Privacy

Privacy Policy

Can I Eat This? China can store your Food Profile locally in your browser. Scan history and recent scan data may also be stored locally in your browser so you can return to previous results on the same device.

Guest identifiers, device identifiers, pass tokens, and structured scan results may be used to operate scan limits, restore paid passes, and diagnose failures. The MVP does not require an account to scan.

When you buy a China Food Pass, your email is used for checkout, receipts, order lookup, and pass recovery. The app stores a one-way identity value rather than the plain email in its pass records. Email verification codes are short-lived and are used only to confirm access to matching purchases.

Uploaded menu images are compressed in your browser and uploaded directly to a private temporary storage bucket. The app then gives the menu analysis service short-lived, signed read links only to identify dishes and provide food-restriction guidance. The app requests deletion of temporary image objects after analysis or a handled failure. Interrupted uploads are removed by the storage lifecycle policy. Do not upload private documents or payment screenshots.

Existing local scan history is not automatically uploaded when you buy a pass. You can clear local browser data or scan history from your browser or device controls.

Sharing and Disclosure

To operate the service, we share limited data with the following third-party providers:

  • Waffo Pancake — payment processing. Receives the email you enter at checkout and order metadata needed to confirm payment.
  • Resend — transactional email. Receives your email address to deliver verification codes and order recovery emails.
  • Neon — Postgres database hosting. Stores checkout and pass records.
  • Vercel — application hosting. Processes all browser requests to the site.
  • Cloudflare — DNS, email routing, edge services, and private R2 object storage for temporary menu images. Receives DNS queries for canieatchina.com and routes inbound support email to our team.
  • OpenRouter — routes menu-analysis requests to the selected vision model. When requests are sent through OpenRouter, the app includes its Zero Data Retention routing requirement.
  • Qwen (menu analysis) — receives short-lived signed links to uploaded menu images only to identify dishes and provide food-restriction guidance.

We do not sell your personal data.

Your Data Rights

You may ask to access, obtain a copy of, or delete personal data stored on our servers that is associated with you. This may include checkout and order records, China Food Pass records, device and pass identifiers, scan records, and hashed email identifiers.

To make a request, email support@canieatchina.com from the email address used for your purchase or pass recovery. If available, include your checkout or order reference. We may ask for additional information to verify that you are authorized to access the requested records before fulfilling the request.

Deleting server-side data is permanent and may prevent us from restoring your order or China Food Pass. We may retain limited records when required for legal, tax, accounting, fraud-prevention, dispute-resolution, or security purposes. We will explain any such limitation when responding to your request.

Server-side requests are separate from data stored locally in your browser. You can clear local Food Profile and scan-history data using your browser or device controls.

Questions about this Privacy Policy or data handling can be sent to support@canieatchina.com.