Privacy Policy

Chemicly Application – Data Protection (GDPR / CCPA / Global)

CRITICAL NOTICE REGARDING YOUR HEALTH AND PRIVACY

Chemicly is designed with a privacy-first approach. Your personal data, including allergies and health restrictions, is stored encrypted on secure Google Firebase servers. Data is protected with encryption in transit (SSL/TLS) and at rest. No third parties have access to your data.

1. Data Controller

The data controller is RM Services s.r.o., Company ID: 29675677, registered office at Zbraslavská 12/11, Malá Chuchle, 159 00 Praha 5. Contact us at: info@chemiclyapp.com.

2. Data Collection and Encryption

  • •Account Data: We process your email address upon registration. Data is securely stored on Google Firebase servers using encryption in transit (SSL/TLS) and at rest. User passwords are cryptographically hashed, and the Operator has no access to them.
  • •Allergy & Health Data: Your allergies and health preferences are stored encrypted on Google Firebase servers, not locally on your device. No third parties have access to this data.
  • •Scan History: Product scan history is stored on secure Firebase cloud servers.
  • •Payment Data: Payments are processed via Google Pay and Apple Pay. We do not store or process your card details – transactions are handled directly through the secure payment interfaces of Google and Apple.
  • •Data Analysis: Inputs for ingredient scanning are sent anonymously to Google Gemini AI. NO personal identifiers or allergy data are transmitted.

3. Your Rights (GDPR & CCPA compliance)

You have the right to access your data and the right to deletion. You can permanently delete your account and all associated data on Firebase servers at any time within the App's settings.

4. Other International Users (including Asia)

We are committed to global privacy. By adhering to the GDPR framework, our data practices meet or exceed the rigorous requirements of international privacy laws across the globe, including Asian frameworks (e.g., APPI, PDPA, PIPA). We employ data minimization principles and all data is encrypted in transit and at rest.

This document becomes effective on July 22, 2026.