NutriLog AI — Privacy Policy

Effective date: 2026-09-04

NutriLog AI ("the app", "we", "us") is a health, fitness, and nutrition tracking application. This policy explains what data we collect, how we use it, who we share it with, and the choices you have. It covers both the Android app and this website, nutrilogai.com. By using either you agree to this policy.

This website sets no cookies and runs no analytics. Visiting nutrilogai.com — including the calculators — creates no account, stores nothing on our servers about you, and places no cookie, tag or tracking pixel in your browser. The calculators run entirely in your browser: the height, weight and age you type are never sent anywhere and are gone when you close the tab.

Two things do happen, and they are the whole list. Our host (Vercel) processes the standard request data any web server sees — your IP address, the page requested, your browser's user agent — to serve the page and to protect the service from abuse. And the typefaces load from Google Fonts, so Google receives your IP address and browser details when a page loads. Neither is linked to an account, because on this website there is no account.

1. Information we collect

We do not collect your precise location, contacts, SMS, call logs, or audio. The app requests no microphone permission — voice logging is disabled in this release.

2. How we use your information

We do not use your data for advertising, we do not sell it, and we do not profile you for anyone else's purposes.

3. How Health Connect data is used and handled

Health Connect data is used to display and compute your in-app health and fitness metrics (such as net calories, workouts, and sleep). We do not use Health Connect data for advertising or marketing, we do not sell it, and we do not share it with any third party for that third party's own purposes. It is transmitted over encrypted connections and stored only to power the features you use.

One exception you should know about. If you use the AI features, your daily summary is sent to Google's Gemini API so it can answer in context (section 4), and that summary includes your step count — which comes from Health Connect if you have connected it. Gemini processes it on our behalf to generate your response; it is not used for advertising and not sold. No other Health Connect metric is sent: sleep, heart rate, resting heart rate, active energy and imported workouts are not part of what leaves our server, and our API strips them before the request is built. Turning off AI Data Sharing (section 4) stops this entirely.

4. AI processing

To produce nutrition estimates and coaching insights, the app sends the relevant input to Google's Gemini API for processing. Depending on the feature, that is: the eight profile details used to calculate your targets (weight, height, gender, goal, target weight, activity level, diet and fasting preference — no name, email or account id); a meal description you type; a food photo; or your daily summary, which includes your calorie and macro totals and your step count. This input is used to generate a response and is not used by us to identify you beyond your account. Food photos are sent for analysis and are not stored on our servers — a copy of a scanned photo is kept on your own phone only, and only once the scan is logged as a meal (see section 1). Do not submit information you consider sensitive that is unnecessary for logging a meal.

Your choice. You can switch this off at Profile → Privacy → AI Data Sharing. The switch is enforced on our servers, not just in the app: with it off, our API refuses every AI request, so nothing reaches Gemini even from an older or modified copy of the app. Manual logging, food search, barcode scanning and all tracking keep working; the AI features stop until you turn it back on.

5. Product analytics (App interactions)

We collect a small amount of first-party usage data to see which parts of the app work and where people get stuck:

5a. Crash diagnostics

When the app fails we collect a diagnostic report so the fault can be found and fixed. This is the only place a third-party SDK is involved, and it exists for a specific reason: a crash that kills the app outright leaves nothing running that could report it, so it has to be written to the device and sent on the next launch.

6. How we share information

We do not sell your personal data. We share data only with service providers that operate the app and this website on our behalf:

We may also disclose data if required by law or to protect the rights, safety, and security of our users and the service.

7. Data retention and deletion

We keep your data for as long as your account exists. You can delete your account from within the app at any time, at Profile → Privacy → Delete Account & Data. Deletion is immediate and cannot be undone: it erases your profile, every log (meals, water, weight, workouts, steps, sleep, resting heart rate, fasting), your custom foods and recipes, your product-analytics events, and it removes you from any challenges and friend connections. Streaks and badges are recalculated from your logs rather than stored, so they go with them. Meal photos are held on your device rather than on our servers, so they are removed by the app itself — when the meal is deleted, when you sign out or delete your account, and automatically after 90 days. Full instructions: How to delete your account.

Two kinds of record are anonymised rather than erased, and we would rather say so than let you discover it. A support conversation and a subscription event (what Google Play told us about a purchase and what we did about it) are both records of an exchange between two parties, and the half that is ours does not stop existing because you closed your account — a refund or a chargeback can arrive after it. So on deletion we detach your identity from both: the account id is removed and the email on a support thread is replaced with [deleted]. What remains cannot be traced back to you from our side, and nothing in it is used to build a profile or contact you. Everything else listed above is deleted outright.

Two categories have their own limits regardless of your account: product-analytics events are deleted automatically 90 days after they are recorded, and the anonymous failed-search rows described in section 1 — which carry no user id and are therefore not linked to you — are deleted 180 days after the last time anyone searched for that text.

Revoking Health Connect permission stops further reads immediately. NutriLog AI only reads from Health Connect and never writes records into it.

8. Who can access your data

Besides you, a small number of our own staff can access your account data through an internal administration tool, in order to provide support, investigate a problem you have reported, or keep the service running. We want to be specific about what that means rather than leave you to assume it.

We do not sell your data, and we do not give staff access to it for any purpose other than the ones above.

9. Security

Access to the app requires an authenticated session, data is transmitted over encrypted (HTTPS) connections, and Pro entitlement is verified server-side. Access to the internal administration tool is separate from your account, requires its own credentials, is limited by role, times out after a period of inactivity, and is logged as described in section 8. No system is perfectly secure, but we take reasonable measures to protect your information.

10. Children's privacy

NutriLog AI is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect data from them.

11. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by a new effective date at the top of this page.

12. Contact

Questions or requests about your data: support@nutrilogai.com.

Related pages