ANDROID CLOSED-TEST PRIVACY POLICY
TriggerScan Privacy Policy
Effective date: 30 August 2026
Release status: Android closed testing only; TriggerScan is not publicly released
Controller/publisher: StarSpun Labs Ltd, company number 17372613, using the public developer name StarSpun Labs
Registered office: Office 9267OC, 182–184 High Street North, Area 1/1, East Ham, London, E6 2JA, United Kingdom
Privacy and support: contact@starspunlabs.com
1. What TriggerScan does
TriggerScan is an informational ingredient-label review aid. A user can photograph a label or choose a saved image, have an online service transcribe the visible wording, review and correct that wording, and then compare the confirmed text with selected histamine and salicylate references on the Android device.
TriggerScan is not a medical device and does not diagnose, treat, cure or prevent any medical condition. Results may be incomplete or incorrect. Always check the original ingredient label and ask a qualified healthcare professional about symptoms, diagnosis or treatment. Do not rely on TriggerScan as the sole basis for deciding whether a product is suitable for you.
TriggerScan has no StarSpun account, advertising, behavioural analytics or cross-app tracking.
2. Information used on the Android device
Depending on use, TriggerScan keeps the following information locally:
- the selected trigger profile;
- a reference to the camera image or system-selected photo while it is prepared;
- a resized JPEG working copy with embedded metadata removed;
- the accepted photo-processing explanation and acceptance date;
- a private pseudonymous installation credential, plus random scan and retry identifiers;
- the returned transcription and corrections made by the user;
- the on-device trigger-match result needed to show the current result;
- a temporary retry copy after an interrupted scan; and
- one current result-image preview in temporary app cache.
The private credential and photo-processing acknowledgement use Android protected storage. Working images use app cache, which Android may remove earlier than the periods below.
TriggerScan asks for camera permission only when the user chooses the camera. Choosing a saved image uses the Android system photo picker; the app does not request broad photo-library access. It does not request location, contacts, microphone or advertising-identifier permission.
3. What leaves the device when a user sends an image
TriggerScan first prepares and displays a resized JPEG of the complete selected frame with embedded JPEG metadata removed. Nothing is uploaded until the user taps Send image.
The app then sends the JPEG, camera-or-photo-picker source, random scan/retry identifiers and the private installation credential over an encrypted connection to a StarSpun-operated Cloudflare Worker. The Worker sends the JPEG to the OpenAI Responses API for one structured transcription and supplies a pseudonymous safety identifier derived from the installation record.
The selected histamine or salicylate profile is not sent with the image. The confirmed transcription is matched with that profile on the device, and the resulting trigger match is not uploaded. If the user corrects the transcription, the corrected wording is not sent back: the confirmation request contains an opaque token and an accepted or rejected decision.
The app does not deliberately add a name, email address, device model or Android version to the scan request. Cloudflare, OpenAI and normal network infrastructure may still receive standard connection information such as IP address, time, request headers and service diagnostics.
Photograph only the ingredient label. Do not include people, faces, addresses, prescriptions, medical records or other identifiable or sensitive information.
4. Pseudonymous service records
The Worker uses Cloudflare D1 for accountless access control, safe retries, security and abuse prevention. It is designed not to store the photograph, extracted wording, selected trigger profile, user corrections or local match result.
D1 stores or derives limited pseudonymous records: a keyed hash of the installation credential; a random entitlement subject; hashed or random request, idempotency and confirmation identifiers; a short-lived request fingerprint; scan reservation, completion, quota, timing and failure state; and provider-attempt counts. At registration, the Worker converts the connection IP address to a keyed digest for rate limiting rather than writing the raw IP address to D1.
5. Current closed-test access and retention
The current Android closed-test build provides authorised tester access. It allows up to eight successful scans per rolling 24 hours, subject to an additional service-wide safety limit. It has no active Google Play purchase or subscription flow.
- A pending local image and retry record are removed when the scan finishes or the user discards it, and are rejected and removed on the next recovery check after 24 hours.
- The current result-image preview is removed when the user leaves the result or starts another image flow; Android may remove cache sooner.
- Provider-attempt records are retained only for the relevant abuse-prevention window, currently no more than 24 hours.
- A completed request fingerprint is replaced with a fixed content-free value after the 15-minute safe-retry period.
- Closed-test metering rows become eligible for deletion after the 30-day accounting window and 15-minute safe-retry period.
- Failed or unmetered scan rows become eligible for deletion after the retry and provider-attempt windows have cleared.
- An unused registration with no scan record becomes eligible for deletion after 90 days of inactivity.
Cloudflare may retain short-lived platform security, diagnostic and recovery records under the settings of StarSpun's account. Data removed from the live D1 database can remain in provider recovery history until the configured recovery window expires.
6. OpenAI and Cloudflare processing
The Worker calls the OpenAI Responses API with store set to false and does not enable tools. OpenAI states that API inputs and outputs are not used to train its models unless the customer opts in. Under standard API data controls, abuse-monitoring logs may contain input and output content for up to 30 days unless approved shorter-retention controls apply or a longer period is legally required.
Cloudflare processes the Worker request, D1 records and connection/security information needed to deliver and protect the service. TriggerScan's own code is designed not to log image bodies, Base64 data, extracted wording, installation credentials or local trigger results. Fixed error categories and aggregate maintenance counts may be logged.
7. Why information is processed
The information above is used to provide the requested transcription, let the user review it, prevent an interrupted retry being counted twice, enforce the tester allowance, prevent abuse, secure the service and investigate failures without storing label content in D1.
Providing a requested scan is based on performing the service requested by the user. Pseudonymous metering, retry protection, rate limiting and security are based on StarSpun's legitimate interests in operating and protecting the service. Support and complaint handling may rely on legitimate interests, contract, legal obligations or legal claims, depending on the circumstances.
8. Recipients and international processing
The principal recipients are Cloudflare, which hosts the Worker and D1; OpenAI, which transcribes the submitted image; Google Play and Android platform services for app distribution and platform functions; and StarSpun's website and support-email providers when a user opens a web page or contacts StarSpun.
These providers may process information outside the United Kingdom. StarSpun uses the processor terms and international-transfer safeguards required for its chosen services.
9. Support, tester administration and the website
If a person contacts StarSpun, joins the closed test, submits feedback or makes a privacy request or complaint, StarSpun receives the information that person supplies. This may include an email address, Reddit username, Android device model/version, selected test apps, participation dates, message, screenshot or attachment. TriggerScan does not automatically send those tester details or support messages.
Ordinary support correspondence is normally retained for 12 months after the matter closes unless a dispute, security incident, legal claim or legal obligation requires longer. Closed-tester administration records are retained while needed to operate and evidence the test and meet release requirements, then deleted or minimised. A tester may request correction or deletion using the contact route below.
The StarSpun website uses no advertising, behavioural analytics or marketing cookies. It is delivered using Cloudflare, which may process standard connection and security information such as IP address, time, requested page and browser information.
10. User controls, deletion and rights
A user can cancel before sending, discard a pending scan, leave a result, clear TriggerScan's Android storage or uninstall the app. Clearing storage or uninstalling removes the app's local records and private credential. It does not instantly erase information already processed in Cloudflare or OpenAI systems.
Send a privacy or deletion request to contact@starspunlabs.com or use the data-request route. Because connected-service records are deliberately pseudonymous and TriggerScan does not currently display a support lookup identifier, StarSpun may not always be able to link a D1 record to an email address. We will explain what can be located and deleted in response to a request and will not ask for unnecessary label or health information.
Depending on the circumstances, a person may have rights to access, correct, erase, restrict, object to or receive a copy of personal information held by StarSpun, and to withdraw consent where consent is the basis used. These rights do not necessarily apply to genuinely anonymous information or local-only data StarSpun does not hold.
A complaint may be submitted through the complaints route or directly to the UK Information Commissioner's Office. A person does not need to complete StarSpun's process first.
11. Children, security and changes
TriggerScan is a general informational utility and is not directed specifically to children under 13. A parent or guardian may use it on behalf of a child, but users must not upload photographs of a child, prescriptions, medical records or other identifiable health material.
TriggerScan minimises connected data, removes image metadata, uses encrypted network connections and private installation credentials, and keeps profile matching on the Android device. No technical measure is infallible.
This policy will be reviewed before any release changes the image provider, data controls, database fields, logging, allowance, purchase model, target audience, permissions or connected features. A future public release will receive a further policy and Google Play Data safety review before it is made available.