1. Scope and regional rights
This Policy applies worldwide. Singapore's Personal Data Protection Act (PDPA) is the planned primary operating framework after incorporation. Privacy laws in your location—including the EU GDPR, UK GDPR, Swiss law, California law and other mandatory regional laws—may give you additional rights. We do not claim that one policy creates universal compliance or removes protections provided by your country or state.
2. Personal data we process
Website and early-access data
- Your email address, subscription status, consent record, source and relevant timestamps.
- A short-lived hash derived from an IP address for in-memory abuse throttling. The current sign-up function does not persist the raw IP address or that hash in the subscriber record.
- Browser, device, approximate location, session and usage information collected by Firebase Analytics where it operates and is permitted.
- Security, diagnostic, request and service logs generated by hosting, Firebase and related infrastructure.
- Messages and information you provide when contacting support or making a privacy request.
Nourishy app data, when those features are enabled
- Name, email, authentication identifiers, and identifiers supplied through Google or Apple sign-in.
- Profile and personalisation information.
- Age or date of birth, sex, height, weight, target weight, physical activity, training, nutrition and wellness goals.
- Dietary preferences, allergies, intolerances and dietary restrictions.
- Meal records, meal photographs, text entries, corrections, voice recordings or audio you choose to submit.
- Connected-service data that you expressly authorise Nourishy to receive.
The current website repository does not contain consumer payments. We do not describe payment collection as an active website practice. If payments are introduced, this Policy will be updated before that processing begins.
3. Sources of data
We obtain data:
- directly from you when you subscribe, create or edit an account, log information, or contact us;
- automatically from your browser, device and interactions with the service;
- from Google or Apple when you choose a social sign-in method;
- from connected services only when you authorise the connection; and
- from service providers that help us operate, secure and diagnose Nourishy.
4. Why we use data and our legal grounds
- Provide the service: create and secure accounts, record meals and activity, personalise the experience, generate requested insights and provide support. The basis is performance of our contract with you or steps requested before entering it.
- Early-access and newsletter messages: send updates you requested and maintain an unsubscribe record. The basis is your consent. You can withdraw it at any time through an unsubscribe link.
- Sensitive wellness information: process health-related profile, dietary, allergy and meal information to provide features you choose to use. Where applicable law treats this as sensitive or special-category data, we rely on explicit consent or another legally available basis disclosed to you.
- Security and reliability: prevent spam, abuse, fraud and unauthorised access; troubleshoot failures; and protect users. The basis is our legitimate interest in operating a secure service and, where relevant, compliance with legal obligations.
- Analytics and improvement: understand how the public website performs and improve usability. Where consent is required, consent is the basis. Elsewhere we rely only on a lawful basis available under local law.
- Legal administration: respond to valid requests, establish or defend legal claims, maintain required records and comply with law.
Where processing relies on consent, you may withdraw consent prospectively. Withdrawal does not make earlier lawful processing unlawful, but some features may no longer work without the data they require.
5. AI-assisted insights
Nourishy is designed to use AI-assisted analysis to turn information you provide—such as meal descriptions, images, audio, activity and profile context—into estimates and personalised wellness insights. AI outputs may be inaccurate and are not medical advice. The current website repository does not identify a production AI model provider; this Policy must be updated before a third-party AI provider receives personal data.
Nourishy does not use the processing described here to make decisions based solely on automation that produce legal or similarly significant effects. If that changes, we will explain the logic, significance, safeguards and available human review before such processing begins.
6. Cookies, analytics and security technologies
The current website includes Firebase Analytics, which may process a first-party client identifier, session statistics, approximate location, browser and device information. Google documents the standard _ga and _ga_<container-id> cookies as lasting up to two years, subject to browser limits and configuration.
The early-access form uses Firebase App Check with reCAPTCHA Enterprise for spam, fraud and abuse prevention. Google states that reCAPTCHA may set the necessary _GRECAPTCHA security cookie when it runs. You can control cookies through browser settings, although blocking essential security storage may prevent the subscription form from working.
7. Service providers and recipients
We disclose data only as reasonably necessary to:
- Google/Firebase: App Hosting, Cloud Firestore, Cloud Functions, Cloud Storage, Authentication when enabled, App Check/reCAPTCHA, and Firebase Analytics;
- Google Gmail: delivery and operational handling of requested newsletters and related lifecycle emails;
- Google or Apple: authentication when you choose the relevant sign-in method;
- professional advisers, authorities or counterparties where disclosure is legally required or necessary to protect rights; and
- a successor in a genuine financing, reorganisation, acquisition or transfer, subject to appropriate safeguards.
We do not sell personal data. The audited repository does not contain advertising technology or a payment provider. We do not share personal data for cross-context behavioural advertising as that term is used under California law.
8. International transfers
Nourishy is intended for worldwide use and its providers may process data in countries other than yours. Firebase states that many services operate on global infrastructure and that Firebase Authentication is processed in the United States. Where required, international transfers will use legally recognised safeguards such as contractual protections, adequacy decisions or comparable-protection requirements.
Following Singapore incorporation, transfers will be managed to meet the PDPA transfer-limitation requirement for a standard of protection comparable to the PDPA. EEA, UK and Swiss transfers will use an applicable transfer mechanism and supplementary safeguards where required.
9. Retention
- Accounts and user content: while the account is active and then until deletion is completed, subject to backups and data required for security, legal claims or legal obligations.
- Early-access subscriptions: while subscribed. After unsubscribe, a limited suppression and consent record may be retained as needed to honour the opt-out and demonstrate compliance.
- Support and privacy requests: until the request is resolved and for a reasonable period needed to keep an accurate record or address legal claims.
- Security and diagnostic logs: only as long as reasonably needed for security, troubleshooting and legal obligations, using provider retention controls where available.
- Analytics: according to the configured Firebase/Google Analytics retention controls. Browser analytics cookies may persist for up to two years unless deleted sooner or limited by the browser.
We delete or anonymise personal data when it is no longer needed for a legitimate business or legal purpose.
10. Security
We use measures designed to protect personal data, including access controls, authenticated administrative access, server-side validation, restricted database rules, encrypted transport and abuse controls. No system is completely secure, and we cannot guarantee that unauthorised access or loss will never occur. Please protect your credentials and contact us if you suspect a security issue.
11. Account deletion and privacy requests
Where an in-app deletion option is available, you may use it. The public website repository does not currently implement a consumer account-deletion flow, so you may always request deletion without reinstalling the app by emailing support@nourishy.app. We may verify your identity using the least information reasonably necessary, such as control of the account email or an authenticated session.
Deletion generally covers account details, profile and personalisation data, meal/activity entries, submitted images or audio, and linked identifiers under our control. Limited records may remain where needed for security, fraud prevention, legal obligations, accounting if payments are later introduced, dispute resolution, or to honour an unsubscribe request. Requests are handled without undue delay and within the deadline required by applicable law.
12. Your privacy rights
Depending on where you live and subject to legal exceptions, you may have rights to:
- know whether and how we process your data and obtain access to it;
- correct inaccurate or incomplete data;
- request deletion or restriction of processing;
- receive portable data in a commonly used machine-readable format;
- object to certain processing, including direct marketing;
- withdraw consent at any time;
- appeal a refusal where local law provides that right; and
- complain to your local privacy regulator.
Under Singapore's PDPA, applicable rights include access to and correction of personal data and information about its use or disclosure, subject to exceptions. EEA and UK users may also have GDPR rights to erasure, restriction, portability and objection. Where the California Consumer Privacy Act applies, California users may have rights to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive information and receive equal service.
To exercise a right, email support@nourishy.app. We will not discriminate against you for making a valid request. You may complain to the Singapore PDPC, your EEA supervisory authority, the UK Information Commissioner, the Swiss FDPIC, the California Privacy Protection Agency, or another regulator with jurisdiction. We encourage you to contact us first so we can try to resolve the concern.
13. Children
Nourishy is not directed to children under 16. Users must also meet any higher minimum age or parental-consent rule that applies locally. The current website repository does not implement an age gate; this must be aligned with the mobile product before consumer account collection begins. If you believe a child provided data without valid permission, contact us so we can investigate and delete it where required.
14. Changes and contact
We may update this Policy when the service, providers, legal requirements or company identity changes. Material changes will be communicated as required, and the date above will be updated. The verified Singapore company name, UEN, registered address and public DPO contact will be added promptly after incorporation.
Privacy and data-rights requests: support@nourishy.app
Telephone: +34 657 456 031
Website: https://nourishy.app