Privacy Policy
Last updated: August 15, 2026
1. Who we are
Nutreefit ("the app", "we") is a nutrition and fitness application. The controller of your data is Sergio Iglesias Leite, a natural person resident in Spain. This policy explains what data we collect, what we use it for, who we share it with, and what rights you have over it.
Contact for any privacy questions: soporte@nutreefit.com
2. What data we collect
Account and profile:
- Email and password (the password is never stored in plain text β it's managed by Supabase Auth).
- Full name, username, profile photo (optional).
- Age, gender, height, weight, activity level, goal (lose/maintain/gain weight), and target macros.
Nutrition and workout data:
- Logged foods, meal plans, shopping lists, saved recipes.
- Food photos you submit for automatic recognition (processed, not stored unless you choose to save them).
- Workouts, exercises, sets, reps, weight lifted, and the perceived effort (RPE) you log.
- Body progress photos, if you choose to upload them (private storage, only you can see them).
Health data (optional, only if you enable syncing):
- Steps and active calories, via Apple Health (iOS) or Google Health Connect (Android).
Social data:
- Posts, comments, likes, who you follow and who follows you.
- If you use "Train Together": approximate city/province, sport, level, schedule, and the messages you send in chat with your training partner.
Other:
- Push notification token, if you enable notifications.
- Basic technical information needed for the app to work (device identifier for notifications, error logs).
3. What we use your data for
- Providing the service: calculating your macros, generating your plans/routines, showing your progress.
- AI features: identifying foods in photos, generating recipes and workout routines, generating progress reports β using your profile and log data as context for those one-off requests.
- Showing you social content (feed, Train Together) and letting you interact with other users.
- Sending you notifications you enable (reminders, Train Together alerts).
- Maintenance, security, and abuse prevention for the service.
- Showing ads (only if you don't have the Premium badge) and managing your subscription, if you have one.
4. Who we share data with
We don't sell your data. We share it only with the providers necessary for the app to work:
- Supabase β hosts the database, authentication, and file storage.
- Google Gemini β processes the food photos and text you send to the AI features (recipes, routines, reports, food recognition). The API key never leaves our server; your photos/text are sent only to generate that one-off response. We use the paid Gemini API, whose terms exclude the use of submitted content to train Google's models: your data is not used to train any artificial intelligence.
- Google AdMob β shows ads if you're not Premium; may use device identifiers for ad personalization based on your operating system's privacy settings.
- RevenueCat β manages the Premium subscription (receives purchase data, not your email or password).
- Apple / Google β if you sign in with Apple or Google, or sync health data with HealthKit / Health Connect.
- OpenFoodFacts β we query their public product database when you scan a barcode; we don't send them any of your data, it's a read-only lookup.
Other app users see what you post publicly (feed, public profile, Train Together listings) and the messages you send within an accepted Train Together chat.
Some of these providers (Google, RevenueCat) are based in the United States and may process data outside the European Union. These transfers rely on the applicable legal safeguards (standard contractual clauses or the EU-US Data Privacy Framework, depending on the provider).
The legal basis for this processing is, depending on the case: performance of the contract for using the app (core features), your explicit consent (health sync, push notifications, personalized ads), or our legitimate interest in keeping the service secure and running correctly. Health data deserves a separate mention β weight, body measurements, progress photos, steps and active calories: the GDPR treats these as a special category, and we process them only with your explicit consent, which you give by entering them or by enabling sync with Apple Health or Health Connect. You can withdraw it at any time by deleting that data from the app or deleting your account; withdrawing it does not affect the lawfulness of processing before that point.
5. Your rights
If you're in the European Union (GDPR) or in general, you have the right to:
- Access the data we have about you.
- Correct inaccurate data (you can edit most of it from your profile).
- Delete your account and your data ("right to be forgotten").
- Export your data in a reusable format (portability).
- Object to or restrict certain uses of your data.
- Withdraw your consent at any time, where the processing is based on it (for example, health data sync).
- Lodge a complaint with your local data protection authority (in Spain, the AEPD, aepd.es) if you believe we haven't handled your data correctly.
To exercise any of these rights, write to soporte@nutreefit.com.
6. Security and retention
We use our providers' standard security measures (encryption in transit, row-level access control in the database). We retain your data while your account is active. If you delete it, we erase your personal data within a maximum of 30 days, unless the law requires us to keep something for longer (for example, billing records for a subscription). Technical error logs are kept for a maximum of 90 days. Deleting your account also deletes your posts, comments, shared recipes and Train Together listings. One exception worth knowing: if another user saved a recipe you shared into their own recipe book, that copy is theirs and stays in their account, already unlinked from your profile.
7. Minors
Nutreefit is not directed at children under 16. If you believe a minor has provided us with data without parental or guardian consent, contact us to have it removed.
8. Changes to this policy
If we make significant changes to this policy, we'll notify you within the app. The "last updated" date at the top of this page always reflects the current version.