Ingredient extraction and scoring are produced by a large language model with vision capability, called through an encrypted server-side gateway. The model follows a strict toxicology-oriented system prompt.
Results are AI-generated and can be incomplete or incorrect. They are not medical advice. A high score signals concern, not proof of harm.
API credentials are stored server-side only and never reach the browser. Requests are encrypted in transit. Our handling follows OWASP-aligned practices, and no personal data is stored on our servers — your scan history lives on your device.