Privacy policy

Your food log stays on your phone.

NutriFit has no account and no server. There is nothing of yours for us to hold, sell or lose. The only data that ever leaves your device is what you choose to send to the AI provider you connect — with your own key, after you have been asked.

Effective 5 September 2026 · Applies to NutriFit for iOS and Android

The short version

We collect
  • Nothing. No account, no analytics, no advertising identifiers, no crash reporting that leaves the device, no tracking.
  • You can withdraw consent to send anything, in one tap, at any time.
You may send, to a provider you choose
  • Meal or label photos
  • What you type about a meal
  • The text of what you say (never the audio)
  • Questions you ask, with a small set of totals
  • Memory items you have explicitly allowed

Who we are

NutriFit is developed and published by Cong Minh Nguyen, an individual developer, and is the same entity named on the App Store and Google Play listings. This policy describes the NutriFit app and this website. It does not describe the AI providers you may connect, who have their own policies linked below.

What NutriFit stores, and where

Everything the app knows about you lives in its own storage on your phone: your meals and their photos, weigh-ins, your profile (age, sex, height, weight, activity, and whether you have told the app you are pregnant or breastfeeding — health information that is kept only on your device and is never sent anywhere), your daily target, favourites, the corrections you make to estimates, your chats, and any memory items. None of it is uploaded to us, because there is no “us” to upload it to.

You can export all of it at any time from Settings → Export — meals and weigh-ins as CSV, corrections as JSON, photos as a ZIP. You can delete your log, photos, profile, favourites, corrections, chats and memory in one action from Settings → Delete data. Your API key lives in the secure store rather than the database; remove it with Replace under Settings → Provider key, or by deleting the app. Deleting the app deletes everything.

Nothing is retained anywhere but your device, so there is no retention period on our side: data lives until you delete it or the app.

Your device's own backup (iCloud, Google) may include the app's storage, under that service's terms. It does not include your API key — see below.

Your AI provider key

Photo, voice and text recognition need an AI provider. Rather than run one ourselves, NutriFit asks you to connect your own key from OpenAI, Anthropic or Google. You pay that provider directly, and the app shows you how many calls it has made.

Your key is stored in the platform's secure store — the iOS Keychain or the Android Keystore — never in the app's database, so it does not appear in exports or in a backup of that database. It is sent to one place only: the provider it belongs to.

What is sent to your provider, and what never is

Before the first byte goes anywhere, the app shows you a consent screen that names the provider and lists exactly what will be sent. It is shown again if you change provider. You can decline — manual entry, favourites, weight tracking, targets and the whole log work with no provider and no network at all.

Sent, after consent
  • The photo you take of a plate or a label (reduced in size first)
  • The description you type
  • The text of a voice note, transcribed on your phone
  • A question you ask in Ask, together with a small named set of totals (for example, your average protein over 14 days) — you see this set on screen before it is sent
  • Memory items you have individually allowed
Never sent
  • Your weight, age, sex, height or activity level
  • Your daily target or its figures
  • Your log — no meals, no days, no history
  • Your exports
  • Your API key, to anyone but its provider

Withdrawing consent

You can withdraw at any time: Settings → Provider key → Withdraw consent. From that moment the app makes no further calls to any provider — the check happens before every request, not once at setup. Manual entry, favourites, weight, targets and your log carry on unchanged. Withdrawal does not recall what a provider has already received; use that provider's own tools for that.

Where your provider is, and what it may do

OpenAI, Anthropic and Google process requests in the United States and elsewhere under their own terms; when you connect a key you are contracting with that provider directly, and it — not NutriFit — is responsible for what it does with what you send. Read its policy before you connect.

In particular: some providers' free or unpaid tiers permit them to use what you send to improve their models. At the time of writing Google's Gemini API does this on its unpaid tier and not on its paid tier. NutriFit cannot see or change this. If it matters to you, use a paid tier, a provider whose terms exclude training, or the on-device model described below.

Two calls are deliberately shaped so the provider sees no numbers about you. When the app explains your target, it sends only the shape of the calculation and receives text with placeholders, which your phone fills in. When it writes your weekly summary, it sends a verdict already computed on your phone — a band such as “slightly over” and one suggested change — never the days behind it.

What a provider does with what it receives is governed by that provider's own terms and privacy policy, not by this one: OpenAI · Anthropic · Google.

Voice

When you hold to talk, your speech is turned into text on your phone, and only that text is sent to your provider. The recording itself never leaves the device.

NutriFit asks the operating system for on-device recognition specifically. If a device can only transcribe by uploading the audio to Apple or Google, NutriFit declines to record and tells you why, rather than sending the audio anywhere. On iOS the permission prompt shows Apple's standard wording about speech data; NutriFit's request is for on-device recognition, and it will not record without it.

Running the model on your phone

On devices that support it, NutriFit can use Apple's on-device model instead of a cloud provider. In that mode nothing is sent anywhere: recognition happens entirely on the device.

Permissions

Every permission is optional. Decline any of them and manual entry, favourites and the rest of the app keep working.

The app asks for nothing else. It does not read your photo library, contacts, location or health data, and it sends no notifications.

Photos

A photo you take for an estimate is kept in the app's storage so it can appear beside the meal. If you cancel before logging, it is deleted. Photos are never uploaded to us; a copy goes only to your chosen provider, once, when you ask for an estimate.

Children

NutriFit is not directed at children under 13 and does not knowingly collect information from anyone — it collects none at all. Users who indicate they are under 18 are limited to weight-maintenance targets and pointed to a clinician.

Not a medical device

NutriFit is a logging tool. It does not diagnose, treat or prevent any condition and is not health advice. Talk to a clinician before changing how you eat, especially if you are pregnant or breastfeeding, under 18, or managing a condition.

Your rights

Because we hold no data about you, there is nothing for us to access, correct, export or erase on your behalf — those controls are on your phone: Settings → Export and Settings → Delete data, and they work immediately, without asking us.

If you are in the EU, EEA or UK. Our understanding is that NutriFit does not process your personal data as a controller: processing on your device is under your control, and anything you choose to send to a provider is sent under your agreement with that provider, which is the controller for it. The legal basis for that transmission is your explicit consent, given on the consent screen and withdrawable as described above. You have the right to complain to your local data-protection authority. We do not use your data to train anything, and we make no automated decisions with legal effect about you.

If you are in California. We do not sell or share personal information and have none to sell. Nothing here is used for targeted advertising.

Contact. For questions about this policy, contact the developer through the app's listing on the App Store or Google Play.

Changes

If this policy changes, the new version is published at this address with its effective date. A change that affects what is sent to a provider will also be shown in the app before anything is sent under the new terms.

This website

This page is served by Cloudflare Pages. To deliver it, Cloudflare receives the technical details of your request (including your IP address) and may keep short-lived logs under its privacy policy. The page sets no cookies, runs no analytics, and its fonts are served from this site rather than a third-party font service, so reading it tells no one else you were here.

NutriFit · © 2026 Cong Minh Nguyen · Effective 5 September 2026 · v1.1
Changes to this policy are dated here. v1.1 added the pregnancy/breastfeeding field, consent withdrawal, provider location and training notes, EU/UK and California statements, and removed permissions the app does not use.