Lifaio Privacy Policy

Last updated: August 10, 2026

Protecting your privacy is central to how Lifaio is designed. This policy explains how we handle your information when you use our mobile application (the “App”). By using Lifaio , you agree to the practices described in this policy.

1. Who we are

Lifaio is an independent application developed and operated by Technologies Marco Prive , located at 1250 boulevard René-Lévesque Ouest, bureau 2200, Montréal, Québec, Canada H3B 4W8. It is not affiliated with any government agency (Health Canada, FDA, CPSC, etc.).

2. The data we collect

If you create an account or use certain features of the application, we may collect the following information:

  • Your email address: used for account creation, authentication, sending the recall alerts you request, and account-related communications (password reset, confirmation, etc.).
  • Your password: never stored in plain text — only in hashed form (irreversibly encrypted), following industry standards (PBKDF2-SHA256).
  • Your IP address at signup: retained temporarily (60 days maximum) for security purposes — preventing abuse of the permanent Free plan and fraudulent login attempts. It is automatically deleted after this period, and immediately erased if you delete your account before then.
  • Your active country and province/state: recorded to apply the correct law and regulations to your situation, and to be able to reach you if a market is ever removed from service. Updated every time you change country in the app.
  • Province/state of your account: used to show province-level content (such as store flyers valid only where a banner operates) and for merchant anti-abuse checks. Detected automatically from GPS when missing, and always editable in Settings → Account.
  • Your approximate GPS location: may be collected when you enable location-based features, to help provide relevant regional recall information and app functionality.
  • Merchant business addresses: may be collected when you submit or interact with merchant offers, listings, or related location-based content in the site or app.
  • Your declared allergies stay on your device. They are health data, and they are never sent to our servers — regardless of any setting. We cannot see them.
  • Your other optional preferences (recall recency window, display settings): linked to your account, unless you enable “Keep my data only on this device” (mandatory for Europe, the United Kingdom, Australia, Brazil, Mexico, Argentina, and Chile; optional for Canada and the United States).
  • Your account number (format LIF-XXXXXXXX): an internal identifier that lets us link your data without using your name or email address.
  • Notification settings, if you enable them: the technical address of your device and which types of alerts you want to receive.
  • Community contributions: when you publish a deal, a coupon, a wish, an out-of-stock report, or a weather observation, that content is stored and visible to other users. Your email address is never shown.
  • Reports and badges: if you report a listing or award a badge to a merchant, we record it in order to apply our moderation rules. Badges are only displayed once three different people have given the same one.
  • Advisory reports (optional): if you submit a community advisory report, we store the municipality, the official link you provide, your optional description, your account email, and — if available — the app’s last known approximate position. The report is published immediately, labelled as a not-verified community report with its official link; your email is never displayed. Reports are community-moderated (votes) and expire automatically.
  • Lost-pet listings (optional): if you post a lost-pet listing, we store the pet’s name, species, description, photo, safety notes, last-seen position, and your account email (never displayed to other users). “I saw it” reports store the finder’s predefined choices, optional approximate position, proof photo (when the pet was taken in), and the shelter/vet name and address (when applicable); the finder’s email is shared with the owner only with the finder’s explicit consent — or as a requirement they accept when they have the pet at home. Listings are hidden as soon as you mark the pet as found, and automatically deleted — photos and sighting reports included — 60 days after posting.
  • Login attempts and IP addresses, kept briefly to block abuse of user accounts and of our admin panel.
  • Establishment details, if you use LIFAIO Pro: the business name and address you enter appear on the certificates you produce. They are stored on your device, not on our servers.

Creating an account is required to use the application. Your scans are never linked to your identity: barcodes are checked in real time against official databases, and nothing about them is stored on our servers.

3. Device permissions

Camera access is required to scan barcodes, products, or receipts. Images are used instantly to identify a product and are neither saved on our servers nor kept after analysis.

4. Automatic recall alert for your inventory (optional, off by default)

This is the only feature that stores anything about the products you own. Only products in your inventory are concerned. Your purchase history and your lists are never sent. It is disabled by default, and you can turn it off and erase everything at any time. When enabled, LIFAIO checks your products against official recall notices even when the app is closed, and notifies you if one of them may be affected. What is stored: an unreadable fingerprint of each product name, linked to your account number — never to your name or email address. We keep no readable product name. Each word of a product name is converted into a fingerprint using a secret key held only on our servers. A stolen database would contain rows such as “LIF-53425011 | t76y 2er3 2ty4” — no product, no identity. What is never sent: your declared allergies, your shopping lists, your purchase history, prices, stores, photos or vehicles. How long: 90 days after a product’s last update, then automatic deletion. To erase: one button in Settings → Account. Erasure is immediate, and the option turns itself off. Without this option: LIFAIO checks your products when you open the app, and nothing about them is kept on our servers. An honest limitation: our servers hold the secret key, so this protects you against a data breach — not against LIFAIO itself. We consider that distinction important enough to state plainly.

5. Third-party services

Paddle (payment processing): acts as our merchant of record. It receives your email address, billing country and payment details in order to process your subscription and remit applicable taxes. We never see or store your card details. See paddle.com/legal/privacy.

Lifaio relies on third-party services that are neither controlled nor endorsed by Lifaio : official recall databases (Health Canada, CPSC, FDA, FSA, ACCC, Senacon, etc., depending on the country), Open Food Facts and UPCitemdb (product identification), and, if you configure your own key, an AI provider of your choice (Anthropic, Google, or OpenAI) for optional photo recognition. See their respective policies for how they handle their own data.

Google Places (merchant verification only): When a business requests publishing rights, we query Google Places once to confirm that a business with that name exists at that address, and to obtain its official website and public phone number for verification. This applies to businesses only — never to regular users. We request only the name, address and status of the business.

Twilio (merchant phone verification only): If a business chooses phone verification, an automated call dictating a one-time code is placed to the business’s publicly listed phone number via Twilio. No user data is involved; only the business’s public number is used. Codes expire after 24 hours.

Google AI / Gemini (store flyers only — no user data): Official store flyers are converted into searchable deals using Google’s Gemini model, operated by our administrators on public flyer documents. No user data of any kind is sent to this service. Every extracted deal is reviewed by a human before publication, and displayed with the notice that the merchant’s posted price prevails in case of error.

Pelmorex (Alert Ready / NAAD) and U.S. National Weather Service: Civil emergency alerts are relayed from the public Alert Ready national feed operated by Pelmorex (Canada) and from api.weather.gov (United States, including IPAWS civil messages). Your device position is compared to the alert’s official polygon on our server to decide whether you are affected; the position is used for this comparison and the issuing authority is always displayed.

Google Weather (weather alerts): where no free official source exists for a country, approximate coordinates are sent to Google to retrieve official weather advisories. Where an alert comes from Google, LIFAIO displays “Powered by Google” and names the issuing authority.

Twilio (merchant phone verification only): If a business chooses phone verification, an automated call dictating a one-time code is placed to the business’s publicly listed phone number via Twilio. No user data is involved; only the business’s public number is used. Codes expire after 24 hours.

Data sources and caching

LIFAIO queries official recall databases directly from your device. Nothing about your searches passes through our servers.

The European Union is the one exception. The EU RASFF database cannot be queried from a browser and returns only 100 records per request, so LIFAIO maintains a copy on its servers, refreshed daily. This copy holds the full history of published notices, so that searches covering older dates return results.

For the EU:

  • Recalls from the last 5 days are always read live from the official source, never from our copy.
  • Older notices come from our copy. If that copy is more than 24 hours old, the app reads everything live instead.

The copy contains only the published notices themselves. It holds nothing about you, your searches or your products.

The RASFF system covers the 27 EU member states plus Norway, Iceland, Liechtenstein and Switzerland. The United Kingdom is not part of RASFF and uses its own source (the Food Standards Agency).

We are not affiliated with, nor endorsed by, any of these authorities.

Resend (email delivery): receives your email address in order to send service messages, including newsletter or update emails when you subscribe through our website.

Google Analytics via Site Kit (website analytics): our website uses Google Analytics, connected through Site Kit, to measure traffic and understand how visitors use the site. This may involve non-essential analytics cookies or similar technologies. Where required by applicable law, we rely on your consent before placing non-essential analytics cookies on your device.

Website forms and newsletter signup: when you contact us through the website contact form, we collect the information you choose to provide, including your name, email address, reason for contact, and message. When you subscribe through the signup form on our Home page, we collect your email address to send you newsletters, product updates, and related communications about LIFAIO.

For newsletter emails, our legal basis is your consent. You can withdraw your consent at any time by clicking the unsubscribe link included in every newsletter email, or by contacting us at info@lifaio.com.

Microsoft OneDrive (backups): receives encrypted backups of our database. Backups are encrypted before they leave our servers.

On-device processing

Ingredient label reading (OCR) happens entirely on your device: the photo is processed locally and never uploaded. Pro verification certificates and dish allergen sheets are generated for you and immediately discarded — LIFAIO keeps no copy of any certificate or sheet.

6. Sharing your information

We do not sell, rent, or share your personal data with data brokers or third parties for advertising, promotional, sponsored content, or marketing purposes. All users are paid subscribers with access to the LIFAIO app. Approved verified merchants may be included for free only when they offer some exclusive offers with LIFAIO, and this does not mean that all of their offers are exclusive. LIFAIO does not sell advertising and does not provide marketing services.

LIFAIO reserves the right to modify its content, features, pricing, terms, descriptions, and policies at any time without prior notice. In the event of any pricing error, description error, or inconsistency, the rules, terms, and information then currently in effect by LIFAIO shall prevail.

Prighter Group, our representative, collects your IP address when you use our Trust Center — only to determine the applicable framework and the competent authority.

7. Your rights

You have the right to access, correct, port, and delete your personal data. Any request can be sent to info@lifaio.com.

Requests are tracked with a 30-day legal deadline (GDPR / Quebec Law 25). You will receive an answer within that period.

Deleting your account: you can permanently delete your account and all associated data directly in the app, under Settings → Delete my account. This action is immediate and irreversible — your email, IP, and all your preferences are erased from our servers. You can also make this request without the app via our account deletion request page.

How long we keep your data

  • Account and subscription: while your account exists
  • Signup IP address: 60 days
  • Login attempts: 24 hours
  • Monitored products (optional alert feature): 90 days after last update
  • Community publications: until they expire or you delete them
  • Encrypted backups: 90 days, with the three most recent always kept
  • Payment records: 7 years, as required by tax law

European Union and United Kingdom users: in accordance with Article 27 of the GDPR and UK GDPR, Technologies Marco Prive commits to designating, if required by law, a representative in the European Union and a representative in the United Kingdom. [This section will be completed with the representative’s contact details once one is appointed.]

Brazil, Mexico, Argentina, and Chile users: specific provisions apply under the LGPD, LFPDPPP, Ley 25.326, and Ley 21.719 respectively — full details are available in the app, under Settings → Disclaimer and Terms of Use.

8. Storage and jurisdiction

Your data is processed and stored on secure servers located in Canada. Regardless of your country of residence, any dispute arising from the use of the application or this policy is subject to the exclusive jurisdiction of the courts of the Province of Quebec, judicial district of Montreal. Nothing in this policy constitutes a waiver of any data protection rights you may have under the laws of your country of residence.

9. Data breaches

If a breach occurs that could cause you serious harm, we will notify you and the relevant authorities without delay — within 72 hours where the GDPR applies. We keep a register of confidentiality incidents, as required by Québec’s Law 25.

10. Changes

This policy may be updated to reflect new features. Any change will be posted on this page with a revised “Last updated” date.

11. Representative

We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following regions:

  • European Union (EU)
  • Switzerland
  • United Kingdom (UK)

Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter or make use of your data subject rights, please visit the following website: https://app.prighter.com/portal/16368411041

Addresses of our representatives

European Union (EU) / GDPR:
PrighterGDPR-Rep by Maetzler Rechtsanwalts GmbH & Co KG
Schellinggasse 3/10, 1010 Vienna, Austria
https://prighter.com/q/16368411041

United Kingdom (UK) / UK GDPR:
PrighterUK-Rep by Rickert Services Ltd UK
PO Box 1487, Peterborough, PE1 9XX, United Kingdom
https://prighter.com/q/16368411041

Switzerland / Swiss FADP:
PrighterCH-Rep by Prighter Group Switzerland GmbH
Leutschenbachstrasse 95, 8050 Zurich, Switzerland
https://prighter.com/q/16368411041

European Union (EU) / Data Act:
Prighter Data Act-Rep by Maetzler Rechtsanwalts GmbH & Co KG
Schellinggasse 3/10, 1010 Vienna, Austria
https://prighter.com/q/16368411041

EU Data Act — legal representative

For the purposes of the EU Data Act, we have appointed Prighter Group with its local partner Maetzler Rechtsanwalts GmbH & Co KG as our legal representative in the European Union.

If you want to contact us via our representative under the EU Data Act, please visit: https://app.prighter.com/portal/16368411041

12. Contact us

Marco Prive is the person responsible for the protection of personal information at Technologies Marco Prive, as required by Québec’s Law 25.

Technologies Marco Prive
Head office: 1250 Rene-Levesque Ouest, Suite 2200, Montreal, Quebec, Canada H3B 4W8
Phone: +1-263-999-2751
info@lifaio.com