Privacy Policy - ColorDetect Pro

Effective date: 2026-09-14

Last updated: 2026-09-15

This Privacy Policy explains how ELPIDA RESEARCH INC SRL, CUI

35588494 ("ELPIDA", "we", "us", or "our") collects, uses, stores, and

protects data when you use the ColorDetect Pro mobile application and related

backend services (the "App").

1. About ColorDetect Pro

ColorDetect Pro helps users photograph colorimetric test strips, select a

sample type and pathogen panel, upload the image to our backend, and receive an

AI-assisted analysis result.

The App may also allow users to order physical test kits.

2. Medical Disclaimer

ColorDetect Pro is intended for research, screening, educational, and

informational support only.

The App is not a medical device, does not provide a medical diagnosis,

does not replace certified laboratory testing, and does not replace a

doctor or qualified healthcare professional.

Do not use the App for emergency decisions. If you believe you or someone else

may need urgent medical care, contact emergency services or a qualified

healthcare professional immediately.

3. Who May Use the App

The App is intended for adults only (18+). It is not directed to children or

minors and is not intended for use by children or minors.

If we learn that a child has provided personal data through the App, we will

delete that data where required by law.

4. Data We Collect

We aim to collect only the data needed to operate the App.

4.1 Account Data

When you sign in, we may process:

Google Sign-In may be used for authentication. Google may process data under

its own privacy policy when you use Google Sign-In.

4.2 Scan and Health-Related Data

When you create a scan, we may process:

Because scan images and results can relate to health screening, they may be

treated as sensitive or health-related data depending on your jurisdiction.

4.3 Device Permissions

The App may request:

The App does not request access to contacts, SMS, call logs, microphone, or

location.

4.4 Payments and Orders

If you buy a physical kit, we may process:

Payments for physical kits are processed by Stripe. We do not store raw card

numbers or full payment card credentials in the App or backend.

Google Play Billing is not used for physical kits. If digital subscriptions or

digital features are sold in the future, Google Play Billing may be used where

required by Google Play policy.

4.5 Diagnostics and Logs

We may process limited technical logs needed for security, debugging, abuse

prevention, and reliability.

Logs should not contain raw images, base64 images, account tokens, payment card

data, or full medical/health results.

5. Explicit Consent for Image Upload and AI Processing

Before a sample image is uploaded and analyzed, the App asks for explicit

consent.

If you do not consent, the App will not upload that image for analysis.

6. How We Use Data

We use data to:

We do not sell personal data.

We do not use scan images or health-related data for advertising.

7. AI Processing

The backend may use a configured AI provider, such as Gemini or OpenAI, to

analyze uploaded sample images and return structured analysis results.

AI API keys are stored only on the backend. They are not included in the

Android application.

When AI analysis is enabled, the image and related prompt data may be sent to

the configured AI provider for processing. We avoid sending unnecessary account

details to the AI provider.

The configured AI provider, model, and processing terms must be documented in

the production backend configuration and reflected in the Google Play Data

Safety form.

8. Sharing and Processors

We may share data with service providers that help us operate the App, such as:

These providers may process data under their own terms and data processing

agreements.

9. Data Retention

We retain personal data only for as long as needed for the purposes described

in this Policy, or for as long as required or permitted by applicable law.

Scan records and account data are retained while the account is active, unless

you delete them or request deletion.

If you delete your account, we delete or anonymize account-related data and

scan history, except where retention is required for legal, security, fraud

prevention, accounting, or dispute-resolution reasons.

Order, invoice, payment, accounting, and tax records may be retained for the

maximum period required by Romanian/EU accounting and tax law. Operational

security logs are kept only as long as needed to investigate reliability,

security, abuse, fraud, or support issues.

Backups may retain deleted data for a limited period before they are

overwritten or expire. Operational backup retention is 60 days, unless a longer

retention period is legally required or needed for legal claims, security,

fraud prevention, accounting, tax, or dispute-resolution reasons.

10. Export and Deletion

The App includes:

You may also contact us to request access, correction, export, deletion,

restriction, or objection, where applicable by law.

11. Security

We use reasonable technical and organizational safeguards, including:

No system is perfectly secure, but we work to protect data against unauthorized

access, alteration, disclosure, or destruction.

12. International Transfers

Depending on where our backend, AI providers, payment processors, or other

service providers are hosted, data may be processed outside your country. Where

required, we rely on appropriate legal safeguards for international transfers.

The production backend is expected to be hosted with Hetzner in Frankfurt,

Germany. AI providers, Stripe, Google, and other processors may process data in

other locations under their own data processing terms and applicable transfer

safeguards.

13. Your Rights

Depending on your location, you may have rights to:

To exercise these rights, use the in-app controls where available or contact

us.

14. Changes to This Policy

We may update this Privacy Policy when the App, backend, providers, or legal

requirements change. The "Last updated" date will show the latest revision.

Material changes may also be shown in the App or store listing.

15. Contact

ELPIDA RESEARCH INC SRL

CUI: 35588494

Email: [email protected]

Postal address: Romania, Jud. Dambovita, Mun. Targoviste, Str. Ion Cioranescu, Nr. 5

Website / Privacy Policy URL: https://color.elpidagreen.com/privacy-policy