Who we are
NutriOct is an independent app. For any privacy question, data export, or deletion request, contact us at info@apeirogonhub.com. Our website address is: https://apeirogonhub.com.
What we collect
- Google account information: If you tap “Sign in with Google,” we receive your Google account name, email address, and a stable account identifier (Google subject ID) from Google’s OAuth service. This links your data to your Google account so it persists across reinstalls and devices. Sign-in is entirely optional; the app is fully functional without it.
- Apple account information: If you tap “Sign in with Apple”, we receive your Apple account name, email address (or an anonymized Apple Private Relay email address if you choose “Hide My Email”), and a stable account identifier from Apple. This links your data to your Apple account so it persists across reinstalls and devices. Sign-in is entirely optional; the app is fully functional without it.
- Scan and usage events. When you tap a scan entry point, a timestamped event is logged. No content is captured — only the fact that the button was tapped. Used for anonymous product analytics.
- Active calories burned (optional). If you grant Health Connect permission, NutriOct reads today’s active calories burned from Health Connect (Android) or HealthKit (Apple Health) to display a net-calorie figure. This value is read at runtime and is not stored on our servers.
- Subscription state. If you purchase a NutriOct Pro subscription, your subscription status (active, expired, cancelled), the billing platform (Google Play), and the product purchased are stored on our server via RevenueCat’s webhook.
what we do not collect
- No advertising identifiers. We do not run ads and do not use any ad SDKs.
- No location data, contact list, or photos beyond the live camera feed during camera scanning.
- No persistent camera or microphone access — both are only active while the scan screen is open.
- No raw payment card numbers or full billing details — those stay with Google Play.
Who else sees your data
- Google Gemini API receives camera frames and audio during a Smart Scan. Google’s handling is governed by Google’s Generative AI API terms and privacy policy.
- Google provides the cloud infrastructure that hosts the NutriOct backend and stores your data. All data is stored in the United States. Encryption at rest and in transit is applied by default. Google also provides analytics services that receive a daily export of anonymized behavioral event counts (no meal content, no food names, no personal identifiers — only anonymous UUIDs and timestamps).
- USDA FoodData Central is queried server-side for nutrition values. Only the food name and portion are sent — no user identifier.
- OpenFoodFacts is queried server-side when a barcode isn’t in the USDA database. Only the GTIN (bare barcode digits) is sent — no user identifier.
- RevenueCat processes subscription events from Google Play and the Apple App Store and forwards normalized purchase/renewal/expiration events to our backend. RevenueCat’s handling is governed by their privacy policy.
- Payment Processors (Google Play Billing & Apple App Store) handle payment processing for NutriOct Pro subscriptions. NutriOct never sees your full card number or billing address. Their respective privacy policies govern payment data.
How long we keep your data
Your data are retained for as long as your account is active, or until you request deletion. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
- If you signed in with Google or Apple, your data is linked to your Google or Apple account and persists across reinstalls until you request deletion.
- If you use NutriOct anonymously (no Google Sign-In), your data is tied to the UUID stored on your device. If you uninstall the app or clear app data, your device loses access to the server-side rows — but those rows persist on the server until you email us to delete them.
What rights you have over your data
- Export your data. The Trust tab inside the app offers one-click JSON or ZIP download of everything we store about your device ID.
- Delete a single meal. Logged meals can be deleted directly from the Today tab.
- Revoke Health access. Android Settings → Health Connect → App permissions → NutriOct→ remove permissions iOS Settings → Health → Data Access & Devices → NutriOct → turn off permissions
- Cancel a subscription. Manage subscriptions via Google Play (Play Store → Profile → Payments & subscriptions). Manage subscriptions via iOS Settings → [Your Name] → Subscriptions
- Delete everything. Email info@apeirogonhub.com with “Delete my data” and include the device ID shown on the Trust tab (or your Google/Apple account email if you signed in). We’ll wipe all server-side rows within 7 days.
Children
NutriOct is not directed at children under 13. If you believe a child has used the app on your device and you would like the associated data removed, please contact us at the address above.
Security
All requests use HTTPS. Your meal log is stored in a secured, access-controlled database accessible only by the NutriOct backend. We have not had a data breach to disclose.
Changes to this policy
If we change what we collect or how we use it, we’ll update this page and bump the effective date at the top. Material changes will also be noted inside the app’s Trust tab.
Contact
For any question or request related to this policy or your data: info@apeirogonhub.com.