Privacy Policy
This Privacy Policy explains how Osana handles personal data in connection with the Osana mobile application, the related website, and communications sent to Osana.
Last updated: May 2026 | Contact: contact@osana.app
Contents
1. Data Controller
For the processing activities described in this Privacy Policy, the data controller is Osana, operated from Lyon, France.
Privacy-related requests may be sent to contact@osana.app.
2. Scope of this Policy
This Privacy Policy applies to:
- Use of the Osana iOS application
- Visits to the Osana website
- Emails and messages sent to Osana
This Privacy Policy does not govern data processing carried out independently by third parties such as Apple, Open Food Facts, or hosting providers acting under their own privacy terms.
3. Categories of Data We Process
3.1 Data stored locally on your device
- Barcode scan history
- Product names, brands, categories, product image URLs and scoring information
- Scan dates and local app state
This information is stored locally on the user's device and is not sent to our servers.
3.2 Camera access
Osana requests access to the device camera solely to scan barcodes. Camera images or video streams are not stored or transmitted to our servers.
3.3 Network request data
When a user scans a barcode, the app sends the barcode to retrieve product information. Network providers may receive technical connection data such as IP address and request headers.
3.4 Contact data
If a user contacts Osana by email, we may process the sender's email address, message content, and any information voluntarily included in the communication.
4. Purposes of Processing and Legal Bases
Provide barcode lookup results
To retrieve and display product information after a scan.
Legal basis: Performance of a service requested by the user
Maintain scan history locally
To enable users to review previously scanned products.
Legal basis: Performance of a service requested by the user
Ensure security and availability
To maintain service resilience and prevent abuse.
Legal basis: Legitimate interest
Handle incoming communications
To answer support, privacy or legal requests.
Legal basis: Legitimate interest
No advertising or tracking: Osana does not use advertising SDKs, third-party behavioural analytics SDKs, or marketing trackers.
5. Recipients and Disclosure
Osana does not sell personal data. Personal data may be disclosed only to the extent necessary to operate the service or comply with legal obligations.
- Hosting provider: For website hosting and technical delivery
- Open Food Facts: When a barcode is queried through the public API
- Apple: For App Store distribution and iOS services
- Authorities: Where required by law or for legal defense
6. International Data Transfers
Osana is based in France. Some service providers may process technical data outside the European Economic Area. Where such transfers occur, they rely on appropriate legal transfer mechanisms recognised under applicable law.
7. Data Retention
- Local app data: Retained on the user's device until removed by the user or when the app is deleted
- Email correspondence: Retained for the time necessary to manage the request and comply with legal obligations
- Website technical logs: Retained according to the hosting provider's practices
8. Your Rights
Subject to applicable law (particularly the GDPR where relevant), you may have the right to request access to, rectification of, erasure of, restriction of, or portability of personal data.
- If your data is stored locally in the app, you can control deletion directly by removing the app
- If you contacted Osana by email, you may exercise your rights by writing to contact@osana.app
9. Security
Osana implements reasonable technical and organisational measures appropriate to the nature of the processing. However, no system can be guaranteed as absolutely secure.
10. Children
Osana is not designed to knowingly collect personal data from children through account registration or direct profile creation. If you believe that personal data relating to a child has been improperly sent to Osana, please contact us promptly.
11. Contact and Complaints
For any privacy, legal or data-protection request, please contact contact@osana.app.
If you are located in the European Union, you may also lodge a complaint with the competent supervisory authority. In France, this authority is the CNIL.
For corporate and publication details, please consult the Legal Notice.