NoTox Lens Privacy Policy

Effective date: June 16, 2026

NoTox Lens is an educational cosmetic ingredient reference app published by PByte. The app helps users photograph cosmetic ingredient labels, extract visible ingredient names with AI, review matched ingredient references, and save products locally on their device.

Data We Collect

NoTox Lens does not sell data, show advertising, use tracking SDKs, or use data for cross-app tracking. We collect the data needed to provide AI label analysis, apply monthly quota, unlock Premium, and monitor AI token/cost usage.

AI Label Analysis

When you start an AI scan, NoTox Lens sends the label photo, image type, locale, app version, install hash, device-vendor hash, account hash, and optional local text hint to the NoTox analysis service. These hashes are SHA-256 pseudonymous identifiers; the raw install identifier, raw iOS identifierForVendor value, and raw Apple user identifier are not sent to the backend. The service uses Gemini to extract visible cosmetic ingredient names and returns structured results to the app. Raw label image bytes are used for analysis and are not stored by default.

Reference Contributions

NoTox may offer an optional reference contribution flow after analysis. If you explicitly choose to contribute a scan, NoTox may store the structured AI result as a reference candidate for moderation. If you separately agree to photo storage, the label image may be stored in a private backend bucket so the submitted reference can be reviewed. Reference contributions are not required for AI analysis.

Account and Usage Tracking

Sign in with Apple is required before AI scans. NoTox requests Apple email and full name for account display; Apple may provide them only on first authorization or after you revoke and re-authorize the app. If provided, those values are stored locally for account display only. The raw Apple user identifier and a random install identifier are stored locally in iOS Keychain. NoTox also reads iOS identifierForVendor for abuse prevention. NoTox sends SHA-256 account, install, and device-vendor hashes to the backend so we can apply the free monthly AI limit, prevent delete/reinstall quota resets, unlock Premium, and track usage. Backend records may include account hash, install hash, device-vendor hash, image hash, model name, prompt/output token counts, total tokens, estimated cost, scan count, latency, and structured AI analysis output.

Saved Products

Saved products, unmatched label terms, AI result snapshots, and watchlist items are stored locally on your device. They are not synced to the NoTox backend.

Device Permissions

NoTox Lens requests camera permission only when you choose to analyze a product label. If camera is unavailable, the app may use the system photo picker so you can choose a label image without granting broad photo-library access. NoTox Lens does not request location, contacts, Bluetooth, HealthKit, calendar, reminders, or motion permissions. Pasteboard content is not read automatically.

Local Data Controls

You can remove saved products and watchlist items from the Data & Privacy screen inside the app. You can remove the local Sign in with Apple mapping from Account settings. You can also delete the app to remove its local app data from your device. To prevent free quota abuse, NoTox may retain a minimal pseudonymous monthly quota record until the quota period and short retention window close.

Subscriptions

NoTox Premium is sold through Apple StoreKit. The app sends the current client subscription state and product id to the backend for quota handling. Purchases, billing, cancellation, and refunds are handled by Apple.

Educational Reference Notice

NoTox Lens is not medical advice. It does not diagnose allergies, predict irritation, assess pregnancy use, rate disease risk, measure sunscreen efficacy, or judge whether a complete product is appropriate for any person or use. Unmatched ingredients mean the label term was not found in the bundled library.

Children

NoTox Lens is not directed to children.

Changes

If this policy changes, the updated version will be posted on this page with a new effective date.

Contact

For privacy questions, contact support@pbyte.bg.