Privacy Policy
Last updated: June 16, 2026
Chaga ("we," "us," or "our") operates the Chaga mobile application. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your data.
What We Collect
- Barcode scans — Product barcodes you scan are sent to our servers to retrieve product data. Scan history is stored locally on your device.
- Usage analytics — We use PostHog to collect anonymized usage events (screens viewed, features used, scan counts). No personally identifiable information is included in analytics events.
- Subscription data — Subscription status is managed by RevenueCat and Apple. We receive subscription status (active/expired) but never see your payment details.
- Preferences — Allergen selections, pet profiles, and dietary preferences are stored locally on your device using AsyncStorage. They are sent as parameters with scan requests to personalize results but are not stored on our servers.
- Device identifier — A randomly generated anonymous device ID is stored locally for community image attribution. It is not linked to your identity.
What We Do Not Collect
- Photos — Product photos taken for community upload are sent directly to our storage service. We do not access your photo library or camera roll beyond the specific image you select.
- Location — Chaga does not request or collect location data.
- Contacts — Chaga does not access your contacts, address book, or social accounts.
- Names or email addresses — Account creation uses Supabase Auth. We store a user ID and email for authentication only.
Third-Party Services
Chaga uses the following third-party services to operate:
- Open Food Facts — Open-source product database. Barcode lookups are made to their public API.
- Supabase — Database and authentication hosting.
- RevenueCat — Subscription management. Processes subscription events between Apple and our database.
- PostHog — Privacy-focused analytics. Hosted in the US. No PII collected.
- Railway — API proxy hosting. Processes barcode lookups and ingredient cross-referencing.
- Spoonacular — Secondary product image source when Open Food Facts lacks images.
- FDA Open Data — Public API for recall alerts. No user data is sent to the FDA.
Data Storage
Scan history, allergen preferences, pet profiles, and app settings are stored locally on your device using AsyncStorage. This data does not leave your device unless you explicitly choose to create an account, in which case authentication tokens are stored securely.
Product data is cached on our servers (Supabase) to improve response times. This cache contains product information only — never user information.
Data Retention
Analytics data is retained for 12 months, then automatically deleted. Product cache data is refreshed every 30 days. You can delete your local scan history at any time from the app's Settings screen.
Your Rights
You may request deletion of any data associated with your account by contacting us at privacy@chaga.app. You may also delete all local data by uninstalling the app or clearing scan history in Settings.
Children's Privacy
Chaga is not directed at children under 13. We do not knowingly collect personal information from children.
Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated revision date.
Contact
For questions about this Privacy Policy, contact us at privacy@chaga.app.
Governing Law
This Privacy Policy is governed by the laws of the State of Texas, United States.