Privacy Policy

Last updated: September 13, 2026

Plain-language summary

Skan helps you understand information on packaged-food labels. To provide analysis based on a health profile, we may need information about a health condition, allergy, intolerance, dietary requirement, or preference. Some of that information may be sensitive, so we treat it carefully.

In simple terms:

  • We use health-profile information only to provide and improve the food analysis you request.
  • We do not sell personal information that identifies you.
  • We aim to delete product-label photos shortly after analysis, unless you choose to save them, report an issue, or we need them temporarily for security, debugging, or legal reasons.
  • Some alternative-product suggestions may be sponsored or commercially supported in the future. If that happens, we will tell you.
  • We do not give brands your identity, contact details, or health profile so they can target you personally.
  • You can ask to access, correct, delete, or withdraw consent for health-profile data.

This summary is provided to make the policy easier to understand. The full Privacy Policy below is the version that governs how we handle your data.

1. Who we are

Skan Africa is currently an early-stage beta product and is not yet operated through a registered limited liability company.

Until a company or business entity is formally registered, the Service is operated by Jesse Nyemitei, Chidinma Akunwa, Roddiyyat Taiwo, located in Ghana.

For the purposes of Ghana’s Data Protection Act, 2012 (Act 843), Skan Africa is responsible for deciding how and why the personal data described in this policy is processed.

Skan Africa is not yet registered as a data controller with Ghana's Data Protection Commission. We intend to complete this registration and will update this section with our registration number once it is issued.

When Skan Africa is later incorporated or otherwise formally registered, this Privacy Policy may be updated so that the registered entity becomes the data controller.

Our privacy contact is:

Skan Africa
Email: support@skan.africa

2. Scope of this policy

This policy covers the Skan mobile application, website, and related beta services.

It explains:

  • what data we collect;
  • why we collect it;
  • how we use it;
  • when we share it;
  • how long we keep it;
  • how we protect it;
  • your rights and choices.

This policy does not cover third-party websites, products, services, or stores that are not controlled by us.

3. Beta-stage notice

Skan is currently an early-stage beta product. This means the product is still being tested, validated, and improved.

Because of this:

  • features may change;
  • data practices may be refined as the product develops;
  • some analysis may be experimental;
  • we may limit or pause the Service;
  • we may update this Privacy Policy as our infrastructure, providers, and legal structure become clearer.

We will try to notify users of significant privacy-related changes before they take effect.

4. Data we collect

4.1 Account data

When you create an account, we may collect:

  • email address;
  • display name, if provided;
  • login/authentication information;
  • account settings;
  • profile preferences.

4.2 Health-profile data

To provide condition-specific or profile-based analysis, we may collect health-profile information you choose to enter.

This may include:

  • hypertension;
  • type 2 diabetes;
  • food allergies;
  • lactose intolerance;
  • gluten-related concerns;
  • dietary restrictions;
  • halal, vegetarian, vegan, or other dietary preferences;
  • a general profile with no health condition.

Health-related information may be treated as special personal data under applicable data-protection law. We process it only with your consent and only for the purposes described in this policy.

4.3 Profiles created for other people

Skan may allow one account to create multiple profiles, for example for a child, parent, family member, or person in your care.

If you create a profile for another person, you confirm that you have permission or legal authority to provide and manage that person’s information.

If the profile relates to a child, you confirm that you are the child’s parent or legal guardian, or that you otherwise have legal authority to create and manage that profile.

4.4 Product scan data

When you scan a packaged-food product, we may collect or generate:

  • the product-label photo you upload or capture;
  • text read from the label;
  • ingredient information;
  • nutrition information;
  • allergen information, where available;
  • product name and brand, where available;
  • barcode, where available;
  • analysis generated by the Service;
  • alternative-product suggestions shown to you;
  • whether the scan was completed, failed, or marked as unclear.

4.5 Guest or non-account scan data

Before you create an account, you may be able to scan products without signing in.

These guest scans are not linked to a registered account, but they may still involve technical data such as a session ID, IP address, device information, or anti-abuse identifiers.

If you later create an account, we will not link previous guest scans to your account unless the app clearly tells you this or gives you a choice to import them.

4.6 Usage data

We may collect information about how the app is used, such as:

  • scans completed;
  • scans that failed;
  • features opened;
  • alternatives viewed or saved;
  • app screens visited;
  • buttons clicked;
  • frequency of use;
  • general user journey information.

We use this to understand whether the product is useful, improve accuracy, fix bugs, and improve the user experience.

4.7 Device and technical data

We may collect basic technical information such as:

  • device type;
  • operating system;
  • app version;
  • browser type, where applicable;
  • IP address;
  • diagnostic logs;
  • crash reports;
  • timestamps;
  • security and anti-abuse signals.

4.8 Dietitian consultation and booking data

If you book or provide a paid consultation through the Service, we may collect:

  • consultation booking details (date, time, dietitian, patient);
  • the stated goal or reason for the call, if you choose to provide one;
  • call duration and basic call metadata (start time, end time, connection status);
  • whether the consultation was completed, cancelled, or refunded.

4.9 AI-assisted consultation notes

With your separate, specific consent, an AI assistant may join a video consultation to listen, transcribe the conversation, and generate written notes for the dietitian's records.

This is a distinct consent from the general consultation consent described in Section 6 — it requires both the patient and the dietitian to separately agree before it is used for a given call, and either party can withdraw this consent at any time from Settings. If consent is not given or is withdrawn, the AI assistant does not join the call and no transcript or AI-generated notes are created.

Where used, this may involve:

  • real-time audio from the call being processed by a third-party speech-to-text provider to produce a transcript;
  • an AI model generating a written summary or notes from that transcript;
  • the resulting notes being stored and made available to the dietitian.

We do not use call audio or AI-generated consultation notes to train third-party AI models.

4.10 Payment data

If you pay for a consultation, or a dietitian receives a payout or pays a subscription fee through the Service, we or our payment processors may collect:

  • mobile money account details (such as a phone number) or card payment details, handled directly by our payment processor;
  • transaction amount, currency, and status;
  • payment references and timestamps;
  • for dietitians, payout account details and subscription/billing status.

We do not store full card numbers or mobile money PINs ourselves — these are handled directly by our payment processors (see Section 9.1).

4.11 Google Calendar data

If a dietitian chooses to connect their Google Calendar (a separate, optional step from signing in with Google), the Service may access:

  • free/busy availability on the connected calendar, to suggest open consultation hours;
  • the ability to create and delete calendar events for booked or cancelled consultations on that calendar.

We do not read the content, description, attendees, or other details of a dietitian's existing calendar events — only free/busy time is read, and event titles created by the Service are generic (e.g. "Skan — booked consultation") and never contain a patient's name or other identifying information.

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Calendar data for advertising, and we do not transfer it to third parties except as necessary to provide the calendar-sync feature itself or as described in Section 9.

4.12 Push notification data

If you enable notifications, your browser or device provides a push-notification subscription (a unique endpoint and encryption keys) that we store so we can send you notifications such as scan reminders, consultation updates, or account alerts. We do not use this to identify you across other apps or websites.

5. How we use your data

We use personal data for the following purposes:

5.1 To provide the scan-and-analysis feature

We process product images, label text, nutrition information, ingredients, and health-profile information to generate food-label analysis.

5.2 To tailor analysis to your profile

If you choose a health profile, we use that profile to compare the product information against relevant thresholds, rules, or guidance.

This is done to provide informational analysis only. It is not medical advice, diagnosis, treatment, or disease management.

5.3 To maintain accounts and profiles

We use account and profile data to let you sign in, manage profiles, view scan history where available, update settings, and delete your account.

5.4 To improve the product

We may use scan outcomes, failed scans, parsed label text, usage patterns, and feedback to improve accuracy, reliability, user experience, and safety.

Where possible, we use de-identified, aggregated, or minimised data for improvement.

5.5 To prevent abuse and protect the Service

We may use technical data, session data, IP address, device signals, and scan activity to detect misuse, prevent fraud, enforce scan limits, protect infrastructure, and keep the Service secure.

5.6 To show alternative-product suggestions

When a scanned product appears not to match a selected profile, the Service may show alternative products.

Some alternatives may be unpaid. In the future, some may be sponsored, promoted, or commercially supported. If a suggestion is sponsored or influenced by a commercial arrangement, we will aim to make that clear.

5.7 To create aggregated insights

We may create aggregated or de-identified insights about product scans, nutrition trends, ingredient patterns, user behaviour, or market trends.

We may use these insights internally or share them externally, but only where they do not identify you personally.

5.8 To process payments and payouts

We use payment data to process consultation payments, dietitian payouts, and subscription billing, and to detect and resolve payment errors or fraud. Payment processing is handled by our payment processors, described in Section 9.1.

5.9 To provide calendar sync

Where a dietitian connects their Google Calendar, we use the access described in Section 4.11 solely to show suggested open consultation hours and to keep booked/cancelled consultations reflected on that calendar.

5.10 To generate AI-assisted consultation notes

Where both the patient and dietitian have separately consented (Section 4.9), we use call audio and a third-party speech-to-text and AI service solely to produce a transcript and written notes for the dietitian's own records of that consultation.

6.1 Health-profile data

We ask for your consent before processing health-profile information for condition-specific analysis.

You can withdraw consent at any time by deleting the relevant profile, changing your settings, or contacting us.

If you withdraw consent, we may no longer be able to provide condition-specific analysis. You may still be able to use general features that do not require health-profile data.

Withdrawing consent does not affect processing that happened lawfully before consent was withdrawn.

6.2 Video consultations

Before your first video consultation, we ask for your separate consent to the video-call provider processing described in Section 7 of our Terms of Service.

6.3 AI-assisted consultation notes

The AI note-taking feature described in Section 4.9 requires its own separate consent from both the patient and the dietitian for a given call. You can grant or withdraw this consent at any time from Settings, independently of your other consents. Withdrawing it only affects future calls — it does not delete notes already generated for a past call, which you can separately request deletion of under Section 13.

7. Skan is not medical advice

Skan provides food-label information and profile-based analysis for general informational purposes.

Skan does not:

  • diagnose any condition;
  • treat any condition;
  • manage any condition;
  • replace a doctor, registered dietitian, pharmacist, nutritionist, or healthcare professional;
  • tell you whether you must eat or must not eat a product;
  • tell you to start, stop, or change medication or treatment.

For medical, dietary, or treatment decisions, speak to a qualified healthcare professional.

8. Brand alternatives and sponsored suggestions

Skan may suggest alternative products when a scanned product appears not to match your selected profile.

Some alternative suggestions may come from brands, retailers, or partners that have a commercial arrangement with us.

Our commitments are:

  • we will not give brands your identity, contact details, or health profile so they can target you personally;
  • we will aim to label sponsored or commercially influenced suggestions clearly;
  • a product suggestion is informational only;
  • a suggestion is not medical advice or a recommendation that you should consume the product.

9. When we share data

We do not sell personal data that identifies you.

We may share data in the following limited situations:

9.1 Service providers

We use the following categories of trusted service providers to operate the Service:

  • Cloud hosting, storage, and database: Amazon Web Services (AWS).
  • Sign-in: Google (Sign in with Google).
  • Calendar sync (dietitians only, optional): Google Calendar API — see Section 4.11.
  • Label reading and food-analysis AI: OpenAI.
  • Video consultations: LiveKit.
  • AI-assisted consultation notes (where separately consented — Section 4.9): a speech-to-text provider, plus an AI model provider for note generation.
  • Payments and payouts: Moolre (mobile money), and Paystack (card payments and dietitian payout splits).
  • Push notifications: your browser's or device's own push-notification service (e.g. Google or Apple's push infrastructure) — this only relays the notification, it does not see its content.

These providers may process data only for the services they provide to us and should not use it for their own independent purposes.

9.2 Aggregated or de-identified insights

We may share aggregated or de-identified insights with partners, brands, public-health bodies, researchers, or other organisations.

For example, we may share trends such as:

  • common product categories scanned;
  • common nutrition-label gaps;
  • general ingredient trends;
  • aggregated interest in certain alternative products.

We will not intentionally share these insights in a way that identifies you personally.

9.3 Legal, safety, and compliance reasons

We may disclose information if we reasonably believe it is necessary to:

  • comply with law;
  • respond to lawful requests from authorities;
  • protect users, the public, or our Service;
  • investigate abuse, fraud, or security issues;
  • enforce our Terms of Service.

9.4 Business changes

If Skan Africa is incorporated, restructured, merged, acquired, or transferred to another operator, user data may be transferred as part of that process.

If that happens, we will aim to ensure that the receiving entity continues to protect the data in line with this policy or gives users notice of material changes.

10. Cross-border processing

Some service providers process data outside Ghana. In particular:

  • our cloud hosting, storage, and database infrastructure (AWS) is located in the European Union (Sweden);
  • our video-consultation infrastructure (LiveKit) routes calls through servers in the European Union (Germany);
  • our AI providers (OpenAI, and our speech-to-text provider for AI-assisted notes) are based in the United States;
  • Google (sign-in and Calendar sync) and our payment processors (Moolre, Paystack) operate their own global or regional infrastructure.

Where data is transferred or processed outside Ghana, we take steps required by applicable data-protection law. This may include using appropriate contractual protections, assessing the destination and provider, or relying on consent where required.

11. Security

We use technical and organisational measures designed to protect personal data.

These may include:

  • encryption in transit;
  • encryption of sensitive profile data at rest where implemented;
  • access controls;
  • role-based restrictions;
  • secure authentication;
  • audit or diagnostic logs;
  • deletion or minimisation of product-label photos after analysis;
  • monitoring for abuse or suspicious activity.

No system is perfectly secure. If we become aware of a data breach that requires notification, we will take steps required by applicable law, which may include notifying affected users and/or the Data Protection Commission.

12. How long we keep data

We keep data only for as long as reasonably needed for the purposes described in this policy, unless a longer period is required by law, security, dispute-resolution, or compliance needs.

Current intended retention periods:

  • Product-label photos: deleted shortly after user leaves analysis screen, unless you choose to save the image, submit feedback, report an issue, or temporary retention is needed for security, debugging, or legal reasons.
  • Parsed label text and scan result: kept for 30 days, unless deleted earlier.
  • Account data: kept while your account is active.
  • Health-profile data: kept while the relevant profile exists or until you delete it or withdraw consent.
  • Guest scan data: kept for 7 days for abuse prevention, debugging, analytics, and product improvement.
  • Technical logs: retained for up to 30 days. Security and abuse-prevention logs may be retained for up to 90 days. Where logs are needed to investigate a security incident, fraud, abuse, legal claim, or compliance issue, we may retain the relevant logs until the matter is resolved, then delete or anonymise them within a reasonable period.
  • AI-assisted consultation transcripts and notes: kept while the underlying consultation record exists, or until the dietitian or patient requests deletion, whichever is sooner.
  • Payment and payout data: kept for as long as required for accounting, tax, dispute-resolution, and legal record-keeping purposes, which may exceed the retention period for other data described in this section.
  • Google Calendar sync tokens: kept while a dietitian's calendar remains connected; deleted when they disconnect it in Settings.
  • Push notification subscriptions: kept while notifications remain enabled; deleted when you disable them or they become invalid.
  • Aggregated or de-identified data: may be kept for longer where it no longer identifies you personally.

13. Your rights and choices

Subject to applicable law, you may have the right to:

  • ask what personal data we hold about you;
  • request a copy of your personal data;
  • correct inaccurate or incomplete data;
  • request deletion of your data;
  • withdraw consent for health-profile processing;
  • object to or restrict certain processing;
  • close your account;
  • complain to the Data Protection Commission.

To exercise these rights, contact us at:

support@skan.africa

We may need to verify your identity before responding to certain requests.

14. Deleting your account or profile

You may request deletion of your account or a specific profile.

When you delete a health profile, we will delete or de-identify the health-profile data linked to that profile, unless we need to keep limited information for legal, security, abuse-prevention, or compliance reasons.

When you delete your account, we will delete or de-identify account-linked personal data within 7 days, unless a longer period is required for legal, security, abuse-prevention, dispute, or compliance reasons.

15. Children’s data

Skan is not intended for children to create their own accounts.

You must be at least 18 years old to create an account.

A parent or legal guardian may create a profile for a child only if they have the legal right to do so and only for the purpose of using the Service to support food-label understanding.

We may update or restrict child-profile features after legal review.

The Service may contain links to third-party websites, products, stores, brands, or resources.

We are not responsible for the privacy practices, content, or accuracy of third-party services. You should review their privacy policies before using them.

17. Changes to this Privacy Policy

We may update this Privacy Policy as the beta develops, as our providers change, or as legal requirements become clearer.

If we make a significant change, we will aim to notify users through the app, website, email, or another reasonable method before the change takes effect.

The “Last updated” date shows when this policy was last revised.

18. Contact

For privacy questions, requests, or complaints, contact:

Skan Africa
Beta product operated by: Jesse Nyemitei, Chidinma Akunwa, Roddiyyat Taiwo
Location: Accra, Ghana
Email: support@skan.africa

Once Skan Africa is formally registered, this section will be updated with the registered legal name, registration number, registered office, and any required data-protection registration details.