This policy describes what the Cal Halal AI mobile app (the “App”) collects, why, who else processes it, and how you can have it deleted. It is written to match what the App actually does — nothing is listed here that we do not collect, and nothing we collect has been left out.
The App is published and operated by Oeanova LLC (“we”, “our”, “us”), a limited liability company registered in New Mexico, United States. Oeanova LLC is the data controller for the personal data described below. This policy takes effect on August 31, 2026.
Halal verdicts in the App are produced by automated ingredient matching and AI models. They can be wrong, incomplete, or out of date. A verdict is not a religious ruling and does not replace a halal certification body or a qualified scholar.
Nutrition figures are estimates. They are not medical, dietary, or nutritional advice.
If you have a severe allergy or intolerance, read the physical label on the product and do not rely on the App.
1. No account, no email, no password
The App has no sign-up screen. The first time you open it, it signs you in automatically using Firebase Anonymous Authentication, a service provided by Google. We never ask for an email address, password, phone number, or social login, and we never receive one.
What this creates is an opaque user identifier generated by Google. It is not linked to your name or to any real-world identity that we hold. Everything described in this policy is stored against that identifier.
There is a practical consequence worth knowing: because we cannot identify you, we need you to tell us which anonymous identifier is yours before we can act on a data request. Section 13 explains how.
2. Profile information you enter
During onboarding, and later from your profile screen, you enter information the App uses to personalize halal checking and nutrition tracking. It is stored on your device and on our servers (Supabase), against your anonymous identifier:
- Display name (optional) and avatar seed
- Gender
- Age, stored as a date of birth
- Height, current weight, and goal weight
- Activity level and weight goal
- Metric or imperial unit preference
- Custom calorie and macronutrient targets
- The allergens you want to be warned about
- Your school of Islamic jurisprudence (fiqh school) and how strict you want halal checking to be
2.1 Two of these are special-category data
Under Article 9 of the GDPR, two items in that list get stronger protection:
- Your fiqh school and halal strictness preferences reveal your religious belief.
- Your weight, height, age, and nutrition targets are health data.
We process both on the legal basis of your explicit consent, which you give by entering them. You can withdraw that consent at any time (Section 13). Withdrawal does not affect processing that already took place.
We will not present this as optional detail: the App cannot do what it exists to do without it. A halal verdict depends on your fiqh school, and a calorie target depends on your body metrics. If you are not comfortable providing them, the App cannot serve you.
3. Scan history
Each time you scan a product, we store the record of that scan:
- The product scanned
- The halal verdict returned
- The reasoning shown to you
- The ingredients text and the nutrition values
- The timestamp
Scan history is kept on your device and on our servers. We keep the 200 most recent scans per user; older entries are deleted automatically.
You can erase the whole history at any time from inside the App, at Profile → Clear history. That deletes the rows on our servers too, not only the copy on your device.
4. Photos of labels and meals
You can photograph a product label or a meal, or pick an existing image from your gallery. This is the most sensitive flow in the App, so here is precisely what happens to that image:
- The image file stays on your device. It is never uploaded and stored as a file.
- To analyze it, the image is sent — encrypted in transit — to our backend, which immediately forwards it to OpenRouter (openrouter.ai). OpenRouter routes it to the AI model that performs the analysis.
- We do not store the image on our servers. It is processed and discarded. It is not written to any database of ours.
- The model providers reachable through OpenRouter at the time of writing are Google (Gemma), NVIDIA (Nemotron), MiniMax, and Thinking Machines. What those providers do with the request is governed by OpenRouter’s terms and their own policies, not by ours.
Because the image is analyzed by a third-party AI provider, please do not photograph anything you would not want processed by one — documents, faces, or anything else personal that happens to be in frame. Point the camera at the label or the plate.
5. Barcodes
When you scan a barcode that is not already in our database, we send the barcode number to Open Food Facts (openfoodfacts.org), a public open-data food database, to look up the product’s name and ingredients.
Only the barcode is sent. No user identifier is included, so Open Food Facts receives nothing that ties the lookup back to you.
6. Grocery list and community submissions
Items you add to your in-app grocery list, and products you submit to be added to our database, are stored on our servers against your anonymous identifier. A product you submit may become part of the shared product database used by other users.
7. Reports of incorrect verdicts
When you flag a halal verdict as wrong, we store the scan in question, the verdict that was shown, the App version, and the language, so the case can be reviewed and corrected. This is how the product becomes more accurate over time.
8. Analytics, crash, and performance data
The App uses Google Firebase for diagnostics and product analytics.
Firebase Analytics
Records usage events — which screens are opened, which features are used — and, on Android, the device advertising identifier (AD_ID). We state this plainly because the permission is present in the App and our Google Play Data safety form declares it.
To be equally clear about what we do not do with it: we do not run advertising in the App, and we do not sell your data. The identifier is used for analytics only.
Firebase Crashlytics
Receives crash reports when the App fails, including your device model, OS version, and the stack trace of the crash.
Firebase Performance Monitoring
Records load times and network timings, so we can find slow screens and slow requests.
Firebase Cloud Messaging
The App asks for permission to send you notifications. We do not send any notification today. The permission is requested for a feature we intend to add later. If you decline it, you lose nothing in the current version of the App.
Firebase Remote Config
Used to change App settings and feature flags without shipping an update. It does not collect personal data about you.
9. Data stored only on your device
Two things live on your device alone. We never receive or store either of them:
- The scan images you capture. The images the App keeps alongside your scan history are held in your device’s own storage. We never upload them as files and we never keep a copy.
- The daily scan counter, which enforces the limit of 10 AI scans per day per device.
To be exact about the one case where image content does leave your device: when you submit a photo for analysis, that single request is transmitted as described in Section 4, then processed and discarded. It is not saved on our servers, and it does not create a copy of your image library anywhere outside your device.
Uninstalling the App removes both items above.
10. Legal bases for processing
Where the GDPR or UK GDPR applies to you, we rely on the following legal bases:
| Data | Legal basis |
|---|---|
| Anonymous identifier, scan history, grocery list, submissions, and non-sensitive profile fields | Performance of a contract — Art. 6(1)(b). Without them the App cannot function. |
| Fiqh school and halal strictness (religious belief) | Your explicit consent — Art. 9(2)(a), given by entering them. |
| Height, weight, goal weight, age, activity level, and nutrition targets (health data) | Your explicit consent — Art. 9(2)(a), given by entering them. |
| Photos submitted for analysis | Performance of a contract — Art. 6(1)(b) — together with your explicit consent under Art. 9(2)(a) where the image reveals health or religious dietary practice. |
| Barcode lookups sent to Open Food Facts | Legitimate interests — Art. 6(1)(f) — in identifying products. No user identifier is sent. |
| Reports of incorrect verdicts | Legitimate interests — Art. 6(1)(f) — in correcting errors and improving accuracy. |
| Analytics, advertising identifier, crash and performance data | Your consent where consent is required in your jurisdiction; otherwise our legitimate interests — Art. 6(1)(f) — in keeping the App stable and understanding how it is used. |
| Push notification permission | Your consent, given through your device’s permission prompt. |
11. Who else processes your data
We do not sell your personal data, and we do not share it with data brokers or advertisers. We do share it with the service providers below, each of which processes it on our behalf or for the limited purpose described:
| Provider | Role | Their policy |
|---|---|---|
| Google LLC | Firebase Authentication, Analytics, Crashlytics, Performance Monitoring, Cloud Messaging, and Remote Config. | firebase.google.com/support/privacy |
| Supabase, Inc. | Our database and serverless functions — profile, scan history, grocery list, submissions, and reports. Hosted in Ireland (EU West). | supabase.com/privacy |
| OpenRouter, Inc. | Routes the photos and the ingredient analysis requests you submit to the AI model that analyzes them. | openrouter.ai/privacy |
| Open Food Facts | Public open-data food database, queried with a barcode number only, to retrieve product names and ingredients. | world.openfoodfacts.org/privacy |
The AI model providers reachable through OpenRouter — Google (Gemma), NVIDIA (Nemotron), MiniMax, and Thinking Machines — process the contents of an analysis request under OpenRouter’s terms. That set of providers can change as models are added or retired.
12. How long we keep things
| Data | Retention |
|---|---|
| Scan history | The 200 most recent scans per user. Older scans are deleted automatically. You can delete all of it immediately at Profile → Clear history. |
| Profile data | Kept while your anonymous account exists, until you ask us to delete it. |
| Photos submitted for analysis | Not retained by us. Processed and discarded. |
| Grocery list | Kept until you remove the items or ask us to delete your data. |
| Community product submissions | Kept on our servers against your anonymous identifier until you ask us to delete your data. A submission that becomes part of the shared product database remains in that database. |
| Reports of incorrect verdicts | Kept while the report is under review, and afterwards as a record of the correction. |
| Analytics, crash, and performance data | Kept for the retention period configured in Firebase and governed by Google’s policies. |
| Scan images and the daily counter on your device | Until you clear them or uninstall the App. |
13. Your rights
If the GDPR or UK GDPR applies to you, you have the right to access your data, to have it corrected, to have it erased, to restrict how we process it, to receive it in a portable format (portability), to object to processing based on legitimate interests, and to withdraw consent you previously gave. You also have the right to lodge a complaint with a supervisory authority. Users in other jurisdictions may have comparable rights; we apply the process below to everyone.
13.1 How to exercise them
- Erasing your scan history — do it yourself, in the App, at Profile → Clear history. It takes effect immediately, on your device and on our servers.
- Everything else — including deletion of your anonymous account and its profile — email info@oeanovallc.com. We answer within 30 days.
We hold no name and no email address for you, so an email on its own does not tell us which data is yours. To make a request, either send it through the App’s Support / Contact flow, which attaches your identifier automatically, or include the user ID shown in the App in your message.
Without one of those we have no way to identify your data, and we will have to come back and ask for it before we can act — which only delays your request.
14. Children
The App is not directed at children under 13, and we do not knowingly collect personal data from them. This matches the target-audience declaration on our Google Play listing. If you believe a child under 13 has provided us with data, email info@oeanovallc.com and we will delete it.
15. International transfers
Our database and serverless functions run in Ireland (EU West), so profile and scan data stays in the European Union at rest.
Some processing nevertheless takes place outside the European Union. Google operates the Firebase services from the United States; OpenRouter, Inc. is a US company; and Supabase, Inc. is a US company that may access infrastructure for support and administration.
In addition, OpenRouter may route an analysis request to a model provider established outside the EU and the UK, including in countries that are not covered by a European Commission adequacy decision. We will not claim a location for each model provider that we have not verified, so we state the position plainly: when you submit a photo or an ingredient list for analysis, its contents may be processed outside Europe by a provider we do not control.
Where these transfers involve personal data leaving the EU or the UK, we rely on the European Commission’s Standard Contractual Clauses (with the UK Addendum where applicable), which our providers incorporate into their data processing agreements.
16. Security
Concretely, the measures in place are:
- Encryption in transit (TLS) for every connection between the App, our backend, and our providers.
- Row-level security on our database, scoped to a verified Firebase ID token, so a request can only read and write the rows belonging to the identifier it authenticated as.
- Photos are not persisted on our servers, which removes an entire category of stored data from the risk surface.
We do not hold ISO 27001, SOC 2, or any other security certification, and we do not claim one. We have not appointed a Data Protection Officer; privacy requests are handled directly by Oeanova LLC at the address in Section 18. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
17. Changes to this policy
If we change this policy, we will publish the new version at this URL and update the “Last updated” date at the top. If a change is significant — a new category of data, a new processor, or a new purpose — we will say so in the App before or when the change takes effect, and where the law requires it we will ask for your consent again.
18. Contact
Oeanova LLC · 1209 Mountain Road Pl NE, Ste N, Albuquerque, NM 87110, USA · info@oeanovallc.com
Registered agent for service of process: Northwest Registered Agent, Inc. · Entity ID 4221701 · Jurisdiction: New Mexico
If you are in the EU or the UK and you are not satisfied with our response, you may complain to your national data protection supervisory authority.