Privacy Policy

Effective Date: August 5, 2026

1. Who We Are

Nutrical ("Nutrical," "we," "us," or "our") is a nutrition tracking application consisting of a website, a progressive web app, a mobile app, a barcode scanner, an AI camera, voice logging, and related features (together, the "Service").

Nutrical is operated by an independent sole trader established in the European Union. For the purposes of the EU General Data Protection Regulation ("GDPR"), that operator is the data controller for the personal data described in this Privacy Policy.

We are not required to appoint a Data Protection Officer, because we do not carry out large-scale monitoring or large-scale processing of special category data. Privacy questions are handled directly by the operator at the address above.

2. What This Policy Covers

This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and what rights you have. It applies to everyone who uses Nutrical, anywhere in the world.

We have written it to meet the GDPR and UK GDPR, and to give the same core protections to users in every other country. Section 14 sets out additional rights that apply if you live in a specific region.

In short: we collect only what the app needs to work, we never sell your data, we show no advertising, we use no analytics or tracking services, we do not store your food photos on our servers, you can permanently delete everything at any time from inside the app, and you can ask us for a complete copy of your data at any time.

3. Information We Collect

We collect the following categories of personal data.

What we do not collect: we do not use advertising identifiers, we do not run analytics or tracking pixels, we do not build advertising profiles, we do not track you across other websites or apps, and we do not buy personal data from data brokers.

4. Why We Use Your Information, and Our Legal Basis

Under the GDPR we must have a legal basis for every use of your personal data. Ours are as follows.

We do not use your personal data for advertising, for profiling for marketing purposes, or for training our own machine learning models.

Providing health and demographic data is not a statutory requirement, but the Service cannot calculate nutritional targets without it. You can use the app without a food photograph or voice input at any time.

5. AI Features: How Food Photos and Descriptions Are Processed

This section describes exactly what happens to an image when you use the AI Camera. Please read it before using the feature.

We do not store your food photographs. When you take or upload a photo, it is passed through our server to a third-party AI provider for analysis and is discarded once the nutritional estimate is returned. It is never written to a database, an object store, or a disk on our infrastructure. Only the resulting text estimate (for example, "grilled chicken salad, 320 kcal") is saved to your account.

Which provider receives your image depends on your plan:

Your choice. If you do not want your images processed on the free-tier route, you can simply not use the AI Camera while on the free trial, log food manually or by barcode instead, or subscribe to Premium, where images are processed under the paid Google terms described above. By using the AI Camera on the free trial, you consent to the processing described in this section.

Please avoid capturing other people, documents, or identifying details in the background of food photographs. Only send images you are comfortable sharing with the providers named above.

Accuracy. AI-generated nutritional estimates are approximations and can be wrong. They must not be relied on for allergen avoidance or for any medical purpose. See our Terms of Service.

6. Voice Input

Voice logging lets you record a meal by speaking instead of typing. If you use it:

If you would prefer that no audio leaves your device, do not use voice logging — every feature it provides is also available by typing or by barcode scan.

7. Cookies, Local Storage, and Similar Technologies

We use strictly necessary storage only. Nutrical uses cookies, local storage, IndexedDB, and a service worker solely to make the Service function: to keep you signed in, to cache your nutritional data so the app works offline, and to remember interface preferences such as dark mode and language.

We set no advertising, analytics, or tracking cookies, and we share no data with ad networks. Because we use only strictly necessary storage, we are not required to show a cookie consent banner under the EU ePrivacy Directive, and we do not show one.

You can clear this storage at any time through your browser or device settings. Doing so will sign you out and remove offline caches, but will not delete data saved to your account.

8. Who We Share Information With

We never sell your personal data, and we never share it for cross-context behavioural advertising. We have never done so, and we do not intend to.

We share data only with the service providers ("processors") needed to run the Service, each bound by a data processing agreement:

Data sources contacted directly by your device. Some food lookups are made by your browser or app straight to a third party, without passing through our servers. This means your IP address and the search or barcode you entered are visible to that third party, under their own privacy policy:

These lookups contain no account identifier and no health data. If you would rather not contact them, use only your own custom meals and recipes.

We may also disclose personal data where we are legally required to do so by a valid court order, subpoena, or binding request from a competent authority; where necessary to establish, exercise or defend legal claims; or where necessary to protect the vital interests, rights, or safety of you, us, or another person. We will resist requests that appear overbroad or unlawful, and will notify you unless legally prohibited from doing so.

If Nutrical is ever sold or transferred, personal data may be transferred as part of that transaction. You will be notified beforehand and this Privacy Policy will continue to apply until you are given notice of any replacement.

9. International Data Transfers

Your account data is stored in the European Union (Google Firebase, europe-west1 region).

Some of our processors are established in, or operate infrastructure in, the United States — in particular Salesforce (Heroku), Stripe, Google, and OpenRouter. When personal data is transferred outside the European Economic Area, we rely on one or more of the following safeguards under GDPR Chapter V:

For transfers of UK personal data we rely on the UK International Data Transfer Addendum. You may request a copy of the relevant safeguards by emailing us.

10. How Long We Keep Your Information

11. How We Protect Your Information

We apply technical and organisational measures appropriate to the risk, including: encryption in transit using HTTPS/TLS; encryption at rest (AES-256) for stored account data; authenticated API access with server-side verification of every request; database rules that prevent any user from reading or writing another user's data; server-side enforcement of subscription and trial status so it cannot be altered from the client; and rate limiting on sensitive endpoints such as data export and account deletion.

No system can be guaranteed completely secure. You are responsible for keeping your Google account credentials safe, and should tell us immediately if you believe your account has been accessed without authorisation.

12. Your Privacy Rights

Wherever you live, we extend the following rights to you:

One limitation to note: if you have an active paid subscription, you must cancel it before deleting your account. This prevents you from being charged for a subscription attached to an account that no longer exists. Cancellation takes effect immediately in the app, after which deletion is available.

13. How to Exercise Your Rights

In the app: open your Profile page, where you can download a complete export of your data, correct your details, cancel a subscription, and permanently delete your account. Most of your logged data can be edited or removed directly on the screen where it appears.

By email: write to [email protected] from the email address on your account. Use this to withdraw or change a consent, to object to or restrict processing, if you cannot sign in to use the in-app export, or for anything else in Section 12.

We respond free of charge. We aim to reply within 30 days, and will tell you if we need to extend that by up to a further 60 days because a request is complex. For requests under California law, we acknowledge within 10 business days and respond within 45 calendar days, extendable once by a further 45 days with notice.

We may ask you to confirm your identity before acting on a request, so that we do not disclose your data to someone else. We will not ask for more documentation than is necessary. You may use an authorised agent to submit a request where the law permits; we may ask for proof of their authority and for you to verify your own identity directly.

14. Additional Rights by Region

European Economic Area, United Kingdom and Switzerland. You have all the rights in Section 12 as a matter of law under the GDPR, the UK GDPR, and the Swiss Federal Act on Data Protection. You may complain to your national supervisory authority — in the UK, the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner. Because we are established in the European Union, we do not require a representative under GDPR Article 27.

California (CCPA/CPRA). We have not sold or shared personal information in the preceding 12 months, and we do not do so now. Your health, biometric-adjacent and precise account data would qualify as sensitive personal information; we use it only to provide the Service you requested and for the purposes permitted under CPRA §7027(m), so no "limit the use of my sensitive personal information" link is required — but you may still ask us to limit it. You also have the rights to know, delete, correct, opt out, and to be free from discrimination, all of which are described in Section 12. We do not knowingly sell or share the personal information of anyone under 16.

Other US states (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and similar). You have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and profiling. We do not conduct targeted advertising, sales, or profiling with legal effects. Where your state provides an appeal process, you may appeal a refused request by replying to our decision; if the appeal is denied you may contact your state Attorney General. Because we process health data, we obtain your consent before processing it.

Brazil (LGPD). You have the rights of confirmation, access, correction, anonymisation or deletion, portability, information about sharing, and to revoke consent. You may petition the Autoridade Nacional de Proteção de Dados (ANPD).

Canada (PIPEDA). You may access and correct your personal information and challenge our compliance. Complaints may be directed to the Office of the Privacy Commissioner of Canada.

Australia (Privacy Act / APPs). You may access and correct your personal information and complain to the Office of the Australian Information Commissioner. We will notify you and the OAIC of any eligible data breach.

South Africa (POPIA). You may access, correct, and delete your personal information and complain to the Information Regulator.

Japan (APPI) and South Korea (PIPA). You may request disclosure, correction, suspension of use, and deletion of your personal information, and withdraw consent.

India (DPDP Act). You may access, correct, and erase your personal data, nominate another person to exercise your rights, and use our grievance process at the contact address in Section 19.

Mainland China. Nutrical is not offered to users in mainland China and we do not process personal information subject to the PIPL.

If your country is not listed and its law grants you a right we have not described, contact us — we will honour it.

15. Children's Privacy

Nutrical is intended for people aged 16 or over, and we do not knowingly collect personal data from anyone under 16. We chose 16 because it is the highest digital consent age permitted under GDPR Article 8, so a single age limit works across every EU member state.

If you believe someone under 16 has created an account, contact [email protected] and we will verify and delete the account and its data promptly.

Nutrition and weight tracking may not be appropriate for young people, or for anyone with a history of disordered eating. Please read the Medical Disclaimer in our Terms of Service.

16. Automated Decision-Making and Profiling

Nutrical uses automated processing to estimate the nutritional content of food from a photo, barcode, or description, and to calculate your calorie and nutrient targets from the profile you provide.

These are informational estimates. We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of GDPR Article 22. You can override any calculated target manually, and you can correct or delete any AI-generated entry.

17. Data Breaches

If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as required by GDPR Article 33, unless the breach is unlikely to result in a risk to your rights and freedoms. Where a breach is likely to result in a high risk to you, we will notify you directly and without undue delay, describing what happened, what data was involved, what we are doing about it, and what you should do.

18. Changes to This Policy

We may update this Privacy Policy. If a change is material — for example, a new category of data, a new processor, or a new purpose — we will give you notice by email or an in-app notice before it takes effect, and where the change requires your consent, we will ask for it. Non-material changes take effect when posted, with the Effective Date updated at the top of this page.

We will keep previous versions available on request so you can see what changed.

19. Contact Us and Complaints

For any privacy question, request, or complaint, email [email protected]. We take complaints seriously and will always try to resolve them with you first.

You also have the right to lodge a complaint with a data protection supervisory authority — in the EU, either the authority in the country where you live or work, or the authority where we are established:

A list of EU supervisory authorities is published by the European Data Protection Board at edpb.europa.eu.