Privacy Policy
Effective August 18, 2026
OriginScout is a food product-intelligence product and application operated by DVL Labs LLC ("DVL Labs," "we," "us," or "our"). OriginScout and getoriginscout.com identify the product and its services; DVL Labs LLC is the legal entity responsible for this policy. This policy explains the information handled when you use the OriginScout Android application and related services.
1. Information we handle
Authentication and account information
OriginScout uses Google Sign-In and Firebase Authentication. Google and Firebase may process your email address, name, profile information, IP address, device or browser information, and authentication events under their own terms and privacy policies. OriginScout uses the resulting identity token to authenticate access.
Our application database stores a Firebase identity issuer and subject identifier, an internal OriginScout user identifier, account status, and account lifecycle timestamps. It does not store your Google password. The current OriginScout backend does not copy your Google display name, profile photo, or email address into its application account tables.
App and device integrity information
We use Firebase App Check with Google Play Integrity to confirm that requests come from the genuine OriginScout app on an eligible installation. Google may process app metadata, licensing status, device integrity information, and attestation data. OriginScout receives and validates security tokens and uses the result to prevent fraud, abuse, tampering, and unauthorized access.
Barcode and product information
When you scan or enter a barcode, the barcode is sent to OriginScout to retrieve and analyze product information. OriginScout may request corresponding public product facts from Open Food Facts and may store product source snapshots and analyses so lookups are reliable and reproducible. Product records are not currently linked to your OriginScout account as a personal lookup history.
Camera access
Camera permission is used to detect a product barcode. Camera frames are processed on your device by the barcode-scanning component. OriginScout does not upload or store those camera images. You can enter a barcode manually instead.
Technical and operational information
Our service providers and infrastructure may process request timestamps, IP address, device or user-agent information, response status, trace identifiers, app version, security events, and the requested API path. We use this information to operate, secure, diagnose, and improve service reliability. OriginScout is designed not to log raw authentication credentials or unbounded upstream payloads.
2. How we use information
- Authenticate users and maintain account access.
- Provide barcode lookup and product-intelligence results.
- Detect tampering, abuse, unauthorized access, and service failures.
- Operate, troubleshoot, monitor, and improve OriginScout.
- Comply with legal obligations and enforce applicable terms.
3. When information is shared
We do not sell personal information. We share or allow processing only as needed:
- Google and Firebase provide Google Sign-In, Firebase Authentication, Firebase App Check, Play Integrity, hosting infrastructure, and operational security.
- Open Food Facts may receive the barcode needed to obtain public product information.
- Authorities or transaction participants may receive information when required by law, to protect rights and safety, or as part of a corporate transaction subject to appropriate safeguards.
These providers may process information in the United States and other countries where they operate, subject to their contractual and legal safeguards.
4. Retention and deletion
We retain active account identifiers and lifecycle records while your account is in use and as needed to provide and secure OriginScout. Operational logs are retained for a limited period based on security, reliability, and provider configuration needs. Product facts and analyses may be retained independently of any user account because they describe products rather than an individual.
After a verified deletion request, we disable account access and delete or irreversibly de-identify account information that is not required for security, fraud-prevention, legal, or audit purposes. We may retain a minimal internal account identifier, provider link, and deletion timestamps to document the request and prevent unintended reprovisioning. Retained deletion records are not used for ordinary product features.
Visit our account deletion page for instructions. Deleting your OriginScout account does not delete your separate Google account; Google account requests must be made directly to Google.
5. Security
We use measures intended to protect information, including encrypted transport, authentication, application attestation, access controls, credential redaction, and restricted operational access. No system can guarantee absolute security.
6. Children
OriginScout is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information, contact us so we can investigate and take appropriate action.
7. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of personal information, or to object to or restrict certain processing. Contact us to make a request. We may need to verify your identity before responding.
8. Changes to this policy
We may update this policy as OriginScout changes. We will post the revised policy here and update the effective date. Material changes may also be communicated through the app or another appropriate channel.
9. Contact us
DVL Labs LLC
Email: privacy@getoriginscout.com
For deletion requests, use the subject line "OriginScout Account Deletion Request" or follow the steps on the account deletion page.