Privacy Policy
Last updated: April 29, 2026 · Effective: April 29, 2026
⚕️ Medical Disclaimer — Not a Medical Device
Nutri IQ Food Intelligence is NOT a medical device and is not intended to diagnose, treat, cure, or prevent any disease or medical condition. All nutrition recommendations are for informational and educational purposes only and are not a substitute for professional medical advice, diagnosis, or treatment. Always consult a qualified healthcare professional or registered sports dietitian before making dietary changes, especially if you have a medical condition.
⚠️ Health & Fitness App Notice
This app collects health-related information including medical conditions and dietary preferences solely to personalise nutrition recommendations. This data is never used for advertising, never sold to third parties, and never shared beyond what is necessary to provide the service.
01 Information We Collect
Name, email address, and encrypted password when you create an account.
Sport, playing level, age, gender, height, weight, dietary preferences (vegetarian, vegan, halal, etc.), medical conditions, training frequency, training time, and fitness goals — all voluntarily provided by you.
Food names you search, photos you take for food identification, barcodes you scan, timing context, and AI recommendations received. This forms your scan history.
City and country only, if you choose to enable location for culturally relevant recommendations. We never collect precise GPS coordinates or track your location.
App version, device type, operating system version, and app usage patterns for improving the service and providing technical support.
02 How We Use Your Information
- To provide personalised AI-powered food recommendations based on your sport, diet, and health profile
- To authenticate your account and maintain security
- To save and display your scan history
- To improve the accuracy and relevance of recommendations
- To send important app updates and service notifications
- To provide customer support and respond to inquiries
- To comply with legal obligations
- To detect and prevent fraudulent or abusive use
We do not use your information for targeted advertising. We do not sell your data.
03 AI Processing
Food scan data is processed by Anthropic's Claude AI to generate nutrition recommendations. The following context is sent to the AI:
- Food name or image
- Your sport and playing level
- Your dietary preference (e.g. vegetarian, halal)
- Your medical conditions (e.g. diabetes, Crohn's disease)
- Your fitness goals and training timing
- Your location (city/country only, if enabled)
We do NOT send your name, email address, or account credentials to the AI. Anthropic's privacy policy governs their processing of this data. Learn more at anthropic.com/privacy.
04 Health & Medical Data
We treat health and medical information with the highest level of protection:
- All medical data is encrypted at rest using AES-256 encryption
- Medical data is only used to personalise food recommendations
- Medical data is never sold, rented, or shared with advertisers
- Medical data is never used for insurance, employment, or credit purposes
- You can delete your medical data at any time from Profile → Health Conditions
- You can delete your entire account and all data from Profile → Privacy & Data
05 Camera & Device Permissions
Required for photo scanning (identifying food from photos) and barcode scanning. Camera is only activated when you initiate a scan. We do not access your camera in the background.
We do not access your photo library. Photos taken for food scanning are processed immediately and not stored on our servers in their original form.
Required to communicate with our backend servers for AI recommendations, authentication, and saving scan history.
06 Data Storage & Security
Your data is stored securely using industry-standard practices:
- AES-256 encryption for all data at rest
- TLS 1.3 encryption for all data in transit
- Row-level security — you can only access your own data
- Servers hosted on Supabase (United States)
- Backend API hosted on Railway (United States)
- Regular security updates and monitoring
- No data stored on our servers beyond what is necessary
While we implement strong security measures, no method of electronic storage is 100% secure. We cannot guarantee absolute security.
08 Data Retention
- Account data is retained while your account is active
- Scan history is retained for up to 2 years or until you delete it
- When you delete your account, all personal data is removed within 30 days
- Anonymised, aggregated usage data may be retained for service improvement
- Backup copies may persist for up to 90 days after deletion
09 Your Rights
You have the following rights regarding your personal data:
- Access — Request a copy of all personal data we hold about you
- Correction — Request correction of inaccurate personal data
- Deletion — Request deletion of your account and all associated data
- Portability — Request your data in a portable, machine-readable format
- Restriction — Request we restrict processing of your data
- Objection — Object to processing of your personal data
- Withdraw consent — Withdraw consent at any time without affecting prior processing
To exercise any right, contact us at yskanth19@gmail.com. We will respond within 30 days.
10 GDPR — European Users
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR):
- Our legal basis for processing your data is contract performance (providing the service you signed up for) and legitimate interests (improving the service)
- Health data is processed based on your explicit consent
- You have the right to lodge a complaint with your local data protection authority
- We do not transfer data outside of the EEA without appropriate safeguards
For GDPR inquiries, contact us at yskanth19@gmail.com.
11 CCPA — California Users
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information we collect and how it is used
- Right to delete personal information we have collected
- Right to opt-out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising your CCPA rights
Categories of personal information collected: Identifiers, health information, internet activity, geolocation data (city/country only).
We do not sell personal information to third parties.
12 Children's Privacy
Nutri IQ is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at yskanth19@gmail.com and we will delete such information promptly.
13 Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of significant changes by:
- Updating the "Last updated" date at the top of this policy
- Sending an in-app notification
- Sending an email notification for material changes
Your continued use of the app after changes are posted constitutes acceptance of the updated Privacy Policy.
14 Contact Us
Questions about your privacy?
We take privacy seriously and are happy to help with any questions or requests regarding your personal data.
yskanth19@gmail.comWe aim to respond to all privacy inquiries within 30 days.