Privacy Policy.

How TL;DR Vision collects, uses and protects your personal data.

Last updated: 1 July 2026 · Effective: 1 July 2026

1. About this Privacy Policy

1.1 This Privacy Policy explains how GF de Swart B.V., trading as TL;DR Vision ("TL;DR Vision", "we", "us", "our"), processes your personal data when you use our website at https://tldr-vision.com and our web application at https://app.tldr-vision.com (together, the "Service").

1.2 We are the controller of your personal data within the meaning of the EU General Data Protection Regulation 2016/679 ("GDPR").

1.3 Our details:

  • GF de Swart B.V., trading as TL;DR Vision
  • Blauwvoetstraat 73, 1061 BM Amsterdam, the Netherlands
  • KvK: 99103052
  • VAT: NL868798265B01
  • Email: info@tldr-vision.com

1.4 This Privacy Policy should be read together with our Terms and Conditions, Cookie Policy, and Medical Disclaimer.

2. Scope

2.1 This Privacy Policy applies to all Users of the Service, including visitors to our website, users of the web application without an account, and account-holders.

2.2 The Service is offered only to residents of the European Economic Area (EEA), as set out in our Terms and Conditions.

3. Personal Data We Collect

3.1 We collect the following categories of personal data:

  • (a) Account data — when you create an account: your email address, hashed password (or, if you use Google Sign-In, your Google account identifier and the data Google shares with us, such as your email address and name).
  • (b) Dietary preferences (health data) — if you choose to enter and save dietary preferences. This is special category data ("data concerning health") within the meaning of Art. 9 GDPR. Providing this data is optional, but most Service functionality is not available without it.
  • (c) Uploaded photographs — photographs of grocery shelves and products that you upload to the Service.
  • (d) Usage data — information about how you use the Service, including the number of scans you perform, frequency of use, features used, timestamps, and session information.
  • (e) Technical and device data — your IP address, approximate geolocation derived from your IP address (used for verifying EEA eligibility and security purposes), device type, operating system, browser type and version, language settings, and similar technical identifiers.
  • (e-bis) Precise device location — if you grant your browser or device permission to share your location with the Service, we collect your precise geolocation (latitude/longitude derived from your device's location services). Providing precise device location is optional and requires your explicit permission via the standard browser/device prompt. We use precise location data to understand patterns of Service use (such as which regions, store areas, or store types the Service is used in) for analytics and product-development purposes. You can refuse or revoke this permission at any time through your browser or device settings; refusing or revoking does not currently affect your ability to use the Service.
  • (f) Pre-account usage tracking — to enforce the three-free-scan limit before account creation, we create an anonymous session associated with your device. This involves processing of an anonymous identifier. We do not use cookies, browser fingerprinting, or marketing trackers for this purpose.
  • (g) Communications — if you contact us (for example by email or via the contact form), we process the content of your communication and your contact details.
  • (h) Marketing preferences — your consent or objection to receiving marketing communications.

3.2 We do not knowingly collect any other categories of personal data, and we do not derive or infer characteristics about you beyond what is listed above and what is necessary to provide the Service.

4. Purposes and Lawful Bases for Processing

4.1 We process your personal data for the following purposes, on the following lawful bases:

#PurposeCategories of dataLawful basis (Art. 6 GDPR)Lawful basis for health data (Art. 9 GDPR)
1Providing the Service, including image analysis and dietary filteringAccount data, dietary preferences, uploaded photographs, technical dataArt. 6(1)(b) — performance of a contractArt. 9(2)(a) — explicit consent
2Managing your account, including authentication and account securityAccount data, technical dataArt. 6(1)(b) — performance of a contractN/A
3Enforcing the free-scan limit before account creationPre-account usage tracking, technical dataArt. 6(1)(f) — legitimate interest (preventing abuse and enforcing service limits)N/A
4aVerifying your geographic eligibility (EEA only)IP address, IP-derived approximate geolocationArt. 6(1)(f) — legitimate interest (enforcing the Terms and managing legal exposure)N/A
4bAnalysing patterns of Service use, including regional and store-environment patterns, for analytics and product developmentPrecise device location (where granted), usage data, technical dataArt. 6(1)(a) — consent (for precise location) and Art. 6(1)(f) — legitimate interest (for related usage analytics)N/A
5Understanding how the Service is used, product analyticsUsage data, technical dataArt. 6(1)(f) — legitimate interest (improving the Service)N/A
6Producing aggregated, anonymised datasets derived from uploaded photographs (including for commercial use), and training, evaluating, and improving our machine-learning modelsUploaded photographs, dietary preferences (where relevant)Art. 6(1)(f) — legitimate interest (developing and commercialising our products)Art. 9(2)(a) — explicit consent
7Sending you service communications (e.g. password reset, security notices, material changes to terms)Account dataArt. 6(1)(b) — performance of a contract / Art. 6(1)(c) — legal obligationN/A
8Sending you marketing communications about the ServiceAccount data, marketing preferencesArt. 6(1)(a) — consentN/A
9Responding to your enquiries and complaintsCommunications data, account dataArt. 6(1)(b) — performance of a contract / Art. 6(1)(f) — legitimate interestN/A
10Security, fraud prevention, and protecting our rightsAll categories as necessaryArt. 6(1)(f) — legitimate interest (security and protection of our rights)Art. 9(2)(f) — establishment, exercise or defence of legal claims
11Complying with legal obligationsAll categories as necessaryArt. 6(1)(c) — legal obligationArt. 9(2)(g) — substantial public interest, where applicable

4.2 Explicit consent for health data — given once at account creation. Because dietary preferences are special category data within the meaning of Art. 9 GDPR, we rely on your explicit consent under Art. 9(2)(a) GDPR to process them. You give this consent once, during account creation, by ticking a dedicated, separate checkbox that is not pre-ticked and is not bundled with your acceptance of the Terms and Conditions. Your consent covers the processing of dietary preferences for the purposes described in this Privacy Policy, including providing the Service, model training, and the production of aggregated anonymised datasets. If we later add new purposes for processing dietary data that are not covered by this Privacy Policy, we will request fresh consent before doing so. You may withdraw your consent at any time by removing your dietary preferences from your account, by deleting your account, or by emailing info@tldr-vision.com. Withdrawal does not affect the lawfulness of processing before withdrawal, but will limit the functionality of the Service.

4.3 Legitimate interests assessment. Where we rely on legitimate interests as the lawful basis, we have carried out a balancing test and concluded that our interests do not override your interests, rights, and freedoms, taking into account the nature of the processing, your reasonable expectations, and the safeguards we apply. You have the right to object to processing based on legitimate interests (see Section 11). On request, we can provide further information about our assessment.

4.4 Consent for precise device location. Where you choose to share precise device location with the Service, we rely on your consent under Art. 6(1)(a) GDPR, expressed through the standard browser or device location prompt. You can withdraw this consent at any time through your browser or device settings.

5. Photographs You Upload — How They Are Used

5.1 Because uploaded photographs are central to the Service and to our development activities, we explain their handling separately here.

5.2 Initial use. When you upload a photograph, it is processed by automated image-analysis models (open-source computer-vision models) running on our own cloud infrastructure within the European Economic Area to identify products and provide the dietary filtering result. These models are open-source and are operated by us; your photographs are not sent to any third-party AI or image-recognition service.

5.3 Retention of the original photograph. We retain the original photograph for up to 12 months from upload, after which the original photograph is deleted from our systems. This retention period reflects the needs of our initial product-development phase, including model evaluation and iteration cycles. We will revisit and, where possible, shorten this retention period at the end of our initial product-development phase, and will update this Privacy Policy accordingly with at least thirty (30) days' prior notice in line with Section 16.

5.4 Derived data. Before deletion, information extracted from the photograph (such as product identifiers, prices visible on shelves, availability information, and similar attributes) may be incorporated into aggregated datasets that we maintain. These derived datasets are anonymised and do not identify you or any other individual. We may use, license, or sell these derived datasets for commercial purposes. Once data is genuinely anonymised, it is no longer personal data and is not subject to GDPR.

5.5 Model training. We may use uploaded photographs to train, evaluate, and improve our own machine-learning models. We do not share photographs with third-party AI providers for training purposes.

5.6 Where photographs are processed and stored. Photographs are processed by our image-analysis models on our own cloud infrastructure within the European Economic Area, and are stored in Microsoft Azure Blob Storage in the West Europe (Netherlands) region. Photographs are not transmitted to any third-party AI or image-recognition service.

5.7 No photographs of identifiable people. Our Terms and Conditions prohibit you from uploading photographs containing identifiable third parties. If we become aware that an uploaded photograph contains such persons, we will delete it.

6. Marketing Communications

6.1 We send marketing communications about the Service (such as product updates, new features, and tips) only with your prior, freely given, specific, informed, and unambiguous consent, given via a clearly labelled opt-in (not a pre-ticked box) at account creation or later.

6.2 You can withdraw your consent at any time by clicking the unsubscribe link in any marketing email, by changing your preferences in your account settings, or by emailing info@tldr-vision.com. Withdrawal does not affect the lawfulness of processing before withdrawal.

7. Recipients and Sub-Processors

7.1 We share your personal data only with the parties listed below, who act as our processors (under Art. 28 GDPR) or, where indicated, as independent controllers.

RecipientRolePurposeLocation of processingTransfer mechanism
Google Cloud (Google Cloud EMEA Limited / Google LLC)ProcessorCloud hosting and computing (running our own self-hosted image-analysis models in our own container; no Google AI or vision services are used)europe-west4 (Netherlands)If any data is transferred outside the EEA in connection with support or operations: EU Standard Contractual Clauses and/or EU-US Data Privacy Framework
Microsoft Azure (Microsoft Ireland Operations Limited)ProcessorCloud hosting and computing; photograph storage (Azure Blob Storage)West Europe (Netherlands)If any data is transferred outside the EEA in connection with support or operations: EU Standard Contractual Clauses and/or EU-US Data Privacy Framework
Supabase (Supabase, Inc., a Delaware corporation)ProcessorBackend-as-a-Service: user authentication, database storage of account and application data, and server-side functionsEU (Central) region (EU Central 2)EU Standard Contractual Clauses, supported by Supabase's Transfer Impact Assessment and supplementary measures
PostHog (PostHog Inc.)ProcessorProduct analytics (cookieless; keyed to an anonymised account identifier, not your email)EU Cloud (Frankfurt, Germany)EU Standard Contractual Clauses where any onward transfer occurs
Google (Google Ireland Limited / Google LLC), for Google Sign-InIndependent controllerAuthentication when you choose to sign in with GoogleGlobalEU Standard Contractual Clauses and/or EU-US Data Privacy Framework; governed by Google's own privacy policy

7.2 We have entered into Data Processing Agreements with each of our processors as required under Art. 28 GDPR.

7.3 We may also share personal data with:

  • (a) Professional advisers (lawyers, accountants, auditors) bound by confidentiality;
  • (b) Authorities, courts, regulators where required by law, court order, or to protect our rights;
  • (c) Acquirers in the context of a merger, acquisition, restructuring, or sale of assets, subject to appropriate confidentiality protections;
  • (d) Purchasers and licensees of aggregated anonymised datasets (the data shared is not personal data — see Section 5.4).

7.4 We do not sell your personal data.

8. International Transfers

8.1 We aim to keep personal data within the EEA. Where any transfer outside the EEA occurs (for example, where a sub-processor relies on staff or support outside the EEA), we ensure that:

  • (a) the recipient country has been recognised by the European Commission as providing an adequate level of protection (including, for the United States, the EU-US Data Privacy Framework where the recipient is certified); or
  • (b) we have put in place appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs), together with supplementary measures where necessary; or
  • (c) another lawful transfer mechanism under Chapter V GDPR applies.

8.2 You can obtain a copy of the safeguards in place by contacting info@tldr-vision.com.

9. Retention

9.1 We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law.

CategoryRetention period
Account data (email, hashed password, Google identifier)For as long as your account is active. Deleted within 90 days of account deletion, except where longer retention is required by law.
Dietary preferencesFor as long as your account is active. Deleted with your account. May also be removed by you at any time via account settings.
Uploaded photographsUp to 12 months from upload, then deleted. This period reflects the needs of our initial product-development phase and will be revisited and, where possible, shortened thereafter (see Section 5.3).
Derived information extracted from photographs and incorporated into anonymised datasetsRetained indefinitely as anonymised data (no longer personal data).
Usage data and analyticsFor as long as your account is active. Deleted or anonymised within 90 days of account deletion. Analytics are keyed to an anonymised account identifier and do not include your email address.
Precise device location data (where granted)Retained in identifiable form for up to 90 days from collection; thereafter retained only in aggregated, anonymised form (no longer personal data).
Pre-account usage tracking identifiersAnonymous sessions that never convert to an account are deleted within 12 months.
Communications (support emails etc.)Up to 5 years after the matter is closed, matching the Dutch limitation period under Art. 3:307 BW.
Marketing consent recordsUntil you withdraw consent, plus 5 years thereafter for evidentiary purposes (in line with the Dutch limitation period under Art. 3:307 BW).
Records required for legal compliance (e.g. tax)As required by Dutch law (typically 7 years for tax records under Art. 52 AWR).

10. Security

10.1 We take appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, loss, or destruction, including:

  • (a) encryption of data in transit using industry-standard TLS;
  • (b) encryption of data at rest, provided by our cloud sub-processors using provider-managed keys;
  • (c) hashed storage of passwords;
  • (d) access controls and authentication for our systems;
  • (e) use of reputable cloud service providers (Google Cloud, Microsoft Azure, Supabase) with established security certifications;
  • (f) restricted access to personal data on a need-to-know basis;
  • (g) logging and monitoring of system access.

10.2 We maintain an internal personal data breach response procedure in accordance with Art. 33 and 34 GDPR.

10.3 No system is perfectly secure. While we take reasonable measures, we cannot guarantee absolute security. If you believe your account has been compromised, contact us immediately at info@tldr-vision.com.

11. Your Rights

11.1 Under the GDPR, you have the following rights in relation to your personal data:

  • (a) Right of access (Art. 15) — to obtain confirmation that we process your data, and a copy of that data;
  • (b) Right to rectification (Art. 16) — to have inaccurate data corrected and incomplete data completed;
  • (c) Right to erasure / "right to be forgotten" (Art. 17) — to have your data deleted in certain circumstances;
  • (d) Right to restriction of processing (Art. 18) — to have processing limited in certain circumstances;
  • (e) Right to data portability (Art. 20) — to receive your data in a structured, commonly used, machine-readable format, and to have it transmitted to another controller;
  • (f) Right to object (Art. 21) — to object to processing based on legitimate interests, and to object to direct marketing at any time;
  • (g) Right to withdraw consent (Art. 7(3)) — where processing is based on consent (including for health data and marketing), you can withdraw consent at any time;
  • (h) Right not to be subject to solely automated decision-making (Art. 22) — where such decision-making has legal or similarly significant effects (note: the Service's automated dietary filtering does not have legal or similarly significant effects, as you remain solely responsible for purchasing and consumption decisions, as set out in our Medical Disclaimer);
  • (i) Right to lodge a complaint with a supervisory authority (see Section 14).

11.2 How to exercise your rights:

  • You can delete your account at any time via the account settings menu in the Service. This will trigger deletion of your personal data as set out in Section 9.
  • For all other rights, contact us at info@tldr-vision.com, indicating which right you wish to exercise.

11.3 We respond to rights requests within one month of receipt, as required by Art. 12(3) GDPR. We may extend this by a further two months for complex requests, in which case we will inform you within the first month.

11.4 We may need to verify your identity before responding, to prevent unauthorised disclosure.

11.5 Exercising your rights is free of charge, except where requests are manifestly unfounded or excessive (in which case we may charge a reasonable fee or refuse the request).

12. Automated Decision-Making

12.1 The Service uses automated image analysis to suggest which products may match your dietary preferences. This is automated processing, but it is not a decision that produces legal effects or similarly significantly affects you within the meaning of Art. 22 GDPR, because:

  • (a) the Service is informational only;
  • (b) you remain solely responsible for purchasing and consumption decisions;
  • (c) you are required by our Medical Disclaimer to verify product information directly on the packaging before purchase or consumption.

12.2 If you have questions about how a result was produced, contact info@tldr-vision.com.

13. Children

13.1 The Service is not directed at, or intended for, children under 16. You must be at least 16 years old to use the Service, as set out in our Terms and Conditions.

13.2 We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact info@tldr-vision.com and we will delete it.

14. Complaints and Supervisory Authority

14.1 If you have a complaint about how we process your personal data, please contact us first at info@tldr-vision.com. We will acknowledge your complaint within thirty (30) days and aim to provide a substantive response within sixty (60) days.

14.2 You also have the right to lodge a complaint with the Dutch supervisory authority:

Autoriteit Persoonsgegevens (AP), Postbus 93374, 2509 AJ Den Haag. Telephone: +31 (0)88 1805 250. Website: https://autoriteitpersoonsgegevens.nl

14.3 You may also lodge a complaint with the supervisory authority in the EEA Member State where you reside or work, or where the alleged infringement occurred.

15. Data Breaches

15.1 In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Autoriteit Persoonsgegevens within 72 hours of becoming aware of the breach, in accordance with Art. 33 GDPR.

15.2 Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay, in accordance with Art. 34 GDPR.

16. Changes to this Privacy Policy

16.1 We may update this Privacy Policy from time to time. The "Last updated" date at the top indicates when changes were made.

16.2 For material changes (including changes to the categories of data we process, the purposes of processing, or recipients), we will notify you in advance by email and/or in-app notice at least thirty (30) days before the changes take effect, and where required by law, we will obtain your renewed consent.

17. Language

17.1 This Privacy Policy is provided in English. A Dutch translation is available. In the event of any discrepancy between language versions, the English version shall prevail, except where Dutch mandatory consumer law requires otherwise.

18. Contact

For any questions about this Privacy Policy or your personal data:

GF de Swart B.V., trading as TL;DR Vision
Blauwvoetstraat 73, 1061 BM Amsterdam, the Netherlands
KvK: 99103052
Email: info@tldr-vision.com