Privacy Policy
Effective date: 23 August 2026 · Last updated: 23 August 2026
This Privacy Policy describes how NutriAI (“we”, “us” or “our”), operated by Vriddhix Technology, collects, uses, stores, and shares information when you use our mobile application, related websites (including marketing pages hosted on Firebase), and associated services (collectively, the “Services”). We are committed to protecting your privacy and handling your data responsibly.
1. Who this policy applies to
This policy applies to individuals who download or use the NutriAI app (Android package identifier:
com.vriddhix.nutriai), visit our web properties, or otherwise interact with the Services.
2. Information we collect
Depending on how you use the Services, we may collect the following categories of information:
- Account and profile data. A display name and, only if you choose to sign in, the email address or authentication identifier provided by your sign-in method (Google, Apple, or email and password), plus a profile photo if you add one. On first launch the app creates an anonymous account so you can start without registering; that account is identified by a generated identifier alone.
- Onboarding and body data. Sex, date of birth, height, current weight, goal weight, activity level and dietary preference, together with your unit and language preferences. These are what your calorie, macro and hydration targets are calculated from.
- Nutrition and wellbeing activity data. Information you create through the app, including meals you log and their nutrition figures, portion adjustments and corrections, water intake, weight entries, streaks, the diet plan generated for you, and feedback you send to us.
- Meal photographs. The images you scan, and the AI's reading of them. See section 6.
- Device and technical data. Device type, operating system version, app version, a generated device identifier, language settings, time zone (which determines when your tracking day rolls over), approximate region derived from IP address for security and diagnostics, crash logs, and performance metrics.
- Identifiers for notifications. A push notification token or similar identifier assigned by your platform or our push provider, used to deliver the account and promotional messages you opt into. Meal, water, weight and weekly-summary reminders are scheduled and fired on your device and are not sent from our servers.
- Purchase data. Subscription status, plan identifier and transaction identifiers received from Google Play through our billing provider. We never receive or store your card details.
- Support communications. The content of emails or in-app messages you send us, including your contact details as provided and any screenshots you attach.
3. How we use information
We use the information above to:
- Provide, maintain, and improve the Services, including food recognition, the calorie and macro diary, hydration and weight tracking, personal targets, plans, and insights;
- Authenticate users, secure accounts, and detect abuse, fraud, and technical issues;
- Send operational messages (for example account verification or security notices) and, where permitted, product updates or promotional communications, which you may opt out of;
- Deliver push notifications you have enabled;
- Manage subscriptions, verify entitlement, and honour restores;
- Analyse aggregated or de-identified usage to improve usability and reliability;
- Comply with legal obligations and enforce our Terms of Service.
We do not use your personal data to build advertising profiles, and we do not use your meal photographs to train models for anyone else's benefit.
4. Legal bases (where applicable)
If data protection laws in your region require a “legal basis,” we rely on one or more of the following, as appropriate: performance of a contract with you; your explicit consent, which is the basis on which we process the health data described in section 5; legitimate interests (securing the Services, improving the product, and communicating with you about the Services), balanced against your rights; and compliance with legal obligations. Where we rely on consent, you may withdraw it at any time, and that does not affect processing already carried out.
5. Health and nutrition data
The meals, water and weight you record, and the body measurements you enter during onboarding, are health-related and are treated in some jurisdictions as a special category of personal data. We process them solely to run the Services for you: to calculate your targets, to keep your diary, and to show you your own history and trends.
We do not sell this data, we do not share it with advertising networks or data brokers, and no advertising SDK in the app has access to it. That separation is enforced in the application itself, not merely stated here. You can delete individual entries at any time in the app, or ask us to delete everything (see section 11).
6. Meal photographs and AI analysis
When you scan a meal, the photograph is uploaded to our storage and sent from our servers to a third-party AI model provider, which returns an estimate of the dish, its ingredients and its nutrition. The app never sends your photograph directly to a model provider, and never carries a model provider's credentials.
Photographs are stored in a private bucket. They are never publicly readable: the app requests a signed link that expires approximately one hour after it is issued, and the durable reference the app keeps is a storage path rather than a URL. Deleting a meal deletes its record; contact us if you would also like the underlying image removed.
Nutrition figures produced this way are estimates, not measurements. See our Terms of Service.
7. How we share information
We do not sell your personal information. We may share data with:
- Service providers who assist us with hosting, databases, authentication, media storage, AI food recognition, analytics, crash reporting, error monitoring, email delivery, subscription management and push notifications, subject to confidentiality and processing terms;
- App stores and platforms (for example Google Play) as needed for distribution, updates, billing, and platform rules;
- Advertising partners, where advertising is shown, and only with the limited data needed to serve an ad. No health, nutrition, body-measurement or meal-photograph data is shared for advertising;
- Authorities when required by law, legal process, or to protect the rights, safety, and integrity of users or the public.
We may also share information in connection with a merger, acquisition, or asset transfer, with notice as required by law.
8. International transfers
Your information may be processed in countries other than where you live, including where our servers or providers operate. Where required, we implement appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) for cross-border transfers.
9. Retention
We retain information for as long as your account is active, as needed to provide the Services, and as necessary to comply with legal, tax, accounting, or dispute-resolution obligations. Diary entries, photographs and profile data are kept while your account exists. Following a deletion request we remove data from live systems within 30 days and from backups within 90. Crash and analytics data are retained on our providers' default schedules.
10. Security
We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. Data is encrypted in transit and at rest. Access tokens are short-lived and refresh tokens rotate on every use. Access to production data is limited to people who need it to operate the Service. No method of transmission or storage is completely secure; we encourage you to keep any credentials confidential and notify us of suspected unauthorized access.
11. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, or export personal data; object to or restrict certain processing; withdraw consent where processing is consent-based; and lodge a complaint with a supervisory authority. You may also control notifications and language through your device or in-app settings.
To exercise these rights, contact us using the details below. We may need to verify your identity before responding. If you are unsatisfied with our response, you may have the right to complain to your local data protection regulator.
A note on anonymous sessions. The app creates an anonymous account on first launch so you can start without signing up. That account is still yours and the rights above still apply to it. Signing out of a linked account begins a new anonymous session. The previous data stays attached to the account you signed out of, not to the new session.
12. Children
The Services are not directed to children, and are intended for people aged 18 or over; onboarding declines a date of birth below that age. If you believe we have collected information from a child without appropriate consent, please contact us and we will take steps to delete it where required.
13. Third-party links and services
The Services may contain links to third-party websites or integrate third-party SDKs. Their collection and use of information is governed by their own policies. We encourage you to review the privacy notices of Google Play, your device manufacturer, and any identity provider you use to sign in.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised version with an updated “Last updated” date and, where appropriate, provide additional notice (such as an in-app message or email). Continued use of the Services after changes become effective constitutes acceptance of the updated policy, to the extent permitted by law.
Email: vriddhixtechnology@gmail.com
Please include “Privacy Request” in the subject line and describe your request clearly so we can assist you promptly.