NutriLog AI — Privacy Policy
NutriLog AI ("the app", "we", "us") is a health, fitness, and nutrition tracking application. This policy explains what data we collect, how we use it, who we share it with, and the choices you have. It covers both the Android app and this website, nutrilogai.com. By using either you agree to this policy.
This website sets no cookies and runs no analytics. Visiting nutrilogai.com — including the calculators — creates no account, stores nothing on our servers about you, and places no cookie, tag or tracking pixel in your browser. The calculators run entirely in your browser: the height, weight and age you type are never sent anywhere and are gone when you close the tab.
Two things do happen, and they are the whole list. Our host (Vercel) processes the standard request data any web server sees — your IP address, the page requested, your browser's user agent — to serve the page and to protect the service from abuse. And the typefaces load from Google Fonts, so Google receives your IP address and browser details when a page loads. Neither is linked to an account, because on this website there is no account.
1. Information we collect
- Account & identity. There are two ways to sign in, and we never ask for
or store a password for either.
- Google Sign-In. We receive your name, email address, profile photo and your Google account identifier, to create and secure your account.
- Email code. You give us your email address and we send a one-time code to it. We store the address on your account, and a hashed copy of the code with a short expiry so it can be checked once and cannot be reused; the code record deletes itself automatically when it expires. No profile photo and no Google identifier are involved on this path.
- Profile & goals. Details you provide during onboarding — such as height, weight, age, sex, activity level, dietary preference, and fitness goals — used to compute your personalized nutrition targets.
- Health & fitness logs. Data you enter or log in the app: meals and their nutrition (calories, macros, micros), water intake, body weight, workouts, and fasting sessions. Streaks and badges are recalculated from these logs rather than stored.
- Camera & food photos (optional). If you use photo meal scanning or the
barcode scanner, the app uses your camera. You can also pick an existing photo from your
gallery instead — the system picker returns only the single image you select, and the app
never reads the rest of your library. Either way the image is sent for AI analysis (section
4) and is not saved on our servers.
When a scan becomes a logged meal, the app keeps a copy of that photo on your phone only, in the app's own private storage, so you can look at the meal again and correct the estimate against the picture. A photo you picked from your gallery is copied there too. These copies never leave the device: they are not uploaded, not included in your data export, and not part of any backup. They are deleted when you delete the meal, when you sign out or delete your account, automatically after 90 days, and when you uninstall the app. - Health Connect data (optional). If you grant permission, the app reads fitness and health data from Android Health Connect — steps, active energy, exercise sessions, heart rate, resting heart rate, and sleep — to give you a fuller energy-balance picture. This access is read-only, requires your explicit on-device consent, and can be revoked at any time in Health Connect settings.
- Product analytics (App interactions). Which screens you open and which features you use — see section 5. No meal names, photos, weights or free text are included, and you can turn this off.
- Support requests and messages. If you contact us from inside the app (Profile → Help & support), we store the subject and the message you write, every later message you send on that request, and our replies — so the conversation survives closing the app and so whoever answers can see what you already told us. The app attaches six device facts to each request (app version, build number, Android version, device model, manufacturer, platform), because "which version are you on" is the first question any support answer depends on. Please do not put anything in a support message you would not want us to read: our staff can see it (section 8), and unlike your logs it is written to be read by a person.
- Food searches that find nothing. When a food search returns almost no results we store the search text with a counter, so we know which foods to add to the catalog. These rows carry no user id and are not linked to your account. Successful searches are not stored.
- Purchase data. Pro subscriptions are not yet available in this release — the app cannot take a payment, so we hold no purchase data today. When Play Billing goes live, Google Play processes the payment and gives us only a purchase token and subscription status. We never receive or store your card or payment details.
- Device & install identifiers. When your account is registered on a device we store an install ID — a random string this app generates for itself, not a hardware, advertising or Google identifier — together with your notification token and basic device facts (model, manufacturer, Android version, app version, language, time zone). The install ID lets us tell one installation from another, so repeated failures from a single phone are recognised as one problem; the notification token is what Google's messaging service needs to deliver a reminder or a support reply to that phone. Both are stored against your account and are removed when you delete it. Turning off Usage & Diagnostics stops this registration entirely — which also means push notifications can no longer reach you, since there is no token to send them to.
- Technical data. Standard request metadata (e.g. timestamps) needed to operate and secure the service.
We do not collect your precise location, contacts, SMS, call logs, or audio. The app requests no microphone permission — voice logging is disabled in this release.
2. How we use your information
- Provide the core tracking features and calculate personalized calorie and macro targets.
- Generate AI-powered insights (e.g. meal estimates, weekly reviews, plateau and coaching suggestions).
- Maintain your account, subscription entitlement, streaks, and history across sessions.
- Understand which parts of the app are used and where people get stuck, so we can improve them (section 5), and decide which foods to add to the catalog.
- Keep the service secure, prevent abuse, and fix problems.
We do not use your data for advertising, we do not sell it, and we do not profile you for anyone else's purposes.
3. How Health Connect data is used and handled
Health Connect data is used to display and compute your in-app health and fitness metrics (such as net calories, workouts, and sleep). We do not use Health Connect data for advertising or marketing, we do not sell it, and we do not share it with any third party for that third party's own purposes. It is transmitted over encrypted connections and stored only to power the features you use.
One exception you should know about. If you use the AI features, your daily summary is sent to Google's Gemini API so it can answer in context (section 4), and that summary includes your step count — which comes from Health Connect if you have connected it. Gemini processes it on our behalf to generate your response; it is not used for advertising and not sold. No other Health Connect metric is sent: sleep, heart rate, resting heart rate, active energy and imported workouts are not part of what leaves our server, and our API strips them before the request is built. Turning off AI Data Sharing (section 4) stops this entirely.
4. AI processing
To produce nutrition estimates and coaching insights, the app sends the relevant input to Google's Gemini API for processing. Depending on the feature, that is: the eight profile details used to calculate your targets (weight, height, gender, goal, target weight, activity level, diet and fasting preference — no name, email or account id); a meal description you type; a food photo; or your daily summary, which includes your calorie and macro totals and your step count. This input is used to generate a response and is not used by us to identify you beyond your account. Food photos are sent for analysis and are not stored on our servers — a copy of a scanned photo is kept on your own phone only, and only once the scan is logged as a meal (see section 1). Do not submit information you consider sensitive that is unnecessary for logging a meal.
Your choice. You can switch this off at Profile → Privacy → AI Data Sharing. The switch is enforced on our servers, not just in the app: with it off, our API refuses every AI request, so nothing reaches Gemini even from an older or modified copy of the app. Manual logging, food search, barcode scanning and all tracking keep working; the AI features stop until you turn it back on.
5. Product analytics (App interactions)
We collect a small amount of first-party usage data to see which parts of the app work and where people get stuck:
- What we collect. Screen views (the screen's name only — never anything you typed or opened on it), and a fixed set of feature-usage events: completing an onboarding step, finishing onboarding, logging a meal (whether it was your first, and only how it was logged — search, photo, barcode, etc.), opening the Pro screen, which button you tapped there, how you left it, whether a subscription purchase completed (which plan, never any payment detail — and nothing today, since purchasing is not yet available), and which AI feature you used.
- What it cannot contain. Event names come from a fixed allowlist and every property must be a number, a boolean, or a short enum token. Our server rejects anything else before it is stored, so meal names, food text, photos, weights, email addresses and free text cannot be recorded here — not even by a modified copy of the app.
- How long we keep it. 90 days. Each event is deleted automatically by the database once it is that old, and all of your events are deleted immediately if you delete your account.
- Who sees it. Only us. There is no third-party analytics SDK and no advertising SDK in the app; these usage events go to our own API and nowhere else. Crash diagnostics are the one exception, and are described in section 5a.
- Your choice. Turn it off at Profile → Privacy → Usage & Diagnostics. With it off the app records and sends nothing, and our server independently discards any event that still arrives for your account.
5a. Crash diagnostics
When the app fails we collect a diagnostic report so the fault can be found and fixed. This is the only place a third-party SDK is involved, and it exists for a specific reason: a crash that kills the app outright leaves nothing running that could report it, so it has to be written to the device and sent on the next launch.
- What we collect. The error and its technical stack trace, the screen it happened on, your app version, your Android version and your device model. For failures inside the app's own code we also record a random install identifier — generated by the app, not a device or advertising ID — purely so repeated failures from one installation can be recognised as one problem rather than many.
- What it cannot contain. The same rule as everything else here: no meal names, food text, photos, voice notes, weights, messages or free text. A report has no field for them.
- Where it goes. Reports from the app's JavaScript layer go to our own API and are deleted after 30 days. Reports of a crash that terminates the app are handled by Firebase Crashlytics (Google), acting as our service provider under their data-processing terms.
- Signed out. A crash during sign-in or onboarding is reported without any account attached, because at that point there is none — it carries only the technical details above.
- Your choice. The same switch: Profile → Privacy → Usage & Diagnostics. Turning it off stops crash collection as well. A report already written to the device by an earlier crash may still be sent once on the next launch, because it exists before the app can read your preference.
6. How we share information
We do not sell your personal data. We share data only with service providers that operate the app and this website on our behalf:
- Google (Gemini API) — AI processing of the inputs described above, only while AI Data Sharing is on.
- Google Play Billing — subscription payments and lifecycle notifications, once Pro purchasing is available.
- Firebase Crashlytics (Google) — crash diagnostics as described in section 5a, only while Usage & Diagnostics is on.
- Cloud database hosting (MongoDB Atlas) — secure storage of your account and logs.
- Resend (email delivery, United States) — sends the one-time sign-in code to your email address, and the weekly summary email if you have not turned it off. Resend receives your email address and the contents of those messages in order to deliver them. You can stop the weekly summary from the link in its footer; the sign-in code is only sent when you ask to sign in.
- Google Fonts — this website loads its typefaces from Google's font servers, so Google receives your IP address and browser details when a page here loads. The app does not use them.
- Open Food Facts — when you scan a barcode, our server (not your device) looks the barcode up in the Open Food Facts product database to fetch the product's name and nutrition. We send only the barcode digits: no account id, no name, no email, no device identifier and no other data about you.
- Social features (optional). If you add friends or join a challenge, other participants can see only derived, non-sensitive metrics you choose to share (such as your display name, photo, streak, and on-budget day count) — never your raw meals, weight, or health readings.
We may also disclose data if required by law or to protect the rights, safety, and security of our users and the service.
7. Data retention and deletion
We keep your data for as long as your account exists. You can delete your account from within the app at any time, at Profile → Privacy → Delete Account & Data. Deletion is immediate and cannot be undone: it erases your profile, every log (meals, water, weight, workouts, steps, sleep, resting heart rate, fasting), your custom foods and recipes, your product-analytics events, and it removes you from any challenges and friend connections. Streaks and badges are recalculated from your logs rather than stored, so they go with them. Meal photos are held on your device rather than on our servers, so they are removed by the app itself — when the meal is deleted, when you sign out or delete your account, and automatically after 90 days. Full instructions: How to delete your account.
Two kinds of record are anonymised rather than erased, and we would rather say so than
let you discover it. A support conversation and a subscription event
(what Google Play told us about a purchase and what we did about it) are both records of an
exchange between two parties, and the half that is ours does not stop existing because you
closed your account — a refund or a chargeback can arrive after it. So on deletion we detach
your identity from both: the account id is removed and the email on a support thread is replaced
with [deleted]. What remains cannot be traced back to you from our side, and nothing
in it is used to build a profile or contact you. Everything else listed above is deleted
outright.
Two categories have their own limits regardless of your account: product-analytics events are deleted automatically 90 days after they are recorded, and the anonymous failed-search rows described in section 1 — which carry no user id and are therefore not linked to you — are deleted 180 days after the last time anyone searched for that text.
Revoking Health Connect permission stops further reads immediately. NutriLog AI only reads from Health Connect and never writes records into it.
8. Who can access your data
Besides you, a small number of our own staff can access your account data through an internal administration tool, in order to provide support, investigate a problem you have reported, or keep the service running. We want to be specific about what that means rather than leave you to assume it.
- What staff can see. Your name, email, subscription status, and the data you have logged — meals and nutrition, weight, water, workouts, steps, sleep, resting heart rate, fasting sessions, recipes, and the product-analytics events described in section 5.
- What staff can do. Correct your daily targets, reset your logged data at your request, suspend an account that is being misused, and delete an account. Only the most privileged staff role can delete an account or change a paid entitlement by hand.
- Support sessions ("impersonation"). To reproduce a problem you have reported, a senior member of staff can open a temporary session that shows them the app as you see it. Such a session lasts a maximum of ten minutes, requires a written reason, cannot be used to delete your account or change your subscription, and is recorded on your own sign-in history as well as in our internal log — so it is visible to anyone reviewing your account, not only to us.
- Everything is logged. Every administrative action on your account is recorded with who performed it, when, and why. Those records are kept so that access to your data remains reviewable, and they are retained even after an account is deleted.
- Sign-in locations. Your sign-in history shows the approximate network your
request came from, stored only as a shortened prefix (for example
203.0.x.x), never your full IP address.
We do not sell your data, and we do not give staff access to it for any purpose other than the ones above.
9. Security
Access to the app requires an authenticated session, data is transmitted over encrypted (HTTPS) connections, and Pro entitlement is verified server-side. Access to the internal administration tool is separate from your account, requires its own credentials, is limited by role, times out after a period of inactivity, and is logged as described in section 8. No system is perfectly secure, but we take reasonable measures to protect your information.
10. Children's privacy
NutriLog AI is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect data from them.
11. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by a new effective date at the top of this page.
12. Contact
Questions or requests about your data: support@nutrilogai.com.