Privacy Policy
NutriScan: Food & Nutrition — food, nutrition, and diabetes support
Last updated: October 3, 2026
NutriScan provides food logging, nutrition tools, glucose-related features, and nearby food-resource search. This policy explains what information is processed, which service providers receive it, how long it is kept, and the choices you have. We do not sell personal information or use health data for advertising.
Looking for the website policy? Read the NutriScan website privacy policy.
Who we are
NutriScan: Food & Nutrition (“NutriScan,” “we,” “us”) is operated by Nuv Ahuja. Our website is www.getnutriscan.com. If you have any questions about this policy or your data, you can reach us at support@getnutriscan.com.
NutriScan is intended only for adults 18 and older. A date-of-birth declaration and explicit adult confirmation are required before app access or account authentication. This is self-attestation, not identity verification.
Information we collect
Account information
When you create an account with email, we collect your name, email address, and password. Passwords are stored as a secure hash, not in plain text. If you choose Google or Apple sign-in, we receive the identity information needed to create or access your NutriScan account. Your self-declared birth date is sent for the 18+ access check; it is not stored as a separate account credential. If you complete onboarding or save it in your profile, your birth date and calculated age are stored with that profile.
Diabetes and health data you enter
NutriScan lets you record blood glucose readings, insulin doses, carbohydrate and meal logs, injection/infusion site and CGM sensor changes, and the settings in your profile (such as diabetes type, glucose units, target glucose range, insulin regimen, CGM source, and any medical notes you choose to add). We store this so the app can show your history, build your Food Playbook, and keep your data in sync across your devices.
Apple Health (HealthKit) data
After you choose Connect Apple Health and approve access in iOS, NutriScan can read the categories you allow: blood glucose; steps, distance, exercise time, and active/resting energy; height, weight, body fat, and lean mass; heart rate; and sleep. Availability depends on the data in Apple Health and the permissions you grant. NutriScan reads this data; it does not write health samples to Apple Health. You can change access at any time in iOS Settings → Health.
Food photos and descriptions
When you ask NutriScan to scan food, the photo you capture or select, or the food description you type, is sent to Google Gemini through NutriScan's server to estimate nutrition. A scan result becomes part of your meal history only if you choose to save or log it. Food photos and descriptions are not used by NutriScan to identify you.
Location and nearby-place searches
If you use the Care Center to find nearby food assistance and fresh-food resources, the app can send your device coordinates or a ZIP code you enter, together with your search terms, to Google Maps Platform to return nearby results. Places you “save” for later are stored only on your device.
Subscription information
NutriScan offers an optional NutriScan Pro subscription. Purchases are processed by Apple, and subscription status is managed through our payments provider (RevenueCat). We receive your subscription status and related identifiers — not your payment card details, which are handled by Apple.
Advertising data
Rewarded video ads and ad-supported Pro access are disabled in the current release. NutriScan does not request or initialize rewarded ads in this release. The app includes an AdMob integration for a possible future opt-in offer; before enabling it, we will update this policy and the App Store privacy disclosures to explain any device or advertising data the provider may collect.
Technical information
Like most apps, our servers automatically receive basic technical information (such as connection data) needed to operate the service securely and reliably.
Optional product analytics
Product analytics is off by default for signed-in accounts. If you turn it on in Profile → Privacy, NutriScan may store account- and device-linked usage events such as app opens, session starts, scan source, meal counts, scan/edit flags, and opaque event identifiers. Analytics does not include food names or contents, photos, raw glucose readings, or Apple Health values. Event records expire after 90 days. Turning analytics off deletes that account's stored event history and analytics-only onboarding markers.
Voice input
If you use voice input, NutriScan transcribes speech on your iPhone when the device supports on-device recognition. Audio is not sent to NutriScan or Google for this transcription. If on-device recognition is unavailable, NutriScan asks you to use text entry instead. If you then submit the transcript to an AI feature, the submitted text is processed as described below.
How we use your information
- To create and secure your account and sign you in.
- To analyze your food photos and descriptions and return nutrition estimates, and to generate recipes in NutriScan Pro.
- To save and sync your meals, carbs, glucose, insulin, and site/sensor logs across your devices.
- To help you find food resources near you when you use the Care Center.
- To answer questions or create nutrition summaries, recipes, and label reviews that you explicitly request, using the limited content described below.
- To process and verify your NutriScan Pro subscription. Ad-supported Pro access is disabled in the current release.
- To send account-related emails, such as password-reset codes.
- To maintain, protect, and improve the reliability and security of the app.
Your diabetes and health data is used only to provide the app's features. We never sell it, and we never use it — or any data obtained from Apple Health — for advertising or marketing.
Apple HealthKit
HealthKit data is used for NutriScan's in-app history, summaries, and account sync. NutriScan does not send Apple Health-imported readings to Google Gemini or product analytics. HealthKit data is not used for advertising or sold. You control the app's access in the iOS Health app.
AI features and Google Gemini
When you choose to submit a request to an AI feature, NutriScan sends the request to the Google Gemini API. The specific information depends on the feature:
- Free Assistant: your current question and three seven-day aggregate values derived from manually logged meal/glucose records. It does not send meal names, raw readings, questionnaire answers, chat history, or Apple Health-imported glucose.
- Pro Assistant: your current message, up to 24 recent chat turns, saved nutrition targets, your selected diabetes focus, and a bounded seven-day summary of manually logged meals and glucose records. Apple Health-imported glucose is excluded. NutriScan does not save the chat transcript as an account record.
- Weekly Pro insight: up to 60 recent meal entries from the last seven days, including meal names, dates, available nutrition values, and explicitly saved nutrition goals. Apple Health glucose readings are not included.
- Pro recipe generation: the carb target, meal type, food preferences, selected nutrition focus, dietary/allergy constraints, foods to avoid, and preparation-time limit you submit. Free-form medical profile notes, insulin regimen, glucose targets, and HealthKit data are not sent.
- Pro grocery label review: the label photo, optional product name and brand, and saved general nutrition targets. NutriScan does not save the photo as a meal or food log.
- Care Center guidance: the model receives a fixed public list of assistance programs and a generic request for guidance. Your ZIP code and profile are not sent to Gemini for this response; location searches use Google Maps as described above.
- Browser recipe analysis (if you use the NutriScan browser helper): the recipe title, ingredients, and serving count submitted for analysis.
AI requests are processed by Google's Gemini API under Google's service terms only when NutriScan's paid-tier configuration has been reviewed. Under Paid Services, Google says prompts and responses are not used for product improvement; Google may still log them for a limited period for safety, security, and legal purposes. We do not claim zero logging or zero retention. NutriScan must independently verify that its production API key belongs to a Google Cloud project with active billing before enabling AI. If that check has not been approved, AI features are disabled while manual logging remains available. Do not submit information you do not want processed by Google.
How your information is shared
We do not sell your personal information. We share information only with the service providers that make the app function, and only as needed:
- Google (Gemini API) — receives the feature-specific photos, questions, manually logged summaries, meal details, and preferences described in the AI section above when you choose those features. Apple's HealthKit-imported readings are excluded from Gemini requests.
- Google Maps Platform (Places) — receives your device coordinates or ZIP code and search terms to return nearby food-resource listings.
- Apple and Google sign-in — process authentication when you choose one of those sign-in methods and return the identity information needed for your NutriScan account.
- Google AdMob — the integration is present but rewarded ads are disabled in the current release. If an opt-in offer is enabled in a future build, its data handling will be disclosed before rollout.
- Apple and RevenueCat — Apple processes App Store purchases; RevenueCat manages subscription status and entitlements for NutriScan Pro.
- Twilio SendGrid — sends transactional emails on our behalf, such as password-reset codes.
- MongoDB Atlas — securely stores your account and app data.
- Render — hosts the application's backend.
- Sentry — if server error monitoring is enabled, receives limited technical error types and stack locations; request bodies, URLs, user identifiers, and raw error text are removed before transmission.
These providers process information under their own terms and privacy practices. See Google's Gemini API terms, abuse-monitoring policy, and data-retention documentation. We may also disclose information if required by law or to protect the rights, safety, and security of our users and the service.
Data retention and deletion
We keep account and log data while your account is active. Deleted meals may be held in a recovery copy for up to 180 days so you can restore them; the recovery copy is then automatically deleted. Product-analytics events, if you opted in, expire after 90 days. You can delete your account at any time from Profile → account settings, or contact support@getnutriscan.com. Account deletion removes the account, its synced records, analytics events, and deleted-meal recovery copies from NutriScan's active database. Third-party providers may retain information already sent to them according to their own terms and retention policies.
How we protect your information
- All data is transmitted over encrypted connections (HTTPS).
- Passwords are stored only as secure one-way hashes, never in plain text.
- Access to stored data is restricted to operating the service.
- Stored data is encrypted at rest by our database provider.
No method of transmission or storage is completely secure, but we work to protect your information using reasonable safeguards.
Your choices and rights
You can review and update your profile information, export a copy of your records, turn product analytics on or off in Profile → Privacy, revoke Apple Health access in iOS Settings → Health, and delete your account in the app. Depending on where you live, you may have additional rights to access, correct, or delete your personal information, or to object to certain processing (for example under GDPR/UK GDPR or CCPA/CPRA). To exercise these rights, contact us at support@getnutriscan.com.
Medical disclaimer
NutriScan is an adult-only (18+) logging and educational tool. Carbohydrate and nutrition values are AI-generated estimates and may be inaccurate. The app does not diagnose conditions, provide treatment plans, calculate, recommend, or adjust insulin doses and is not a medical device. Always confirm carb counts and all treatment decisions with your healthcare provider.
Children's privacy
NutriScan is for adults 18 and older and is not directed to minors. We ask users to self-declare their date of birth and explicitly confirm adult status before entering the app or creating/signing into an account; we do not independently verify identity. We do not knowingly provide accounts to minors. If you believe a minor has provided us with personal information, please contact us so we can investigate and delete it as appropriate.
Changes to this policy
We may update this policy from time to time. When we do, we will revise the “Last updated” date above. Significant changes will be reflected here, and your continued use of the app means you accept the updated policy.
Contact us
Questions about this policy or your data?
support@getnutriscan.com