1. Introduction

Prova ("we", "our", or "the app") is a food product scanner that helps you make informed decisions about what you eat. This Privacy Policy explains what data we collect, how we use it, and your rights.

We built Prova with privacy in mind. We do not build profiles, sell data, or require you to create an account. Most personal preferences stay on your device; product lookups and optional label photos are processed as described below.

2. Information We Collect

Camera access

The app uses your camera to (1) scan product barcodes and (2), if you choose Identify with photos when a product is not found, photograph the front and back labels. Barcode scan frames are processed on your device and are not uploaded as photos or video. Label photos you submit are sent to our backend over HTTPS, processed by Google Gemini to extract product details, and may be stored (including a front-label image in Firebase Storage) so the product can be shown again.

Anonymous identifier

The app signs in anonymously using Firebase Authentication. This generates a random, device-specific identifier with no connection to your name, email address, or any personal information. You never need to provide credentials.

Product barcode lookups

When you scan a product, the barcode number is sent to our backend to retrieve product information. When you use Identify with photos, extracted product fields may be cached by barcode so later lookups work without re-photographing. Cached product records and retained front-label images are public product-reference data readable by barcode; they are not associated with a user, dietary profile, or scan history.

Usage analytics

Firebase Analytics collects pseudonymous app-usage data, including screen views, feature interactions, session information, device and app information, and an app-instance identifier. It also derives approximate location (such as country or city) from a masked IP address; Prova does not collect precise location or GPS data. We use this data solely to understand and improve the app and do not attach your name, email address, dietary profile, or scan history to it.

Crash, error, and performance reports

The app uses Sentry and Firebase Crashlytics to automatically report crashes and technical errors. Sentry also samples performance traces so we can diagnose slow or unreliable app behavior. These reports may include an app-installation identifier, device type, operating system version, app version, timestamps, relevant application state, stack traces, and performance spans. We do not attach your name, email address, dietary profile, or scan history to these reports.

3. Data Stored on Your Device Only

The following data is stored exclusively on your device using local storage. It is never uploaded to our servers or shared with any third party:

You are in full control. You can delete your scan history and reset your dietary profile at any time from within the app. Uninstalling the app removes all locally stored data.

4. Data We Do Not Collect

5. Third-Party Services

The app uses the following third-party services. Each has its own privacy policy governing their data handling:

Firebase (Google LLC) Used for anonymous authentication, product lookup via Cloud Functions, Firestore product cache, optional product images in Storage, usage analytics, and Crashlytics crash reporting. firebase.google.com/support/privacy ↗
Google Gemini (Google LLC) Used to extract structured product data from label photos you voluntarily submit when a product is not found. policies.google.com/privacy ↗
Sentry (Functional Software, Inc.) Used for automatic crash reporting, error monitoring, and sampled performance tracing to improve app stability and responsiveness. sentry.io/privacy ↗

6. Data Retention

Analytics data is retained by Firebase according to Google's configured retention settings. Firebase Crashlytics retains crash stack traces and associated installation identifiers for 90 days before beginning deletion. Sentry retains crash, error, and sampled performance reports for up to 90 days. We do not intentionally include data that directly identifies you in these reports.

7. Security

All communication between the app and our backend is encrypted using HTTPS/TLS. Firebase security rules deny client writes to the shared product cache and product-image store; only the backend can create or update those records. Product records and front-label images are intentionally public so any device can retrieve the same product by barcode. Label photos are only uploaded when you choose Identify with photos.

8. Your Rights

Since we do not collect personally identifiable information, most data subject rights (access, rectification, deletion) are exercised directly on your device by clearing your history and profile within the app settings.

If you have any concerns about data handled by our third-party providers, please refer to their respective privacy policies linked above.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the app after any changes constitutes your acceptance of the updated policy.

10. Contact

If you have any questions or concerns about this Privacy Policy, please contact us:

App name Prova
Developer masimplo
Package com.markneer.prova