🔬 WellScan

Scan ingredients. Get the truth.

← Back

Privacy Policy

Last updated: March 2026

WellScan is designed with privacy in mind. We do not require accounts, and we collect the minimum amount of data needed to provide and improve the service.

What data we collect

  • Photos of product labels — processed to extract ingredient text, then discarded. Images are not stored permanently.
  • Ingredient text input — the text you type or that we extract from photos is used for analysis.
  • IP address (hashed) — your IP address is SHA-256 hashed before storage. The hash is used solely for rate limiting. We cannot reverse this to identify you.
  • Basic usage analytics — scan count, product types analyzed, and response times. These are anonymous and help us improve the service.

What we do NOT collect

  • Personal information, names, or email addresses — there is no account system
  • Location data
  • Device identifiers or fingerprints

How your data is used

  • Ingredient text is hashed and cached to speed up future scans of the same product. If someone else scans the same ingredients, they get a faster result.
  • Cached analyses are stored for up to 90 days.
  • IP addresses are SHA-256 hashed before storage — we cannot reverse this to identify you. Hashes are used only for rate limiting and anonymous analytics.
  • Anonymous usage analytics help us understand how the service is used and where to improve it.

Third-party services

WellScan relies on the following third-party services to operate:

  • Anthropic (Claude AI) — processes ingredient text to generate safety analyses. Ingredient text is sent to Anthropic's API for analysis.
  • PubChem & NIH databases — publicly available research databases queried for ingredient safety data and citations.
  • Sentry — error monitoring to help us fix bugs. No personally identifiable information (PII) is collected by Sentry.

Data retention

Cached ingredient analyses are retained for 90 days, after which they are automatically deleted. Hashed IP addresses are retained alongside scan events for analytics purposes.

Your rights

Because WellScan has no account system, we do not hold personal data tied to your identity. Cached analyses are keyed by ingredient content hash, not by any user identifier. There is nothing to delete because nothing is linked to you personally.

California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with specific rights regarding your personal information. This section describes those rights and how to exercise them.

Categories of personal information collected

In the preceding twelve months, we have collected the following categories of personal information:

  • Internet or network activity — hashed IP addresses (used solely for rate limiting), scan counts, product types analyzed, and response times.
  • Information you provide — ingredient text and photos of product labels submitted for analysis.

We do not collect names, email addresses, postal addresses, phone numbers, Social Security numbers, or other direct personal identifiers. WellScan does not require account creation.

Your rights under the CCPA

  • Right to know — you have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collecting it, and the categories of third parties with whom we share it.
  • Right to delete — you have the right to request that we delete the personal information we have collected from you, subject to certain exceptions.
  • Right to opt-out of sale — you have the right to opt out of the sale of your personal information. However, we do not sell your personal information. We have not sold personal information in the preceding twelve months.
  • Right to non-discrimination — we will not discriminate against you for exercising any of your CCPA rights. We will not deny you goods or services, charge you different prices, provide a different level of quality, or suggest that you may receive a different price or quality for exercising your rights.

How to exercise your rights

To exercise any of the rights described above, please submit a verifiable consumer request to us at privacy@wellscan.app. We will respond to verifiable consumer requests within 45 days of receipt. If we require additional time, we will inform you of the reason and the extension period (up to an additional 45 days).

Contact

If you have questions about this privacy policy, please contact us at privacy@wellscan.app.