Privacy Policy
This page explains how Decido handles personal data when you use our services.
Last updated: June 14, 2026
1. Data Controller and Scope
The data controller for personal data processed through Decido is Matteo Laureti (sole proprietor operating the Decido service), P.IVA 17723751008, with contact address at Viale Giulio Agricola 115, 00174 Rome, Italy. For data-protection inquiries, contact [email protected].
This Privacy Policy explains how Decido collects, uses, and protects personal data when you use our website, iOS and Android applications, and related services (collectively, the "Service").
It applies to information provided directly by you, generated through your use of the Service, or received from trusted service providers that support Decido operations.
2. Data We Collect
The categories of personal data we may process include:
- Account and contact data — email address, login identifiers, and authentication provider metadata (e.g. Apple Sign-In or Google Sign-In tokens).
- Profile and preference data that you choose to provide in the app, including language and locale preferences.
- Product interaction data — barcode scans, product lookups, saved results, ingredient lists, allergen profiles, food categorization labels, product scores, and any notes or reports you submit.
- Usage and analytics data — we operate a first-party analytics pipeline that records events such as onboarding steps, authentication events, paywall interactions, and subscription state changes. Each event may include an anonymous identifier, session identifier, device platform, app version, build number, and locale. Anonymous identifiers are linked to your user account when you sign in or sign up.
- Technical and diagnostic data — device type, operating system version, IP address (processed transiently for rate-limiting and security; not stored alongside your profile), and diagnostic logs.
- AI processing data — when you use features like product enrichment, ingredient analysis, allergen detection, or scoring, the relevant product data (e.g. product name, barcode, ingredient text, images) is sent to third-party AI providers for processing. Prompts and responses may be logged for operational monitoring and quality improvement.
- Subscription and purchase metadata — subscription status and entitlement data synchronized through our subscription management provider. Payment card details are handled exclusively by Apple or Google and are never stored by Decido.
- Images — product photos you capture or upload are stored securely and may be sent to AI providers for analysis.
3. Why We Use Your Data
We use personal data to:
- Provide and maintain core features — product scanning, ingredient analysis, allergen detection, product scoring, food processing categorization, and object material analysis.
- Secure accounts and prevent abuse through authentication, rate-limiting, and anomaly detection.
- Process and synchronize subscriptions and in-app purchases.
- Operate first-party analytics to understand how the Service is used, measure feature adoption, diagnose issues, and improve product performance.
- Generate AI-powered outputs — product enrichment, scoring, categorization, and allergen/trace detection are performed using artificial intelligence and machine learning. Your product data is processed by third-party AI providers solely for this purpose.
- Communicate essential service updates, security alerts, and (with your consent) promotional communications.
4. AI and Automated Processing
Decido uses artificial intelligence and machine learning models provided by third-party services to analyze product data, detect ingredients and potential allergens, assign product scores, and categorize food items (e.g. processed, ultra-processed, natural, single-ingredient).
When you scan or look up a product, relevant data (such as product name, barcode, ingredient text, and images) may be sent to external AI providers for analysis. The results are returned to the app and stored in our systems.
These automated processes do not constitute profiling of you as an individual under GDPR Article 22 — they analyze products, not people. However, if you believe an automated output has affected you, you may contact us to request human review.
AI outputs are informational estimates and may contain errors. They must not be relied upon as the sole basis for health, dietary, safety, or medical decisions. See our Terms of Service for full disclaimers.
5. Legal Bases for Processing
Depending on the processing activity, we rely on one or more legal bases under applicable privacy law (including GDPR Articles 6 and 9 where relevant):
- Contract — processing necessary to provide the Service you requested, including account management, product analysis features, and subscription handling.
- Consent — for optional processing such as promotional communications, expanded personalization, or any future processing that requires your explicit agreement. You may withdraw consent at any time.
- Legitimate interest — to secure and improve the Service, operate analytics, prevent fraud, and monitor system health, balanced against your rights and freedoms.
- Legal obligation — where retention or disclosure is required by applicable law.
6. Third-Party Service Providers
We do not sell personal data. We share limited data with the following categories of processors that help us operate Decido:
- Cloud infrastructure and database hosting — for storing account data, product data, analytics, and images.
- Authentication services — for managing sign-in, session tokens, and identity verification.
- AI and machine learning providers — for product enrichment, ingredient analysis, allergen detection, scoring, and categorization. Product data (not your personal profile) is sent to these providers.
- Web data extraction services — for retrieving publicly available product information to supplement analysis.
- Subscription management — for synchronizing purchase state and entitlements across platforms.
- App store platforms (Apple App Store, Google Play) — for processing payments, managing subscriptions, and distributing the app.
All providers are contractually required to process data only for authorized purposes, maintain appropriate security measures, and comply with applicable data protection law. We maintain an internal register of sub-processors as required by GDPR.
7. Cookies and Similar Technologies
The Decido website uses a limited number of cookies:
- Authentication session cookies — strictly necessary to maintain your signed-in state. These are set by our authentication provider and expire at the end of your session or after a defined security period.
- Locale preference cookie — stores your language preference to provide the site in your chosen language. This cookie persists for approximately one year.
We do not use advertising cookies, third-party tracking pixels, or cross-site tracking technologies on our website. The iOS and Android apps do not set browser cookies.
8. International Data Transfers
Some of our service providers process data outside your country or outside the European Economic Area (EEA). This may include AI providers and cloud infrastructure located in the United States.
When personal data is transferred outside the EEA, we use legally recognized safeguards such as European Commission standard contractual clauses (SCCs), adequacy decisions, or equivalent mechanisms approved under applicable law to ensure your data remains protected.
9. Data Retention
We keep personal data only for as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements.
Analytics event data is retained for operational and product-improvement purposes and is periodically aggregated or anonymized.
AI processing logs (prompts and responses) are retained for a limited period for quality monitoring and are not used to build profiles about you.
When data is no longer required, we delete or anonymize it. If you request account deletion, we aim to complete the deletion within 30 days, including removal of your data from our primary systems and a request to subscription management providers to disassociate your records. Some data may be retained longer where required by law.
10. Security
We use technical and organizational safeguards designed to protect personal data, including access controls, encrypted transport (TLS), encrypted storage where appropriate, rate-limiting, and operational monitoring.
No system is completely risk-free, but we continuously evaluate and improve our security controls. In the event of a personal data breach that poses a risk to your rights, we will notify the competent supervisory authority within 72 hours and inform affected individuals where required by GDPR.
11. Your Privacy Rights
Under GDPR and applicable privacy law, you have the following rights regarding your personal data:
- Access — request a copy of the personal data we hold about you.
- Rectification — request correction of inaccurate or incomplete data.
- Erasure — request deletion of your data ("right to be forgotten"), subject to legal retention obligations.
- Restriction — request that we limit processing of your data in certain circumstances.
- Objection — object to processing based on legitimate interest, including for direct marketing.
- Portability — receive your data in a structured, commonly used, machine-readable format.
- Withdraw consent — revoke consent at any time for any consent-based processing, without affecting the lawfulness of prior processing.
- Automated decisions — request human review of any automated decision that significantly affects you.
To exercise any of these rights, contact [email protected]. We will respond within 30 days as required by law. You may also delete your account directly from within the app.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local supervisory authority. In Italy, this is the Garante per la protezione dei dati personali (www.garanteprivacy.it).
12. Children
Decido is not intended for children under 16 years of age (or the minimum age required by local law to provide valid consent without parental authorization).
We do not knowingly collect personal data from children below this age. If we learn that data was provided by a child without required parental authorization, we will take steps to delete that data promptly.
13. Changes to This Policy
We may update this Privacy Policy to reflect product, legal, or operational changes.
When updates are material, we will provide clear notice through the app or website and update the "Last Updated" date at the top of this page. We encourage you to review this page periodically.
14. Contact
For privacy questions, data protection inquiries, or to exercise your rights, contact [email protected].