nutrician
Privacy Policy
Last updated: August 15, 2026
Nutrician is your AI nutrition agent, operated by PIQ Labs LLC, an Ohio limited liability company ("PIQ Labs," "we," "us"). We are the controller of the personal information described here. This policy explains, in plain language, what we collect, how we use and share it, and the controls you have. The short version: your data exists to coach you, we don't sell it, we don't use it for ads, and you can see, export, or delete all of it yourself, in the app, any time.
1. Information we collect
- Account: your email and a hashed password (we cannot see the password). Optional two-factor secrets are stored encrypted.
- What you log: meals you describe or photograph, and the nutrition estimates we compute for them.
- Photos (see Section 4 for detail): meal and nutrition-label photos you upload, and — only if you turn the feature on — private progress/body photos.
- Health information you choose to share: targets, dietary preferences, and — only if you tell us — GLP-1 details (medication, weekly shot day, injection sites), body measurements, weight, water, and symptoms you log (e.g. nausea, fatigue). This is consumer health data; you provide it by choosing to, we use it only to remind and coach you (never for medical advice), and you can remove it.
- Memory facts: durable things you tell the coach (routines, preferences, goals), each visible and deletable under You → What I remember.
- Payment information: if you subscribe, our payment processor (Stripe) collects and processes your payment details. We do not receive or store your full card number — we keep only a customer/subscription reference and status from Stripe so we can manage your plan.
- Information collected automatically: to run and secure the Service we process technical data such as IP address, device/browser type, timestamps, and request/error logs. We use privacy-preserving essential storage on your device (local storage) for your login session and preferences (theme, text size); we do not use third-party advertising or tracking cookies.
- Consent records: the version of the Terms/Privacy you accepted, when, and the IP address and browser used — kept as proof of agreement and deleted with your account.
2. How we use your information
We use your information to: provide the Service (log and estimate meals, coach you, remind you); operate and secure our systems and prevent abuse; process your subscription and payments; respond to your requests; comply with law; and improve the Service. We do not use your information for advertising, and we do not sell or "share" it for cross-context behavioral advertising.
3. Sensitive & consumer health data
Nutrition, GLP-1/medication, body-measurement, weight, symptom, and body-photo information is sensitive consumer health data. By choosing to enter it, you consent to our collecting and using it to provide the Service to you, as described in this policy. We do not sell it, we do not use it for advertising, and we do not share it except with the service providers needed to run the Service (Section 5). You can withdraw consent by removing the data or deleting your account.
We provide this notice to support your rights under consumer-health-data laws (including Washington's My Health My Data Act, Nevada SB 370, and the health provisions of other U.S. state privacy laws). We do not collect precise geolocation that is stored (Section 5), and we do not use health data to make decisions that produce legal or similarly significant effects about you.
Apple Health (iOS app only)
The iPhone app can connect to Apple Health. It is off until you turn it on in You → Apple Health, and iOS asks for your permission separately before any data moves. Two things happen while it is on, and nothing else:
- We read your weight from Apple Health so your weight trend stays current without you re-typing it. Those readings are stored on our servers with the rest of your weight history, and are treated as the sensitive consumer health data described above.
- We write the nutrition of meals you logged in Nutrician back into Apple Health, so your other health apps can see them. That is the calories, protein, carbohydrate and fat, and with each entry the meal’s name and a short note of where the number came from — a label you scanned, a food database, or our own estimate.
We do not read anything else from Apple Health, we never use data obtained through Apple Health for advertising or marketing, we never sell or share it with third parties for their own purposes, and we never store it in iCloud. Turning the setting off stops all further syncing; you can also revoke access at any time in the iPhone’s Health app under Sharing → Apps → Nutrician, which is also where you can delete what Nutrician has written there.
4. Photos — how they're handled
- Meal & nutrition-label photos you upload are sent to our AI provider to read them (identify food or transcribe a label) and are stored (unencrypted) so you can view them. They are used only to estimate and log food.
- Progress/body photos are a separate, opt-in feature: they are encrypted at rest, visible only to you, and never sent to the AI or seen by our team, and you can delete any of them at any time.
- Your device strips location (GPS/EXIF) metadata from photos before upload.
- We do not perform facial recognition, face-geometry scanning, or any biometric identification, and we do not collect or store biometric identifiers or biometric information (including under the Illinois Biometric Information Privacy Act). Please avoid including other people in photos you upload.
5. How we share information (service providers)
We share the minimum necessary with providers who process data on our behalf, under contract, only to run the Service, not for their own purposes:
- Anthropic — the AI that powers coaching and reads meal/label photos. Under Anthropic's API terms, your data is not used to train their models.
- Heroku (Salesforce/AWS, US) — application hosting and database.
- Cloudflare R2 — photo storage.
- Stripe — subscription payments (their handling is governed by Stripe's privacy policy).
- Resend — delivery of account-recovery email.
- USDA FoodData Central — anonymous public food lookups (no personal data).
We may also disclose information if required by law or valid legal process, to protect the rights, safety, or security of users or the public, or in connection with a merger, acquisition, or sale of assets (with notice as required by law and this policy continuing to apply).
6. What we never do
- Location: if you turn on 📍 for a message, your coordinates are used once to match nearby restaurant menus and are never stored. The toggle is off by default.
- No ads, no sale or "sharing" of personal information for advertising, no third-party tracking or analytics scripts on this site.
- No marketing email — the only email we send is account recovery.
7. Security & breach notification
We use industry-standard safeguards: encryption in transit (HTTPS), hashed passwords, encrypted two-factor secrets, encrypted-at-rest progress/body photos, access controls, and rate limiting. No system is perfectly secure, but if a breach affecting your personal information occurs, we will notify affected users and authorities as required by applicable law.
8. Retention & deletion
- Your data is kept until you delete it. Deleting your account (You → delete my account) is an immediate hard delete of your account, meals, photos, conversations, and memory — not a deactivation. Residual copies in routine backups age out on our normal backup cycle.
- Photos that never became part of a meal are automatically purged within about a day.
- We may retain limited records where the law requires (e.g. tax/payment records for subscriptions).
9. Your rights & choices
You can, directly in the app and without emailing us: access/export the data we hold (You → download my data), delete individual memory facts, meals (in chat), photos, or your entire account, and correct logged values. Depending on where you live, you may also have rights to know, access, correct, delete, and to limit the use of sensitive personal information, and to not be discriminated against for exercising them.
U.S. state privacy rights (California and others): in the past 12 months we have collected the categories of personal information described in Section 1 (identifiers, account and health/wellness information you provide, photos, payment reference, and internet/device activity), used for the purposes in Section 2, and disclosed only to the service providers in Section 5. We do not sell personal information and do not "share" it for cross-context behavioral advertising. We use and disclose sensitive personal information only to provide the Service, not for inferring characteristics — so no separate "limit" action is required, though you can remove the data anytime. To exercise rights, use the in-app tools or email us; we will verify via your account. You may appeal a decision by replying to our response.
If you are in the EEA/UK, our legal bases are performance of our contract with you, your consent (for sensitive data and photos), our legitimate interests in operating and securing the Service, and legal obligations; you may have rights to access, rectify, erase, restrict, port, object, and to lodge a complaint with a supervisory authority.
10. Automated processing
The Service uses AI to estimate nutrition and generate coaching. These outputs are informational and can be wrong (see the Terms); they do not make automated decisions that produce legal or similarly significant effects about you, and a human (you) decides what to do with them.
11. International
We operate in the United States and our providers process data in the U.S. If you use the Service from outside the U.S., you understand your information is processed in the U.S., which may have different data-protection laws than your country.
12. Children
Nutrician is for ages 16 and up and is not directed to children under 13. We do not knowingly collect information from anyone under 16 — if you believe we have, email us and we'll delete it.
13. Changes to this policy
We may update this policy as the product evolves. We'll post the new version here with an updated date and note material changes in the app; where the law requires, material changes to how we use sensitive data take effect only after notice and, where required, your consent.
14. Contact
Privacy questions or requests: PIQ Labs LLC · contact@piqlabs.com