Naturswap

Privacy

Last updated: 15 August 2026

Naturswap has no accounts. You never sign in, you never enter a name or an email address, and we do not know who you are. Everything we collect is listed here.

Controller

Melvin Morina
Johann-Konrad-Vogel-Straße 4a, 4020 Linz, Österreich
melv00705@gmail.com

What stays on your device

The swaps and the recipes live inside the app, not on a server. Your searches run on the device. What you tick off, which rooms you picked during onboarding and your scan diary, meaning the list of what you have scanned, stay on your iPhone. The diary never leaves your device. Delete the app, or tap Reset everything under More, and it is gone.

The scanner

This is where data leaves your device, and it differs by what you scan.

Barcode. The digits go to our server and from there to Open Food Facts, an open food database. Only the product code is sent, nothing about you. We do not store the barcode, except when the database does not know it: then we keep the digits on their own, so we can see which items are missing, with nothing attached about who scanned.

Photo. When you take a photo it is downscaled and sent to our server and from there to OpenAI in the United States. A model there reads what is visible in the picture: the ingredient list, the components of a meal, or the object and its material. The assessment itself is then calculated by our server from fixed rules, with no model involved.

The legal basis for scanning is performance of the contract under Article 6(1)(b) GDPR, because scanning is the service you are paying for.

So that nobody drains the interface at our expense, we count how many photo scans were made per installation id per day. Stored for that are the id, the date and a number, no image and no result. The row is deleted after thirty days.

We also store one row per scan with the resulting value, the kind of scan and the product name, without the installation id, without the barcode and without the image. It cannot be used to work out who scanned what.

Usage data, PostHog

We measure how the app is used, with PostHog on European servers. A random id is generated that belongs to your installation and to nothing else. It contains no name, no Apple device identifier and no advertising id.

What is transmitted:

The purpose is to improve the app and to see where it loses people. The legal basis is our legitimate interest in a working app under Article 6(1)(f) GDPR. You can object, just write to us.

Subscription, Apple and RevenueCat

The purchase runs through your Apple account. We see no payment details, no card, no billing address. RevenueCat manages for us how the purchase is handled and whether it is still active. RevenueCat receives the same random installation id plus what Apple reports about the purchase, so product, price, country and term. RevenueCat is based in the United States, and the transfer relies on the European Commission's standard contractual clauses.

Feedback

If you send us a missing swap or a message through the app, we store the text, your installation id, the app version and the country Cloudflare derives from the connection. That lives in a database at Cloudflare in the EU. The purpose is to add the missing entries.

Servers

These pages and the app's interfaces run on Cloudflare. Cloudflare processes technically necessary connection data, including your IP address. We do not store IP addresses.

How long

Usage data in PostHog is deleted after twelve months. Feedback is kept until the missing swap is written, at most twenty four months. The daily count for photo scans is deleted after thirty days. Photos are not stored at all.

Your rights

You have the right to access, rectification, erasure, restriction, portability and objection. Because we do not know you, we need your installation id for that. It is in the app under More, at the very bottom. Send it to melv00705@gmail.com and we will delete everything attached to it.

You can also complain to a data protection supervisory authority.