TurboScanner Privacy Policy
Effective September 15, 2026
This policy explains how the TurboScanner Android app
(org.tvoidom.turboscanner) handles your information. It covers the app and the
server it talks to. It does not cover the Tvoidom Studio website or our studio services, which
have their own Privacy Policy — and that policy also covers the website
analytics running on this page.
1) Who we are
TurboScanner is made by Tvoidom Studio.
Legal entity: LLC Ecoformers LLC
400 Corporate Pointe, Suite 300, PMB 6040
Culver City, CA 90230, United States
Contact: privacy@tvoidom.org
Our server is located in the United States (Oregon). We do not move your data outside the United States ourselves. Google processes some of it as described in section 6, on its own infrastructure. Store websites you open from the app are run by those stores, as described in section 4.
2) What the app sends to our server
TurboScanner works by sending a picture of your list to our server, reading the products out of it and matching them against a store catalog. It also looks up the barcodes you scan and, only if you choose, shares product photos with other shoppers. That means the following leaves your device.
| What | When | Why |
|---|---|---|
| Pictures of your list | Every time you import a screenshot or photo, or send one from your computer through the QR page | To recognize the products on it and return a checklist |
| Your Google account: email address and Google account identifier | Only if you choose to sign in with Google | To keep your Pro subscription working across your devices, to stop the same account from claiming a free trial repeatedly, and to let you share product photos |
| An app-generated device identifier | On first launch, then with each request | To keep your session and your subscription state. It is created by the app. It is not your advertising ID and not a hardware serial number. |
| Subscription state from Google Play | When you subscribe, start a trial, renew or cancel | To unlock Pro. We receive whether a subscription is active, which plan it is, a purchase identifier, and the amount and currency Google reports for each payment. We never receive your card details. |
| A Google Play Integrity check | When the app verifies a purchase or redeems a promo code | A signed statement from Google that the app and the device are genuine. We use it only against fraud. It carries no shopping data. |
| Problem reports | Only when you report a problem | Your message, the item you reported, your device's time zone and local time, and the picture that item came from — the app attaches that picture automatically so we can see what you saw |
| Barcodes you scan | When you scan a product | The barcode is stored against the product it belongs to, so other shoppers find it too. A barcode is a number printed on a package and says nothing about you. |
| Barcodes you look up | Each time the barcode lookup reads a code | To show you a card for the product. The app sends the code, the store you are shopping in (a chain such as Costco, never a branch or a location, and no store at all when you scan from Anywhere) and the app version. We keep a record of each lookup: the code, the store, what we found and where it came from, the time, the app version, your device or account identifier, and which button you then used on the card (added to your cart or list, added as is, showed the barcode). It tells us which products we fail to recognize. |
| Names you type for barcodes we don't know | Only when you tap Add as is while shopping in a store | The barcode, the store, the name you typed (optional, up to 80 characters), your device or account identifier, and the shopping session and lookup it belongs to. We use it to find products missing from our catalog. It is not shown to other shoppers. If you are offline, the app sends it once you are connected. |
| Product photos you choose to share | Only in a store, only if you are signed in with Google, after you agree once and tap Share photo | The photo, the barcode, the store, the product name if you typed one, the shopping session and lookup it belongs to, and the version of the agreement you accepted, sent with your account identifier. It is checked and, if approved, shown to other shoppers. See section 3. |
| Reports on shared photos | Only when you tap Report photo | Which photo, the reason you picked and your device or account identifier, so we can hide photos that break the rules. See section 3. |
| How the app was installed | Once, on the first launch after installing | Google Play tells the app which link the install came from — the campaign tag on a link of ours, nothing more. We use it to know which of our own pages and posts bring people in. It says nothing about you and is not shared. |
| That the app was opened | On each launch | The server keeps one row per phone: when it was first seen, when it was last seen, how many times it has been opened and the app version. It tells us whether people come back. There is no third-party analytics service involved, no screen-by-screen tracking and no advertising identifier. |
| What you type into catalog search | While you search | Sent to the server to return matching products. We do not build a search profile. Like any web server, ours records requests in technical logs (section 7), and a search request includes the words you typed. |
The app asks for camera access and uses the camera only while you have a scanner or the product photo screen open. Scanner frames are read on your device to decode the barcode; they are not saved and not uploaded, and only the decoded number is sent. When you tap Add photo or Take a photo, the app takes one picture, cuts the product out onto a white background on your phone, and saves a square copy of up to 1024 pixels without location or other photo details. A photo you take while scanning from Anywhere stays on your phone and is never uploaded. A photo you take in a store is uploaded only as described in section 3. Pictures of your lists come from your gallery or from the QR page, never from the camera in the background.
3) Product photos you share
When you scan a product in a store whose catalog doesn't carry it, and we have no picture of it, the app can offer Take a photo. Sharing a photo is optional. It needs Google sign-in, and the app asks you to agree before your first shared photo. Tapping Not now changes nothing else in the app.
On your phone
The photo is cut out onto a white background on your phone, using Google ML Kit, which runs on the device. If the cut-out does not work, the photo is used as it is, background included, and the app tells you so before you share it. When you tap Share photo, the app uploads it once you have a connection.
On our server
Our server makes a fresh copy of the image, no larger than 1024 pixels on its longer side and without location, camera details or any other photo details, and stores only that copy. Google Gemini then checks it automatically. We send Google the image, the barcode, the store and a product name: one from our catalog or a public product database, or the name you typed if it passes our filter for links, email addresses and phone numbers. Your name, email address and account identifier are not sent to Google. If a check does not complete, the photo can be sent again.
The check rejects a photo that shows a person, personal information (such as a name, an address, a prescription or shipping label, a document, a receipt or a screen), something other than one packaged product, a picture too blurry or dark to recognize, inappropriate content, or a product that does not match its name. It also reads the brand, name and size printed on the package, and we may use that as the product name. When the check is unsure or cannot run, or when a photo is reported, a person on our team may look at the photo and decide. People on our team can also approve or hide any photo, and set the name shown with it.
Who sees an approved photo
An approved photo and its product name become part of the product card for that barcode. Every TurboScanner user who scans that product can see it: in the store where you took it, as long as that store's catalog doesn't carry the product; and, whenever we have no other picture of the product, in other stores that don't carry it and when scanning from Anywhere. The card carries the store where the photo was taken. It never carries your name, your email address or your account.
Approved photos are served at an address made of api.tvoidom.org/community_photos/
and a random 32-character code. The address is part of the product card, so everyone who is
shown the photo, in the app or by calling our server directly, receives it, and anyone who has the
address can open the image without signing in. It cannot practically be guessed. When a photo is
hidden or deleted, the address stops working. A phone that already showed the photo may keep
displaying its saved copy for a while: usually up to an hour, longer while the app stays open or
the phone is offline.
Reports and moderation
Anyone using the app can report a shared photo with Report photo. We store which photo, the reason, the time and the reporter's device or account identifier. Our moderation screen shows the reason and time of each report, not who sent it. A photo reported by two different people is hidden for everyone automatically; we may restore it after a look. The phone that reported a photo stops showing it at once.
We can block an account from sharing photos. A block hides that account's approved photos and rejects the ones still waiting, and it affects photo sharing only. So that deleting the account and signing in again does not undo a block, we also keep a one-way key made from the Google account identifier. The key cannot be turned back into an email address or an identity; it only lets us recognize the same Google account when it signs in again. It exists only for blocked accounts, stays after account deletion, and is removed only if we lift the block.
4) Comparing prices on store websites
When you scan from Anywhere, the product card can offer Compare prices: buttons for Walmart, Target, Amazon, eBay and Google Shopping. Tapping one opens that company's own search page inside the app. The search is the product's brand, name and size, or its barcode number if you switch on Search by barcode, and it goes straight from your phone to that website.
From there you are on the company's website, as in any browser. It receives what a browser normally sends, such as your IP address, device and browser details and its own cookies, and it may run its own analytics and advertising. What it collects, and anything you sign in to or buy there, is covered by that company's privacy policy and terms, not by this policy.
We do not see, read or keep anything you search, view or type on those websites, and nothing about those visits is sent to our server. The in-app browser keeps its own cookies, site data and cache on your phone, separate from your regular browser, so a website may recognize the in-app browser on a later visit. Deleting your account does not remove that data; clearing the app's storage in Android settings, or uninstalling the app, does. Open in browser hands the page to your regular browser.
5) What we do with it
- Turn your picture into a list of products and match them to a store catalog.
- Show product photos, sizes, prices and barcodes for the matched products.
- Look up the barcodes you scan and show what we know about each product.
- Check the product photos you share, and show approved ones to other shoppers.
- Find products and barcodes our catalog is missing.
- Keep your subscription in sync across your devices.
- Prevent abuse of free trials, promo codes, photo sharing and reports.
- Improve recognition, using the diagnostic copies described in section 7.
We do not profile you. The only automatic decisions we make are matching products, the automatic check that approves or rejects a photo you share or leaves it for a person, and hiding a photo after two reports. Blocking an account from photo sharing is always a decision made by a person.
6) Who else processes your data
A small number of providers process data on our behalf.
- Google (Gemini) — the picture you import is sent to Google's Gemini vision service to read the products out of it. A product photo you share is sent, with its barcode, store and product name, for the automatic check described in section 3. We also send Gemini product descriptions from public databases and product names from our catalog, to tidy a product's name or to match a barcode to our catalog; those carry nothing about you.
- Google ML Kit and Google Play services — the barcode scanner and the photo cut-out use Google ML Kit, which runs on your phone. Google Play services delivers the cut-out model to your phone. Your pictures are not sent to Google for this. Google states that ML Kit collects device and app information, performance metrics and similar diagnostics, and does not share them with third parties.
- Google Play Billing — runs the subscription and the payment. What Google does with your payment is covered by Google's own privacy policy.
- Google Sign-In and Google Play Integrity — used only if you sign in, and for the fraud check described above.
- Serper — when we have no catalog photo for a product, we send that product's name, and nothing else, to a search service to find one. Your picture and your account are not sent.
- Hetzner — hosts our server in Oregon, United States, including the product photos you share.
Product data. Product names, brands and sizes on barcode cards come from our own catalog and from our copies of two public databases: USDA FoodData Central (public domain) and Open Food Facts, whose data comes from Open Food Facts contributors under the Open Database License. We keep those copies on our own server, so the barcodes you scan are not sent to either of them. When a card uses Open Food Facts data it says so, and tapping that line opens the product's page on the Open Food Facts website in your browser.
Other shoppers see the photos you share once approved, as described in section 3. The websites you open with Compare prices are not our providers; see section 4.
We do not sell your data. We do not share it with advertisers. The app contains no advertising and no third-party analytics SDK. It does count its own launches and read the install link Google Play provides, as described in section 2; both go only to our own server and nowhere else. Store websites you open inside the app run their own analytics and advertising, as described in section 4.
If you arrived through a referral partner's promo code, that partner sees a de-identified row for your account in their dashboard: the dates and amounts of subscription payments, under a random identifier. They never see your name, your email or anything you scanned.
7) How long we keep things
- Pictures you import. Read and then discarded. A picture sent from your computer through the QR page sits on the server only until the transfer finishes, and at most 20 minutes. A downscaled copy is kept for up to 30 days whenever the recognition was not fully confident — an item that could not be matched, or a picture that could not be read — so we can tell a missing catalog product from an unreadable picture. In practice that covers a large share of imports.
- What was recognized. The list of products read out of a picture, not the picture itself, is cached for 7 days under a fingerprint of the image, so sending the same list twice does not cost a second recognition pass. It is not linked to your account.
- Technical session logs. Up to 30 days. A log line records what the recognizer read from your list — item names, quantities, prices and your notes — and how well each item matched.
- Problem reports. The text entries and the picture attached to a report are kept up to 30 days.
- Barcode lookups and names you typed for unknown barcodes. Kept until you delete your account or ask us to delete them. There is no shorter automatic limit today.
- Product photos you share. See the table below.
- Reports on shared photos. Kept until the photo's record is deleted (when the person who shared it deletes their account or asks us to), until the reporter's account is deleted or the reporter asks us to delete them, or until we restore the photo after a look. They are not removed when the picture itself is deleted.
- Photo-sharing blocks. The block is deleted with the account. The one-way key described in section 3 stays after account deletion, until we lift the block.
- Your account. Your Google identity, the link to your devices and your subscription record are kept until you delete your account, or until you ask us to delete them.
- Your lists and shopping history. These live on your phone, not on our server. Deleting your account from inside the app clears them on that phone, and uninstalling the app removes them.
- Recent scans and product photos on your phone. Recent scans keeps the last 100 products you looked up. A product photo you took stays on the phone while it is still being uploaded or checked, while its product is in Recent scans, or for 90 days after a cart item last used it; the app keeps no more than 150. You can remove a photo that is not being shared with Remove photo. Deleting your account from inside the app, clearing the app's storage or uninstalling the app removes them all.
- Barcodes you scanned. Kept as part of the shared product catalog. Today the stored record also carries the identifier of the device that scanned it; ask us and we will remove that link.
- Launch counts and the install link. Kept while your account or device is known to us, and deleted with your account. This is one row of counters and one row with the campaign tag — not a history of what you did in the app.
- A record that a free trial was used. Kept after account deletion, so the same account cannot claim the trial again. It holds an internal account key and the device the trial was used on. It never holds your email address and no shopping data.
- Backups. Our databases are backed up daily, and each daily backup is deleted within 16 days. Before we update our server software we also take a copy of the databases, and those copies are deleted within 30 days. So a record deleted from our live database can remain in a backup for up to 30 more days. Product photo files are not in these backups.
- Server logs. Our server logs the requests it receives. For a barcode lookup the logged address includes the code, the store and the app version; for a shared photo, the log line includes the barcode, the store and the first characters of the photo and account identifiers. Server logs are deleted within 30 days.
A product photo you share has two parts: the picture, with the names that came with it (the name you typed and the brand, name and size read from the package), and a record of the upload: the barcode, the store, the dates, the result of the check, a fingerprint and the size of the image, the lookup and shopping session it came from, and your account identifier. These deletions run automatically on our server every few minutes.
| Situation | The picture and its names | The record |
|---|---|---|
| Approved and shown | Kept until the photo is hidden (see below) or you delete your account | Kept until you delete your account |
| Still waiting for a decision | If nobody has decided within 14 days of the upload, the photo is rejected and the picture is deleted | Kept until you delete your account |
| Rejected for showing a person, personal information or inappropriate content | Deleted as soon as the check decides | Kept until you delete your account |
| Rejected for another reason (not one product, unreadable, name does not match, account blocked) | Deleted 30 days after the decision | Kept until you delete your account |
| Hidden after two reports, by us, or because the account was blocked | Deleted 30 days after it was hidden | Kept until you delete your account |
| You delete your account | Deleted right away | Deleted right away, together with the reports on the photo |
8) Deleting your data
If you signed in, you can delete your account from inside the app: Settings → Delete account. That removes your account and the data linked to it from our server, including the product photos you shared and your barcode lookups, and clears your lists, history, product photos and Recent scans on that phone. You can also ask us by email to delete your account, or to delete only your data while keeping the account. See Delete your TurboScanner account for the steps, including for people who never signed in, and for exactly what is removed and what stays.
Deleting your account does not cancel your Google Play subscription. Cancel it separately in your Google Play subscriptions.
9) Your choices
- You can use the app without signing in with Google. Signing in is what carries your subscription between devices, and it is needed to share product photos.
- You choose which pictures to import. The app never reads your gallery on its own.
- Sharing product photos is optional. Nothing is uploaded until you agree and tap Share photo, and barcode lookup works without it. Photos you take while scanning from Anywhere never leave your phone.
- To have a photo you shared taken down, write to privacy@tvoidom.org from the Google address you signed in with, and tell us the product's barcode and the store. Deleting your account deletes all of your shared photos.
- If you see a shared photo that shows a person or someone's personal information, tap Report photo and also write to privacy@tvoidom.org with the barcode, so we can hide it quickly.
- Compare prices opens nothing until you tap a store.
- You can revoke camera access in Android settings. Scanning and product photos stop working, the rest continues.
- You can ask us for a copy of the data associated with your account, or ask us to correct it, by writing to privacy@tvoidom.org.
10) California privacy rights
If you live in California, you have the right to know what personal information we collect and why, to request a copy of it, to request its deletion, and to correct it. You also have the right not to be treated differently for exercising those rights. We do not sell or share personal information as those terms are used in the California Consumer Privacy Act, and we do not use your data for cross-context behavioural advertising. To exercise any of these rights, write to privacy@tvoidom.org from the address you signed in with. We answer within 45 days.
11) If you are outside the United States
The app is built for stores in the United States, and our server is in the United States. If you use it from elsewhere, your data is processed in the United States. Where the laws of the European Economic Area or the United Kingdom apply to you, we process your data to provide the service you asked for, on your consent for the product photos you choose to share, and on our legitimate interest in preventing fraud and abuse and in fixing what does not work. You may object, withdraw your consent, ask for a copy, or ask for deletion at the address above.
12) Children
TurboScanner is a shopping tool meant for adults 18 and over. It is not directed to children under 13, and we do not knowingly collect personal information from them. Shared photos must not show any person. The automatic check is built to reject a photo that does and to delete it straight away; if one gets through and we take it down, it is hidden at once and its picture is deleted within 30 days. If you believe a child has given us personal information, write to us and we will delete it.
13) Security
Traffic between the app and our server is encrypted in transit with HTTPS. The diagnostic copies and session logs described in section 7, the pictures attached to problem reports, and shared product photos that have not been approved are reachable only through our administration tools, which require an authorised device. Approved product photos are the exception by design: anyone with a photo's exact address can open it, as described in section 3. Shared photos are stored without location or other photo details. No system is perfectly secure, and we do not claim otherwise.
14) Changes to this policy
If we change how the app handles your data, we update this page and change the effective date at the top. Material changes are also described in the app's release notes on Google Play.
15) Contact
Tvoidom Studio (LLC Ecoformers LLC)
400 Corporate Pointe, Suite 300, PMB 6040
Culver City, CA 90230, United States
Email: privacy@tvoidom.org
Product page: tvoidom.org/turboscanner