Salus Privacy Policy
Last updated: 3 August 2026 Provided by: Teal Networks LLC, 725 Main Street Suite 100, Woodland CA, 95695 Contact: support@teal.net
The short version
Salus is built so that most of what it knows about you never leaves your phone. Your body measurements, health preferences, and scan history are stored as files on your device.
You can use Salus without an account. Scanning, scores, ingredient ratings, better choices, and the pregnancy, allergy and keto checks all work in Guest mode, and in Guest mode we never learn your name or email address. An account is needed only for Salus Pro and the AI explanations that come with it, because a subscription has to belong to a person rather than to a handset.
If you do create an account, these leave your phone:
1. An email address — one you type, or the address Apple passes us when you use Sign in with Apple. If you choose Apple's Hide My Email, we only ever see the relay address, never your real one. 2. A name, if you give one. Optional, and used to greet you.
Whether or not you have an account, these leave your phone:
3. A barcode, when you scan something — sent to Open Food Facts to look the product up, and to our own server so the product is added to our catalog. 4. A random installation ID, so the server can tell one device from another. 5. Product details and, if you turn it on, your calculated daily nutrition targets — sent to our server and on to xAI when you ask for an AI explanation. 6. A photograph of a package, only if you ask us to read one. Salus reads nutrition labels on your phone by default and uploads nothing. If that reading comes back thin and you tap Ask our reader, that one photo is sent to our server, read by xAI, and kept against the product's barcode — not against you — so a person can check the values that came out of it. This is off until you agree to it, in front of the button, and you can turn it off again in Profile → Label photos. 7. Nothing else about a scan. Not your score, not your history, not the time you scanned it.
You can delete your account, and everything identifying you with it, from inside the app at any time. See Your choices.
What we collect, and where it lives
Stays on your device, always
- Your profile: height, weight, age, biological sex, activity level, goal.
- Your health preferences: pregnancy mode, allergy selections, nutrient limits and
goals.
- The cached product records behind your history — the facts and scores themselves.
- Your scan history, in Guest mode. With no account there is nowhere to sync it to, so
the list is never assembled anywhere but your phone.
These are ordinary files in the app's private storage. We cannot read them, we have no copy, and deleting the app deletes them. They are included in an encrypted iPhone backup if you make one; that backup is between you and Apple.
Sent to Open Food Facts
When you scan, the barcode goes to Open Food Facts, a public non-profit food database, to retrieve product information. No identifier of yours accompanies it. Their privacy practices are their own: https://world.openfoodfacts.org/
Your account, if you create one
Guest mode creates no account and this whole section does not apply to you.
- Your email address, stored so you can sign back in and so we can reach you about
your subscription. We do not send marketing email and there is no mailing list to be on.
- A password, if you signed up with one. Stored only as a PBKDF2-HMAC-SHA256 hash with
a random per-account salt — we cannot read your password, and neither can anyone who obtains a copy of our database.
- Sign in with Apple: Apple sends us a signed token containing a stable identifier for
you, and an email address. If you chose Hide My Email that address is a relay Apple operates, and your real address is never disclosed to us. We keep the identifier so the same person signing in next month reaches the same account.
- Which devices you are signed in on, as an installation identifier per device, so you
can sign out of one without signing out of all of them.
- Your scan history, so it follows you to a new phone rather than dying with the old
one. For each product: its barcode, its name and brand, its picture, the score it had when you scanned it, how many times you have scanned it, and when you last did.
Not a trail of individual scans. We keep one row per product with a count and a last-seen date, not a timestamped record of every time you picked something up. The finer-grained version would be a surveillance record with no feature to justify it.
Signing in on a phone that already has history adds that history to your account rather than replacing it, and nothing is deleted from either side by the merge. You can clear the whole list at any time from the History screen, which clears our copy too.
Your account is linked to your subscription and to any corrections you have submitted. It is not linked to your scan history, your body measurements, or your health preferences — those never reach us at all, with or without an account.
Sent to our server
- A random installation identifier (a UUID generated on your device). Not your phone
number, advertising ID, or device serial. It exists so contributions can be attributed to a consistent submitter — so a reviewer cannot approve their own — and so a subscription can be recognized.
- The barcode of a product you scan, so that product is added to our catalog. We keep
our own product database, seeded from Open Food Facts and corrected by hand, because a scanner is only as good as the records behind it.
The catalog entry is not linked to you. The request is authenticated so that strangers cannot write to our database, and your installation identifier is then discarded rather than stored: the catalog records how many times a product has been scanned and when it was last seen, and nothing about who scanned it. That is separate from your own history above, which is linked to your account when you have one and stays on your phone when you don't.
- Product data you submit as a correction, plus any note you write.
- A photograph of a package, if and only if you ask us to read one. See **Label
photographs** below.
- A record of your subscription status, from Apple's receipt.
- The product being explained, when you request an AI explanation: its name, brand,
barcode, category, ingredients, and the score factors Salus computed.
Sent to xAI, only if you turn it on
If — and only if — you enable "Let explanations use my targets and scanning", two things are included in the AI request.
Your calculated daily figures. For example: *"2,400 kcal, protein 79g, fiber 34g, sodium under 1,500mg."*
A summary of your recent scanning. How many times you have scanned the product in your hand before and roughly how long ago, how many things you have scanned in the last seven days, and their average score. For example: *"They have picked this exact product up 3 times before, most recently 4 days ago. In the last week they have scanned 11 things, averaging 62 out of 100."*
The list of what you scanned is never sent — only those counts and that average. A record of what somebody eats is not something we will hand to anybody, and no sentence in a speech bubble is worth sending one for.
Your name is never sent. Salus greets you by name on your own screen, using the name already stored on your phone. The AI is not told it, and does not know who it is writing for.
Your height, weight, age, and biological sex are never transmitted. Only the figures derived from them.
This setting is off by default and is separate from the switch that turns personalized scoring on, because sending data off the device is a materially different thing from calculating something on it.
Explanations that include your figures are never cached and never shared with any other user.
AI explanations are generated by xAI (https://x.ai/), which processes the request on its own systems under its own terms and privacy policy. We send it the product being explained and, only with the switch above turned on, your derived targets. We do not send your name — we do not have one — your installation identifier, your scan history, or your body measurements.
What xAI then does with a request is governed by xAI, not by us. We are not in a position to promise on their behalf that a request is never retained or never used to improve their models; if that matters to you, read their policy at https://x.ai/legal/, and note that the sharing switch is off by default and that explanations are an optional feature you can simply not use. Everything else in Salus — the score, the ingredient ratings, the allergen and pregnancy checks — is computed on your phone and involves no third party at all.
Label photographs, only if you ask for one
Filling in a product Open Food Facts has never heard of means transcribing its Nutrition Facts or Supplement Facts panel. Salus reads those panels on your phone, using Apple's on-device text recognition. That is the default, it is free, it works with no signal, and no image leaves the handset.
On-device recognition is also imperfect on small, glossy, or badly lit print, and it sometimes returns four rows off a panel printing twenty. When that happens the scanner offers a second reader that is much better at the job and does not run on your phone. Tapping it does all of the following, which is why we ask first and ask once, on a screen in front of the button rather than in a settings menu:
- The photo you just took is sent to our server, together with the product's barcode and
whether it is a food or a supplement. Nothing else. Not your name, your account, your installation ID, your history, or your location.
- From there it goes to xAI, embedded in the request itself rather than published at a
URL, so at no point is the image reachable from the internet by anyone who has a link.
- We keep it, filed against the barcode, and it is shown to whoever reviews the
catalog beside the values that were read off it. That is the point of keeping it: a machine transcribing six-point type gets things wrong, and a stored photograph is the only way a wrong figure is ever found and corrected for everybody. A reading with no evidence behind it would be a rumour we scored people's food against.
- It is not linked to you. As with a scan, the request is authenticated so strangers
cannot write to our database and your installation identifier is then discarded. We do not record who photographed which product, and there is therefore no per-person photo history — ours or yours — to hand over or to delete.
- It is deleted after 12 months, automatically, whether or not anyone has looked at it.
Two things worth saying plainly. Only the photo you took is sent — there is no access to your camera roll, then or ever; the app has no photo-library permission at all. And whatever is in frame goes with it, so the consent screen asks you to photograph the package and nothing else.
Values read from a photograph are marked as unchecked in the form and are never written to the product record on their own. You check them against the packet, they become a contribution like any other, and a second person reviews it before anybody else sees it.
This is off by default. Reading labels on your device is unaffected either way, and turning the switch off in Profile → Label photos stops any further photo being sent.
What we never collect
- Your phone number
- Your location
- Your contacts, or anything from your camera roll — the app never asks for photo-library
access, so the only image it can send is one you take inside it and ask us to read
- Advertising identifiers
- Analytics or third-party trackers of any kind
- Your name or email address in Guest mode. With an account we hold the address you
signed up with and nothing more.
The camera feed never leaves the phone. Barcode scanning and label reading both run on your device, and the video stream is processed frame by frame and discarded.
One photograph can leave the phone, and only when you tap the button that says so. If you ask our reader to look at a label you photographed, that single still image is uploaded — see Label photographs above for exactly what happens to it. Until you agree to that, and after you switch it off again, nothing you photograph is uploaded at all.
*This paragraph previously read "Photographs are never uploaded." That was true of every version of Salus before label reading existed, and it is no longer true, so it has been rewritten rather than quietly narrowed.*
Health data
Your body measurements and health preferences are health-related information, and we treat them that way:
- They are stored only on your device.
- Nothing derived from them is transmitted without separate, explicit consent — the
AI sharing switch, off by default.
- Even with consent, only derived targets go out, never the underlying measurements.
- Personalized AI responses are never cached or reused for anyone else.
- Energy targets require an age of 18 or over. Salus does not compute body-based figures
for minors.
Consumer Health Data Privacy Policy
*This section is the Consumer Health Data Privacy Policy required by the Washington My Health My Data Act, and applies to residents of Washington and Nevada. It is linked from our homepage. It applies in addition to everything above, and where it is more protective, it governs.*
What consumer health data we collect. On our servers, none. The information that could be considered consumer health data — your height, weight, age, biological sex, activity level, goal, pregnancy mode, allergy selections, and nutrient limits — is created on your phone, stored on your phone, and never sent to us. We hold no copy and cannot read it.
Three things related to it do leave your device, and only these:
1. Derived nutrition targets, and only if you switch on "Let explanations use my targets and scanning", which is off until you turn it on. These are figures like "2,400 kcal, protein 79 g, sodium under 1,500 mg". The measurements they were calculated from are never sent. 2. Counts drawn from your scan history, behind that same switch: how many times you have scanned the product in front of you, how many things you scanned in the last seven days, and their average score. The list itself never leaves your phone — what you scanned, in order and over time, stays there. 3. The barcode of a product you scan, which is sent to build our product catalog. It is not linked to you: the request is authenticated so strangers cannot write to our database, and your installation identifier is then discarded rather than stored.
Where it comes from. From you, typed into the app. We collect no health data from any other source, and we do not infer it from your scans.
What we use it for. The derived targets and the scan counts are used once, to write the AI explanation you asked for, and are then gone. Barcodes are used to build the product catalog. Neither is used for advertising, profiling, or any purpose you did not ask for.
Who we share it with.
- xAI, and only the derived targets and those scan counts, and only when you have
turned the switch on and requested an explanation. See "Sent to xAI" above.
- Nobody else. We do not share consumer health data with any other third party.
We do not sell consumer health data. Not for money and not for anything else of value. No such sale has ever occurred, and none is planned. If that ever changes we would need your separate written authorization first, and we would ask for it.
No employee or contractor has access to consumer health data on our servers, because there is none there to access.
Your rights. You may ask us to confirm whether we hold consumer health data about you, to give you a copy of it, to delete it, and to withdraw a consent you previously gave. To exercise any of them, email support@teal.net from any address and include the installation identifier the app shows in Profile → About. We will respond within 45 days, and will tell you if we need a further 45, which the law allows.
Two honest notes about what those rights mean here:
- Because we hold no consumer health data on our servers, an access or deletion request will
usually be answered by telling you so. The data is on your phone: deleting the app deletes it, and Profile has controls for clearing history and cached products individually.
- Because we hold no name or email address, **we cannot identify you from our records
alone.** That is deliberate. It is also why a request needs the installation identifier from your device — without it we have nothing to look up.
Withdrawing consent takes effect immediately and needs no email: turn off Profile → Tailored to you → AI explanations. Nothing derived from your measurements, and nothing drawn from your scan history, is sent after that.
If we deny a request we will say why, and you may appeal by replying to that decision. If we deny the appeal we will tell you how to complain to the Washington Attorney General.
Retention
On your device: until you delete it in the app or remove the app.
On our server:
- Your account — email address, sign-in identifier, subscription status, and scan
history — persists until you delete it, which you can do from inside the app at any time. Clearing your history removes those rows immediately without closing the account.
- Your installation ID persists while that installation exists, and is removed with the
account it belongs to.
- Contributions you submit persist as part of the product record, since that is their
purpose — a correction that expired would undo itself.
- Product records and scan counts persist as our catalog. They describe products, not
people, and carry no identifier of yours.
- AI requests are not retained at all. We do not keep the request, the prompt, or any log
of who asked for what. What we keep is the generated answer, stored against the product and the score it explains, with no user attached — so that the next person to scan the same product reads the same explanation instead of paying to generate it again. A personalized explanation, one that used your targets, is never stored, not even as an answer.
- A report you file about a bad answer keeps your installation ID alongside the flagged
text, because a complaint nobody can trace back to a specific answer cannot be investigated. These are deleted automatically after 12 months.
- A label photograph you asked us to read, and the values read off it, are kept against
the product's barcode with no identifier of yours, and are **deleted automatically after 12 months** — reviewed or not, useful or not. Deletion removes the image file and the row together.
Your choices
- Turn off AI sharing — Profile → Tailored to you → AI explanations. Immediate.
- Stop sending label photos — Profile → Label photos. Immediate, and it is off unless you
turned it on. Photos already sent are deleted on the 12-month schedule above; because they carry no identifier of yours, ask at support@teal.net with the barcode if you want a specific one removed sooner.
- Clear your history — the History screen. With an account this clears our copy as
well as the one on your phone.
- Keep your history off our servers entirely — use Guest mode.
- Clear cached products — History → the gear beside Clear.
- Use Salus without an account — choose Guest mode. Everything except Salus Pro works.
- Sign out — Profile → the gear → Sign out. Signing out on one device leaves your
other devices signed in; "sign out everywhere" ends every session at once.
- Delete your account — Profile → the gear → Delete Account, at the bottom. This
removes your email address, your sign-in identifier, your devices, and your Salus Pro entitlement immediately and permanently. Corrections you submitted stay in the product database, unlinked from you, because other people's product records now depend on them.
Deleting your account does not cancel your Apple subscription. Only you can do that, in Settings → your name → Subscriptions on your iPhone, and Apple will keep charging you until you do. Cancel first, then delete.
- Delete everything local — delete the app. Local data goes with it.
- Requests about server data —
support@teal.net. If you have an account, write from
the address you signed up with. In Guest mode we will ask for your installation ID, which the app shows in Profile.
In Guest mode we hold no name or email, so we generally cannot identify you from server data alone. That is deliberate, and it is why a Guest deletion request needs the installation ID from your device.
Children
Salus is not directed to children under 13 and we do not knowingly collect data from them. Body-based targets require an age of 18 or over.
Changes
Material changes will be reflected here with a new date, and — where consent is involved — asked for again rather than assumed.
Not medical advice
Salus provides information, not medical advice, diagnosis, or treatment. Scores follow published U.S. dietary guidance; they are not a clinical assessment of you. Talk to a clinician about your diet, and never use Salus to make a decision about medication.