Legal
Privacy Policy
Last updated: September 9, 2026
This policy explains what the PRODX app collects, how it is used, the providers involved, and how to access or delete your information. It is written in plain language; where a term has a specific meaning it is defined where it is used.
1. About this policy
PRODX is a mobile app that helps you understand packaged food products — their nutrition, ingredients, dietary fit and allergens — in relation to information you choose to give about your allergies, dietary needs, health context and goals. This policy explains what the PRODX app collects, how that information is used, and the choices you have.
PRODX is operated by Hajar El Kabir, an individual developer based in Tangier, Morocco (“PRODX”, “we”, “us”). The app is published as “Prodx” (package com.prodx.app) and the website is prodx.ma. PRODX is currently released on Android, version 1.0.0.
This policy covers the PRODX app and the prodx.ma website. It does not cover Open Food Facts or other independent services, which have their own policies.
2. Information we collect
In summary, PRODX processes:
- information you give when you create an account and set up your profile (Sections 3 and 4);
- profiles you create for children in your household (Section 5);
- activity you generate in the app — scans, verdicts, saved products and meal logs (Section 6);
- a small amount of information kept only on your device (Section 7).
PRODX does not collect location, contacts, microphone audio, or your photo library, and does not use advertising identifiers. Scanning uses your device camera to read a barcode; PRODX does not take or store photographs. PRODX contains no analytics, advertising or tracking software, and does not send push notifications.
3. Account information
When you create a PRODX account, we process:
- your email address;
- a password, stored only as a securely hashed value by our authentication provider — it cannot be seen by us in readable form;
- an optional display name;
- an optional avatar image URL field (image upload is not currently used in the app);
- an internal account identifier (a UUID);
- your onboarding status and related timestamps;
- subscription-related fields stored on your account record (see Section 11).
4. Health and personalization information
This section matters, so it is explicit. When you choose to, you can add information to your profile so that verdicts and scores reflect your situation. This is optional — you can use PRODX without providing it, though personalization will be limited. It can include:
- your persona and any secondary personas, fitness goals, dietary preferences and activity level;
- named health conditions you choose to record — for example diabetes, heart disease, high blood pressure, celiac disease, IBS, high cholesterol, PCOS or hypothyroidism;
- allergies and the severity you assign to them, which can include anaphylactic severity;
- parent status;
- sex, age, weight and height;
- training days per week, and your calorie, protein, carbohydrate and fat targets.
Some of this is health-related information, and we recognise it as sensitive. PRODX processes it only to personalize the product analysis, verdicts and scores shown to you, and to support features such as Today’s Plate. This information:
- is processed only because you chose to provide it for personalization;
- is stored in and processed through PRODX’s Supabase backend (Section 10);
- is never sold, and is never used for advertising;
- is not sent to Open Food Facts (Section 9);
- is not sent to any artificial-intelligence or large-language-model service — PRODX’s scoring is deterministic (Section 9);
- is not used to make decisions about employment, insurance, credit or any similar eligibility;
- can be changed or removed by you at any time by editing your profile, or deleted entirely by deleting your account (Sections 14 and 16).
You can withdraw this information at any time by removing it from your profile or deleting your account. If you have questions about how health-related information is handled, contact privacy@prodx.ma.
5. Child profiles
If you are a parent or guardian, PRODX lets you create profiles for children in your household so that verdicts can be tailored to each child.
- Children do not have their own PRODX accounts and cannot sign in. A child profile exists only inside your account and is managed by you.
- A child profile can include a name or label, age, allergies, dietary preferences, sex, weight, height and activity level.
- This information is provided and controlled by you, the account holder, and is used only to personalize verdicts and scores for that child.
- You can edit or delete a child profile at any time in the app. Deleting your account deletes every child profile in it (Section 14).
6. Scan, saved-product and meal activity
As you use PRODX, the following is stored with your account:
- your scan history (products you have looked up);
- the personalized verdicts, scores and verdict reasons PRODX generated for you;
- products you save or favourite;
- your Today’s Plate / meal logs.
A meal log entry can include the product, meal type, date and time, calories, protein, carbohydrates, fat, sugar, salt and fibre, and the child profile it relates to where applicable.
You can clear your scan history in the app (Clear History), and remove saved products and meal entries individually.
7. Device-local information
Some information stays only on your device and is never sent to PRODX’s servers:
- your recent search terms — the app keeps up to the last 8, in local storage on your device, to make searching quicker.
Because this is stored on your device, deleting your account does not remove it. You can clear it by clearing recent searches in the app, or by removing the app.
8. How PRODX uses information
PRODX uses the information above to:
- create and secure your account and sign you in;
- produce the product analysis, personalized verdicts and scores that are the core of the app, using deterministic rules (Section 9);
- power the features you use — saved products, Today’s Plate, per-child verdicts, history;
- operate a shared product cache so lookups are fast (Section 9);
- send you transactional emails needed to run your account, such as email verification and password resets (Section 10);
- maintain the security and integrity of the service and diagnose problems;
- manage a paid subscription, if you take one in the future (Section 11).
PRODX does not use your information for advertising, does not sell it, and does not use it to build profiles about anyone other than you and the child profiles you create.
9. Product information and Open Food Facts
Product facts in PRODX come primarily from Open Food Facts, an open database of packaged foods.
- When you scan or search, PRODX sends Open Food Facts either the product barcode or the text you searched for. That is all. It does not send your identity, email, name, allergies, allergen severity, health conditions, dietary preferences, goals, body metrics, child profiles, verdicts, or any account identifier.
- Product data PRODX retrieves — barcode, name, brand, image, Nutri-Score, NOVA, Eco-Score, ingredients, declared allergens, traces and “may contain” statements, labels, categories, additives, serving information and nutrient information — is stored in a shared product cache. This cache is not linked to any user, has no user identifier, and is shared by everyone using PRODX. It is product reference data, not personal data about you, and it is not deleted when an account is deleted.
- Your verdicts and scores are calculated by PRODX using fixed, deterministic rules (nutrient bands, the official Nutri-Score method, and matching your declared allergens and dietary rules against the ingredient text). No artificial-intelligence or large-language-model service is involved, and PRODX does not send your data to one.
10. Service providers
PRODX relies on a small number of providers:
- Supabase — authentication, database and backend processing (Edge Functions). Supabase stores and processes your account information and the profile, health-related, child-profile, activity and subscription information described above, on PRODX’s behalf.
- Resend — delivery of transactional authentication emails (for example email verification and password reset), configured through Supabase’s email sending. It receives the recipient email address and the contents of those messages. These messages are sent from
no-reply@auth.prodx.ma, which does not receive replies. - RevenueCat and Google Play Billing — if paid subscriptions are enabled in the future, these would process your purchase and manage your subscription status. Subscriptions are not currently live (Section 11).
- Crash reporting — the app contains an integration with Sentry for crash diagnostics. It is not currently enabled and no crash data is being sent to it. If crash reporting is enabled in future, this policy will be updated first; it would receive technical crash information, not your profile or health data.
PRODX has no analytics, advertising, social-login or tracking providers.
11. Subscriptions, if enabled
PRODX is currently free to use. Your account record contains subscription-related fields, and the app includes the groundwork for paid plans, but paid subscriptions are not live and no purchases are being processed.
If subscriptions are enabled later, purchases would be handled by Google Play Billing and subscription status managed through RevenueCat. Google Play would process your payment; PRODX would receive your subscription status, not your card details. This policy and the Terms of Use will be updated before that happens.
12. Data security
- Passwords are handled and stored only as salted hashes by our authentication provider and cannot be seen by us.
- Information is transmitted over encrypted connections (HTTPS/TLS).
- Access to your account data is restricted at the database level so that your records are reachable only by your authenticated account; derived tables such as verdicts and scores are written only by PRODX’s server.
- No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
13. Data retention
- PRODX does not run any scheduled deletion, expiry or clean-up of account data. There is no automatic “we delete after a set number of days” rule.
- Information tied to your account is kept until you remove it — by deleting your account (Section 14), by using an in-app control such as Clear History, or by removing individual saved products or meal entries.
- The shared product cache is kept and refreshed for performance (product entries are re-checked for freshness about hourly). This is a caching mechanism for public product data, not retention of personal data about you.
- After account deletion, see Section 14 for what happens to backups.
14. Account deletion
- You can delete your PRODX account and its data from inside the app: Settings → Delete Account.
- This runs immediately. There is no soft delete, no grace period and no undo. It deletes the authentication account and email/identity, your profile and display name, your preferences and health-related information, allergies and body metrics, your child profiles, your scan history, verdicts, scores and verdict reasons, your saved products, your Today’s Plate / meal logs, and the subscription-related fields on your account.
- Your account and associated personal data are removed from PRODX’s active systems when deletion is completed. Routine infrastructure backups may retain copies temporarily until they expire through the provider’s normal backup cycle.
- The shared Open Food Facts product cache is not affected, because it contains public product data and is not linked to you (Section 9).
- Recent search terms stored on your device are not removed by account deletion, because they never reach PRODX’s servers (Section 7).
If you cannot sign in, you can still request deletion — see prodx.ma/delete-account.
15. Children's information and parent-managed profiles
- PRODX is not directed to children, and children cannot create accounts or sign in.
- The only information about a child that PRODX holds is what a parent or guardian enters into a child profile within their own account (Section 5), to tailor verdicts to that child.
- A parent controls that information and can edit or delete it, or delete the whole account, at any time.
- If you believe a child has provided information to PRODX directly, contact privacy@prodx.ma and we will help.
16. Your privacy rights
- Depending on where you live, you may have rights to access, correct, export or delete your personal information, to object to or restrict certain processing, and to withdraw consent.
- Much of this is available directly in the app: you can view and edit your profile, allergies, goals and child profiles, clear your history, and delete your account and its data at any time.
- For anything you cannot do in the app, or to make a formal request, contact privacy@prodx.ma. We may need to verify your identity before acting, particularly for deletion requests made outside the app.
- Health-related information is processed only because you chose to provide it for personalization; you can withdraw it at any time by removing it from your profile or deleting your account.
- We do not sell personal information and we do not use it for targeted advertising.
17. International processing
- PRODX is operated from Morocco and uses the service providers listed in Section 10, which may store and process information on infrastructure located outside your country.
- Where your information is transferred across borders, we rely on those providers’ safeguards for such transfers.
18. Changes to this policy
We may update this policy as the app changes. Material changes will be reflected here with a new “Last updated” date and, where appropriate, highlighted in the app.
19. Contact
- Privacy questions and requests: privacy@prodx.ma
- General support: support@prodx.ma
- Operator: Hajar El Kabir, individual developer, based in Tangier, Morocco.