Privacy
Privacy Policy
There are no accounts. We never ask for your name, email address, or phone number. The app works fully without any health information. Health-based personalisation is optional, off by default, and only ever begins after you explicitly consent to it. Your meals and health details are analysed and returned to you, but they are not stored on our servers. What we keep on our side is a count of how many analyses you have run, so the free allowance and daily limit work.
Two kinds of analysis
Generic analysis is what you get by default. Your meal is analysed on general nutritional merit. No information about you is collected, stored, or sent anywhere.
Personalised analysis scores the meal against your own body, goals and health context. It requires you to turn it on and consent first, in Settings → Personalised analysis.
Information you provide
Meal contents — the ingredients you add to a meal. Used in both modes.
A health profile — only if you have granted consent for personalised analysis. It may include age, sex, weight, height, activity, dietary goal, dietary restrictions, the health conditions you select, protein targets, and a free-text notes field where you may add anything relevant, such as medications or laboratory results.
Nothing in the health profile is requested during onboarding, and none of it is collected or transmitted before you consent.
What stays on your device
Your health profile, your meal history, and your past analyses are stored locally on your device only. They are not uploaded to us, and we cannot read them. Deleting the app removes them.
What is sent off your device, and to whom
To our analysis service
When you tap Analyze, the meal’s ingredients and your health profile are sent to our server, which passes them to OpenAI to generate the report. The report comes back to your device.
We do not write your meal contents or your health profile to our database, and we do not log them. Our server logs record only the number of ingredients and the resulting score.
OpenAI processes this data as our service provider in order to produce the report. Under OpenAI’s API terms, data submitted through the API is not used to train their models and is retained only briefly for abuse monitoring. Their current policy governs; see OpenAI’s privacy documentation for details.
To our payments provider
Purchases are processed by RevenueCat together with the Apple App Store or Google Play. We never see or handle your payment card. RevenueCat assigns your install an anonymous identifier and tells us whether that identifier holds an active subscription.
To our analytics provider
We send usage events to PostHog — for example, that an analysis started, completed, or failed, and that a paywall was shown. These events carry the anonymous identifier described below. They do not carry your meals, your health profile, or your notes.
What we store on our servers
Only this:
- Your anonymous identifier.
- How many analyses you have run in total and today.
- A record of subscription events (purchase, renewal, cancellation) received from RevenueCat.
How you are identified
You are identified by two random values, neither of which is linked to your real identity:
- An anonymous app user ID generated by RevenueCat.
- A random per-install ID generated on your device, used to rate-limit requests.
Both are random. Neither is derived from your device’s hardware identifiers. Reinstalling the app generates new ones.
Consent, and withdrawing it
Health personalisation is opt-in. Consent is recorded on your device with the date and a version number identifying the wording you agreed to, so it is always possible to establish what you consented to. The consent record itself contains no health information.
You can withdraw at any time from Settings → Personalised analysis → Manage consent. When you withdraw, we immediately:
- stop sending your health information with any analysis,
- disable personalised analysis and return you to generic analysis,
- delete the health profile stored on your device, and
- record the withdrawal, with its timestamp.
Reports already generated stay on your device until you delete them. Analyses already sent to OpenAI cannot be recalled; under OpenAI’s API terms that data is not used to train models and is retained only briefly for abuse monitoring.
Health information
Some of what you may choose to enter — the health conditions you select, and anything you add in the notes field — is sensitive. Please note:
- The app is fully usable without any of it, and none of it is collected until you consent.
- Only provide information necessary for your analysis.
- Anything you enter is sent to OpenAI as part of producing your report.
- This app provides nutrition education. It is not medical advice, does not diagnose or treat any condition, and must not be used to make decisions about medication. Talk to a qualified clinician.
Retention and deletion
Data on your device is deleted when you delete the app, or when you reset your profile in Settings.
Because our server records are tied only to an anonymous identifier, we usually cannot connect them to you. If you want your server-side records deleted and can supply your app user ID, contact us at the address above and we will delete them.
Children
This app is not directed at children under 13, and we do not knowingly collect information from them.
Changes
If this policy changes materially, we will update the effective date above and post the revised version at this address.
Contact
Questions about this policy: support@nutritionloop.app