Inra
Privacy Policy
Last updated: 20 August 2026 · Applies to the Inra mobile app and inra.app
This policy is binding on us today. We will update this page whenever our practices change, and we will tell you in the app before any change that materially affects you.
1. Who we are (Data Fiduciary)
Inra is an informational wellness app that helps you read and understand packaged-food labels. For the purposes of India's Digital Personal Data Protection Act, 2023 (DPDP Act), Inra is the Data Fiduciary for the personal data described below.
Contact: contact@inra.app
2. What we collect, and why
We collect only what the app needs to work. Specifically:
- Your mobile phone number. This is how you sign in (a one-time password sent over SMS). We do not store your phone number in our database. Your scan history is linked to you by an irreversible code derived from your number — see section 10. Purpose: to create and secure your account.
- The label photographs you take. Each photo is sent to our server and then to Google's Vertex AI service, which reads the text on the label. By default we do not keep your photographs — the image is deleted from our server immediately after it is read. Only if you turn on “Help improve Inra” in your profile (it is off unless you switch it on) do we keep a copy of the label photo, on our encrypted server in India, for up to 90 days, to check and improve how accurately the app reads packs. You can turn it off at any time, which deletes any copies we are holding. Purpose: to read the label, and — only with your consent — to improve our reading.
- The dietary focus you choose (for example lower-sugar or heart-conscious). Under the DPDP Act and Apple's rules we treat this as health-related information and handle it accordingly. Purpose: to show you how a product fits the preference you set.
- Your scan history — the products you scanned, what we read from the label, and the resulting fit. Purpose: to show you your history and to improve accuracy.
- Your subscription and read balance. If you buy a subscription or a top-up pack, Apple takes the payment and tells our server what was bought and when. We keep that record — the plan, its renewal dates, the reads you have left and the reads you have used — against the same irreversible code, so that your plan works on your account. We never see or hold your card, bank or billing details; those stay with Apple. Purpose: to give you the reads you paid for, and to restore them on a new device.
- A product barcode, only if you choose to scan one. The barcode step is optional and you can skip it. Purpose: to identify the product more reliably.
We do not collect your name, email, address, contacts, location, or advertising identifiers. We do not track you across other apps or websites.
3. Your consent — and your right to withdraw it
We process your personal data on the basis of the consent you give when you sign up. You may withdraw your consent at any time, and it must be as easy to withdraw as it was to give: use Profile → Delete my account in the app, or write to us at contact@inra.app. Withdrawing consent stops any further processing and triggers the erasure described in section 6.
4. Who else processes your data
We use a small number of service providers (Data Processors). We do not sell your data, and we do not share it for advertising.
- Google Firebase Authentication — sends your one-time password (OTP) and holds your phone number for sign-in. Firebase is a global Google service, and your phone number may be processed on Google infrastructure outside India.
- Google Vertex AI — reads the text on your label photo. This happens on Google servers in Mumbai (asia-south1), in India. Google does not keep the photo after it has been read. Any copy kept for the optional “Help improve Inra” setting is held only on our own encrypted server in India — see section 5.
- Amazon Web Services (AWS) — hosts the Inra server, in the Mumbai (ap-south-1) region. Your account and scan history are stored here, in India.
- Open Food Facts — an open product database we query only when you choose to scan a barcode. We send it the barcode number and nothing else. No personal data is sent.
- Netlify and Google Analytics — used for this website (inra.app) only, not inside the app.
5. Where your data is processed
Your label photos and your scan history stay in India. The Inra server runs in AWS Mumbai (ap-south-1), and your label photos are read by Google Vertex AI in Mumbai (asia-south1). By default a photo is used only to read the label and is not retained afterwards. If you turn on the optional “Help improve Inra” setting, a copy of the photo is kept on our encrypted server disk in India (AWS Mumbai) for up to 90 days and then deleted automatically — it is also deleted the moment you turn the setting off or delete your account. This does not create any transfer of your photo outside India.
The one exception we know of is sign-in: Firebase Authentication is a global Google service, so your phone number may be processed on Google infrastructure outside India when we send your OTP and verify it.
The DPDP Act permits the transfer of personal data outside India except to territories the Central Government restricts; we will stop any transfer that becomes restricted. If we ever begin processing your label photos or scan history outside India, we will update this policy and tell you before that change takes effect.
6. Deleting your account, and what we keep
You can permanently delete your account at any time from Profile → Delete my account. When you do:
- We delete your account and phone number from our authentication system (Firebase).
- We irreversibly sever the link between you and your scan history, by erasing the code that connects them. Your history can no longer be traced back to you or retrieved by anyone, including us.
- We delete any label photos we were keeping for you under the optional “Help improve Inra” setting, along with that setting.
- We delete your payment and subscription records held against your account, including the log of purchases and credits.
We keep the remaining de-identified product information — the nutrition facts read from a label, and how often a product is scanned — because once the link to you is destroyed it is no longer personal data. We use it to maintain and improve Inra's product database and the accuracy of our reading. We do not keep your phone number, your account, or a personal scan history after deletion.
One thing we do keep, and why. Inra gives every new phone number a one-time allowance of free reads. So that this allowance cannot simply be reset by deleting and re-creating an account on the same number, we retain a single number — how many free reads that number has used — against the same one-way code described above. It is only that count: it is not your phone number, it holds no scan history, no photos and no purchase details, and it cannot be used to retrieve anything about you. If you would prefer we erase this too, write to contact@inra.app and we will, on the understanding that the free allowance is not granted a second time.
7. How long we keep your data
We keep your account and scan history for as long as your account is open, because the history is the feature. If you delete your account, erasure happens as described above. If your account stays inactive for 24 months, we will erase it on the same basis. Server backups are retained for 30 days and then overwritten. Any label photos kept under the optional “Help improve Inra” setting are held for at most 90 days and then deleted automatically.
8. Your rights under the DPDP Act
- Access — get a summary of the personal data we hold about you. Use Profile → Export my data, or write to us.
- Correction and completion — correct anything inaccurate. You can edit a product's details in the app before saving a scan, or write to us.
- Erasure — see section 6.
- Grievance redressal — see section 9.
- Nomination — you may nominate another person to exercise your rights if you die or become incapacitated. Write to us to register a nominee.
9. Grievance Officer
If you have a complaint about how we handle your data, contact our Grievance Officer at contact@inra.app with the subject line “Grievance”. We will acknowledge within 72 hours and respond within 30 days.
If you are not satisfied with our response, you have the right to complain to the Data Protection Board of India.
10. How we protect your data
- We do not store your phone number. Our database holds only an irreversible code derived from it (a keyed cryptographic hash). The key is held separately from the database and is never stored alongside it, so the code cannot be turned back into your number — not by an attacker, and not by us. If our database were ever exposed, it would contain no phone numbers.
- The database is encrypted at rest. Your scan history is stored on an encrypted disk in AWS Mumbai.
- Encrypted in transit. All traffic between the app and our server uses HTTPS/TLS.
- Isolated accounts. Every request is authenticated, and one account cannot read another account's scans.
- Restricted access. Access to the Inra server is key-based and limited.
No system is perfectly secure. We will notify you and the Data Protection Board if a personal data breach occurs, as the DPDP Act requires.
11. Children
Inra is intended for people aged 18 and over. Under the DPDP Act, anyone under 18 is a child, and we do not knowingly process a child's personal data. If we learn that we have, we will erase it.
12. What Inra is not
Inra is an informational wellness tool. It reads what is printed on a label and shows how it lines up with a preference you set. It does not diagnose, treat, or manage any medical condition, and it is not a substitute for advice from a qualified doctor or dietitian.
13. Changes to this policy
If we change this policy, we will update the date at the top of this page, and we will notify you in the app before any change that materially affects how we use your data.