Privacy Policy
26 Feb 2026
This Privacy Policy explains how this app ("App", "we", "us", "our") collects, uses, stores, discloses, and protects your information when you use the Spike FoodScanner demo application.
Because this App may process nutrition- and health-related information, this policy includes a detailed disclosure of Health Data access, collection, processing, and usage.
By using the App, you agree to this Privacy Policy.
Who We Are
This App is operated as a Spike demo experience and aligns with Spike privacy principles.
- Company: Spike Technologies, Inc.
- Address: 242 West 53rd Street, New York, NY 10019, USA
- General privacy contact:
support@spikeapi.com - Data protection contact:
dpo@spikeapi.com
If you have privacy questions, requests, or complaints, contact us using the details above.
Scope of This Policy
This policy applies to personal data processed through:
- The Spike FoodScanner demo mobile app
- Related APIs, analytics, and support channels
- Communications with us regarding the App
This policy does not apply to third-party websites, SDKs, or services that have their own privacy notices.
Personal Data We Collect
We collect data in three ways: (a) information you provide, (b) information collected automatically, and (c) information generated by the App's processing features.
A. Information You Provide
- Account/contact information (if enabled): name, email, phone, organization
- App inputs: food photos, barcode scans, meal descriptions, notes
- Support communications: messages, screenshots, and troubleshooting details
B. Information Collected Automatically
- Device and technical data: device model, OS version, app version, language, timezone
- Log data: timestamps, request metadata, error/crash diagnostics
- Usage data: features used, session events, interaction patterns
C. Data Generated by Processing
- Nutrition analysis outputs (for example: calories, macros, food category inferences)
- Confidence scores and quality signals
- Safety/abuse signals (for misuse detection and service protection)
Comprehensive Health Data Disclosure
What We Mean by "Health Data"
For this App, "Health Data" includes information that may reveal or describe your diet, nutrition, wellness, or potential health status, such as:
- Food and beverage images and related metadata
- Meal logs, ingredient lists, and dietary notes
- Nutrition analysis outputs (for example, calories, carbohydrates, fat, protein)
- Dietary patterns inferred from repeated use (for example, meal timing trends)
- Any user-provided health or wellness context entered into notes
Health Data We Access and/or Collect
Depending on your use of App features, we may access and/or collect:
- Camera/gallery content you choose to upload for scanning
- Text you enter describing food, nutrition goals, or dietary constraints
- App-generated nutrition and classification outputs
- Technical context tied to scans (timestamps, app/device metadata, API logs)
How We Use Health Data
We use Health Data only for legitimate product and service purposes, including:
- Core functionality
- Analyze food inputs and return nutrition-related insights
- Improve scan quality, accuracy, and response relevance
- Service operations
- Maintain, troubleshoot, and secure the App
- Detect abuse, fraud, or anomalous usage
- Product improvement and research
- Evaluate model and feature performance
- Build aggregate insights to improve quality and reliability
- Where feasible, use de-identified or aggregated data
- Compliance and legal obligations
- Comply with applicable laws, regulations, lawful requests, and audits
What We Do Not Do With Health Data
- We do not sell your Health Data.
- We do not use Health Data for unrelated advertising profiling.
- We do not knowingly collect Health Data from children under 16.
Health Data Sharing
We may share Health Data only when needed for service delivery and legal compliance:
- Service providers/subprocessors (hosting, analytics, infrastructure, support) under contractual confidentiality and data protection terms
- Professional advisers (legal/compliance) where required
- Authorities/lawful process when legally required
- Business transfer scenarios (for example merger/acquisition), subject to continued privacy protections
We require third parties handling Health Data on our behalf to process it only under our instructions and with appropriate safeguards.
Health Data Retention
- We retain Health Data only as long as needed for the purposes listed in this policy, unless longer retention is required by law.
- Retention periods may vary by data type (for example, logs vs. user-submitted inputs).
- When no longer needed, data is deleted, de-identified, or anonymized according to our retention procedures.
Health Data Security
We apply administrative, technical, and organizational safeguards to Health Data, including:
- Access controls and least-privilege practices
- Encryption in transit and, where appropriate, at rest
- Monitoring, logging, and incident response procedures
- Vendor due diligence and contractual controls
No system is 100% secure, but we continuously work to protect your data.
Important Use Limitation
This App provides informational outputs and is not medical advice, diagnosis, or treatment. You should seek qualified medical guidance for healthcare decisions.
Legal Bases for Processing (Where Applicable)
Depending on your jurisdiction, we rely on one or more legal bases:
- Performance of a contract (providing the App and requested features)
- Legitimate interests (service security, quality improvement, abuse prevention)
- Consent (where required by law for certain processing)
- Legal obligation (compliance, legal process, regulatory duties)
You can withdraw consent where consent is the legal basis.
Cookies, SDKs, and Similar Technologies
If this App uses analytics SDKs, log technologies, or related tools, we may collect device identifiers and usage events to:
- Keep services functioning
- Measure and improve App performance
- Diagnose crashes and errors
You can manage permissions and many tracking settings through your device/app controls.
Data Sharing Categories
We may disclose personal data (including Health Data where necessary) to:
- Infrastructure and cloud hosting providers
- Analytics and diagnostics providers
- Customer support and operations vendors
- Legal/compliance advisers and authorities where required by law
We do not disclose more data than needed for the relevant purpose.
International Transfers
Your data may be processed in countries other than your own. Where required, we implement safeguards for cross-border transfers (for example, contractual protections and equivalent safeguards).
Your Privacy Rights
Depending on your location, you may have rights to:
- Access your personal data
- Correct inaccurate data
- Delete data
- Restrict or object to certain processing
- Request portability of eligible data
- Withdraw consent (where processing is based on consent)
- Lodge a complaint with a regulator
To exercise your rights, contact: support@spikeapi.com or dpo@spikeapi.com.
We may verify your identity before fulfilling requests.
Children's Privacy
This App is not intended for children under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided data, contact us and we will take appropriate steps.
Data Breach and Security Incidents
If we confirm a data breach affecting personal data, we will respond under applicable law, including notification obligations where required.
Changes to This Privacy Policy
We may update this policy from time to time. If material changes are made, we will update the effective date and provide notice where required.
Contact
- Email:
support@spikeapi.com - Data protection contact:
dpo@spikeapi.com - Address: 242 West 53rd Street, New York, NY 10019, USA
If you have questions about Health Data handling in this App, contact us and include "Health Data Privacy Request" in the subject line.