Privacy Policy
Last updated: 7 May 2026
This Privacy Policy explains what information Peanut collects, how it is used, and the choices you have. By using Peanut you agree to this Policy.
1. Information we collect
From owners (people who create tags):
- Account information: phone number or email used to sign in, display name, and any profile photo you upload.
- Tag content: the fields you store on each tag (name, photo, notes, contacts, medical info), and your visibility settings for each field.
- Push notification token: a device-specific identifier used to deliver notifications to your phone.
From scanners (people who scan a tag):
- The message body they send.
- An optional name and contact (email or phone) if they choose to share it.
- The IP address and approximate timestamp of the request, used for abuse prevention.
2. How we use information
- To operate the Service: deliver scan messages to owners, notify owners of new messages.
- To enforce our Terms and prevent abuse.
- To respond to support requests.
We do not sell personal information. We do not use it for advertising or third-party tracking.
3. Visibility of tag fields
A scanner viewing a public scan page only sees the fields the owner has marked visible. Owner identity, push tokens, raw account identifiers and fields not marked visible are never returned to scanners.
4. Push notifications
We use Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM) — relayed via Expo’s push service — to deliver alerts to your device. The notification token is stored against your account so we can target the right device.
5. Storage and security
Data is stored in Supabase Postgres (region: ap-south-1, Mumbai). Owner data is protected by row-level security so a user can only access their own rows. Scanner-facing reads go through purpose-built database functions that filter fields by visibility. Service-level secrets are stored in environment variables and never shipped to clients.
6. Data retention
- Tags and messages persist until you delete them or close your account.
- Scanner IPs are retained for up to 90 days for abuse triage.
- You can request deletion of your account at any time (see Contact).
7. Your rights
Depending on your jurisdiction, you may have the right to access, correct, or delete your personal information, and to object to certain processing. To exercise these rights, email us.
8. Children
Peanut is not directed to children under 13. If you create a tag for a child, you must be the child’s legal guardian or have appropriate consent.
9. Third parties
We use the following service providers solely to operate the Service:
- Supabase — database, auth, file storage.
- Vercel — hosting for the public scan page.
- Expo / Apple APNs / Google FCM — push notification delivery.
These providers process data on our behalf under their own security and privacy commitments.
10. Changes
We may update this Policy. Material changes will be announced in the app or by email; continued use indicates acceptance.
11. Contact
Questions or requests? Email support@inyralabs.com.