Back
Privacy

Privacy

How your health data is used

Who we are

NutriBuddyAI is the data controller for the personal data processed in this app and on nutribuddyai.com. For any privacy question or request, contact privacy@nutribuddyai.com.

What we collect (account & coaching)

  • Account and profile data (email, name, weight, height, date of birth, gender, training plan) — to operate your account and generate your nutrition plan. Legal basis: performance of a contract.
  • Food and activity you log in the app — to provide the coaching you asked for. Legal basis: performance of a contract.

Google Health API (Health Connect)

If you connect Google Health / Health Connect on Android, we access data only through the Google Health API and only for the categories you explicitly authorize. We do not sell this data and we do not use it for advertising.

Through the Google Health API we may collect:

  • Sleep data — sleep duration, timing, stages when available, and related sleep sessions.
  • Activity data — steps, movement, daily activity / strain summaries.
  • Health metrics — heart rate, HRV, resting heart rate, blood oxygen, VO2 max, and recovery-related metrics when you grant access.
  • Fitness data — workouts and exercise sessions (type, duration, intensity, calories).

Apple Health (Apple Watch / HealthKit)

If you connect Apple Health on iPhone (including data written by Apple Watch), we access data only through Apple HealthKit and only for the categories you explicitly authorize in the iOS Health permission sheet. We do not sell this data and we do not use it for advertising.

Through Apple Health / HealthKit we may collect:

  • Sleep data — sleep duration, timing, stages when available, and related sleep sessions.
  • Activity data — steps, movement, daily activity / strain summaries.
  • Health metrics — heart rate, HRV, resting heart rate, blood oxygen, VO2 max, and recovery-related metrics when you grant access.
  • Fitness data — workouts and exercise sessions (type, duration, intensity, calories).

Whoop

If you connect Whoop, we access data only through Whoop’s official connection / API for your account and only after you authorize NutriBuddyAI. We do not sell this data and we do not use it for advertising.

Through Whoop we may collect:

  • Sleep data — sleep duration, timing, and Whoop sleep performance metrics.
  • Activity data — daily strain and activity summaries.
  • Health metrics — HRV, resting heart rate, recovery score, and related physiological metrics when available.
  • Fitness data — workouts and exercise sessions (type, duration, strain, calories when available).

Why we collect connected health data

Whether the source is the Google Health API, Apple Health (Apple Watch / HealthKit), or Whoop, we use Sleep data, Activity data, Health metrics, and Fitness data solely to personalise nutrition guidance, adapt daily fueling to training and recovery, detect fueling risks, and show performance-related scores in the product you requested.

Legal basis: your explicit consent, given when you connect a source and grant permissions. You can withdraw consent at any time (see Data deletion). Withdrawal stops further collection and does not affect processing already completed lawfully before withdrawal.

Where we store it

Account, diary, and synced health data from Google Health API, Apple Health / HealthKit, and Whoop are stored on our servers in a managed cloud database (MongoDB) and related cloud infrastructure operated by our hosting and service providers, acting on our instructions under data-processing agreements.

Data may be processed in the United Kingdom / European Economic Area and, where needed for hosting, in other regions with appropriate safeguards. After sync, the source of truth for coaching features is your NutriBuddyAI account — not only the copy that remains on your phone, Apple Health, Google Health, or Whoop.

How we protect personal and sensitive data

We use technical safeguards to protect the confidentiality of personal and sensitive data, including Google user data and health data from connected services, and to help prevent unauthorized access or disclosure:

  • Encryption in transit — We use HTTPS/TLS to encrypt data transmitted between the app or website and our servers, and between our servers and the Google Health and Whoop APIs.
  • Access controls — Our API verifies your identity before granting access to account and health data. Requests for your health records are scoped to your authenticated account.
  • Encrypted connection tokens — Google Health and Whoop OAuth access and refresh tokens are encrypted with AES-256-GCM before they are stored in our database. The encryption key is held in server configuration, separately from the stored tokens.
  • Password protection — Account passwords are stored as salted bcrypt hashes.

How to revoke access and delete data

You can revoke Google Health / Health Connect, Apple Health (Apple Watch), and Whoop access, and permanently delete your NutriBuddyAI data, at any time. Step-by-step instructions: https://www.nutribuddyai.com/data-deletion.

In short: disconnect wearables in Account (and/or revoke NutriBuddyAI in Google Health / Health Connect, iOS Health, or Whoop connected-apps settings), then delete your account from Account → Danger Zone, or email us to request deletion.

Who receives it

We do not sell your data and we do not use your health data for advertising. Your data is shared only with the cloud infrastructure and service providers that run this app, acting on our instructions.

If you join a coach's group, your coach can see your plan, adherence, and progress until you leave the group.

How long we keep it

For as long as your account exists. Deleting your account permanently deletes your profile, diary, and synced health data from connected sources (including Google Health API, Apple Health / HealthKit, and Whoop), subject to short-lived backups required for security and continuity.

Your rights

You can access, correct, export, or delete your data, withdraw consent, and object to or restrict processing. Contact privacy@nutribuddyai.com or use https://www.nutribuddyai.com/data-deletion.

You can also lodge a complaint with your data-protection authority (in the UK, the ICO; in the EU, your national authority).

Not medical advice

NutriBuddy is a nutrition and training companion, not a medical device and not a source of medical advice. Scores, signals, and recommendations are estimates computed from your data and can be inaccurate. They are not a substitute for a doctor, registered dietitian, or other qualified professional. Never ignore professional medical advice or delay seeking it because of something shown in this app.