← Back

Privacy Policy

Last updated: October 1, 2026

Nutriq is a calorie tracking app provided by Robert-Paul van den Born. This policy explains what data we collect, why, and where it goes. Account and tracking records are stored in the EU, while the processors described below may process some data elsewhere. We don't sell your data or show ads.

What we collect

When you use Nutriq, we store:

Meal and activity logs and biometric data are health data. We process them only with your explicit consent, which Nutriq asks for before you start tracking. You can withdraw consent at any time by deleting your account; processing then stops and your data is deleted as described below.

Optional dictation

If you use voice input, Android's system speech provider or your browser's speech recognition service processes your voice. The provider may require an internet connection, and its own settings and privacy policy apply. Nutriq receives the recognized text and does not receive or store audio recordings. When submitted, that text follows the same meal logging and AI processing described in this policy.

Where your data is stored

Your account and tracking records are stored in Supabase in Ireland (eu-west-1). Nutriq is hosted on Vercel, which also provides website page-view and performance measurements. AI requests are processed by OpenAI; we do not promise that all processing stays within the European Union.

AI processing

When you log a meal or exercise, your input is sent to OpenAI's API to generate calorie and macro estimates. Weekly observations use a summary of your recent logs. OpenAI does not train on API data by default. We disable response storage; abuse-monitoring logs may still be retained for up to 30 days, with exceptions described in its policies. See OpenAI's data controls for details. Where a nutrition database lookup is used, the meal description is also sent to Open Food Facts.

You can report unsafe, offensive, or inaccurate AI-generated answers inside Nutriq. Reports are reviewed privately by Robert-Paul van den Born. A report does not automatically change your saved tracking data or trigger an automated decision.

Health information

Calorie, nutrient, exercise, and goal values in Nutriq are estimates for general wellness and tracking. They are not medical advice and are not intended to diagnose, treat, cure, or prevent any condition. Consult a qualified healthcare professional for medical advice, diagnosis, treatment, or decisions about a medically supervised diet.

What we don't do

Cookies and tracking

The website uses essential authentication cookies and browser storage to maintain your session and preferences. In the Android app, session and preference data are stored in the app's private WebView storage. Entries submitted without a connection may be kept in that private storage until they sync successfully. Signing out or deleting your account clears that offline queue on a best-effort basis; clearing the app's storage or uninstalling it also removes the local copy. Android cloud backup is disabled. Nutriq does not use product analytics.

Data export and deletion

You can export your tracking records and profile as JSON from Settings. Delete all data in Settings removes meals, activities, weight entries, and saved meals, but retains your account and profile settings. To also remove your sign-in account and profile, choose Delete account permanently in Settings. Account and tracking records are kept while your account is active and are deleted when you use that control. Offline entries remain only until successful sync or local storage is cleared. In the active database, Nutriq's operational rate-limit security records are deleted hourly once they are more than 48 hours old. Encrypted disaster-recovery backups are separate copies: deletion and the hourly operational cleanup do not rewrite an existing backup, so deleted records may remain there until that encrypted backup is deliberately retired. The early-access backup process is manually triggered and documented separately; it is not the hourly operational cleanup. Backups are used only for recovery. Unresolved AI output reports remain in the active database while they need investigation or a response. Resolved reports are deleted by a daily scheduled cleanup after they have remained resolved for at least 90 days. Reopening a report clears its resolution date; editing a report that remains resolved does not restart that period. Deleting your account removes its active report records immediately, while older encrypted backups are handled under the separate manual recovery process. Nutriq no longer collects product analytics. Historical website analytics, and analytics from older Android app versions, can follow separate provider retention schedules and may not be removed by the in-app control. Email us to request deletion of analytics records associated with your account or to ask about a specific retention period.

Your rights under GDPR

If you're in the EU, you have the right to access, correct, delete, or export your personal data. You can do most of this directly in the app. For anything else, contact us.

Contact

Questions about your data? Email privacy@nutriq.space. The current online version of this policy is always available at nutriq.space/privacy

nutriq