MCAS AI Scanner Privacy Policy
Last updated: July 20, 2026
Overview
MCAS AI Scanner helps users analyze meals and ingredient labels for food-compatibility guidance. The app is informational and does not provide medical advice.
Photos
Photos selected or captured for analysis are processed into smaller JPEGs before upload. Full-resolution photos are not stored by the app. Processed images are sent to the analysis API, stored for up to 30 days with request metadata, and sent to the AI analysis provider to provide the requested result.
On-Device Data
Scan history and personal safe-food overrides are stored on the device. The backend stores processed scan images for up to 30 days and structured model extraction, final analysis, validation, and minimal correction metadata for up to 180 days. Users can delete on-device history from the app settings.
Account and Subscription Data
Users may scan as a guest for the free trial. If users sign in with Apple, the app stores the Apple account identifier, name, email address when Apple provides it, and an app account token in the device Keychain. The backend verifies Apple identity tokens, stores account records and hashed session tokens, and uses the app account token to associate App Store subscription transactions with the app account.
Signed-in users can permanently delete their account from Settings > Account > Delete Account. Deletion removes the backend user record, active sessions, account-linked scan images and audit records, and account usage records, then clears the account credentials stored by the app. App Store subscriptions are managed separately through Apple.
Guests can permanently delete uploaded scan images, structured analyses, minimal correction events, and usage records associated with their installation from Settings > Account > Delete uploaded guest scan data.
Subscription status is checked on-device with StoreKit and may be verified by the backend using Apple's signed transaction data. Payment details are handled by Apple, not by this app.
Usage Limits
The backend stores salted hashes of guest installation IDs or account IDs with trial and daily scan counts. This enforces the free scan allowance, subscription access, and abuse-prevention limits. This data is used only for app functionality, security, and cost control.
Service Providers
Processed images and request metadata are stored by the backend and sent to an AI analysis provider for the user-requested food identification task. Food compatibility ratings are matched against the app's bundled food index when possible. Versioned audit records are stored so uncertain or incorrect scan results can be investigated and improved.
Accept, replace, and remove feedback contains only the analysis request ID, stable ingredient item ID, action, and replacement food ID when applicable. Symptoms, diary notes, and tolerance history are not sent with correction feedback.
Tracking
The app uses Meta App Events to measure advertising performance. It sends content-free events such as app activation, onboarding completion, subscription-paywall views, trial starts, and subscriptions. It does not send food names, images, symptoms, diary entries, notes, scan results, Apple account data, or app account identifiers to Meta.
On iOS, the app asks for permission through App Tracking Transparency after onboarding. If the user allows tracking, Meta may use a device advertising identifier and link app-event data with data from other companies’ apps or websites for advertising measurement and campaign optimization. If the user declines, the app does not grant access to that identifier; privacy-preserving aggregated attribution may still be used. The user can change tracking permission in iOS Settings at any time.
The app does not sell personal data.
Contact
Questions can be sent to mail@maximilian.business.