Privacy Policy
Last updated: 30 July 2026. Gluten Zero is committed to Australian Privacy Principles (APPs) under the Privacy Act 1988.
Data we collect
- Profile data — Name, coeliac severity, dietary preferences (onboarding).
- Scan history — Product barcodes, ingredients analysed, risk results.
- Symptom journal — Self-reported symptoms and suspected foods.
- Analytics — Anonymised usage events (scans, feature usage).
- Community contributions — User-submitted restaurant/product reports (moderated).
Data we do not collect by default
- OCR camera images — processed on-device via Tesseract.js.
- Precise geolocation — unless you explicitly share it for restaurant discovery.
Storage & security
Data is stored locally on your device and optionally synced to Supabase (encrypted in transit via TLS). Admin access is JWT-protected. We do not sell personal health data.
Cross-border processing
AI providers may process data outside Australia. We minimise data sent and select providers with strong security commitments.
Your rights
You may request access, correction, or deletion of your data by contacting privacy@glutenzero.com.au.
Security statement
We implement TLS encryption, environment-isolated API keys, row-level security on Supabase, and admin session verification. Report security issues to security@glutenzero.com.au.