Privacy Policy

Effective date: 23 August 2026 · Last updated: 23 August 2026

This Privacy Policy describes how NutriAI (“we”, “us” or “our”), operated by Vriddhix Technology, collects, uses, stores, and shares information when you use our mobile application, related websites (including marketing pages hosted on Firebase), and associated services (collectively, the “Services”). We are committed to protecting your privacy and handling your data responsibly.

1. Who this policy applies to

This policy applies to individuals who download or use the NutriAI app (Android package identifier: com.vriddhix.nutriai), visit our web properties, or otherwise interact with the Services.

2. Information we collect

Depending on how you use the Services, we may collect the following categories of information:

3. How we use information

We use the information above to:

We do not use your personal data to build advertising profiles, and we do not use your meal photographs to train models for anyone else's benefit.

4. Legal bases (where applicable)

If data protection laws in your region require a “legal basis,” we rely on one or more of the following, as appropriate: performance of a contract with you; your explicit consent, which is the basis on which we process the health data described in section 5; legitimate interests (securing the Services, improving the product, and communicating with you about the Services), balanced against your rights; and compliance with legal obligations. Where we rely on consent, you may withdraw it at any time, and that does not affect processing already carried out.

5. Health and nutrition data

The meals, water and weight you record, and the body measurements you enter during onboarding, are health-related and are treated in some jurisdictions as a special category of personal data. We process them solely to run the Services for you: to calculate your targets, to keep your diary, and to show you your own history and trends.

We do not sell this data, we do not share it with advertising networks or data brokers, and no advertising SDK in the app has access to it. That separation is enforced in the application itself, not merely stated here. You can delete individual entries at any time in the app, or ask us to delete everything (see section 11).

6. Meal photographs and AI analysis

When you scan a meal, the photograph is uploaded to our storage and sent from our servers to a third-party AI model provider, which returns an estimate of the dish, its ingredients and its nutrition. The app never sends your photograph directly to a model provider, and never carries a model provider's credentials.

Photographs are stored in a private bucket. They are never publicly readable: the app requests a signed link that expires approximately one hour after it is issued, and the durable reference the app keeps is a storage path rather than a URL. Deleting a meal deletes its record; contact us if you would also like the underlying image removed.

Nutrition figures produced this way are estimates, not measurements. See our Terms of Service.

7. How we share information

We do not sell your personal information. We may share data with:

We may also share information in connection with a merger, acquisition, or asset transfer, with notice as required by law.

8. International transfers

Your information may be processed in countries other than where you live, including where our servers or providers operate. Where required, we implement appropriate safeguards (such as standard contractual clauses or equivalent mechanisms) for cross-border transfers.

9. Retention

We retain information for as long as your account is active, as needed to provide the Services, and as necessary to comply with legal, tax, accounting, or dispute-resolution obligations. Diary entries, photographs and profile data are kept while your account exists. Following a deletion request we remove data from live systems within 30 days and from backups within 90. Crash and analytics data are retained on our providers' default schedules.

10. Security

We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction. Data is encrypted in transit and at rest. Access tokens are short-lived and refresh tokens rotate on every use. Access to production data is limited to people who need it to operate the Service. No method of transmission or storage is completely secure; we encourage you to keep any credentials confidential and notify us of suspected unauthorized access.

11. Your choices and rights

Depending on your location, you may have rights to access, correct, delete, or export personal data; object to or restrict certain processing; withdraw consent where processing is consent-based; and lodge a complaint with a supervisory authority. You may also control notifications and language through your device or in-app settings.

To exercise these rights, contact us using the details below. We may need to verify your identity before responding. If you are unsatisfied with our response, you may have the right to complain to your local data protection regulator.

A note on anonymous sessions. The app creates an anonymous account on first launch so you can start without signing up. That account is still yours and the rights above still apply to it. Signing out of a linked account begins a new anonymous session. The previous data stays attached to the account you signed out of, not to the new session.

12. Children

The Services are not directed to children, and are intended for people aged 18 or over; onboarding declines a date of birth below that age. If you believe we have collected information from a child without appropriate consent, please contact us and we will take steps to delete it where required.

13. Third-party links and services

The Services may contain links to third-party websites or integrate third-party SDKs. Their collection and use of information is governed by their own policies. We encourage you to review the privacy notices of Google Play, your device manufacturer, and any identity provider you use to sign in.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised version with an updated “Last updated” date and, where appropriate, provide additional notice (such as an in-app message or email). Continued use of the Services after changes become effective constitutes acceptance of the updated policy, to the extent permitted by law.