NutriLog AI — Privacy Policy
Effective date: 2026-08-04
NutriLog AI ("the app", "we", "us") is a health, fitness, and nutrition tracking application.
This policy explains what data we collect, how we use it, who we share it with, and the choices
you have. By using the app you agree to this policy.
1. Information we collect
- Account & identity. When you sign in with Google, we receive your name,
email address, profile photo, and your Google account identifier, to create and secure your
account. Google Sign-In is the only way in — we never ask for or store a password.
- Profile & goals. Details you provide during onboarding — such as height,
weight, age, sex, activity level, dietary preference, and fitness goals — used to compute your
personalized nutrition targets.
- Health & fitness logs. Data you enter or log in the app: meals and their
nutrition (calories, macros, micros), water intake, body weight, workouts, and fasting
sessions. Streaks and badges are recalculated from these logs rather than stored.
- Camera & food photos (optional). If you use photo meal scanning or the
barcode scanner, the app uses your camera. You can also pick an existing photo from your
gallery instead — the system picker returns only the single image you select, and the app
never reads the rest of your library. Either way the image is sent for AI analysis (section
4) and is not saved on our servers; we keep only the nutrition estimate you
choose to log.
- Health Connect data (optional). If you grant permission, the app reads
fitness and health data from Android Health Connect — steps, active energy, exercise sessions,
heart rate, resting heart rate, and sleep — to give you a fuller energy-balance picture. This
access is read-only, requires your explicit on-device consent, and can be revoked at any time
in Health Connect settings.
- Product analytics (App interactions). Which screens you open and which
features you use — see section 5. No meal names, photos, weights or free text are included,
and you can turn this off.
- Food searches that find nothing. When a food search returns almost no
results we store the search text with a counter, so we know which foods to add to the
catalog. These rows carry no user id and are not linked to your account.
Successful searches are not stored.
- Purchase data. Pro subscriptions are not yet available in this release —
the app cannot take a payment, so we hold no purchase data today. When Play Billing goes
live, Google Play processes the payment and gives us only a purchase token and subscription
status. We never receive or store your card or payment details.
- Device & install identifiers. When your account is registered on a
device we store an install ID — a random string this app generates for itself, not a
hardware, advertising or Google identifier — together with your notification token and basic
device facts (model, manufacturer, Android version, app version, language, time zone). The
install ID lets us tell one installation from another, so repeated failures from a single
phone are recognised as one problem; the notification token is what Google's messaging
service needs to deliver a reminder or a support reply to that phone. Both are stored against
your account and are removed when you delete it. Turning off Usage &
Diagnostics stops this registration entirely — which also means push notifications
can no longer reach you, since there is no token to send them to.
- Technical data. Standard request metadata (e.g. timestamps) needed to operate
and secure the service.
We do not collect your precise location, contacts, SMS, call logs, or audio.
The app requests no microphone permission — voice logging is disabled in this release.
2. How we use your information
- Provide the core tracking features and calculate personalized calorie and macro targets.
- Generate AI-powered insights (e.g. meal estimates, weekly reviews, plateau and coaching
suggestions).
- Maintain your account, subscription entitlement, streaks, and history across sessions.
- Understand which parts of the app are used and where people get stuck, so we can improve
them (section 5), and decide which foods to add to the catalog.
- Keep the service secure, prevent abuse, and fix problems.
We do not use your data for advertising, we do not sell it, and we do not profile you for
anyone else's purposes.
3. How Health Connect data is used and handled
Health Connect data is used to display and compute your in-app health and fitness metrics (such
as net calories, workouts, and sleep). We do not use Health Connect data for
advertising or marketing, we do not sell it, and we do not
share it with any third party for that third party's own purposes. It is transmitted over
encrypted connections and stored only to power the features you use.
One exception you should know about. If you use the AI features, your daily
summary is sent to Google's Gemini API so it can answer in context (section 4), and that
summary includes your step count — which comes from Health Connect if you have
connected it. Gemini processes it on our behalf to generate your response; it is not used for
advertising and not sold. No other Health Connect metric is sent: sleep, heart rate, resting
heart rate, active energy and imported workouts are not part of what leaves our server, and our
API strips them before the request is built. Turning off AI Data Sharing
(section 4) stops this entirely.
4. AI processing
To produce nutrition estimates and coaching insights, the app sends the relevant input to Google's
Gemini API for processing. Depending on the feature, that is: the eight profile details used to
calculate your targets (weight, height, gender, goal, target weight, activity level, diet and
fasting preference — no name, email or account id); a meal description you type; a food photo;
or your daily summary, which includes your calorie and macro totals and your step count. This
input is used to generate a response and is not used by us to identify you beyond your account.
Food photos are sent for analysis and are not stored on our servers. Do not submit information you consider sensitive that is unnecessary for logging a
meal.
Your choice. You can switch this off at
Profile → Privacy → AI Data Sharing. The switch is enforced on our servers, not
just in the app: with it off, our API refuses every AI request, so nothing reaches Gemini even
from an older or modified copy of the app. Manual logging, food search, barcode scanning and all
tracking keep working; the AI features stop until you turn it back on.
5. Product analytics (App interactions)
We collect a small amount of first-party usage data to see which parts of the app work and where
people get stuck:
- What we collect. Screen views (the screen's name only — never anything you
typed or opened on it), and a fixed set of feature-usage events: completing an onboarding
step, finishing onboarding, logging a meal (whether it was your first, and only how
it was logged — search, photo, barcode, etc.), opening the Pro screen, which button you tapped
there, how you left it, whether a subscription purchase completed (which plan, never any
payment detail — and nothing today, since purchasing is not yet available), and which AI
feature you used.
- What it cannot contain. Event names come from a fixed allowlist and every
property must be a number, a boolean, or a short enum token. Our server rejects anything else
before it is stored, so meal names, food text, photos, weights, email addresses and free text
cannot be recorded here — not even by a modified copy of the app.
- How long we keep it. 90 days. Each event is deleted automatically by the
database once it is that old, and all of your events are deleted immediately if you delete
your account.
- Who sees it. Only us. There is no third-party analytics SDK and no
advertising SDK in the app; these usage events go to our own API and nowhere else. Crash
diagnostics are the one exception, and are described in section 5a.
- Your choice. Turn it off at
Profile → Privacy → Usage & Diagnostics. With it off the app records and
sends nothing, and our server independently discards any event that still arrives for your
account.
5a. Crash diagnostics
When the app fails we collect a diagnostic report so the fault can be found and fixed. This is
the only place a third-party SDK is involved, and it exists for a specific reason: a crash that
kills the app outright leaves nothing running that could report it, so it has to be written to
the device and sent on the next launch.
- What we collect. The error and its technical stack trace, the screen it
happened on, your app version, your Android version and your device model. For failures
inside the app's own code we also record a random install identifier — generated by the app,
not a device or advertising ID — purely so repeated failures from one installation can be
recognised as one problem rather than many.
- What it cannot contain. The same rule as everything else here: no meal
names, food text, photos, voice notes, weights, messages or free text. A report has no field
for them.
- Where it goes. Reports from the app's JavaScript layer go to our own API and
are deleted after 30 days. Reports of a crash that terminates the app are handled by
Firebase Crashlytics (Google), acting as our service provider under their
data-processing terms.
- Signed out. A crash during sign-in or onboarding is reported without any
account attached, because at that point there is none — it carries only the technical details
above.
- Your choice. The same switch:
Profile → Privacy → Usage & Diagnostics. Turning it off stops crash
collection as well. A report already written to the device by an earlier crash may still be
sent once on the next launch, because it exists before the app can read your preference.
6. How we share information
We do not sell your personal data. We share data only with service providers that operate the app
on our behalf:
- Google (Gemini API) — AI processing of the inputs described above, only
while AI Data Sharing is on.
- Google Play Billing — subscription payments and lifecycle notifications,
once Pro purchasing is available.
- Firebase Crashlytics (Google) — crash diagnostics as described in section
5a, only while Usage & Diagnostics is on.
- Cloud database hosting (MongoDB Atlas) — secure storage of your account and
logs.
- Open Food Facts — when you scan a barcode, our server (not your device)
looks the barcode up in the Open Food Facts product database to fetch the product's name and
nutrition. We send only the barcode digits: no account id, no name, no email, no device
identifier and no other data about you.
- Social features (optional). If you add friends or join a challenge, other
participants can see only derived, non-sensitive metrics you choose to share (such as your
display name, photo, streak, and on-budget day count) — never your raw meals, weight, or health
readings.
We may also disclose data if required by law or to protect the rights, safety, and security of our
users and the service.
7. Data retention and deletion
We keep your data for as long as your account exists. You can delete your account from within the
app at any time, at Profile → Privacy → Delete Account & Data. Deletion is
immediate and cannot be undone: it erases your profile, every log (meals, water, weight,
workouts, steps, sleep, resting heart rate, fasting), your custom foods and recipes, your
product-analytics events, and it removes you from any challenges and friend connections. We keep
no post-deletion copy of your account, and there is no separate purchase or transaction record
that outlives it. Streaks and badges are recalculated from your logs rather than stored, so they
go with them. Full instructions:
How to delete your account.
Two categories have their own limits regardless of your account: product-analytics events are
deleted automatically 90 days after they are recorded, and the anonymous failed-search rows
described in section 1 — which carry no user id and are therefore not linked to you — are
deleted 180 days after the last time anyone searched for that text.
Revoking Health Connect permission stops further reads immediately. NutriLog AI only reads from
Health Connect and never writes records into it.
8. Who can access your data
Besides you, a small number of our own staff can access your account data through an internal
administration tool, in order to provide support, investigate a problem you have reported, or
keep the service running. We want to be specific about what that means rather than leave you to
assume it.
- What staff can see. Your name, email, subscription status, and the data you
have logged — meals and nutrition, weight, water, workouts, steps, sleep, resting heart
rate, fasting sessions, recipes, and the product-analytics events described in section 5.
- What staff can do. Correct your daily targets, reset your logged data at your
request, suspend an account that is being misused, and delete an account. Only the most
privileged staff role can delete an account or change a paid entitlement by hand.
- Support sessions ("impersonation"). To reproduce a problem you have reported,
a senior member of staff can open a temporary session that shows them the app as you see it.
Such a session lasts a maximum of ten minutes, requires a written reason, cannot be used to
delete your account or change your subscription, and is recorded on your own sign-in history
as well as in our internal log — so it is visible to anyone reviewing your account, not
only to us.
- Everything is logged. Every administrative action on your account is recorded
with who performed it, when, and why. Those records are kept so that access to your data
remains reviewable, and they are retained even after an account is deleted.
- Sign-in locations. Your sign-in history shows the approximate network your
request came from, stored only as a shortened prefix (for example
203.0.x.x),
never your full IP address.
We do not sell your data, and we do not give staff access to it for any purpose other than the
ones above.
9. Security
Access to the app requires an authenticated session, data is transmitted over encrypted (HTTPS)
connections, and Pro entitlement is verified server-side. Access to the internal administration
tool is separate from your account, requires its own credentials, is limited by role, times out
after a period of inactivity, and is logged as described in section 8. No system is perfectly
secure, but we take reasonable measures to protect your information.
10. Children's privacy
NutriLog AI is not directed to children under 13 (or the minimum age required in your country),
and we do not knowingly collect data from them.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by a new effective
date at the top of this page.
12. Contact
Questions or requests about your data: support@nutrilogai.com.
Related pages