NutriForMe is an informational and educational nutrition and lifestyle app. It is not medical advice and not a medical device. Decisions about your health belong with you and your clinician.
Only what you put in: your profile (name, age, height, goals, targets), food and water logs, phone workout sets, reps, loads, effort and notes, weights, conditions, medications, allergies and lab results you choose to record, and — if you turn Apple Health access on — readings the app lists when asking permission (such as steps, weight, sleep, heart-rate variability, resting heart rate, glucose, blood pressure, respiratory rate, blood oxygen, wrist temperature, VO2max and workouts). By recording lab results, conditions or medications you consent to the app storing them for the features that use them. There are no ads, no trackers, and no third-party analytics in this app.
Your health record is kept in the app's private storage on your phone. If you create an account, the health backup is encrypted on your device with AES-GCM before upload. You choose Sydney, Australia or Virginia, United States for that encrypted backup at signup. Its key is held in your device Keychain and can sync through iCloud Keychain when available; a recovery phrase lets you restore that key. The key is not sent to our server, so our server and Supabase cannot read the health record inside the backup. Account identity, email address, selected backup region, plan and AI usage counts, saved cloud recipes, generated recipe pictures and feedback use NutriForMe's control-plane Supabase project in Sydney. App lock with Face ID is available.
1. Encrypted health backup, as above — unreadable to the server. 2. Food lookups send the barcode or food-search words you enter to Open Food Facts. 3. Recipe import contacts the web address you provide to retrieve that page. 4. AI features — Ask, meal-photo analysis, label reading, product web lookup, recipe design and recipe pictures — send only the content needed for the request through NutriForMe's Supabase gateway to OpenAI after you allow AI data sharing. Depending on the feature, that can include your question, a photo you chose, a product name, recipe ingredients, recorded allergies, food logs and targets. Ask attaches recorded conditions, medication names, allergies, weight trends or recent Apple Health readings only when you separately turn health context on. Information you type into a request is still sent even with health context off. Recipe design does not send recorded conditions or medications. Voice food search uses on-device recognition only; microphone audio is not uploaded by NutriForMe. You can revoke AI consent or turn off health context in Profile → AI and privacy.
NutriForMe does not store AI prompts, uploaded analysis photos or AI replies in gateway request logs. The gateway records operational details such as request identifier, feature, status, timing and token counts and keeps per-account monthly usage totals. A recipe and recipe picture are stored only when you choose to save or generate them. OpenAI processes API requests under its API data controls and states that API data is not used to train its models by default. Choosing an encrypted health-backup region does not move these optional third-party requests into that region.
The conversational setup wizard collects answers on your phone. If you explicitly allow it, your selected setup answers, including any conditions, medication names or allergies you typed, are sent through NutriForMe to OpenAI to organise an editable draft. Stored health records, name, body measurements and clinician notes are not automatically attached. Text you type into a shared answer is still sent. The app calculates targets locally; AI cannot set them. You review the draft before saving. This separate setup permission does not enable everyday AI features. The server stores an account-linked lifetime attempt count, not your setup answers or draft. There are at most three draft attempts per account, including unsuccessful requests, with no monthly reset. Confirmed planning preferences and notes are saved in your profile and included in encrypted sync when enabled. Unsaved interview text is held in memory and is lost if the app closes.
When you purchase or restore a subscription, Apple processes payment. NutriForMe sends Apple's signed transaction, including the product and transaction identifiers and an app-account token, to its Supabase verification service. The service checks ownership and current subscription status with Apple before enabling paid features. Signed transactions and payment details are not written to our request logs, and we do not receive your card details. TestFlight transactions use Apple's sandbox and do not create production entitlements. Deleting your NutriForMe account does not cancel an Apple subscription; manage or cancel it in your Apple account settings.
We never sell your data, never share it with advertisers or data brokers, and never use Apple Health data for marketing. Health data is used only to provide the health features you see.
If you use NutriForMe on Apple Watch, the watch reads the Apple Health data needed for the features you choose, including steps, activity progress and sleep; during a workout it uses heart rate, active energy and distance. Starting a walk, run, ride or strength session records a workout in Apple Health. Outdoor route recording uses precise GPS location with your permission. Location is used only to draw, measure and save that route — never for advertising or profiling, and never sent to our AI provider.
With your Apple Health write permission, NutriForMe can write a weight you recorded yourself — typed in, read from your scale or logged on Apple Watch — and blood-pressure readings you record. A weight that came from Apple Health is never written back. On Apple Watch, a workout and its outdoor route are written when you choose to start a supported workout. Meals, water, blood results, conditions and medications are not written to Apple Health. You can change access in Settings → Privacy & Security → Health → NutriForMe. Records already written to Apple Health remain under your control in the Health app.
Saved routes are stored on the watch, in the app's own private storage. They are not uploaded to our server, not synced through the AI features, and not shared with anyone. You can delete any saved route from the app at any time, which removes its GPS points permanently; deleting the app removes them all. Workouts written to Apple Health are managed by you in the Health app, and deleting them there is independent of us.
If you choose workout music, NutriForMe asks Apple Music or Spotify to list or control music through the account and app you already use. NutriForMe does not send your health readings, workout measurements or saved routes to either music service. Their handling of account and playback data is governed by their own privacy policies.
The encrypted health backup stays in the region selected at signup. NutriForMe's control plane is in Australia. When you deliberately use a connected feature, OpenAI and other service providers may process the limited request data in the United States or other countries described in their current privacy terms; an imported recipe is retrieved from the country where that website is hosted. Apple Health and iCloud are provided by Apple under your Apple account settings. Open Food Facts, Spotify and Apple Music handle only the requests described above under their own terms. Privacy protections and legal remedies can differ outside Australia.
NutriForMe contains no advertising SDK, third-party analytics SDK or cross-app tracker. Health, workout and location data are not used for advertising. The AI gateway keeps a per-account monthly count by feature to enforce usage limits and writes operational logs such as request identifier, feature, status, timing and token counts; it does not log questions, health context, photos or replies. Infrastructure providers may keep their own security and service logs under their terms.
Your app data stays until you delete it. Deleting entries removes them from the device and, when sync is on, from the next encrypted backup. Delete account requests removal of the regional encrypted backup, account identity, plan and usage records, saved cloud recipes, generated recipe pictures and feedback, then removes this account's local app data and encryption key. If a server step fails, the app reports what remains instead of claiming deletion completed. Saved watch routes are deleted when you remove them or delete the Watch app. Deleting the iPhone app removes its local data. Apple Health records remain under your control in the Health app.
If a breach compromises user data we will notify affected users promptly, in line with applicable law, including the Australian Privacy Act's notifiable data breaches scheme.
You can view the health record held in the app, export it from Profile → App, correct it or delete it. To ask for access or correction, question this policy or make a privacy complaint, email chris.dunn@retina-ms.com.au with 'Privacy' in the subject. We will acknowledge the request, investigate it and explain the outcome and any action taken. If you are not satisfied, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.