Nutrition AI Privacy Policy

Last updated: 9 September 2026

Nutrition AI collects account details, profile and nutrition information, meal descriptions, pantry items, dietary preferences, allergy information, selected food photos, feedback, and feature preferences to provide account access, meal logging, planning, coaching, support, and Premium features.

Optional Focus-Friendly and Health Context information—including user-selected condition categories, life stage, pregnancy response, medication categories, cycle records, symptoms, and private weight records—is stored in a file-protected area on the device in this version. It is not used for advertising or sent to analytics. User-created clinician summaries are generated locally, shared only through an explicit share action, and the temporary export is removed after sharing closes.

Apple Intelligence

When supported and enabled, eligible features use Apple’s on-device model. Recipe drafts can finish on-device without OpenAI permission. Meal text can be interpreted on-device, but nutrition estimates still require OpenAI cloud processing and permission. Information processed only by the on-device model is not sent to OpenAI.

OpenAI processing

Nutrition AI uses OpenAI for requested cloud-AI features. Before the first such request, the app asks for explicit permission. If you allow it, the information needed for the feature is sent through the Nutrition AI backend to OpenAI. Depending on the feature, this can include:

This information is used to provide the analysis or suggestion you requested. The iOS app does not include your email address, authentication token, Apple sign-in identifier, or device identifier in OpenAI prompts. Authentication information is sent to the Nutrition AI backend to protect your account and requests. Apple Intelligence features explicitly described as on-device do not send their prompt to OpenAI; any cloud fallback is subject to the OpenAI consent gate.

If you do not allow cloud AI processing, Nutrition AI will not send this information to OpenAI. You can decline and continue using non-AI features and eligible on-device recipe drafting. Requests already sent cannot be recalled. You can review or withdraw permission at any time in Profile → Privacy → AI Data Processing. After withdrawal, no new cloud-AI request is sent unless you allow it again.

The production OpenAI project uses Global data residency and standard/default retention controls; Zero Data Retention is not enabled. OpenAI dashboard API-call logging is enabled per call. Requests already sent to OpenAI are not deleted by deleting your Nutrition AI account.

Storage, retention, and choices

Nutrition AI stores account, profile, meal, generated recipe and plan, feedback, subscription, purchase-verification, and service-usage records in its backend. Selected food photos and uploaded audio are processed in memory and are not stored as files by the backend, but technical usage metadata may be retained, including file size, image dimensions, and a cryptographic image fingerprint. The production service and PostgreSQL database run in Render's Oregon, US region. Render retains service logs and PostgreSQL point-in-time recovery data for 7 days. No Render logical exports or external log streams are currently configured.

Google and Apple process information when you choose their sign-in services. Apple processes App Store purchases. Nutrition AI does not use collected data for advertising, cross-app tracking, or third-party advertising. The current iOS project contains no analytics or crash-reporting SDK.

You can revoke camera, photo, microphone, speech, and notification permissions in iOS Settings. Profile → Delete account deletes the active account, authentication data, profile, meals, generated and saved recipes and plans, feedback linked to the authenticated account (including its screenshot attachment), usage records, and account-linked subscription and purchase-verification records. Minimal account-unlinked App Store notification audit records are retained for 365 days to prevent duplicate processing and support security, fraud, and subscription-dispute investigations across an annual subscription cycle, then automatically purged. Render logs and point-in-time recovery data expire under Render's 7-day retention. Deletion does not delete records independently retained by OpenAI, Apple, Google, or other processors. You can delete individual wellness-data categories or all local Health Context information from Profile → Everyday support → Privacy controls.

Your rights and contact

You may request access to, correction of, or deletion of your personal information, subject to applicable law. For privacy questions or assistance, contact:

Email: [email protected] Business address: Flat 7, Jarman House, Hawkstone Road, Surrey Quays, London SE16 2PW, United Kingdom

Security