1. Overview
This policy explains what Vanilyst ("the Service") collects, why it is collected, how long it is kept and what control you have over it. It applies to the Service only. The Adarsh Yadav website has its own privacy policy.
The Service is operated by Adarsh Yadav, an independent software developer working as a sole trader rather than an incorporated company. The guiding principle is simple: collect the minimum needed to make the product work, be explicit about it, and delete it when it is no longer needed.
Product photos can be personal. They are processed and stored locally on your device and are never uploaded automatically — the only way a photo leaves the app is if you choose to export a backup and share it yourself.
2. What is collected and why
Every category of data handled by the Service is listed below, together with its purpose and retention period.
| Category | Examples | Purpose | Retention |
|---|---|---|---|
| Product information | Names, brands, categories, collections, purchase and opened dates, expiration dates, PAO values, notes, barcodes | To organize your products and calculate expiry dates | Stored locally until you delete it; never sent to the developer |
| Product photos | Photos you attach to a product | To help you recognize products at a glance | Stored locally on your device only |
| Reminder settings | Which products have reminders and when they fire | To schedule local expiry notifications | Stored locally until changed or deleted |
| App preferences | Sort order, filters, favorites, theme | To remember how you like the app set up | Stored locally until changed or the app is deleted |
| Approximate location | A coarse, city-level coordinate, only while the optional UV Index feature is turned on | To request today's local UV Index from Apple Weather and the nearby place name shown on the card | Not stored at all — used for the single request, then discarded. Only the UV number, level, place name and reading time are kept, in memory, until the app closes |
| Routines & completion history | Morning/Evening routine steps, completion history, streaks, optional reminder timing | To track skincare routines and remind you to complete them | Stored locally until changed or deleted; not included in JSON backup |
| Skin Diary entries | Dated notes you add about your skin | To keep a personal log of how your skin responds over time | Stored locally until deleted |
| Product usage & cost data | Purchase price, currency, usage events, and a finished/discarded outcome for a product | To calculate cost-per-use and highlight waste across your collection | Stored locally until changed or deleted; included in JSON backup |
| Repurchase list | A name, brand, category, barcode and price snapshot of products you want to buy again | To remind you what to restock | Stored locally until removed; not included in JSON backup |
3. Permissions the app requests
Each permission is requested in context, with an explanation, at the moment it is first needed — never in a burst at first launch. Optional permissions can be declined and the app keeps working without them.
| Permission | Platform identifier | Why | Required |
|---|---|---|---|
| Camera | NSCameraUsageDescription | Optional — take a product photo, scan a barcode instead of typing it in, or scan a product label to read its expiry and Period After Opening details. All three are processed on your device; no image is uploaded anywhere. | Optional |
| Location (while using the app) | NSLocationWhenInUseUsageDescription | Optional, and off by default — used only to request today's local UV Index from Apple Weather, after you turn UV Index on and confirm. Vanilyst asks for approximate, city-level accuracy only, never tracks you in the background, and never stores or shares the coordinate. | Optional |
| Notifications | UNUserNotificationCenter | Optional — local reminders for products approaching their expiry date, and for Morning/Evening routines. | Optional |
Any permission can be revoked at any time in your device settings. Revoking a required permission stops the features that depend on it, but does not delete your account or your data.
4. Barcode lookup
Vanilyst can look a barcode up against Open Beauty Facts, a public open database of beauty products, to pre-fill a product's name, brand and category so you do not have to type them. This is the only feature that sends anything to a non-Apple service.
- It runs only when you explicitly look a barcode up — never automatically, and never in the background.
- The request contains the barcode and nothing else. No device identifier, advertising identifier, account or location is attached, and none of your other products are included.
- The response is shown to you as a suggestion; nothing is saved until you choose to apply it.
- Open Beauty Facts receives the barcode and the standard information any web request carries, such as an IP address. Their own terms and privacy policy govern what they do with it.
- If you never use barcode lookup, Vanilyst never contacts them at all.
5. Label scanning
Vanilyst can read the text on a product label with the camera to suggest an expiry date or a Period After Opening value. This runs entirely on your device using Apple's built-in text recognition.
- No photo, frame or recognized text is uploaded anywhere — there is no cloud OCR involved.
- No artificial-intelligence service outside your device is used, and nothing is used to train any model.
- The scan produces a suggestion you can accept or discard; only what you accept is saved.
6. UV Index and location
Vanilyst can show today's local UV Index and a short sunscreen prompt on the Home screen. This feature is off until you turn it on, and it is the only reason Vanilyst ever asks for location.
- Location is never requested at launch. Vanilyst asks only after you open the UV card or the Settings toggle and confirm on an explanation screen first.
- Only While Using the App access is requested — never Always — and accuracy is deliberately coarse, at roughly city level, because a UV reading does not need a precise position.
- Your position is read once per refresh. Vanilyst never continuously monitors your location and does no background tracking.
- The coordinate is used for that single request to Apple Weather and then discarded. It is never written to storage, never included in a backup, and never sent to the developer or to Open Beauty Facts.
- Only the resulting UV number, its level, an optional nearby place name and the time of the reading are kept, in memory, until the app closes.
- Turning UV Index off in Settings immediately stops any request in progress, clears the reading, and prevents any further location or weather requests.
7. Backups and exports
Vanilyst can export a JSON backup of your collection, but only when you explicitly choose to. Nothing is backed up automatically.
- A backup file is generated only after you take that action in the app.
- You choose where to save the file or who to share it with using the system share sheet.
- Vanilyst does not automatically upload backup files anywhere.
- A backup may contain the product information and photos you have added, so treat it like any other personal file.
- You are responsible for securing exported backup files once they leave the app.
8. In-app purchases
Vanilyst 1.0 does not offer any in-app purchase or subscription. Every feature is free for every user, with no account, paywall or purchase of any kind.
The app contains inactive code for a possible future paid tier, but it is never invoked in this version — no product list is loaded, no purchase or restore screen is reachable, and no payment or billing information is collected.
9. What is never done
- Your data is never sold, rented or traded.
- Your content is never used to train machine learning models.
- There is no advertising in the Service and no advertising trackers are embedded.
- No data is shared with data brokers.
- No profile is built about you for any purpose beyond operating the Service.
10. Legal basis for processing
Personal information is handled in line with applicable privacy law wherever you are. Where GDPR-style law applies, processing rests on one of the following bases:
- Contract — processing needed to provide the Service you signed up for.
- Legitimate interests — keeping the Service secure, reliable and free from abuse, balanced against your rights.
- Consent — optional features such as marketing email, which you can withdraw at any time.
- Legal obligation — retaining billing records where tax or accounting law requires it.
11. Service providers
The Service connects to the outside parties listed below, and only for the purposes described. Each connection carries the minimum needed for that purpose — no account, profile or usage history is sent to any of them, because none exists.
| Provider | Purpose | Region |
|---|---|---|
| Open Beauty Facts | Optional barcode lookup. Only the barcode itself is sent, to fetch a public product name, brand and category. No device identifier, account or other product data is included, and the lookup only runs when you ask for it. | France / EU (public open database) |
| Apple Weather (WeatherKit) | Optional UV Index only. If you turn UV Index on, an approximate location is sent to Apple to retrieve the current UV reading and the nearby place name shown on the card. Nothing about you or your products is sent. | Apple, global |
12. Security
- Your data is protected by the same on-device encryption and sandboxing Apple applies to every app's local storage.
- There is no developer-operated server, so your data is never uploaded to one. Any outside connection the app makes is listed under Service providers above and uses HTTPS.
- Vanilyst does not currently offer any in-app purchase or subscription — no payment or billing information is collected.
- If you export a backup file, its security in transit and at rest becomes your responsibility once it leaves the app.
No system is perfectly secure. If you believe you have found a security issue, email support@adarshyadav.com and it will be looked at promptly.
13. Your rights
Regardless of where you live, you can exercise all of the following:
- Access — request a copy of the data held about you.
- Correction — fix anything inaccurate.
- Deletion — remove any data you have entered, at any time, from within the app.
- Portability — export your data in a machine-readable format.
- Objection and restriction — object to or limit certain processing.
- Withdraw consent — for anything based on consent, at any time.
Most of these are self-service inside the Service. For anything else, email support@adarshyadav.com and it will be actioned within 30 days.
14. Regional privacy rights
The rights above are offered to everyone, everywhere. Some regions add specific rights or wording, set out below. Exercising any of them is free, and you will never be treated differently for doing so.
| Region | Framework | What it adds |
|---|---|---|
| European Economic Area | GDPR | Legal bases as listed above, data portability, objection to processing, and the right to lodge a complaint with your supervisory authority. |
| United Kingdom | UK GDPR & Data Protection Act 2018 | The same rights as the EEA, with complaints directed to the Information Commissioner's Office (ico.org.uk). |
| California | CCPA / CPRA | Rights to know, delete, correct and opt out of sale or sharing. No personal information is sold or shared for cross-context behavioural advertising, so there is nothing to opt out of. Sensitive information is used only to provide the Service. |
| Canada | PIPEDA | Access and correction rights, meaningful consent, and the right to complain to the Office of the Privacy Commissioner of Canada. |
| Brazil | LGPD | Confirmation of processing, access, correction, anonymisation, portability, deletion, and information about data sharing. |
If your region is not listed, the rights in the previous section still apply — email support@adarshyadav.com and your request will be handled the same way.
No authorised agent, verification fee or account requirement stands between you and these rights. Requests are verified only to the extent needed to confirm you are the person the data relates to.
15. Retention and deletion
There are no accounts and no backend, so there is nothing held on a server to retain or delete. Data you enter stays on your device until you delete it — either individually, by archiving or removing it in the app, or entirely by deleting the app. Any backup file you have exported persists wherever you chose to save it until you delete it yourself.
16. International transfers
The providers listed above may process data outside your country. Where personal data leaves the UK or EEA, transfers are covered by Standard Contractual Clauses or an equivalent approved safeguard.
17. Children
The Service is not directed at children under 13. If you believe a child has provided personal data that reached us directly (for example, in a support email), email support@adarshyadav.com and it will be deleted promptly.
18. Changes to this policy
If this policy changes materially, the effective date at the top of this page is updated and the current version is always available here and inside the app. Past versions are available on request.
19. Contact
Questions, requests or complaints about privacy: support@adarshyadav.com. If you are not satisfied with the response, you can complain to the data protection authority in your country.