Privacy Policy
Last updated: August 27, 2026
Tagor (tagor.ai) is operated by Vaveti Inc. This policy explains what information we collect, why we use it, when it is shared, how long it is kept, and the choices and rights available to you. Camera, microphone, precise-location, smart-glasses, and community-contribution features are optional and are used only when you invoke or enable them.
1. Who is responsible for your information
Vaveti Inc. operates Tagor and is responsible for the personal information described in this policy. The person holding the role of Privacy Officer at Vaveti Inc. is accountable for our privacy program. Privacy questions, requests, or complaints may be sent to tagor.ai@vaveti.com.
2. Information we collect
- Account and profile information: email address, display name, profile image, authentication identifiers, language, country, currency, plan, credits, rewards, and preferences.
- Shopping activity: searches, scans, barcodes, product matches, prices, stores, saved products, shopping-list items, alerts, agent conversations, memory timeline entries, feedback, and timestamps.
- Optional precise location: when you choose features such as Nearby, store detection, local flyers, or an in-store scan, we may request latitude and longitude while the app is in use. Coordinates may be associated with a private scan or price observation and used to identify a nearby store or area. You may refuse or revoke this permission; features that require location may then be unavailable or ask you to select a store manually.
- Camera and smart-glasses media: when you deliberately scan a product, read a price tag, ask about an image, attach a diagnostic frame, or use a visual smart-glasses feature, Tagor may receive the selected image or camera frame. A frame may include its surroundings. We do not currently guarantee that every face, badge, screen, licence plate, document, or other background detail is removed before transmission.
- Voice and audio: when you activate Tagor Agent or another voice feature, we process microphone audio, speech-recognition results, conversation content, and session state to understand and answer your request. We do not continuously listen when the feature is inactive.
- Device and service information: IP address, browser and device type, operating system, app version, session and security events, crash or diagnostic information, Bluetooth/smart-glasses connection state, notification tokens, and feature usage.
- Community contributions: product, barcode, price, store, observation time, optional coordinates, image or evidence, account identifier when signed in, and trust or moderation activity. These records are personal or pseudonymous when collected even if a privacy-protected version is later displayed publicly.
- Communications and reports: support correspondence, content reports, privacy requests, and information reasonably needed to investigate them.
3. How and why we use information
- Provide requested services, including product identification, price comparison, store detection, saved products, alerts, rewards, memory, smart-glasses displays, voice responses, and account administration.
- Process a camera frame or audio request that you deliberately submit, generate a result, and present it on your phone or compatible glasses.
- Validate community prices, prevent abuse, resolve disputes, and publish privacy-protected price observations without publicly exposing the contributor account or raw coordinates.
- Secure, debug, maintain, and improve Tagor, including optional diagnostic uploads you choose to attach.
- Send service messages and notifications you request, such as price alerts. Marketing or non-essential notifications require any consent applicable in your region.
- Comply with legal obligations, enforce our Terms, and protect users, Vaveti Inc., retailers, providers, and the public.
4. Legal grounds and consent
Depending on your location and the feature, we rely on your consent, performance of our agreement with you, compliance with law, or our legitimate interests in operating a secure and accurate service. Device permission is not the same as consent for every purpose: Tagor provides a contextual explanation before requesting camera, microphone, precise-location, or cloud-image use. For a signed-in account, Tagor records affirmative grants and later withdrawals—including the purpose, policy version, time, locale, and request source—in a server-side consent ledger. Choosing “Not now” leaves the optional feature off but is not currently written as a separate decline event. A guest capability grant may remain only on that device. You may withdraw optional Tagor consent in Privacy Settings and change operating-system permission separately. Withdrawal does not affect processing that was lawful before withdrawal.
5. Location and nearby-store processing
Tagor collects precise location only after an applicable device or browser permission is granted and a location-enabled feature is used. We may send coordinates to mapping or place providers, including Google Places or OpenStreetMap Nominatim, to identify a nearby store or convert coordinates into a place name. We also infer a less precise country or market from your IP address for currency and regional results. Raw coordinates are not included in Tagor's public community price-history response. Select a store manually or say “no store” if you do not want to use precise location.
6. Camera, cloud AI, and smart glasses
- Camera and smart-glasses analysis is user-initiated. Do not use Tagor for covert or continuous recording, and point the camera only at the product, barcode, or shelf label needed for your request.
- Selected images or frames may be sent to cloud providers such as Google Gemini or Google Vision, Amazon Rekognition, SerpAPI, Lykdat, or other product-search providers used for the requested workflow. A single scan may use more than one provider. Provider availability and routing can vary by product, country, and request.
- Covered scan workflows crop to a product-focused region, resize the image, remove embedded metadata by fresh JPEG encoding, and enforce upload-size limits before cloud transmission. A provider or device workflow may still receive a selected frame rather than a perfect product-only crop. Because automatic face, badge, document, and background redaction is not guaranteed, avoid capturing people, employee badges, payment details, health information, private screens, documents, or licence plates.
- Diagnostic-image upload is separate and optional. If selected, the captured frame may be stored securely for private quality review. Tagor-controlled diagnostic files associated with your account are removed when the account is deleted; any shorter retention rule shown for a specific diagnostic workflow also applies.
- Visible device indicators and Tagor's own status controls show when supported cameras or microphones are active. Manufacturer privacy indicators cannot be disabled by Tagor.
7. Community prices and public presentation
A submitted shelf price is private by default. You can choose whether future eligible scans are proposed automatically, require confirmation each time, or remain private. Automatic sharing applies only to the disclosed community-price purpose and may be changed at any time. Every proposed contribution still requires a fresh, one-use server record and a verified store; keeping a scan private still allows a private save but earns no community-contribution points. An eligible verified in-store price that you choose to share may earn 10 loyalty points, subject to the displayed limit of one award in a rolling 24-hour period. A candidate remains private while moderation is pending and cannot enter the public aggregate until at least 24 hours have passed and the same product, store, currency, place, and calendar day have at least five qualifying observations from five distinct eligible contributors. Public output is a median aggregate and may include product, price, store, city/country, source class, calendar date, and contributor/observation counts. It does not include a raw observation ID, contributor account, image, raw latitude/longitude, precise street address, or visit time. Withdrawing community-publication consent removes that account’s candidates from future aggregate results and does not remove points already awarded solely because you exercised that choice; fraud, duplicate evidence, or an invalid submission may still result in reversal. This community choice does not authorise sale, third-party AI training, or commercial redistribution of contributions; any materially different purpose requires a separate disclosure and, where required, a separate choice. Masking an identifier is pseudonymisation rather than anonymisation. You can submit an in-app report about inaccurate, abusive, illegal, or privacy-invasive content and request removal of your own contribution.
8. Sources, retailers, and affiliate activity
Tagor combines voluntary first-party observations with data made available through licensed, authorised, or contractually permitted retailers and providers. A source is not enabled merely because a technical endpoint exists; restricted source integrations must be affirmatively approved. When you follow an affiliate link, we may send a referral or campaign identifier needed to attribute a purchase, but we do not send your Tagor account name or email to the retailer for that purpose. The retailer handles checkout under its own policy.
9. Service providers and disclosures
- Infrastructure, authentication, database, storage, and delivery providers, including Supabase and hosting or app-distribution providers.
- AI, vision, speech, product-search, mapping, place, price, commerce, affiliate, messaging, analytics, security, and error-diagnostic providers used to perform the feature you request.
- Smart-glasses and mobile-platform providers where their SDK, operating system, or companion service is needed for the connection or display.
- Authorities, courts, regulators, or other parties when disclosure is legally required or reasonably necessary to protect rights, safety, and service integrity.
- A successor in a merger, financing, reorganisation, or sale, subject to applicable notice and protection requirements.
10. Sale, advertising, and tracking
We do not sell personal information and do not share it for cross-context behavioural advertising. Tagor may earn affiliate commissions from outbound shopping links. Essential storage supports authentication, security, country, currency, and preferences. Non-essential analytics or similar technologies are used only as permitted by your settings and applicable law. See the Affiliate Disclaimer for commercial-link details.
11. Retention
We keep information only as long as reasonably necessary for the purposes above, our stated product functions, security and dispute resolution, and legal obligations. Active-account information, deliberate saves, shopping-list items, alerts, and memory may remain until you delete them or your account. Transient frames and provider requests are not intended to become public content; provider-side retention follows the applicable provider agreement and configuration. Tagor-controlled diagnostic images remain private and are removed on account deletion. We periodically review retention rules and may de-identify or delete older activity. We do not promise a fixed deletion period unless it is implemented and stated for that specific record.
12. Account and data deletion
- Use the in-app account deletion control or follow our Data Deletion instructions.
- Account deletion removes account-linked profile, shopping, alert, memory, price-history, push-token, and diagnostic records handled by Tagor, including diagnostic files in Tagor-controlled storage.
- Data that has been irreversibly de-identified and can no longer be connected to you may remain as an aggregate fact. Legally required records and temporary disaster-recovery copies may remain for the applicable restricted period and are not returned to normal use.
- Deleting Tagor does not delete information you provided directly to a retailer, operating-system provider, glasses manufacturer, or other independent service.
13. Security and incidents
We use safeguards appropriate to the sensitivity of the information, including encrypted transport, access controls, service-role separation, authentication, logging, and restricted storage. No system is perfectly secure. We assess privacy and security incidents and provide notice where applicable law requires it. Report a suspected incident to the Privacy Officer immediately.
14. International processing
Vaveti Inc. and its providers may process information outside your province, state, or country, including in Canada and the United States. Foreign laws may permit lawful access by courts or authorities. Where required, we assess transfers and use contractual, technical, and organisational safeguards appropriate to the destination and information.
15. Your choices and rights
- Access and portability: request information about, or a copy of, personal information we hold about you.
- Correction: request correction of inaccurate or incomplete information.
- Deletion: delete your account in the app or submit a verified request.
- Consent: withdraw an optional consent or device permission and change notification or analytics preferences.
- Objection or restriction: ask us to stop or limit certain processing where applicable law provides that right.
- Community content: correct, dispute, report, or request removal of an observation associated with you.
- Complaint: contact our Privacy Officer at tagor.ai@vaveti.com. Québec residents may also contact the Commission d’accès à l’information; residents elsewhere may contact their competent privacy authority.
- We verify requests and respond within the period required by applicable law. We will explain any lawful exception.
16. Québec privacy governance
Vaveti Inc. is responsible for maintaining privacy governance proportionate to Tagor's activities, including accountability by the Privacy Officer, purpose and retention review, access controls, incident handling, service-provider review, and privacy-impact assessments where Québec law requires one—for example, certain new technologies or transfers outside Québec. Privacy settings for sensitive features are designed to be off or minimally intrusive until the user chooses the feature. Contact the Privacy Officer for information about the governance measures applicable to a request.
17. California and other regional disclosures
Residents of California and other jurisdictions may have additional rights to know, correct, delete, or obtain personal information and to opt out of sale or sharing. Tagor does not sell personal information or share it for cross-context behavioural advertising. We do not discriminate against a person for exercising a privacy right.
18. Children and young people
Tagor is not directed to children under 14 and does not currently permit anyone under 14 to create or use a Tagor account, including with parent or guardian authorisation. Minors who are eligible to use Tagor must also meet the age and parental-permission requirements of the app store, device, retailer, and service they use. Contact us if you believe a child created an account or provided personal information contrary to this rule; we will investigate and take appropriate deletion or restriction measures.
19. Changes to this policy
We may update this policy as Tagor, providers, and laws change. We will provide notice of material changes in the app, by email, or through another appropriate channel. Where a new purpose requires consent, continued use alone will not replace that consent.
20. Contact the Privacy Officer
Privacy Officer, Vaveti Inc. Email: tagor.ai@vaveti.com. Website: https://vaveti.com/. Please include enough information for us to understand and verify your request, but do not email passwords or unnecessary sensitive documents.