Privacy Policy

This Privacy Policy explains how Osana handles personal data in connection with the Osana mobile application, the related website, and communications sent to Osana.

Last updated: May 2026 | Contact: contact@osana.app

1. Data Controller

For the processing activities described in this Privacy Policy, the data controller is Osana, operated from Lyon, France.

Privacy-related requests may be sent to contact@osana.app.

2. Scope of this Policy

This Privacy Policy applies to:

  • Use of the Osana iOS application
  • Visits to the Osana website
  • Emails and messages sent to Osana

This Privacy Policy does not govern data processing carried out independently by third parties such as Apple, Open Food Facts, or hosting providers acting under their own privacy terms.

3. Categories of Data We Process

3.1 Data stored locally on your device

  • Barcode scan history
  • Product names, brands, categories, product image URLs and scoring information
  • Scan dates and local app state

This information is stored locally on the user's device and is not sent to our servers.

3.2 Camera access

Osana requests access to the device camera solely to scan barcodes. Camera images or video streams are not stored or transmitted to our servers.

3.3 Network request data

When a user scans a barcode, the app sends the barcode to retrieve product information. Network providers may receive technical connection data such as IP address and request headers.

3.4 Contact data

If a user contacts Osana by email, we may process the sender's email address, message content, and any information voluntarily included in the communication.

4. Purposes of Processing and Legal Bases

Provide barcode lookup results

To retrieve and display product information after a scan.

Legal basis: Performance of a service requested by the user

Maintain scan history locally

To enable users to review previously scanned products.

Legal basis: Performance of a service requested by the user

Ensure security and availability

To maintain service resilience and prevent abuse.

Legal basis: Legitimate interest

Handle incoming communications

To answer support, privacy or legal requests.

Legal basis: Legitimate interest

No advertising or tracking: Osana does not use advertising SDKs, third-party behavioural analytics SDKs, or marketing trackers.

5. Recipients and Disclosure

Osana does not sell personal data. Personal data may be disclosed only to the extent necessary to operate the service or comply with legal obligations.

  • Hosting provider: For website hosting and technical delivery
  • Open Food Facts: When a barcode is queried through the public API
  • Apple: For App Store distribution and iOS services
  • Authorities: Where required by law or for legal defense

6. International Data Transfers

Osana is based in France. Some service providers may process technical data outside the European Economic Area. Where such transfers occur, they rely on appropriate legal transfer mechanisms recognised under applicable law.

7. Data Retention

  • Local app data: Retained on the user's device until removed by the user or when the app is deleted
  • Email correspondence: Retained for the time necessary to manage the request and comply with legal obligations
  • Website technical logs: Retained according to the hosting provider's practices

8. Your Rights

Subject to applicable law (particularly the GDPR where relevant), you may have the right to request access to, rectification of, erasure of, restriction of, or portability of personal data.

  • If your data is stored locally in the app, you can control deletion directly by removing the app
  • If you contacted Osana by email, you may exercise your rights by writing to contact@osana.app

9. Security

Osana implements reasonable technical and organisational measures appropriate to the nature of the processing. However, no system can be guaranteed as absolutely secure.

10. Children

Osana is not designed to knowingly collect personal data from children through account registration or direct profile creation. If you believe that personal data relating to a child has been improperly sent to Osana, please contact us promptly.

11. Contact and Complaints

For any privacy, legal or data-protection request, please contact contact@osana.app.

If you are located in the European Union, you may also lodge a complaint with the competent supervisory authority. In France, this authority is the CNIL.

For corporate and publication details, please consult the Legal Notice.