Climfy
Climfy Privacy Policy
Last updated: July 2026
1. About This Policy
Climfy shows you the carbon behind everyday things. Scan a product, barcode, or receipt and Climfy estimates its carbon impact; log daily climate actions to build a streak; explore lower-carbon alternatives based on what you scan; and track your footprint over time. This policy explains what data we collect to make that possible, why we collect it, and what rights you have over it.
2. What We Collect
Your Account
• Email address — used for login and account recovery • Password — managed by Firebase Authentication; Climfy never sees it • Username — set by you at signup • Profile photo — optional, stored in Firebase Storage • Google or Apple tokens — only if you use social sign-in
Your Scans
• The product, barcode, or receipt image you capture • Items extracted from a scan, their estimated carbon (kg CO₂e), and tier • The date and running totals used for your dashboard • Climate actions you log (e.g. taking transit, eating plant-based) and your check-in history • Items you save from the Discover feed
App Preferences
• Notification settings (on/off per type) • Language preference • Feedback you voluntarily submit • Onboarding completion status
3. How We Use Your Data
• Power core features: scanning, your carbon dashboard, the Discover feed, and your climate action streak • Personalize your Discover feed from your in-app activity • Generate and send your weekly carbon impact report by email • Power search — your query is processed live and not retained • Send notifications according to your preferences • Understand usage patterns through aggregated, anonymized data to improve the app
4. AI-Powered Features
Scan analysis & search
Scan images are sent to our AI provider to read the item and estimate carbon, then processed and not retained beyond what's needed to return your result. Search queries are processed in real time and are not stored after the session ends.
Discover feed
Your Discover feed is generated by AI and personalized from your in-app activity — such as what you scan, save, and search. It is produced on demand and temporarily cached for speed.
5. Data Sharing
We do not sell your data. We work only with the providers needed to run Climfy: • Google Firebase — database, authentication, file storage, and cloud functions • RevenueCat — subscription and payment handling • OpenAI — scan analysis and search (image and query text only; not retained) We may also share data when required by law or to protect user safety.
6. Security
• Firebase Firestore and Storage run on Google's enterprise-security infrastructure • All data in transit is encrypted over TLS/HTTPS • Passwords are handled solely by Firebase Authentication — we have no access to them • Your scan images and saved items are stored with owner-only access controls • All payment processing is handled by RevenueCat, Apple, or Google — Climfy never touches payment details
7. Your Rights
You stay in control of your data: • View your scans anytime in the app • Edit your username and profile photo in Account Settings • Delete individual scans • Delete your entire account — and everything linked to it — via Settings → Account → Delete Account Deletion is permanent and removes all scans, saved items, and profile data from our servers.
8. Children's Privacy
Climfy is not intended for users under 13. We do not knowingly collect data from children. If we learn that a child has created an account, we will delete the data immediately.
9. Updates & Contact
We may revise this policy as Climfy grows. Significant changes will appear as an in-app notice. Continuing to use the app after an update means you accept the revised terms. For questions or concerns about your privacy: contact@climfy.tech