Foocat Privacy Policy
Last updated: 2026-08-10
Foocat is an app that helps you scan barcodes on cat food and calculate the carbohydrate content. This privacy policy describes what data the app handles, how it is used, and the choices you have. By using Foocat you accept the processing described below.
In short: Foocat requires no account, collects no personal data such as your name or email, and contains no advertising or ad-tracking. It does send technical diagnostics — crashes and performance data — tied only to your anonymous device ID and never to you as a person. See “Diagnostics and crash reporting” below.
What data we handle
Foocat has no login account. When the app starts for the first time, a random device ID (a UUID) is created. This ID contains no personal information and cannot be linked to you as a person — it is used solely to tie your submitted products, favorites, and ratings to your device.
The following data may be sent to our servers when you use the app’s features:
- Barcodes (EAN) you scan or type in, to look up a product.
- Recognized text from the packaging — when you analyze the nutrition content on a package, the text is read directly on your device, and it is primarily only that recognized text (not the photo) that is sent to our servers. See the packaging-analysis section below.
- Product and nutrition details you choose to submit (name, brand, protein, fat, fibre, moisture, ash, and similar values from the packaging).
- Product photos you choose to upload. These are stored on our servers and may be shown to other users of the app alongside the product.
- Favorites — the barcodes of the products you mark as favorites.
- Ratings you give a product (a number from 1–10).
- Your random device ID and timestamps for the above.
All traffic to our servers is encrypted via HTTPS.
Data stored only on your device
The following is stored locally on your device and is not automatically sent to us:
- Your scan history (previously scanned products with nutrition values).
- Your favorites list (synced to the server only when you add or remove a favorite).
- Photos you have taken, in the app’s private storage.
You can delete this data directly in the app at any time.
How packaging analysis works
When you photograph the analytical constituents on a package, the text is normally read directly on your device (using Google ML Kit on Android and Apple’s text recognition on iOS). Only the recognized text — a few kilobytes — is then sent to our server, which uses Google’s Gemini service to interpret the nutrition values. The text is processed transiently and is not stored.
Only if on-device recognition fails is the photo itself sent to our server for analysis. Such photos are processed transiently and discarded immediately after analysis — they are not stored. (This applies to packaging analysis; product photos you choose to upload are stored as described in the list above.)
The app also offers an optional on-device analysis (using Gemini Nano on Android and Apple Intelligence on iOS) that can step in when the network is unreachable. It sends nothing at all, and can be turned off in the app’s settings.
Permissions
- Camera — to scan barcodes and photograph packaging. Barcode scanning happens locally on your device.
- Internet and network state — to communicate with our servers.
Foocat does not request access to your location, contacts, microphone, or any hardware identifier.
Diagnostics and crash reporting
To find crashes and fix features that are broken or slow, the app sends technical diagnostics about its own behavior. This data describes the app and the device — never the contents of your packaging photos, your recognized values, or your scan history.
New Relic (Android and iOS) receives:
- Crash reports — where in the code the app crashed, and the error message.
- App activity — app launches, how long a session lasts, and which screens and features were used.
- Requests to our servers — the address called, the status code, the response time, and the response size. Not the contents.
- Log lines the app writes about its own state, such as
App started. - Device and app details — device model and manufacturer, OS version, app version, and mobile carrier name.
- Your random device ID, so a crash can be tied to the rest of the diagnostics from the same install.
Like any web service, New Relic also sees the IP address your device connects from. The address is translated into an approximate location — country and region — and then discarded; the address itself is not stored. The location is therefore derived from the connection: the app never requests access to, and never reads, your device’s position. No advertising identifier is collected.
Firebase Performance Monitoring (Android only) receives timing measurements for the optional on-device analysis: how long text recognition and the on-device model took, how many characters were recognized, and whether the analysis succeeded or fell back to the server. No text and no images are sent there.
Our server also forwards its own logs to New Relic. Those logs may contain your random device ID together with the barcodes and addresses requested.
Third-party services
- Google Gemini (AI): Used on our server to interpret recognized text from the packaging (or, as a fallback, a photo of the packaging) as described above. The input is processed transiently and is not stored.
- Google ML Kit / Apple text recognition: Barcode and text recognition happen locally on your device. No image data is sent to Google or Apple for this.
- Cloudflare: Used for encryption (TLS) and caching of product images in transit between the app and our servers.
- New Relic: Receives crash reports, diagnostics from the app, and forwarded log lines from both the app and our server, as described above. Processed in New Relic’s EU region.
- Firebase Performance Monitoring (Google), Android only: Receives timing measurements for the on-device analysis, as described above.
We use no advertising, ad-tracking, or cross-app tracking tools, we sell no data, and we send no push notifications. The diagnostics above are used solely to run and improve Foocat.
Where your data is stored
Your data is stored on servers within the EU. Products you choose to submit may become visible to other users of the app. Diagnostics sent to New Relic are processed in its EU region. Timing measurements sent to Firebase Performance Monitoring are processed by Google on Google’s own infrastructure.
Sharing of data
We do not sell or rent your data. Beyond the services described above — Gemini for interpreting the nutrition content, and New Relic and Firebase for diagnostics — we do not share it with any third party, other than where required by law.
Retention and your rights
Data on your device remains until you delete it in the app or uninstall the app. Data on the server (submitted products, favorites, and ratings) is tied to your anonymous device ID and is kept for as long as it is needed for the service. Diagnostics are kept for as long as New Relic’s and Firebase’s respective retention periods for our plan allow, and are then deleted automatically.
Since there is no account, you are identified only by your anonymous device ID.
Children
Foocat is not directed at children and does not knowingly collect data about children.
Changes to this policy
We may update this privacy policy. The latest version is always available on this page, with the date of the most recent change at the top.
Contact
If you have questions about this privacy policy, contact:
Email: foocatcontact@gmail.com