Privacy Policy
Effective Date: August 5, 2026
1. Who We Are
Nutrical ("Nutrical," "we," "us," or "our") is a nutrition tracking application consisting of a website, a progressive web app, a mobile app, a barcode scanner, an AI camera, voice logging, and related features (together, the "Service").
Nutrical is operated by an independent sole trader established in the European Union. For the purposes of the EU General Data Protection Regulation ("GDPR"), that operator is the data controller for the personal data described in this Privacy Policy.
- Country of establishment: Slovakia
- Email: [email protected]
We are not required to appoint a Data Protection Officer, because we do not carry out large-scale monitoring or large-scale processing of special category data. Privacy questions are handled directly by the operator at the address above.
2. What This Policy Covers
This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and what rights you have. It applies to everyone who uses Nutrical, anywhere in the world.
We have written it to meet the GDPR and UK GDPR, and to give the same core protections to users in every other country. Section 14 sets out additional rights that apply if you live in a specific region.
In short: we collect only what the app needs to work, we never sell your data, we show no advertising, we use no analytics or tracking services, we do not store your food photos on our servers, you can permanently delete everything at any time from inside the app, and you can ask us for a complete copy of your data at any time.
3. Information We Collect
We collect the following categories of personal data.
- Account identifiers. Your name, email address, profile picture, and authentication tokens, provided when you sign in with Google Sign-In. We derive a stable internal user ID from this.
- Health and demographic data. Biological sex, age, height, weight, activity level, dietary goals, and any weight, sleep, water, or workout entries you log. Under GDPR Article 9 this is special category data concerning health, and we process it only with your explicit consent (see Section 4).
- Food and activity logs. Meals, portions, custom recipes, custom meals, favourites, and barcode scans.
- Food photographs. Images you capture or upload through the AI Camera. See Section 5 — these are relayed for analysis and are not stored on our servers.
- Voice recordings and transcripts. If you use voice logging, your device microphone is accessed and your speech is converted to text. See Section 6.
- Subscription and billing status. Your plan, subscription status, renewal date, trial status, and the identifiers issued by our payment processor. We never receive or store your full card number, CVC, or bank details — those are handled entirely by Stripe.
- Technical and diagnostic data. Device type, operating system, browser, app version, IP address (processed transiently by our hosting providers for routing, rate limiting, and abuse prevention), and error and crash information.
What we do not collect: we do not use advertising identifiers, we do not run analytics or tracking pixels, we do not build advertising profiles, we do not track you across other websites or apps, and we do not buy personal data from data brokers.
4. Why We Use Your Information, and Our Legal Basis
Under the GDPR we must have a legal basis for every use of your personal data. Ours are as follows.
- To create and secure your account — identifiers, technical data. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
- To calculate your calorie, macronutrient and micronutrient targets, and to show your dashboard, progress and history — health and demographic data, food logs. Legal basis: your explicit consent (Art. 6(1)(a) and Art. 9(2)(a)). You give this consent during onboarding, and you can withdraw it at any time.
- To identify food from barcodes, photographs and voice input, and return nutritional estimates — barcode data, images, voice transcripts. Legal basis: performance of a contract, and your explicit consent where the input reveals health information.
- To process subscriptions, payments, refunds and trials — billing status. Legal basis: performance of a contract, and compliance with a legal obligation for tax and accounting records (Art. 6(1)(c)).
- To send you service messages — security alerts, account notices, billing notices, and replies to your support requests. Legal basis: performance of a contract and our legitimate interests in operating the Service (Art. 6(1)(f)).
- To keep the Service secure and prevent abuse — technical data, rate limiting, audit records. Legal basis: our legitimate interests in protecting the Service and our users (Art. 6(1)(f)).
- To meet legal obligations and to establish, exercise or defend legal claims — as required. Legal basis: legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f)); for health data, Art. 9(2)(f).
We do not use your personal data for advertising, for profiling for marketing purposes, or for training our own machine learning models.
Providing health and demographic data is not a statutory requirement, but the Service cannot calculate nutritional targets without it. You can use the app without a food photograph or voice input at any time.
5. AI Features: How Food Photos and Descriptions Are Processed
This section describes exactly what happens to an image when you use the AI Camera. Please read it before using the feature.
We do not store your food photographs. When you take or upload a photo, it is passed through our server to a third-party AI provider for analysis and is discarded once the nutritional estimate is returned. It is never written to a database, an object store, or a disk on our infrastructure. Only the resulting text estimate (for example, "grilled chicken salad, 320 kcal") is saved to your account.
Which provider receives your image depends on your plan:
- Premium subscribers. Your image is sent to the Google Gemini API (paid tier), operated by Google. Under Google's paid-tier API terms, content submitted through the paid API is not used to train Google's models and is retained only transiently for abuse detection.
- Free trial and free-tier users. Your image is sent to OpenRouter, Inc., which routes it to a free-tier model. The models currently used are meta-llama/llama-4-maverick, nvidia/nemotron-nano-12b-v2-vl, and google/gemma-4-31b-it. Free-tier model access is governed by OpenRouter's terms and by the terms of the underlying model provider. We cannot guarantee that images processed through free-tier models are excluded from provider logging or from being used to improve those providers' models.
Your choice. If you do not want your images processed on the free-tier route, you can simply not use the AI Camera while on the free trial, log food manually or by barcode instead, or subscribe to Premium, where images are processed under the paid Google terms described above. By using the AI Camera on the free trial, you consent to the processing described in this section.
Please avoid capturing other people, documents, or identifying details in the background of food photographs. Only send images you are comfortable sharing with the providers named above.
Accuracy. AI-generated nutritional estimates are approximations and can be wrong. They must not be relied on for allergen avoidance or for any medical purpose. See our Terms of Service.
6. Voice Input
Voice logging lets you record a meal by speaking instead of typing. If you use it:
- The app requests access to your device microphone. Access is only active while you are actively using the feature, and you can refuse or revoke it in your browser or device settings at any time.
- Speech is converted to text using your browser's or device's own speech recognition. In most browsers — including Google Chrome and Microsoft Edge — this means your audio is transmitted to and processed by the browser vendor's servers (for Chrome, Google's), under that vendor's own privacy policy, not ours. We have no control over, and receive no copy of, that transmission.
- We receive only the resulting text transcript, which we process to identify the food you described. We do not receive, store, or have access to the underlying audio recording.
- The transcript is used to create your food log entry and is retained as part of that entry.
If you would prefer that no audio leaves your device, do not use voice logging — every feature it provides is also available by typing or by barcode scan.
7. Cookies, Local Storage, and Similar Technologies
We use strictly necessary storage only. Nutrical uses cookies, local storage, IndexedDB, and a service worker solely to make the Service function: to keep you signed in, to cache your nutritional data so the app works offline, and to remember interface preferences such as dark mode and language.
We set no advertising, analytics, or tracking cookies, and we share no data with ad networks. Because we use only strictly necessary storage, we are not required to show a cookie consent banner under the EU ePrivacy Directive, and we do not show one.
You can clear this storage at any time through your browser or device settings. Doing so will sign you out and remove offline caches, but will not delete data saved to your account.
8. Who We Share Information With
We never sell your personal data, and we never share it for cross-context behavioural advertising. We have never done so, and we do not intend to.
We share data only with the service providers ("processors") needed to run the Service, each bound by a data processing agreement:
- Google (Firebase Authentication and Realtime Database) — account authentication and the storage of your account data. Hosted in the EU (europe-west1).
- Salesforce (Heroku) — hosting of our application server, which processes requests in transit.
- Stripe — subscription payments, billing, and invoicing. Stripe acts as an independent controller for payment data and handles your card details directly; we never see them.
- Google (Gemini API) — AI food image and text analysis for Premium subscribers. See Section 5.
- OpenRouter, Inc. and the underlying model providers it routes to — AI food image and text analysis for free trial and free-tier users. See Section 5.
Data sources contacted directly by your device. Some food lookups are made by your browser or app straight to a third party, without passing through our servers. This means your IP address and the search or barcode you entered are visible to that third party, under their own privacy policy:
- Open Food Facts — barcode and packaged product lookups.
- USDA FoodData Central — generic food and nutrient reference data.
These lookups contain no account identifier and no health data. If you would rather not contact them, use only your own custom meals and recipes.
We may also disclose personal data where we are legally required to do so by a valid court order, subpoena, or binding request from a competent authority; where necessary to establish, exercise or defend legal claims; or where necessary to protect the vital interests, rights, or safety of you, us, or another person. We will resist requests that appear overbroad or unlawful, and will notify you unless legally prohibited from doing so.
If Nutrical is ever sold or transferred, personal data may be transferred as part of that transaction. You will be notified beforehand and this Privacy Policy will continue to apply until you are given notice of any replacement.
9. International Data Transfers
Your account data is stored in the European Union (Google Firebase, europe-west1 region).
Some of our processors are established in, or operate infrastructure in, the United States — in particular Salesforce (Heroku), Stripe, Google, and OpenRouter. When personal data is transferred outside the European Economic Area, we rely on one or more of the following safeguards under GDPR Chapter V:
- Standard Contractual Clauses adopted by the European Commission (2021 version), incorporated into our agreements with those providers;
- the EU–US Data Privacy Framework, where the provider is certified under it; and
- adequacy decisions of the European Commission, where one applies to the destination country.
For transfers of UK personal data we rely on the UK International Data Transfer Addendum. You may request a copy of the relevant safeguards by emailing us.
10. How Long We Keep Your Information
- Account, health, and food log data — kept while your account is active. Deleted immediately when you delete your account.
- Food photographs — never stored. Discarded as soon as the analysis is returned.
- Voice audio — never received or stored by us. Transcripts are retained as part of the food log entry they created.
- Recipes and meals you published to shared collections — removed when you delete your account.
- Payment and invoice records held by Stripe — retained by Stripe after account deletion, because tax, accounting, and anti-fraud law requires it. This is a legal obligation and is not affected by an erasure request.
- Internal audit record — we keep a minimal log of subscription and account events (event type, timestamp, subscription identifier, and your former internal user ID) for tax, accounting, anti-fraud, and billing-dispute purposes, for as long as required by the accounting law of our country of establishment. It contains no health data, no food logs, no images, and no contact details.
- Server logs and diagnostics — retained for a short period for security and troubleshooting, then discarded.
11. How We Protect Your Information
We apply technical and organisational measures appropriate to the risk, including: encryption in transit using HTTPS/TLS; encryption at rest (AES-256) for stored account data; authenticated API access with server-side verification of every request; database rules that prevent any user from reading or writing another user's data; server-side enforcement of subscription and trial status so it cannot be altered from the client; and rate limiting on sensitive endpoints such as data export and account deletion.
No system can be guaranteed completely secure. You are responsible for keeping your Google account credentials safe, and should tell us immediately if you believe your account has been accessed without authorisation.
12. Your Privacy Rights
Wherever you live, we extend the following rights to you:
- Access. Obtain confirmation of whether we process your data, and a copy of it.
- Portability. Receive your data in a structured, commonly used, machine-readable format. Download a complete export of your account as a JSON file at any time from Profile → Your Data → Download my data.
- Rectification. Correct inaccurate or incomplete data. Most data can be edited directly in the app.
- Erasure. Delete your account and personal data. Deletion in the app is immediate and irreversible.
- Restriction. Ask us to limit how we use your data while a dispute about it is resolved.
- Objection. Object to processing based on our legitimate interests.
- Withdraw consent. Withdraw your consent to health data processing or AI processing at any time. You do not need to delete your account to withdraw consent. Withdrawing consent does not affect the lawfulness of processing carried out beforehand.
- Complain. Lodge a complaint with a data protection supervisory authority — see Section 19.
- No discrimination. We will not deny you service, charge you a different price, or give you a lower quality of service because you exercised a privacy right.
One limitation to note: if you have an active paid subscription, you must cancel it before deleting your account. This prevents you from being charged for a subscription attached to an account that no longer exists. Cancellation takes effect immediately in the app, after which deletion is available.
13. How to Exercise Your Rights
In the app: open your Profile page, where you can download a complete export of your data, correct your details, cancel a subscription, and permanently delete your account. Most of your logged data can be edited or removed directly on the screen where it appears.
By email: write to [email protected] from the email address on your account. Use this to withdraw or change a consent, to object to or restrict processing, if you cannot sign in to use the in-app export, or for anything else in Section 12.
We respond free of charge. We aim to reply within 30 days, and will tell you if we need to extend that by up to a further 60 days because a request is complex. For requests under California law, we acknowledge within 10 business days and respond within 45 calendar days, extendable once by a further 45 days with notice.
We may ask you to confirm your identity before acting on a request, so that we do not disclose your data to someone else. We will not ask for more documentation than is necessary. You may use an authorised agent to submit a request where the law permits; we may ask for proof of their authority and for you to verify your own identity directly.
14. Additional Rights by Region
European Economic Area, United Kingdom and Switzerland. You have all the rights in Section 12 as a matter of law under the GDPR, the UK GDPR, and the Swiss Federal Act on Data Protection. You may complain to your national supervisory authority — in the UK, the Information Commissioner's Office; in Switzerland, the Federal Data Protection and Information Commissioner. Because we are established in the European Union, we do not require a representative under GDPR Article 27.
California (CCPA/CPRA). We have not sold or shared personal information in the preceding 12 months, and we do not do so now. Your health, biometric-adjacent and precise account data would qualify as sensitive personal information; we use it only to provide the Service you requested and for the purposes permitted under CPRA §7027(m), so no "limit the use of my sensitive personal information" link is required — but you may still ask us to limit it. You also have the rights to know, delete, correct, opt out, and to be free from discrimination, all of which are described in Section 12. We do not knowingly sell or share the personal information of anyone under 16.
Other US states (Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and similar). You have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and profiling. We do not conduct targeted advertising, sales, or profiling with legal effects. Where your state provides an appeal process, you may appeal a refused request by replying to our decision; if the appeal is denied you may contact your state Attorney General. Because we process health data, we obtain your consent before processing it.
Brazil (LGPD). You have the rights of confirmation, access, correction, anonymisation or deletion, portability, information about sharing, and to revoke consent. You may petition the Autoridade Nacional de Proteção de Dados (ANPD).
Canada (PIPEDA). You may access and correct your personal information and challenge our compliance. Complaints may be directed to the Office of the Privacy Commissioner of Canada.
Australia (Privacy Act / APPs). You may access and correct your personal information and complain to the Office of the Australian Information Commissioner. We will notify you and the OAIC of any eligible data breach.
South Africa (POPIA). You may access, correct, and delete your personal information and complain to the Information Regulator.
Japan (APPI) and South Korea (PIPA). You may request disclosure, correction, suspension of use, and deletion of your personal information, and withdraw consent.
India (DPDP Act). You may access, correct, and erase your personal data, nominate another person to exercise your rights, and use our grievance process at the contact address in Section 19.
Mainland China. Nutrical is not offered to users in mainland China and we do not process personal information subject to the PIPL.
If your country is not listed and its law grants you a right we have not described, contact us — we will honour it.
15. Children's Privacy
Nutrical is intended for people aged 16 or over, and we do not knowingly collect personal data from anyone under 16. We chose 16 because it is the highest digital consent age permitted under GDPR Article 8, so a single age limit works across every EU member state.
If you believe someone under 16 has created an account, contact [email protected] and we will verify and delete the account and its data promptly.
Nutrition and weight tracking may not be appropriate for young people, or for anyone with a history of disordered eating. Please read the Medical Disclaimer in our Terms of Service.
16. Automated Decision-Making and Profiling
Nutrical uses automated processing to estimate the nutritional content of food from a photo, barcode, or description, and to calculate your calorie and nutrient targets from the profile you provide.
These are informational estimates. We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of GDPR Article 22. You can override any calculated target manually, and you can correct or delete any AI-generated entry.
17. Data Breaches
If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours of becoming aware of it, as required by GDPR Article 33, unless the breach is unlikely to result in a risk to your rights and freedoms. Where a breach is likely to result in a high risk to you, we will notify you directly and without undue delay, describing what happened, what data was involved, what we are doing about it, and what you should do.
18. Changes to This Policy
We may update this Privacy Policy. If a change is material — for example, a new category of data, a new processor, or a new purpose — we will give you notice by email or an in-app notice before it takes effect, and where the change requires your consent, we will ask for it. Non-material changes take effect when posted, with the Effective Date updated at the top of this page.
We will keep previous versions available on request so you can see what changed.
19. Contact Us and Complaints
For any privacy question, request, or complaint, email [email protected]. We take complaints seriously and will always try to resolve them with you first.
You also have the right to lodge a complaint with a data protection supervisory authority — in the EU, either the authority in the country where you live or work, or the authority where we are established:
- Our lead supervisory authority: [[FILL IN: name and website of the data protection authority in your EU member state]]
A list of EU supervisory authorities is published by the European Data Protection Board at edpb.europa.eu.