Privacy Policy
Effective date: {{DATE}}
This policy explains what Nality collects when you use the app, why, and what you can do about it. We try to keep it plain. If something here is unclear, email us.
1. Who we are
Nality ("we", "us") is operated by {{LEGAL_NAME}}. You can reach us at {{SUPPORT_EMAIL}}. [CONFIRM: postal address for privacy requests and complaints, if you want to publish one]
2. What we collect
- Account and identifiers. The first time you open the app it creates an anonymous account on our servers: a random ID, with no name or email. You can use Nality like this for as long as you like. You can add a sign-in later to back up your log. If you sign in with Apple, we receive an Apple identifier and, if you allow it, your name and email; Apple may give us a private relay address instead of your real one. Sign in with Apple is the only way to sign in, and there are no passwords.
- Profile details. Your name, and the details you enter to set your goals: sex (optional), age, height, weight, weight goal and activity level. Also your calorie, macro and water goals, your display units, your reminder settings, your weigh-ins, and any workout energy you enter.
- Food and water logs. What you eat and drink, how much, when, and how each entry was found (a food database, a label, or a photo estimate). A copy of your log and profile is saved to our database under your ID, so it can be restored on a new phone once you have an account.
- Photos and label images you choose to scan. Only images you deliberately capture or select. See section 3.
- Label results. When you scan a nutrition label for a barcode, the values read from it are saved in a shared cache against that barcode, so the next person who scans the product gets the same numbers. The entry records which account created it. The image itself is not kept.
- Voice input. If you use voice to describe a meal, the speech is turned into text by Apple's speech recognition, which your device may run on the device or send to Apple, depending on your device and language. We receive only the resulting text. We do not receive or store audio.
- Search terms and barcodes. What you search for and the barcodes you scan, so we can return food results. Our servers pass the search text or barcode, and nothing that identifies you, to the food databases in section 4. Search text is kept in a cache keyed by the text, not by you.
- Purchase status. Whether you have an active subscription. We do not receive your card details.
- Usage analytics. A short, fixed list of events: onboarding completed, first food logged, a food was logged and by which method (search, barcode, photo, label or manual), a paywall was shown, a purchase was started or completed, restore was tapped, a scan limit was reached, and the type of a scan error. Never food names, nutrients, weights, photos, barcodes or anything you type. The events are tied to your random account ID. They are only sent from the released app. There is no setting in the app to switch them off; email us and we will ask PostHog to remove the events tied to your account ID. [CONFIRM: whether to offer an in-app switch, and whether the law where you sell the app requires consent before analytics]
- Error reports. When the app hits an unexpected JavaScript error, a report of that error is sent with the analytics above, and is switched off by the same setting. We do not collect native crash reports and we do not record your screen.
- Reminders. Reminders are scheduled on your device. We do not send push notifications and do not store a push token.
- Technical data to prevent abuse. A random device identifier created by the app, your time zone (so daily limits are counted in your own day), and a one-way hash of your network address. We use these to limit how many scans and lookups can be made per minute or per day, and to apply the fair-use ceiling described in our terms to features described as unlimited. Our rate-limit records store the hash, not the address itself. [CONFIRM: how long the hosting platform keeps request logs, which may include network addresses]
3. How photos and labels are processed
When you scan a photo or nutrition label, the app re-encodes the image, which removes location and camera details embedded in it, and sends it to our server. Our server sends it on to Anthropic's Claude API to identify the food or read the printed nutrition panel, and returns the result. Nutrition numbers for foods matched in a food database come from that database, not from the AI. Foods that cannot be matched are shown as an AI estimate.
Our servers do not store your images: they are processed and discarded, and only the result is returned to you. Anthropic's handling of data is described in its privacy policy. Data sent through Anthropic's commercial API is not used to train its models, and Anthropic keeps it only as its terms describe. [CONFIRM: verify the training and retention statements against Anthropic's current commercial terms before publishing]
4. Service providers
We use these providers to run the app. Each receives only what it needs for the purpose listed.
- Supabase: database, authentication and server functions. Holds your account, profile, the cloud copy of your log and your usage counters. Hosted in Sydney, Australia. Privacy policy.
- Anthropic: AI analysis of the photos and label images you scan. Privacy policy.
- RevenueCat: subscription management and purchase status. Receives an app user identifier and your purchase and subscription status. Privacy policy.
- Apple: payments, Sign in with Apple, speech recognition for voice input, and the App Store. Privacy policy.
- PostHog: product analytics and error reports, using PostHog's United States cloud. Events are linked to your random account ID. Privacy policy.
- Food databases: when you search or scan a barcode, our servers query public food databases (the Australian Food Composition Database, USDA FoodData Central and Open Food Facts). Only the search text or barcode is sent, never your identity.
5. What we don't do
- We don't sell your personal data.
- We don't show advertising.
- We don't share your data with data brokers.
6. Health information
Your food logs, water logs and body measurements are sensitive. We use them only to run the app: calculating your goals, showing your history and keeping your account in sync. Nality does not read from or write to Apple Health.
7. Automated decisions and AI
Nality uses AI to read photos and labels and to estimate foods and portions. These are suggestions you can edit, and you can always change the result. We do not make decisions about you that have legal or similarly significant effects, and we do not use your data to profile you for advertising.
8. Where data is stored
Your data is stored with Supabase in Sydney, Australia. If you use the app from outside Australia, your data is transferred there. Analytics and error reports are processed in the United States, and images you scan are processed by Anthropic, which may be outside Australia. Where required, we rely on appropriate safeguards for those transfers. Under the Australian Privacy Principles we take reasonable steps to make sure overseas providers handle your information consistently with those principles. [CONFIRM: list the countries where providers process data and the safeguards in place, for example standard contractual clauses]
9. Retention and deletion
You can delete your account from inside the app: open Settings and choose Delete account. This permanently removes your profile, the cloud copy of your log, your usage counters, your subscription link and your sign-in; if you signed in with Apple, the app also asks Apple to end the link between your Apple ID and the app. Label results you contributed stay as product data but are no longer linked to you. Two kinds of record are not deleted automatically: analytics events held by PostHog (tied to a random ID, with no food data), and purchase records held by Apple and RevenueCat. Email us and we will ask those providers to remove them. When we decide how long to keep something, we consider what it is, how sensitive it is, why we collected it, and any legal requirement to keep it. When we no longer need it, we delete it or remove what identifies you. [CONFIRM: how long PostHog keeps events, and the backup retention period for deleted accounts] You can also email {{SUPPORT_EMAIL}} and we'll delete your account for you.
10. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, receive a portable copy, restrict or object to some uses, and withdraw consent you have given. We give these options to everyone, not only people in places where the law requires it.
How to make a request
- Email {{SUPPORT_EMAIL}}, or use Delete account in the app's Settings for deletion.
- Because most accounts are anonymous, we may ask you to show the request comes from the account holder, for example by writing from the email linked to your Sign in with Apple or by sharing your in-app account ID. We won't ask for more than we need.
- We aim to reply within 30 days, or sooner where the law requires. If we say no to all or part of a request, we'll explain why. [CONFIRM: response time commitment]
- You won't be treated worse for using your rights.
- You can ask someone to make a request for you. We may ask for proof they are authorised to act for you.
- If you disagree with our decision, reply to our message and ask us to review it.
Australia
We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. That includes your right to deal with us anonymously or under a pseudonym where practical, which is why you can use Nality without signing in, your right to ask for access to and correction of your information, and our duty to take reasonable steps before disclosing information overseas (see section 8).
If you want to make a privacy complaint, email us first and we'll respond within a reasonable time. If you are not satisfied, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
European Economic Area and United Kingdom
Under the GDPR and UK GDPR, {{LEGAL_NAME}} is the controller of the personal data described in this policy. We rely on the legal bases below. [CONFIRM: have a lawyer confirm the legal bases and whether a representative or data protection officer is required for the EEA and UK]
| What we do | Data involved | Legal basis |
|---|---|---|
| Run the app and keep your log | Account ID, profile, food and water logs, label results, search terms, barcodes, voice text | Contract: it is needed to provide the app to you |
| Read photos and labels with AI | Images you choose to scan | Contract: you ask for the feature when you scan |
| Manage Pro | Purchase and subscription status | Contract |
| Keep the service secure and limits fair | Random device ID, time zone, hashed network address | Legitimate interests: preventing abuse and keeping costs fair for everyone |
| Understand and improve the app | Usage events and error reports tied to your random account ID | Legitimate interests: fixing problems and improving the app. [CONFIRM: consent may be required for analytics in some EU countries] |
| Health-related information you enter | Weight, height, age, sex, food and water logs | Your explicit consent when you enter it, and you can withdraw it by deleting the data or your account. [CONFIRM: confirm the in-app consent wording for health data] |
| Comply with law and protect rights | Whatever is relevant | Legal obligation, or legitimate interests in defending legal claims |
You can ask us to give you access to your data, correct it, delete it, give you a machine-readable copy, restrict our use of it, or stop using it where we rely on legitimate interests. Where we rely on consent, such as camera, microphone and photo access, you can withdraw it at any time in your device settings. If you are unhappy with how we handle your data, you can complain to your local data protection authority. In the UK, that is the Information Commissioner's Office. For the EEA, find yours on the European Data Protection Board's list.
California and other US states
Under the CCPA/CPRA and similar state laws you can ask what personal information we hold, ask us to delete or correct it, and ask for a copy. We do not sell or share personal information, as those terms are defined in California law, and we do not use ads. Health-related information such as your weight and food log is sensitive personal information, and we use it only to provide the app to you. We do not use or disclose it for other purposes. We do not offer financial incentives for personal information. California's "Shine the Light" law lets residents ask which third parties receive their information for direct marketing. We share nothing for that purpose. [CONFIRM: confirm these US statements before offering the app to US users]
11. This website
This website does not use cookies, analytics or advertising trackers, and it does not ask you to sign in. Our web host, like any host, may keep basic server logs, such as your network address and the pages requested, for security and reliability. If you email us, we keep your message and address so we can reply and keep a record of the request. [CONFIRM: web host name, whether it keeps request logs and for how long] Browsers may send a "Do Not Track" signal. There is nothing here to turn off, so we do not act on it.
12. Children
Nality is not directed at children under [CONFIRM: age threshold, 13 or 16 for GDPR regions]. We don't knowingly collect personal information from them. If you think a child has given us data, email us. If we learn we have collected it without the consent of a parent or guardian where the law requires it, we will delete it.
13. Security
We use encryption in transit and keep our service API keys on our servers, not in the app. No system is perfectly secure, so we can't promise absolute protection.
14. Changes to this policy
If we change this policy we'll update the effective date above and, for material changes, tell you in the app before they take effect. Continuing to use Nality after that means you accept the updated policy, and you can delete your account if you don't.