Privacy Policy
Last updated: 25 September 2026
Summary (one-glance)
| Storage | history on device · scan records on our server |
| User account | none |
| Location | not requested |
| Advertising ID | not read |
| Photos | sent for analysis · kept only if you allow |
| Photo sharing | opt-in (off by default) |
| IP address | one-way hash · rate limiting only |
| Data export | JSON · CSV |
| Camera | only at capture time |
1. What we collect
1.1 Data that stays on the device
- Measurement history (chemical, ppm, timestamp, device model)
- App settings (tier, haptics, language preference)
- Monthly quota counter
This data is stored in the app's private storage on your device. The history itself is not copied to a server; what our server records about each scan is described in 1.2.
1.2 What happens when a strip is read
When a measurement is analysed, the test strip photo passes through:
iPhone → stripvision-api.vercel.app → api.anthropic.com
(proxy) (AI Vision)
The photo is sent to our server (a Vercel function), which forwards it to Anthropic's Claude to locate the colour chart and the strip in the picture. Our server then measures the colours from the photo itself and sends the readings back to the app. Unless you have turned on photo sharing (1.3), the photo is not stored: it is discarded when the request completes. For Anthropic's own retention policy see anthropic.com/legal.
For every scan our server keeps a record with no account or identity attached: the time, the strip type, the device model, which AI model answered, the measured colours of the pads and chart swatches, the result or the reason a reading was refused, and the processing cost. These records are used to check reading accuracy and to account for scans of partner strips.
To prevent abuse, our server keeps a request counter per IP address. The address itself is not stored: the counter is keyed by a one-way hash of it, made with a secret key, and deleted about an hour after its last use. It is not linked to scan records.
Partner code: a business partner, or one of our own testers, can set a code on their phone — from a link we send them or in Settings → Partner. Scans from that phone are then labelled with that partner's name, so their testing can be told apart from their customers' scans. Other users don't have one. It can be removed in Settings at any time.
AI Image Analysis Consent: Before the first photo is sent, the app asks for your permission and names who receives it. Without it no photo is sent — the app enforces this where the photo leaves the device, not only on screen. You can withdraw it at any time in Settings → Allow AI analysis; the next scan will ask again.
1.3 Photo sharing (off by default)
If you allow it — when the app asks on the New measurement screen, or with Settings → Share photos for accuracy — the photo sent for a reading is also kept, privately, in our storage, linked to that scan's record and to nothing else. It is used only to improve reading accuracy. No account or identity is attached, which also means we cannot pick out a particular person's photos afterwards. You can turn it off at any time; photos are not kept from then on.
2. What we don't collect
- Location (GPS, Wi-Fi, Bluetooth)
- Personal identifiers (email, phone, name)
- Advertising ID / IDFA
- Camera access (only during manual capture)
- Contacts, calendar, health, or banking data
3. Third parties
- Anthropic (Claude API) — locates the colour chart and the strip in each photo, reached through our server. See anthropic.com/legal for how Anthropic handles API data.
- Vercel — edge function hosting. Maintains standard HTTP logs (timestamp, IP, status code). Photo content is not logged.
- Supabase — database and file storage, in the EU (Frankfurt). Holds the scan records and IP counters described in 1.2, the photos you choose to share (1.3), and the app's reading configuration. Keeps standard access logs.
- Apple App Store + StoreKit — for app distribution and subscription processing. Your payment data stays entirely with Apple; StripVision only receives a "subscription active" boolean.
- RevenueCat — third-party SDK used for Apple StoreKit receipt validation and subscription state management. Receives only an anonymous app_user_id (UUID); no name, email, or payment data is shared. RevenueCat does not see payment data — card number, IBAN, address always stay with Apple.
4. Data retention
- On-device measurement history — visible duration varies by tier (Free 30 days, Premium 365 days, Pro all-history). The data always stays on your device; it remains until you remove the app or tap "Clear all measurements".
- Scan records (1.2): kept to check accuracy and account for partner scans; they carry no identity.
- Shared photos (1.3): kept for accuracy work; not linked to you.
- IP counters (1.2): a one-way hash, deleted about an hour after its last use.
- Vercel proxy logs: Vercel's standard retention (~1 month)
- Anthropic API: see anthropic.com/legal for retention policy
- RevenueCat: subscription receipt for the lifetime of your subscription; cleared per RC retention after cancellation, or on request.
5. Children's privacy
StripVision is not directed at children under 13 and does not knowingly collect data from them.
6. Changes
When we update this policy we'll change the "Last updated" date. Material changes are surfaced via an in-app notification.
7. Contact
Privacy questions: destek@takil.app