The short version
- Nothing. No account, no analytics, no advertising identifiers, no crash reporting that leaves the device, no tracking.
- You can withdraw consent to send anything, in one tap, at any time.
- One typed word deletes everything, your key included.
- Meal or label photos
- What you type about a meal
- The text of what you say (never the audio)
- Questions you ask, with a small set of totals
- Memory — the sentences shown in Settings → Memory, and only while you have turned memory on there. It is off until you do; pausing or turning it off sends none of it, and you can forget any item.
Who we are
NutriFit is developed and published by Cong Minh Nguyen, an individual developer, and is the same entity named on the App Store and Google Play listings. This policy describes the NutriFit app and this website. It does not describe the AI providers you may connect, who have their own policies linked below.
What NutriFit stores, and where
Everything the app knows about you lives in its own storage on your phone: your meals and their photos, weigh-ins, your profile (age, sex, height, weight, activity, and whether you have told the app you are pregnant or breastfeeding — health information that is kept only on your device and is never sent anywhere), your daily target, favourites, the corrections you make to estimates, and any memory items. Questions you ask in Ask are answered and not kept. None of it is uploaded to us, because there is no “us” to upload it to.
You can delete your log, photos, profile, favourites, corrections and memory in one action from Settings → Delete data. You can export all of it from Settings → Export everything: meals, weigh-ins and favourites as CSV, corrections and your profile and target as JSON, and — if you switch it on — your photos as a ZIP. The files are handed to your phone’s share sheet and go wherever you send them; NutriFit keeps no copy and is not part of that transfer. Delete data → Delete everything also removes your API key from the secure store and withdraws consent, so a phone can be handed on with nothing that bills your account left behind. Deleting the app deletes everything.
Nothing is retained anywhere but your device, so there is no retention period on our side: data lives until you delete it or the app.
Your device's own backup (iCloud, Google) may include the app's storage, under that service's terms. It does not include your API key — see below.
Your AI provider key
Photo, voice and text recognition need an AI provider. Rather than run one ourselves, NutriFit asks you to connect your own key from OpenAI, Anthropic or Google. You pay that provider directly, and the app shows you how many calls it has made.
Your key is stored in the platform's secure store — the iOS Keychain or the Android Keystore — never in the app's database, so it does not appear in exports or in a backup of that database. It is sent to one place only: the provider it belongs to.
What is sent to your provider, and what never is
Before the first byte goes anywhere, the app shows you a consent screen that names the provider and lists exactly what will be sent. It is shown again if you change provider. You can decline — manual entry, favourites, weight tracking, targets and the whole log work with no provider and no network at all.
- The photo you take of a plate or a label (reduced in size first)
- The description you type
- The text of a voice note, transcribed on your phone
- A question you ask in Ask, together with a small named set of totals (for example, your average protein over 14 days) — you see this set on screen before it is sent
- The memory sentences described above, only while memory is on
- Your weight, age, sex, height or activity level
- Your daily target or its figures
- Your log — no meals, no days, no history
- Your exports
- Your API key, to anyone but its provider
Withdrawing consent
You can withdraw at any time: Settings → Provider key → Withdraw consent. From that moment the app makes no further calls to any provider — the check happens before every request, not once at setup. Manual entry, favourites, weight, targets and your log carry on unchanged. Withdrawal does not recall what a provider has already received; use that provider's own tools for that.
Where your provider is, and what it may do
OpenAI, Anthropic and Google process requests in the United States and elsewhere under their own terms; when you connect a key you are contracting with that provider directly, and it — not NutriFit — is responsible for what it does with what you send. Read its policy before you connect.
In particular: some providers' free or unpaid tiers permit them to use what you send to improve their models. At the time of writing Google's Gemini API does this on its unpaid tier and not on its paid tier. NutriFit cannot see or change this. If it matters to you, use a paid tier, a provider whose terms exclude training, or the on-device model described below.
Two calls are deliberately shaped so the provider sees no numbers about you. When the app explains your target, it sends only the shape of the calculation and receives text with placeholders, which your phone fills in. When it writes your weekly summary, it sends a verdict already computed on your phone — a band such as “slightly over” and one suggested change — never the days behind it.
What a provider does with what it receives is governed by that provider's own terms and privacy policy, not by this one: OpenAI · Anthropic · Google.
Voice
When you hold to talk, your speech is turned into text on your phone, and only that text is sent to your provider. The recording itself never leaves the device.
NutriFit asks the operating system for on-device recognition specifically. If a device can only transcribe by uploading the audio to Apple or Google, NutriFit declines to record and tells you why, rather than sending the audio anywhere. On iOS the permission prompt shows Apple's standard wording about speech data; NutriFit's request is for on-device recognition, and it will not record without it.
Running the model on your phone
On devices that support it, NutriFit can use Apple's on-device model instead of a cloud provider. In that mode nothing is sent anywhere: recognition happens entirely on the device.
Permissions
Every permission is optional. Decline any of them and manual entry, favourites and the rest of the app keep working.
- Camera — to photograph a plate or a nutrition label.
- Photos — to choose a meal photo you already took. This uses the system's own picker, which hands NutriFit only the one photo you choose; the app never reads your library, and on iOS is never even asked for library access.
- Microphone and speech recognition — to say what you ate instead of typing it, transcribed on the device as described above.
- Notifications — an optional weekly-report reminder, weigh-in reminder and log nudge, off until you turn them on. They are scheduled on your phone; there is no push service and no server. The notification says only that something is ready — it never carries a number.
The app asks for nothing else. It does not read your contacts, location or health data.
Photos
A photo you take for an estimate is kept in the app's storage so it can appear beside the meal. If you cancel before logging, it is deleted. Photos are never uploaded to us; a copy goes only to your chosen provider, once, when you ask for an estimate.
Children
NutriFit is not directed at children under 13 and does not knowingly collect information from anyone — it collects none at all. Users who indicate they are under 18 are limited to weight-maintenance targets and pointed to a clinician.
Not a medical device
NutriFit is a logging tool. It does not diagnose, treat or prevent any condition and is not health advice. Talk to a clinician before changing how you eat, especially if you are pregnant or breastfeeding, under 18, or managing a condition.
Your rights
Because we hold no data about you, there is nothing for us to access, correct, export or erase on your behalf — those controls are on your phone: Settings → Export everything and Settings → Delete data, and they work immediately, without asking us.
If you are in the EU, EEA or UK. Our understanding is that NutriFit does not process your personal data as a controller: processing on your device is under your control, and anything you choose to send to a provider is sent under your agreement with that provider, which is the controller for it. The legal basis for that transmission is your explicit consent, given on the consent screen and withdrawable as described above. You have the right to complain to your local data-protection authority. We do not use your data to train anything, and we make no automated decisions with legal effect about you.
If you are in California. We do not sell or share personal information and have none to sell. Nothing here is used for targeted advertising.
Contact. For questions about this policy, contact the developer through the app's listing on the App Store or Google Play.
Changes
If this policy changes, the new version is published at this address with its effective date. A change that affects what is sent to a provider will also be shown in the app before anything is sent under the new terms.
This website
This page is served by Cloudflare Pages. To deliver it, Cloudflare receives the technical details of your request (including your IP address) and may keep short-lived logs under its privacy policy. The page sets no cookies, runs no analytics, and its fonts are served from this site rather than a third-party font service, so reading it tells no one else you were here.
Changes to this policy are dated here. v1.4: export is built and described; memory is described as it works — a switch in Settings → Memory, off by default, sending only the sentences shown there. v1.3: removed the export promise until the feature exists, and no longer lists chats as stored — they are not. v1.2: Delete everything now also removes the API key; the Photos and Notifications permissions describe features that now exist. v1.1 added the pregnancy/breastfeeding field, consent withdrawal, provider location and training notes, EU/UK and California statements, and removed permissions the app does not use.