Product-specific document. This schedule applies only to PlateGuard (com.ryantinklepaugh.plateguard). It supplements the separate PlateGuard Terms of Service and Privacy Policy, each with its own immutable version and SHA-256 hash.
Product purpose
PlateGuard reads a food ingredient label on the device and checks the recognized text against user-selected dietary-preference and intolerance rules, showing the ingredient-level basis for a red, amber, or green result.
Not for life-threatening allergies
PlateGuard is for dietary preferences and intolerances. It is not a medical device and must not be relied on to prevent an allergic reaction or to decide that a food is safe for a person with a life-threatening or anaphylactic allergy. Always read the package and follow advice from a qualified clinician.
Recognition and label limits
OCR can misread small, curved, damaged, reflective, incomplete, or poorly lit packaging. Manufacturers can reformulate products, and cross-contact or manufacturing conditions may not appear in an ingredient list. Green means only that the captured list was anchored, every parsed token was recognized, and no selected rule matched under the current database.
Rule and database limits
Ingredient names, E-numbers, synonyms, umbrella terms, FODMAP, histamine, oil, sugar, and allergen classifications can be incomplete, context-dependent, or deliberately conservative. An amber or red result is a prompt to review the actual label and reliable sources, not a diagnosis.
Free access and PlateGuard Pro
The verdict engine is the same in Free and Pro. Pro adds the scan volume, history, profiles, custom terms, and E-number tools shown in the app. Apple's purchase sheet controls current price, trial eligibility, duration, and renewal terms.
Limited mode
After a decline or withdrawal, the user can review or delete available profiles and saved scans, read legal and support information, and manage or restore an Apple purchase. New scans, profiles, rules, purchases, and Pro actions can remain unavailable until the current documents are accepted.
Current product data boundary
The following categories and operational boundaries are specific to PlateGuard and form part of this schedule.
- Transient camera frames or a user-selected label image used for on-device text recognition
- Recognized ingredient text, parse state, ingredient evaluations, verdict, and optional saved raw label text
- Diet profiles, selected rule categories, and custom avoid terms
- Private CloudKit identifiers and synchronization state
- Anonymous App Store purchase and RevenueCat offering, transaction, purchase, and entitlement metadata
- Privacy-minimal legal-choice evidence
Camera, photos, and on-device recognition
PlateGuard uses a live camera capture or a user-selected image to recognize an ingredient list with Apple Vision on the device. The image is not saved as a PlateGuard record or uploaded to Uncommon Weather, RevenueCat, an advertising service, or an artificial-intelligence API.
The recognized text is passed through the deterministic bundled rule engine. If the user saves a result, the verdict and ingredient evaluation are stored; raw recognized text is retained only when the user enables that preference.
Optional on-device ingredient annotation
On supported devices, Apple's on-device model can annotate unknown or ambiguous ingredient tokens. It cannot upgrade or change the deterministic verdict and its suggestion is labeled for verification. PlateGuard does not send the prompt or result to a developer-operated model service.
Profiles, history, and private iCloud
Profiles, custom rules, and saved scans remain local and can synchronize through the user's private CloudKit database. Apple processes that content under the user's iCloud account. Uncommon Weather does not receive it merely because synchronization is enabled and cannot restore it for the user.
Purchases and legal choices
Apple processes payments. RevenueCat receives an anonymous app-user identifier and limited app, device, offering, transaction, purchase, and entitlement metadata needed to present products, restore purchases, provide aggregate subscription analytics, and determine Pro access. PlateGuard does not send camera frames, OCR text, ingredient results, profiles, or custom rules to RevenueCat.
The separate legal-choice service receives only signed, privacy-minimal evidence of an acceptance, decline, or withdrawal and no PlateGuard product content.
Retention and deletion
Records remain locally and in private CloudKit until deleted with available controls, Delete All App Data, app removal, or Apple storage changes. Product deletion does not erase Apple or RevenueCat purchase records, provider security records, or privacy-minimal legal-choice evidence.
Legal choices and verification
A decline or withdrawal takes effect locally at once and remains limited without a recurring prompt. A user can review the current documents and affirmatively accept from Legal & Privacy settings. A current affirmative acceptance takes effect after it is durably saved on the device and unlocks main-app access while signed-receipt delivery retries in the background. A non-terminal network, Apple, or service outage does not lock the main app or create another prompt. Widgets, Live Activities, and other extension surfaces that require a verifiable cross-process receipt may wait until the server-signed receipt is received and verified. If the server explicitly rejects the exact saved acceptance as terminal, the client quarantines that failed record and returns to the appropriate decision or limited-state screen. A current choice is not repeatedly requested.
Related documents
PlateGuard Terms of Service · PlateGuard Privacy Policy · Legal Center