Skip to content
UNVEIL
Privacy Terms
Back to Unveil

Legal

Privacy Policy

Last updated: September 2026

In short: Unveil has no accounts, so we never ask for your name or email address. The app creates a random ID on your device and uses it to run the scanning service, understand how the app is used, and measure our advertising. Photos you take are analysed and then discarded, and we never sell your data.

Contents

  1. Who we are
  2. What we collect
  3. Why we use this data
  4. Legal bases under GDPR
  5. Who we share data with
  6. How long we keep data
  7. International transfers
  8. Your rights
  9. Children
  10. Security
  11. Changes to this policy
  12. Contact

1. Who we are

Unveil is operated by Wintermute Agency, a company registered in Denmark (CVR-registered).

Address: Niels Andersens Vej 57, 2900 Hellerup, Denmark
Email: support@wintermute.agency

Wintermute Agency is the “data controller” for the personal data described in this policy. That means we decide how and why this data is used, and we are the ones responsible for it.

2. What we collect

A random device identifier. When you first open Unveil, the app generates a random identifier (a UUID) and stores it on your device. This ID is not derived from your name, email, phone number, or any Apple account. It is how we recognise your install without knowing who you are. It is sent with requests to our server and is used as your subscription identifier with RevenueCat.

Scan and usage data. When you scan a barcode, our server logs the barcode, the product lookup result, the analysis result, and the outcome of the scan, linked to your device identifier. We also log app events such as screens viewed, scan outcomes, and subscription funnel steps (for example, that a trial was started), along with your platform.

Photos, briefly. If you photograph a product or its ingredient label, the photo is sent through our server to Anthropic (the AI provider) to read the text or identify the product. Photos are processed transiently and are not stored on Unveil's servers. Camera snapshots used to display the product on your result screen stay on your device.

Purchase state. If you subscribe, we receive subscription lifecycle events (for example trial started, renewed, cancelled) including the price and country, linked to your device identifier. We never see your card number or payment details. Apple handles payment.

Crash reports. If the app crashes or hits an error, a technical error report is sent to Sentry. We have configured Sentry not to collect personal information.

What we do not collect: your name, your email address (unless you choose to email us), any account or login, your precise location, your contacts, or your payment card details. Unveil has no user accounts at all.

3. Why we use this data

  • To provide the service. Looking up products, generating analyses, remembering your free scans, and managing your subscription.
  • To improve the app. Understanding which scans succeed or fail, which screens people use, and where the app breaks, so we can fix and improve it.
  • To make results faster for everyone. Analysed products are cached anonymously (barcode to result, with no device identifier) so the next person who scans the same product gets an instant answer.
  • To measure advertising. We run ads (currently on Meta platforms) and need to know whether they lead to installs and subscriptions.
  • To fix crashes. Error reports tell us when and why the app fails.

4. Legal bases under GDPR

If you are in the EU, UK, or a similar jurisdiction, each use of your data needs a legal basis. Ours are:

PurposeLegal basis
Providing the scanning service and analysisPerformance of a contract (the service you asked for)
Managing subscriptions and free-scan limitsPerformance of a contract
First-party analytics and app improvementLegitimate interest (understanding and improving our own app)
Crash reportingLegitimate interest (keeping the app working)
Anonymous product result cachingLegitimate interest (faster results for all users)
Advertising measurement with MetaConsent, where required. On iOS we ask through Apple's App Tracking Transparency prompt before your device's advertising data is used for cross-app ad measurement. If you decline, events sent to Meta do not include the cross-app advertising identifier.

Where we rely on legitimate interest, you have the right to object (see section 8). Where we rely on consent, you can withdraw it at any time (Settings › Privacy & Security › Tracking).

5. Who we share data with

We never sell your data. We share data with the service providers below, each for a specific job:

ServiceWhat it does for UnveilWhat it receives
Anthropic (Claude AI, USA) Reads ingredient labels from photos, identifies products, and generates the analysis Product photos (transiently, not stored by us), barcodes, product names and ingredient text. No device identifier is sent to Anthropic.
Cloudflare (global network, including the EU) Runs our server, product cache, and analytics database Barcodes, scan results, app events, and your device identifier
Meta (Facebook) (USA) Ad measurement and attribution App events such as install, trial start, purchase, and funnel steps, with device identifiers and a shared event ID, sent both from the app (Meta SDK) and from our server (Conversions API) so Meta can de-duplicate them. Subject to your ATT choice.
RevenueCat (USA) Manages subscription state across devices Your device identifier and subscription events (trial, purchase, renewal, cancellation, price, country)
Apple App Store Processes payment and distributes the app Your payment, handled entirely under Apple's own terms. We never see card details.
Sentry (EU-hosted) Crash and error reporting Technical error reports only. Configured to not send personal information.
Product databases — publicly available product databases and search services Look up product names and ingredients Only the barcode or product name. No device identifier, ever.

6. How long we keep data

  • Anonymous product cache: 30 days per product result.
  • Scan logs and analytics events: up to 24 months, then deleted or anonymised.
  • Crash reports: retained by Sentry for around 90 days.
  • Subscription records: as long as needed for the subscription and for accounting and tax obligations under Danish law.
  • On your device: the device identifier, scan history, and snapshots stay on your device until you delete the app.

7. International transfers

Unveil is operated from Denmark and our crash reporting is EU-hosted. Some providers (for example Anthropic, Meta and RevenueCat) are based in the United States, and Cloudflare operates a global network. Where your data leaves the EU, the transfer is protected by European Commission Standard Contractual Clauses or by the provider's certification under the EU-US Data Privacy Framework. You can ask us for details about a specific provider at any time.

8. Your rights

If you are in the EU, UK, or Switzerland, you have the right to:

  • Access: ask for a copy of the data we hold that relates to your device.
  • Rectification: ask us to correct inaccurate data.
  • Erasure: ask us to delete your data.
  • Restriction: ask us to limit how we process your data.
  • Portability: receive your data in a portable format, where applicable.
  • Objection: object to processing based on legitimate interest, and to any automated processing that significantly affects you.
  • Withdraw consent: at any time, without affecting past processing.
  • Complain: lodge a complaint with your data protection authority. In Denmark this is Datatilsynet (www.datatilsynet.dk). You can also complain to the authority in your own EU country.

How to exercise these rights: email support@wintermute.agency. Because Unveil has no accounts, your data is linked only to the random device identifier, not to your name or email. To find and delete your data we will work with you to identify your device identifier. Deleting the app removes the identifier and all Unveil data from your device, and permanently breaks any link between you and the server-side scan logs.

We respond to requests within one month.

9. Children

Unveil is not directed at children under 16, and we do not knowingly collect data from children under 16. If you believe a child under 16 has used Unveil and you want the related data deleted, contact us.

10. Security

Data travels encrypted (HTTPS) between the app, our server, and our providers. Access to our databases is restricted. No system is 100% secure, but the small amount of personal data we hold, with no names or emails, limits what could ever be exposed.

11. Changes to this policy

When we change this policy we will update the date at the top. If a change is significant, we will let you know in the app.

12. Contact

Questions, requests, or complaints:

Wintermute Agency
Niels Andersens Vej 57, 2900 Hellerup, Denmark
support@wintermute.agency

Unveil is an educational tool for reading labels, not medical or dietary advice. If you're managing a health condition, talk to a qualified professional before changing what you eat.

© 2026 Unveil · Terms of use