Privacy Policy

Last updated: 7 February 2026

This Privacy Policy explains how NutriTracker (“we”, “us”, “our”) collects, uses, shares, and protects your personal information when you use our website, apps, and services (together, the “Service”).

Who we are

Our website address is: https://www.nutritracker.io.

If you have questions about this policy or your data, you can contact us at: privacy@nutritracker.io.

What data we collect

Depending on how you use NutriTracker, we may collect the following types of information:

  • Account data: name, email address, password (stored as a secure hash), and basic profile details.
  • App and coaching data you provide: goals, preferences, dietary information, workouts you log, messages you send to your AI coach, and files/media you upload (for example, meal photos).
  • Usage and device data: app interactions, pages viewed, feature usage, device type, operating system, app version, language, and approximate location (derived from IP address).
  • Health and fitness data (optional): if you choose to connect Apple Health, Garmin, or similar services, we may access the data you authorise via those integrations to provide coaching insights.
  • Support and communications: information you share with support, bug reports, and feedback.

Health and fitness data and your choices

NutriTracker may process health and fitness-related information to provide personalised coaching. You control whether to provide this information and whether to connect third-party services (for example, Apple Health). You can disconnect integrations at any time using your device or account settings.

We aim to minimise what we store. Where possible, we use health and fitness data to generate coaching insights and summaries. We do not sell your health data.

How we use your data

We use your information to:

  • Provide, operate, and improve NutriTracker, including personalised AI coaching and recommendations.
  • Create and manage your account, authentication, and preferences.
  • Analyse usage to improve performance, reliability, and user experience.
  • Communicate with you about updates, security notices, and support requests.
  • Protect against fraud, abuse, and security incidents.
  • Comply with legal obligations and enforce our terms.

AI processing

NutriTracker uses AI to generate coaching responses and insights based on the information you provide and, if enabled, the data from connected services. AI outputs can be imperfect and should not be treated as medical advice. If you have medical concerns, consult a qualified healthcare professional.

We may use your interactions to improve our Service, including improving AI quality and safety, subject to applicable law and your settings where available.

Legal bases for processing (UK GDPR)

If you are in the UK or EEA, we process your personal data when we have a legal basis to do so, including:

  • Contract: to provide the Service you request.
  • Legitimate interests: to run and improve our business and keep the Service safe (balanced against your rights).
  • Consent: for certain integrations, marketing communications, or optional data collection where required.
  • Legal obligation: where we must comply with the law.

Cookies

We use cookies and similar technologies to help the website work, keep you signed in, remember preferences, and understand how the site is used.

If you visit our login page, we may set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser.

When you log in, we may set cookies to save your login information and display preferences. Login cookies typically last for two days, and display preference cookies may last for up to a year. If you select “Remember Me”, your login may persist for up to two weeks. If you log out, the login cookies are removed.

You can usually control cookies through your browser settings. If you disable cookies, parts of the Service may not work properly.

Comments

If visitors leave comments on the site, we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

An anonymised string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service Privacy Policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Media

If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

Embedded content from other websites

Articles on this site may include embedded content (for example videos, images, and articles). Embedded content from other websites behaves in the exact same way as if you visited the other website.

These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction if you have an account and are logged in to that website.

Who we share your data with

We share data only as needed to provide the Service, including with:

  • Service providers: hosting, analytics, customer support tools, email delivery, error monitoring, and security services that process data on our behalf under contractual obligations.
  • Integration partners: if you connect third-party services (for example Apple Health or Garmin), we receive and send data as needed to provide the integration based on your authorisation.
  • Legal and safety: if required by law, or to protect rights, safety, and security of NutriTracker, our users, or others.
  • Business transfers: if we’re involved in a merger, acquisition, financing, reorganisation, or sale of assets, your information may be transferred as part of that transaction.

If you request a password reset, your IP address may be included in the reset email.

International transfers

Your information may be processed in countries other than where you live. Where required, we use appropriate safeguards for international transfers, such as standard contractual clauses.

How long we retain your data

We retain personal data only for as long as necessary to provide the Service and for legitimate business purposes, including legal, accounting, or reporting requirements.

If you leave a comment, the comment and its metadata may be retained indefinitely to help recognise and approve follow-up comments automatically.

If you create an account, we store the information in your user profile. You can see, edit, or delete certain information at any time (except you typically cannot change your username). Website administrators may also see and edit that information.

Your rights

Depending on where you live, you may have rights including:

  • Access your personal data and receive a copy.
  • Correct inaccurate or incomplete data.
  • Delete your data (subject to legal exceptions).
  • Object to or restrict certain processing.
  • Port your data to another service.
  • Withdraw consent where processing is based on consent.

To exercise your rights, contact us at privacy@nutritracker.io. We may need to verify your identity before responding.

Security

We use reasonable technical and organisational measures designed to protect your data. However, no method of transmission over the internet or method of electronic storage is completely secure.

Children’s privacy

NutriTracker is not intended for children under 13 (or the minimum age required in your country). We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us so we can take appropriate steps.

Changes to this policy

We may update this Privacy Policy from time to time. We will update the “Last updated” date above and, where appropriate, provide additional notice.

Where your data is sent

Visitor comments may be checked through an automated spam detection service.