Privacy Policy
Snacco Privacy Policy
Last updated: 9 September 2026
The short version: Snacco has no accounts, no sign-in, no ads, and no advertising or analytics trackers. We don't know who you are, and we never sell data. Label photos are read on your device and never uploaded. Your scan history lives only on your phone.
Who we are
Snacco is developed by Josh Waller (Kovus), based in Australia. Contact: josh@kovus.dev. We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles.
What leaves your device, and when
Snacco is designed so that as little as possible leaves your phone:
- Label scans (free): the photo of an ingredients label is processed entirely on your device using on-device text recognition. The photo is never uploaded. Only the recognised ingredient text is sent to our server to be checked against our toxin database, and it is not stored or linked to you.
- Barcode scans: the barcode number is looked up against Open Pet Food Facts, an open public database. The returned product information is then checked against our toxin database the same way as label text.
- "Can my dog or cat eat this?" photo checks: this optional feature sends the single photo you take to our server, where Anthropic's Claude API is used only to name the food in the photo. Before upload, the photo is downscaled and its metadata (including any location data) is stripped. Snacco does not retain the submitted photo on its backend. Separately, in version 3.2 you can choose to keep a photo copy in Snacco's app storage on this iPhone, as described below.
- App verification for Snacco+ photo checks: Apple App Attest gives our server an installation public key, an Apple attestation receipt, and a changing assertion counter. We store those anonymous security records with a server-issued RevenueCat identifier so we can verify the app and subscription before processing a photo. They are not linked to your name, email, scan history, photos, or advertising identifiers.
- Recall alerts (optional): if you enable recall alerts, an anonymous device push token is registered with our server so we can send a silent "recall list updated" signal. The token is not linked to your identity or to anything you have scanned — matching recalls against your scan history happens entirely on your device. Turning recall alerts off in Snacco requests removal of the token and retries after a temporary failure. If you turn notification permission off in iOS Settings, Snacco does the same when you next open the app.
- Purchases: the optional Snacco+ subscription is processed by Apple and managed through RevenueCat using an anonymous identifier issued by our server after App Attest succeeds. We never see your name, email, or payment details.
What stays on your device
- Your scan history, favourites, pet profiles, and optional pet profile photos.
- Recall matching against your history.
- App preferences (onboarding state, notification choices).
Deleting the app removes its local database, scan history, and app-managed photos. iOS Keychain items used for security and preferences may persist if the same app is reinstalled. The random secret used to request exact recall-token removal is held only in Keychain; if it is unavailable, the server token can remain until a later delivery failure identifies it as inactive.
Optional photos saved on your iPhone
In version 3.2, you can choose to keep a separate photo copy with a scan or pack on this iPhone. Choosing to keep a copy does not add another upload. Label photos are read on the device; an optional Photo check still sends a reduced, metadata-stripped image through our backend to Anthropic to identify the food.
You can remove a saved copy, or clear saved scan and pack photos in Settings, without removing your text history or pet-profile photos. Removing a copy from Snacco does not delete the original image from your Photos library. If a local deletion fails, Snacco reports that it needs to be retried.
App storage may be included in device backups according to your device settings. We do not promise that an on-device copy is excluded from backups.
What we never collect
- No name, email address, phone number, or account of any kind.
- No location data.
- No advertising identifiers, no ad networks, and no advertising or product-analytics SDKs. The only third-party SDK in Snacco is crash reporting (see Service providers), which receives error reports — never your scans, photos, pets or history.
- No sale or sharing of personal information with data brokers — ever.
Service providers
We use a small number of infrastructure providers to run Snacco:
- Supabase — hosts our backend and toxin/recall database.
- Anthropic (Claude API) — processes photos from the optional "Can my dog or cat eat this?" feature, solely to identify the food.
- Open Pet Food Facts — public product database queried for barcode lookups.
- Expo — delivers push notifications for recall alerts.
- RevenueCat & Apple — process and manage subscriptions.
- Sentry — receives crash and error reports so we can fix faults. Reports carry the error itself plus the device model, iOS version and app version. They are stripped of user, request and breadcrumb data before sending, contain no scans, photos, pet details or history, and are not linked to you. Sentry processes them in the United States.
Each provider receives only the minimum described above.
Data retention
- Ingredient text and photos sent for checking are processed transiently and are not retained on Snacco's backend. Optional photo copies you choose to keep remain in app storage on your iPhone until removed through the app or when the app's local data is deleted. The original photo in your Photos library is separate.
- Anonymous App Attest key, receipt, counter, and RevenueCat mapping records are retained for subscription enforcement, replay prevention, and abuse protection. Reinstalling the app may create a new anonymous record.
- Anonymous push tokens are retained until Snacco successfully requests removal or Expo reports the token inactive after a delivery failure. Snacco requests removal after you turn alerts off in the app or return with notification permission off, and retries after a temporary failure.
- A keyed hash of the request IP may be stored for up to two days so public endpoints can throttle abuse. The raw IP is not retained, and the hash is not used to determine your location or identity.
- Our service providers may retain transient data for their own security and abuse-prevention periods under their service terms.
Children
Snacco is not directed at children and does not knowingly collect personal information from anyone, including children.
Not veterinary advice
Snacco is an informational tool. It is not veterinary advice and not a medical device. If your pet has eaten something concerning, contact your veterinarian or nearest emergency veterinary clinic. The Animal Poisons Helpline lists 1300 869 738 for Australia and (917) 722-5958 for the United States.
Changes and contact
If this policy changes, the updated version will be published at this address with a new "last updated" date. Questions, or want something deleted? Email josh@kovus.dev. Because Snacco has no account or contact identifier, tell us which feature the request concerns; we will explain which anonymous record can be located, the applicable retention period, and any legal or security reason for retaining it. You may also lodge a complaint with the Office of the Australian Information Commissioner (oaic.gov.au).