Privacy Policy

Last updated: 25 August 2026

Your health data is personal. Nourivo is built so your information stays with you. We don't sell your data, we don't run ads, and we never use your Apple Health data for advertising.

The short version. Your meals, weight, water, and symptoms live on your device. Meal photos and coach questions are sent to our backend only to generate your estimate or answer, and aren't tied to your name. Release builds also send crash reports and technical diagnostics to Firebase Crashlytics so we can fix reliability problems. We have no accounts and ask for no login. The only thing we collect by name is the email you give us for the launch waitlist.

1. Who we are

Nourivo is operated by Tran Danh Huong. You can reach us anytime at support@nourivo.app.

2. What we collect, and where it lives

On your device

The information you enter — your profile, meals, protein and nutrition logs, weight, water, side-effect notes, reminders, and grocery list — is stored locally on your device. We don't upload it to a server or hold a copy of it.

Apple Health

If you connect Apple Health, Nourivo requests read-only access to your weight and water data so it can show up in the app. We never write to Apple Health, and we never use Apple Health data for advertising. You can turn this off anytime in iOS Settings → Health.

Meal photos, descriptions, and coach questions

When you photograph or describe a meal, or ask the coach a question, that content — together with the basic context the coach needs from your logs (like your goals or recent meals and symptoms) — is sent to our backend (hosted on Supabase) and forwarded to our AI provider (Google, for the Gemini model) only to generate your nutrition estimate or coaching answer. The app asks for your permission before the first time anything is sent, and you can decline and still browse your logs. This content is processed to answer your request and is not stored on our servers. Because Nourivo has no accounts, it is not linked to your identity. We don't use your meals or questions to train AI models, and we don't sell them. Google processes this content as our service provider, under API terms that prohibit using it to train their models, with protections equivalent to this policy.

Subscriptions

Purchases are handled by Apple (or Google Play on Android) and by RevenueCat, our subscription provider, using an anonymous app-user identifier. We receive your subscription status (trial, active, expired) so we can unlock features — we never receive your card or payment details.

Website waitlist

If you join the launch waitlist on this website, we collect the email address you provide, only to notify you when Nourivo launches. You can unsubscribe at any time, and we won't use it for anything else.

Diagnostics

Release builds use Firebase Crashlytics, a crash-reporting service provided by Google. When the app crashes, Crashlytics automatically receives a stack trace, relevant app state, the app and operating-system version, point-in-time device metadata, and random installation identifiers. We use this information only to measure, diagnose, and fix app reliability problems.

We do not set a Crashlytics user ID or add your health logs, meal photos, coach questions, or contact details to crash reports. Crashlytics data is not used for advertising or cross-app tracking and is not linked to your identity. Apple may separately provide aggregate, anonymous App Store and crash statistics.

3. How we use your information

4. What we never do

5. Who processes data for us

We use a small set of trusted providers strictly to run the service: Apple (App Store, payments, Apple Health), RevenueCat (subscription status), Supabase (our backend that proxies meal and coach requests), and Google (Gemini for estimates and answers, and Firebase Crashlytics for crash reporting and app diagnostics). Each receives only what's needed to do its job.

6. Keeping and deleting your data

Because your app data lives on your device, you can delete all of it at any time from Profile → Delete my data, or by deleting the app. Meal and coach requests are processed transiently to generate a result and are not stored as a personal profile. Firebase retains Crashlytics crash traces and associated installation identifiers for 90 days before beginning removal from its live and backup systems. To remove your waitlist email or ask us about a crash report, email support@nourivo.app or use the unsubscribe link.

7. Security

Requests to our backend are sent over encrypted connections. No method of storage or transmission is perfectly secure, but we keep what we hold to a minimum precisely to reduce risk.

8. Your rights

Depending on where you live, you may have rights to access, correct, delete, or limit the use of your personal data. Because we hold so little — essentially your waitlist email, anonymous subscription status, and crash diagnostics — most of your data is already in your hands on your device. To exercise any right, email support@nourivo.app.

EU/EEA & UK (GDPR): our legal bases are performing our contract with you (providing the app you subscribe to), your consent (the waitlist email), and our legitimate interests in diagnosing crashes and keeping the app reliable. California (CCPA): we do not sell or share your personal information, and we don't discriminate against you for exercising your rights.

9. International transfers

Our providers may process data in countries other than yours, including the United States. Where required, we rely on appropriate safeguards for those transfers.

10. Children

Nourivo is for adults (18+) using GLP-1 medication and is not directed to children. We don't knowingly collect data from anyone under 18.

11. Changes to this policy

If we change how we handle your data, we'll update the date above and, for material changes, let you know in the app or by email.

12. Contact

Privacy questions or requests: support@nourivo.app.