Privacy Policy
Privacy Policy
Last updated: 23 July 2026
1. Introduction
Viggan is a food product decision-support web application operated by ArchiusComus. This Privacy Policy explains what information Viggan processes when you use the website and application.
Viggan is designed to work primarily in your browser and can be used fully without an account. We do not sell personal data.
2. Information You Provide
You may enter profile and nutrition information such as age, height, weight, activity level, goal, meal entries, product amounts, saved meals and manually corrected nutrition values. When you use Viggan without an account, this information is stored only locally in your browser using IndexedDB, with localStorage as a fallback if IndexedDB is unavailable.
Local browser data remains on your device unless you clear browser storage, use the in-app local data deletion control, or choose to share information outside the application.
3. Optional Viggan Account and Cloud Sync
Creating a Viggan account is optional and all core features work without one. If you sign up, the following applies:
- Authentication: accounts are managed with Amazon Cognito. Cognito processes your email address and password; Viggan's application backend does not store your password.
- Synced data: when signed in, your profile (age, height, weight, activity level, goal, personal targets, daily focus and chosen meal-suggestion collections), your daily meal entries and, if you use meal-photo logging, the resized plate photos are stored on Viggan's servers so they are available on all your devices.
- Campaign benefits: if you redeem a campaign benefit, Viggan stores the campaign identifier and the benefit's start and end times on your account. This is used only to grant the promised account features and prevent the same one-time benefit from being redeemed repeatedly.
- Where data is processed: account data is stored in Amazon Web Services in the EU (Ireland, eu-west-1), encrypted at rest and in transit. Each user's data is isolated under their own account identifier; photos are stored in a private bucket accessible only through short-lived signed links tied to your login.
- History: signed-in users can view their recent entry history in the app. Older entries remain stored on your account.
- Meal suggestions you choose to share: if you tick the optional "May Viggan recommend this meal to other users?" checkbox, the meal is saved as a suggestion marked for later review. Suggestions are currently visible only to you and will not be shown to other users without a separate review process.
- Legal basis: cloud storage of your profile and meal entries, including health-related information, is based on the explicit consent you give when creating the account. You can withdraw this consent at any time by deleting your account.
- Retention: account data is kept until you delete your account or request deletion; it is not used for any other purpose in the meantime.
- Deletion: you can delete individual entries in the app, and you can delete your entire account with the "Poista tili" button on the profile page. Deletion permanently removes your entries, profile, campaign benefits, photos and the Cognito account. You can also request deletion by email (see Contact).
- Your rights: you may request access to, correction of, or deletion of your account data at any time via the contact below. You also have the right to lodge a complaint with the supervisory authority, in Finland the Office of the Data Protection Ombudsman (tietosuoja.fi).
Health-related profile information is processed solely to provide the nutrition decision support you request and is not used for advertising or sold to third parties.
4. Cookies
Viggan does not use cookies or tracking technologies. Local browser storage (IndexedDB, localStorage, Cache Storage) is used solely to operate the application and store the data you enter. The optional intro video is embedded using YouTube's privacy-enhanced mode (youtube-nocookie.com), which does not set cookies unless you choose to play the video.
5. Camera, Barcode and OCR Data
EAN barcode scanning runs locally in the browser. The camera stream is used for scanning and is stopped when scanning ends.
When a barcode is detected, Viggan sends the barcode to Open Food Facts to fetch product data. If no barcode is found and you save an image for interpretation, the image may be sent to Viggan's AWS OCR endpoint for text recognition and classification as a nutrition table, menu, receipt or meal photo. Receipt line-item importing is not currently enabled.
When you choose meal-photo or menu analysis, the selected image is resized in the browser and sent to Viggan's AWS endpoint. The endpoint calls OpenAI's vision-capable API to identify broad meal components or visible menu options and returns a structured, approximate result. The OpenAI API key is stored server-side and is not sent to the browser.
6. Third-Party Services
Viggan may use these third-party services:
- Amazon Web Services for hosting, CloudFront delivery, optional OCR processing and, for optional Viggan accounts, authentication (Amazon Cognito) and data storage (DynamoDB, S3) in the EU.
- OpenAI for optional meal-photo and menu interpretation when you explicitly use those features.
- Open Food Facts for product and nutrition data fetched by barcode.
7. Product Data License Notice
Product data from Open Food Facts is provided by Open Food Facts contributors and is made available under the Open Database License (ODbL) 1.0. Product information can be incomplete or inaccurate and should be checked against the product label.
8. Health Disclaimer
Viggan does not provide medical diagnosis, treatment or professional nutrition advice. The application provides general decision support based on nutrition labels and user-provided goals.
9. Contact
The data controller is ArchiusComus. Questions about this policy and all data protection requests (access, correction, deletion) can be directed to viggan.support@archiuscomus.com.