Privacy

Privacy Policy

Information you provide

The app lets you enter, entirely at your discretion:

Every one of these fields is optional. The app works without them, though the analysis is less tailored.

What stays on your device

Your health profile, your meal history, and your past analyses are stored locally on your device only. They are not uploaded to us, and we cannot read them. Deleting the app removes them.

What is sent off your device, and to whom

To our analysis service

When you tap Analyze, the meal’s ingredients and your health profile are sent to our server, which passes them to OpenAI to generate the report. The report comes back to your device.

We do not write your meal contents or your health profile to our database, and we do not log them. Our server logs record only the number of ingredients and the resulting score.

OpenAI processes this data as our service provider in order to produce the report. Under OpenAI’s API terms, data submitted through the API is not used to train their models and is retained only briefly for abuse monitoring. Their current policy governs; see OpenAI’s privacy documentation for details.

To our payments provider

Purchases are processed by RevenueCat together with the Apple App Store or Google Play. We never see or handle your payment card. RevenueCat assigns your install an anonymous identifier and tells us whether that identifier holds an active subscription.

To our analytics provider

We send usage events to PostHog — for example, that an analysis started, completed, or failed, and that a paywall was shown. These events carry the anonymous identifier described below. They do not carry your meals, your health profile, or your notes.

What we store on our servers

Only this:

How you are identified

You are identified by two random values, neither of which is linked to your real identity:

Both are random. Neither is derived from your device’s hardware identifiers. Reinstalling the app generates new ones.

Health information

Some of what you may choose to enter — health conditions, medications, lab results — is sensitive. Please note:

Retention and deletion

Data on your device is deleted when you delete the app, or when you reset your profile in Settings.

Because our server records are tied only to an anonymous identifier, we usually cannot connect them to you. If you want your server-side records deleted and can supply your app user ID, contact us at the address above and we will delete them.

Children

This app is not directed at children under 13, and we do not knowingly collect information from them.

Changes

If this policy changes materially, we will update the effective date above and post the revised version at this address.

Contact

Questions about this policy: support@nutritionloop.app