ANDROID CLOSED-TEST PRIVACY POLICY

TriggerScan Privacy Policy

Effective date: 30 August 2026
Release status: Android closed testing only; TriggerScan is not publicly released
Controller/publisher: StarSpun Labs Ltd, company number 17372613, using the public developer name StarSpun Labs
Registered office: Office 9267OC, 182–184 High Street North, Area 1/1, East Ham, London, E6 2JA, United Kingdom
Privacy and support: contact@starspunlabs.com

AccountNo StarSpun account
Ads/analyticsNone
Current test accessUp to eight successful scans per rolling 24 hours; no purchase flow
Connected serviceCloudflare Worker and OpenAI text transcription

1. What TriggerScan does

TriggerScan is an informational ingredient-label review aid. A user can photograph a label or choose a saved image, have an online service transcribe the visible wording, review and correct that wording, and then compare the confirmed text with selected histamine and salicylate references on the Android device.

TriggerScan is not a medical device and does not diagnose, treat, cure or prevent any medical condition. Results may be incomplete or incorrect. Always check the original ingredient label and ask a qualified healthcare professional about symptoms, diagnosis or treatment. Do not rely on TriggerScan as the sole basis for deciding whether a product is suitable for you.

TriggerScan has no StarSpun account, advertising, behavioural analytics or cross-app tracking.

2. Information used on the Android device

Depending on use, TriggerScan keeps the following information locally:

The private credential and photo-processing acknowledgement use Android protected storage. Working images use app cache, which Android may remove earlier than the periods below.

TriggerScan asks for camera permission only when the user chooses the camera. Choosing a saved image uses the Android system photo picker; the app does not request broad photo-library access. It does not request location, contacts, microphone or advertising-identifier permission.

3. What leaves the device when a user sends an image

TriggerScan first prepares and displays a resized JPEG of the complete selected frame with embedded JPEG metadata removed. Nothing is uploaded until the user taps Send image.

The app then sends the JPEG, camera-or-photo-picker source, random scan/retry identifiers and the private installation credential over an encrypted connection to a StarSpun-operated Cloudflare Worker. The Worker sends the JPEG to the OpenAI Responses API for one structured transcription and supplies a pseudonymous safety identifier derived from the installation record.

The selected histamine or salicylate profile is not sent with the image. The confirmed transcription is matched with that profile on the device, and the resulting trigger match is not uploaded. If the user corrects the transcription, the corrected wording is not sent back: the confirmation request contains an opaque token and an accepted or rejected decision.

The app does not deliberately add a name, email address, device model or Android version to the scan request. Cloudflare, OpenAI and normal network infrastructure may still receive standard connection information such as IP address, time, request headers and service diagnostics.

Photograph only the ingredient label. Do not include people, faces, addresses, prescriptions, medical records or other identifiable or sensitive information.

4. Pseudonymous service records

The Worker uses Cloudflare D1 for accountless access control, safe retries, security and abuse prevention. It is designed not to store the photograph, extracted wording, selected trigger profile, user corrections or local match result.

D1 stores or derives limited pseudonymous records: a keyed hash of the installation credential; a random entitlement subject; hashed or random request, idempotency and confirmation identifiers; a short-lived request fingerprint; scan reservation, completion, quota, timing and failure state; and provider-attempt counts. At registration, the Worker converts the connection IP address to a keyed digest for rate limiting rather than writing the raw IP address to D1.

5. Current closed-test access and retention

The current Android closed-test build provides authorised tester access. It allows up to eight successful scans per rolling 24 hours, subject to an additional service-wide safety limit. It has no active Google Play purchase or subscription flow.

Cloudflare may retain short-lived platform security, diagnostic and recovery records under the settings of StarSpun's account. Data removed from the live D1 database can remain in provider recovery history until the configured recovery window expires.

6. OpenAI and Cloudflare processing

The Worker calls the OpenAI Responses API with store set to false and does not enable tools. OpenAI states that API inputs and outputs are not used to train its models unless the customer opts in. Under standard API data controls, abuse-monitoring logs may contain input and output content for up to 30 days unless approved shorter-retention controls apply or a longer period is legally required.

Cloudflare processes the Worker request, D1 records and connection/security information needed to deliver and protect the service. TriggerScan's own code is designed not to log image bodies, Base64 data, extracted wording, installation credentials or local trigger results. Fixed error categories and aggregate maintenance counts may be logged.

7. Why information is processed

The information above is used to provide the requested transcription, let the user review it, prevent an interrupted retry being counted twice, enforce the tester allowance, prevent abuse, secure the service and investigate failures without storing label content in D1.

Providing a requested scan is based on performing the service requested by the user. Pseudonymous metering, retry protection, rate limiting and security are based on StarSpun's legitimate interests in operating and protecting the service. Support and complaint handling may rely on legitimate interests, contract, legal obligations or legal claims, depending on the circumstances.

8. Recipients and international processing

The principal recipients are Cloudflare, which hosts the Worker and D1; OpenAI, which transcribes the submitted image; Google Play and Android platform services for app distribution and platform functions; and StarSpun's website and support-email providers when a user opens a web page or contacts StarSpun.

These providers may process information outside the United Kingdom. StarSpun uses the processor terms and international-transfer safeguards required for its chosen services.

9. Support, tester administration and the website

If a person contacts StarSpun, joins the closed test, submits feedback or makes a privacy request or complaint, StarSpun receives the information that person supplies. This may include an email address, Reddit username, Android device model/version, selected test apps, participation dates, message, screenshot or attachment. TriggerScan does not automatically send those tester details or support messages.

Ordinary support correspondence is normally retained for 12 months after the matter closes unless a dispute, security incident, legal claim or legal obligation requires longer. Closed-tester administration records are retained while needed to operate and evidence the test and meet release requirements, then deleted or minimised. A tester may request correction or deletion using the contact route below.

The StarSpun website uses no advertising, behavioural analytics or marketing cookies. It is delivered using Cloudflare, which may process standard connection and security information such as IP address, time, requested page and browser information.

10. User controls, deletion and rights

A user can cancel before sending, discard a pending scan, leave a result, clear TriggerScan's Android storage or uninstall the app. Clearing storage or uninstalling removes the app's local records and private credential. It does not instantly erase information already processed in Cloudflare or OpenAI systems.

Send a privacy or deletion request to contact@starspunlabs.com or use the data-request route. Because connected-service records are deliberately pseudonymous and TriggerScan does not currently display a support lookup identifier, StarSpun may not always be able to link a D1 record to an email address. We will explain what can be located and deleted in response to a request and will not ask for unnecessary label or health information.

Depending on the circumstances, a person may have rights to access, correct, erase, restrict, object to or receive a copy of personal information held by StarSpun, and to withdraw consent where consent is the basis used. These rights do not necessarily apply to genuinely anonymous information or local-only data StarSpun does not hold.

A complaint may be submitted through the complaints route or directly to the UK Information Commissioner's Office. A person does not need to complete StarSpun's process first.

11. Children, security and changes

TriggerScan is a general informational utility and is not directed specifically to children under 13. A parent or guardian may use it on behalf of a child, but users must not upload photographs of a child, prescriptions, medical records or other identifiable health material.

TriggerScan minimises connected data, removes image metadata, uses encrypted network connections and private installation credentials, and keeps profile matching on the Android device. No technical measure is infallible.

This policy will be reviewed before any release changes the image provider, data controls, database fields, logging, allowance, purchase model, target audience, permissions or connected features. A future public release will receive a further policy and Google Play Data safety review before it is made available.