Legal

Privacy Notice

Version 2.0 · updated 7 September 2026

This notice is written to the Digital Personal Data Protection Act 2023. It tells you, item by item, what personal data Falose processes, why, on what basis, for how long, who else sees it, and how you exercise your rights. The short version: we process only what a feature needs, we ask separately before touching anything about your health, we never sell data or run advertising, and no company ever sees you as an individual.

1. Who is responsible

The data fiduciary is Falose, operated by Mihir Panchal (sole proprietor) until a company is incorporated; the entity name will be updated here when that happens. Questions about personal data: privacy@falose.com. Grievance Officer: Mihir Panchal, grievance@falose.com. We acknowledge every complaint within 24 hours and resolve it within 15 days, as the Information Technology (Intermediary Guidelines) Rules 2021 require. If you are not satisfied, you may approach the Data Protection Board of India for personal-data matters or a consumer forum for others.

2. What we collect, and why, item by item

Account: name, email address, a bcrypt hash of your password (we cannot read the password), the time and version of each consent you gave, a hash of the IP address at that moment (never the address itself) and your browser's user-agent string. Purpose: to run your account and to prove consent. Basis: consent, and our legal duty to keep records.

Household profiles (optional): a name or nickname, life stage (such as adult, pregnant, child, older), birth year, sex, diet, and, only with a separate consent, health conditions and allergens. Purpose: to show which label facts matter for that person and to compare a day's logged food with public reference intakes. Basis: your specific consent, given the first time you add a condition or allergen, withdrawable in one tap. Health facts are never joined to anything a company can see, are never used for advertising, and never leave our systems except as described in section 5.

Consumption log and kitchen list (optional): products you say you had or have at home, with dates and grams. Purpose: the day and week summaries and better-alternative suggestions. Basis: consent by using the feature.

Activity: products viewed or scanned, searches, taps on interface elements, taste votes, with timestamps. Purpose: running the Service and improving the catalogue (for example, which searches return nothing). Anonymous visitors are logged under a random device key stored in the browser; no name, no IP. Basis: legitimate operation of the Service you asked to use.

Coarse location (optional): latitude and longitude rounded to two decimals (about 1 km), only when you agree on the scan screen, only while you use it. Purpose: to show where a product is sold near you and which regional brands exist. Never an IP address, never a precise position, never stored against a health profile. Basis: consent, withdrawable on the same screen.

Pack photographs you upload: the images, when they were taken, and the numbers read from them. Purpose: to read the label and, under the Terms, to describe the product publicly. Do not photograph people.

Assistant: your messages, the replies, and the "memories" the assistant keeps. Every memory is listed in the Memory drawer and can be deleted one by one; there is no memory outside that list. Purpose: to answer you and remember what you told it. Basis: consent by using the assistant.

Weekly note (optional): your email address is used once a week only if you switch the note on. The switch is the consent; every mail carries a one-click link that switches it off.

Sharing with a dietitian or doctor (optional): when you create a share link, the person holding it can read the household profile and the food log it covers until the link expires or you revoke it. You choose to create it; you can revoke it at any time from your profile.

Brand and distributor accounts: company name, business email, GSTIN, FSSAI licence numbers, a contact name, phone and website, and everything the company submits. Purpose: to run the portal and verify the company. Basis: contract.

Server logs: standard web-server logs (IP address, path, time) are kept for security for up to 30 days and are not joined to your account.

3. What we do not do

We do not sell personal data. We do not run third-party advertising or tracking. We do not use cookies other than the one that keeps you signed in. We do not profile you for anyone else. We do not share your profile, log, conversations or identity with any brand, distributor or retailer. Companies see only aggregate counts computed over at least twenty people, and never anything derived from a health profile. We do not train models on your personal data.

4. Cookies and browser storage

One essential cookie, named "session", keeps you signed in and expires when you sign out or after a period of inactivity. The browser also stores small settings locally under names beginning with "falose": your theme, the last market you chose, an anonymous device key for taste votes and the kitchen list, and whether you answered the location question. None of this is sent to anyone but us, and clearing your browser storage removes it.

5. Who else processes data, and where it lives

Our database runs on servers we rent from Hostinger International Ltd. in India. To generate replies and read labels we send the text of your message, the relevant profile fields you chose to fill, retrieved product data, and the label photographs to Google's Vertex AI (Gemini) under Google Cloud's data-processing terms; Google does not use this data to train its models. Emails are sent through our SMTP provider. No other processor sees personal data.

We do not transfer personal data outside India except to the extent Google Cloud processes requests in the region configured for our account; the DPDP Act permits transfer except to countries the Government restricts, and we comply with any such restriction.

6. Your rights, and how to use them

Access and a copy: your profile page shows your data; write to us for a machine-readable export, delivered within 30 days.

Correction: edit your profile, household, kitchen and log yourself at any time.

Erasure: delete your account yourself from your profile (password required). Deletion is immediate and removes your account, profiles, logs, kitchen list, scan history, events, reviews, taste votes, conversations, memories, share links and consent records. Aggregate statistics that identify nobody may remain. Pack photographs you contributed may remain as evidence for numbers already published, with your account reference removed.

Withdraw consent: switch off health processing, the weekly note or location in your profile or on the screen where you gave it; withdrawal is as easy as consent and takes effect at once. Withdrawing the required consents (age, terms, this notice) means deleting the account.

Nominate: you may nominate a person to exercise these rights for you if you are unable to, by writing to us.

Complain: to the Grievance Officer first, then to the Data Protection Board of India.

7. Children

The Service is for people aged 18 and over. We do not knowingly process a child's personal data as a data principal. A parent or lawful guardian may describe their child in a household profile on their own account; that is the parent's consent, given as the Act requires, and the same deletion and withdrawal rights apply. We do not track children, target advertising at them, or use their data for anything but the parent's own view.

8. Retention

Account and profile data: while the account exists, then deleted with it. Activity events: 24 months, then aggregated and the raw rows deleted. Assistant conversations: until you clear them or delete the account. Consent records: while the account exists. Server logs: 30 days. Brand data: for the life of the account plus the period tax law requires for invoices.

9. Security and breaches

Passwords are hashed with bcrypt. Sessions use a random identifier in a secure cookie. Access to production data is limited to the operator. If a breach affecting your personal data occurs, we will inform the Data Protection Board and you, as the Act requires, without unreasonable delay, saying what happened and what we did.

10. Changes

When this notice changes materially we raise its version number, change the date, and ask you to read and accept it again at your next sign-in. Your acceptance is recorded with the version.

All legal documentsTerms of UseBrand and Distributor TermsContent and Corrections PolicyAI and Data Sources Notice← Back to Falose