your data ("right to be forgotten")
- Restriction: Limit processing of your data
- Portability: Receive data in machine-readable format
- Object: Object to certain processing
- Automated Decision-Making: Not be subject to solely automated decisions
8.2 Under CCPA (California Users)
- Know: What personal information we collect, use, and share
- Delete: Request deletion of personal information
- Opt-Out: Of the sale of personal information (we don't sell data)
- Non-Discrimination: Equal service regardless of privacy choices
8.3 How to Exercise Rights
- In-App: Settings → Account → Manage Data
- Email: [email protected]
- Response Time: Within 30 days
9. Children's Privacy
Our Service is not intended for children under 13 (or 16 in EU). We do not knowingly collect data from children. If you are a parent and believe your child provided information, contact us immediately at [email protected].
17. Contact Information
For privacy concerns or questions:
Email: [email protected]
Data Protection Officer: [email protected]
Mailing Address: Ruunaoja tn 3, Lasnamäe linnaosa Tallinn, Harju maakond, 11415
By using NoWaste.ai, you acknowledge that you have read and understood this Privacy Policy.
This policy is provided in English. Translations are for convenience only. In case of conflicts, the English version prevails.