The short version
- Nothing. No account, no analytics, no advertising identifiers, no crash reporting that leaves the device, no tracking.
- You can withdraw consent to send anything, in one tap, at any time.
- Meal or label photos
- What you type about a meal
- The text of what you say (never the audio)
- Questions you ask, with a small set of totals
- Memory items you have explicitly allowed
Who we are
NutriFit is developed and published by Cong Minh Nguyen, an individual developer, and is the same entity named on the App Store and Google Play listings. This policy describes the NutriFit app and this website. It does not describe the AI providers you may connect, who have their own policies linked below.
What NutriFit stores, and where
Everything the app knows about you lives in its own storage on your phone: your meals and their photos, weigh-ins, your profile (age, sex, height, weight, activity, and whether you have told the app you are pregnant or breastfeeding — health information that is kept only on your device and is never sent anywhere), your daily target, favourites, the corrections you make to estimates, your chats, and any memory items. None of it is uploaded to us, because there is no “us” to upload it to.
You can export all of it at any time from Settings → Export — meals and weigh-ins as CSV, corrections as JSON, photos as a ZIP. You can delete your log, photos, profile, favourites, corrections, chats and memory in one action from Settings → Delete data. Your API key lives in the secure store rather than the database; remove it with Replace under Settings → Provider key, or by deleting the app. Deleting the app deletes everything.
Nothing is retained anywhere but your device, so there is no retention period on our side: data lives until you delete it or the app.
Your device's own backup (iCloud, Google) may include the app's storage, under that service's terms. It does not include your API key — see below.
Your AI provider key
Photo, voice and text recognition need an AI provider. Rather than run one ourselves, NutriFit asks you to connect your own key from OpenAI, Anthropic or Google. You pay that provider directly, and the app shows you how many calls it has made.
Your key is stored in the platform's secure store — the iOS Keychain or the Android Keystore — never in the app's database, so it does not appear in exports or in a backup of that database. It is sent to one place only: the provider it belongs to.
What is sent to your provider, and what never is
Before the first byte goes anywhere, the app shows you a consent screen that names the provider and lists exactly what will be sent. It is shown again if you change provider. You can decline — manual entry, favourites, weight tracking, targets and the whole log work with no provider and no network at all.
- The photo you take of a plate or a label (reduced in size first)
- The description you type
- The text of a voice note, transcribed on your phone
- A question you ask in Ask, together with a small named set of totals (for example, your average protein over 14 days) — you see this set on screen before it is sent
- Memory items you have individually allowed
- Your weight, age, sex, height or activity level
- Your daily target or its figures
- Your log — no meals, no days, no history
- Your exports
- Your API key, to anyone but its provider
Withdrawing consent
You can withdraw at any time: Settings → Provider key → Withdraw consent. From that moment the app makes no further calls to any provider — the check happens before every request, not once at setup. Manual entry, favourites, weight, targets and your log carry on unchanged. Withdrawal does not recall what a provider has already received; use that provider's own tools for that.
Where your provider is, and what it may do
OpenAI, Anthropic and Google process requests in the United States and elsewhere under their own terms; when you connect a key you are contracting with that provider directly, and it — not NutriFit — is responsible for what it does with what you send. Read its policy before you connect.
In particular: some providers' free or unpaid tiers permit them to use what you send to improve their models. At the time of writing Google's Gemini API does this on its unpaid tier and not on its paid tier. NutriFit cannot see or change this. If it matters to you, use a paid tier, a provider whose terms exclude training, or the on-device model described below.
Two calls are deliberately shaped so the provider sees no numbers about you. When the app explains your target, it sends only the shape of the calculation and receives text with placeholders, which your phone fills in. When it writes your weekly summary, it sends a verdict already computed on your phone — a band such as “slightly over” and one suggested change — never the days behind it.
What a provider does with what it receives is governed by that provider's own terms and privacy policy, not by this one: OpenAI · Anthropic · Google.
Voice
When you hold to talk, your speech is turned into text on your phone, and only that text is sent to your provider. The recording itself never leaves the device.
NutriFit asks the operating system for on-device recognition specifically. If a device can only transcribe by uploading the audio to Apple or Google, NutriFit declines to record and tells you why, rather than sending the audio anywhere. On iOS the permission prompt shows Apple's standard wording about speech data; NutriFit's request is for on-device recognition, and it will not record without it.
Running the model on your phone
On devices that support it, NutriFit can use Apple's on-device model instead of a cloud provider. In that mode nothing is sent anywhere: recognition happens entirely on the device.
Permissions
Every permission is optional. Decline any of them and manual entry, favourites and the rest of the app keep working.
- Camera — to photograph a plate or a nutrition label.
- Microphone and speech recognition — to say what you ate instead of typing it, transcribed on the device as described above.
The app asks for nothing else. It does not read your photo library, contacts, location or health data, and it sends no notifications.
Photos
A photo you take for an estimate is kept in the app's storage so it can appear beside the meal. If you cancel before logging, it is deleted. Photos are never uploaded to us; a copy goes only to your chosen provider, once, when you ask for an estimate.
Children
NutriFit is not directed at children under 13 and does not knowingly collect information from anyone — it collects none at all. Users who indicate they are under 18 are limited to weight-maintenance targets and pointed to a clinician.
Not a medical device
NutriFit is a logging tool. It does not diagnose, treat or prevent any condition and is not health advice. Talk to a clinician before changing how you eat, especially if you are pregnant or breastfeeding, under 18, or managing a condition.
Your rights
Because we hold no data about you, there is nothing for us to access, correct, export or erase on your behalf — those controls are on your phone: Settings → Export and Settings → Delete data, and they work immediately, without asking us.
If you are in the EU, EEA or UK. Our understanding is that NutriFit does not process your personal data as a controller: processing on your device is under your control, and anything you choose to send to a provider is sent under your agreement with that provider, which is the controller for it. The legal basis for that transmission is your explicit consent, given on the consent screen and withdrawable as described above. You have the right to complain to your local data-protection authority. We do not use your data to train anything, and we make no automated decisions with legal effect about you.
If you are in California. We do not sell or share personal information and have none to sell. Nothing here is used for targeted advertising.
Contact. For questions about this policy, contact the developer through the app's listing on the App Store or Google Play.
Changes
If this policy changes, the new version is published at this address with its effective date. A change that affects what is sent to a provider will also be shown in the app before anything is sent under the new terms.
This website
This page is served by Cloudflare Pages. To deliver it, Cloudflare receives the technical details of your request (including your IP address) and may keep short-lived logs under its privacy policy. The page sets no cookies, runs no analytics, and its fonts are served from this site rather than a third-party font service, so reading it tells no one else you were here.
Changes to this policy are dated here. v1.1 added the pregnancy/breastfeeding field, consent withdrawal, provider location and training notes, EU/UK and California statements, and removed permissions the app does not use.