NutriApexa Privacy Policy
Effective date: 2026-06-20
Last updated: 2026-07-25
This Privacy Policy explains how Claudio Torrens, an individual developer based in Pointe-Claire, Quebec, Canada ("Claudio Torrens", "we", "us", or "our"), collects, uses, discloses, retains, and protects personal information when you use the NutriApexa mobile application (the "App"), and the choices and rights you have in relation to that personal information. References to "we", "us", and "our" mean Claudio Torrens acting as the individual developer and operator of NutriApexa, not a corporation.
This Policy applies in addition to our Terms of Use. It is written in plain language wherever possible, with the formal disclosures required by Canadian, U.S. (California), European (GDPR), and U.K. data-protection laws set out in dedicated sections below.
We've built NutriApexa to keep your nutrition, weight, and health data on your devices and in your private iCloud — never on our servers, never shared with advertisers, never sold.
1. Who we are and how to contact us
| Data controller | Claudio Torrens, individual developer, Pointe-Claire, Quebec, Canada |
|---|---|
| claudio.torrens@gmail.com | |
| Postal address | Available on written request to the email above |
| Subject line for privacy inquiries | Privacy Request |
If you contact us about privacy, please tell us the country or province you are writing from so we can apply the rights of your jurisdiction.
2. Summary — what we collect, in plain words
- You tell us: your Apple ID identifier via Sign in with Apple, the profile data you enter, and the content you log, including food entries, photos, voice transcripts, weight measurements, water entries, exercise entries, saved foods, favourite recipes, and notes.
- Apple HealthKit gives us, with your consent per category: steps, active energy burned, basal energy burned, body weight, body mass index, workouts, and dietary energy consumed. HealthKit data stays on your device and never leaves through us.
- We use your data to: run the App for you. Period.
- We don't use your data to: sell, advertise, profile, train AI, or otherwise commercialise it.
- Where it lives: locally on each device you install the App on; in your private iCloud CloudKit container; and, for AI features only, transiently with our AI subprocessor while it processes the single text, voice transcript, or photo you submitted.
3. Personal information we collect
3.1 Account information from Sign in with Apple
When you create your account using Sign in with Apple, we receive your Apple-issued user identifier, your name only if you choose to share it, and your email address only if you choose to share it. You may choose Apple's private email relay address. We never receive your Apple ID password.
3.2 Profile and goal information entered by you
- Sex assigned at birth or selected for calorie calculation, used to apply the correct Mifflin-St Jeor equation;
- Year of birth, height, weight, activity level, goal type, target weight, target pace, daily calorie and macronutrient targets, display name, and preferences.
3.3 Logging information entered by you or generated from your input
- Food log entries, including food name, brand, barcode, serving size, quantity, calories, macronutrients, fiber, sugar, sodium, meal type, date, time, source, AI confidence score, and AI assumptions text;
- Photos submitted for meal photo or label scan analysis;
- Voice transcripts produced on-device by Apple's Speech framework;
- Weight, water, and exercise entries;
- Saved foods, favourite recipes, achievement badges, and app settings such as notification preferences, units, AI consent state, photo retention preference, and selected interface language.
3.4 Information we read from Apple HealthKit with your consent
| Category | Why we read it |
|---|---|
| Step count | Display in the daily dashboard |
| Active energy burned | Optional inclusion in daily calorie balance |
| Basal energy burned | Display only |
| Body mass (weight) | Show on the weight chart without duplicate entry |
| Body mass index | Show in the profile card |
| Workouts | Display in the daily dashboard |
| Dietary energy consumed | Avoid double-counting on the daily dashboard |
HealthKit data is read on demand and is not transmitted off your device. It is not copied into your iCloud CloudKit container, is not sent to our AI subprocessor, and is not retained by the App beyond the current display refresh.
3.5 Information we write to Apple HealthKit with your consent
We write body mass, dietary water, and dietary energy consumed only when you explicitly save or confirm the value in the App. We never write derived or estimated values without your action.
3.6 Information we do not collect
- Precise or coarse location, contacts, calendar, or photo library beyond the specific photos you choose to submit;
- Browsing history, search history outside the App, or app usage outside the App;
- Advertising identifiers, financial information, government IDs, biometrics, sexual orientation, religion, political opinions, trade-union membership, ethnic origin, or genetic information.
3.7 Information collected automatically
The App does not include analytics SDKs, crash-reporting SDKs, attribution SDKs, or telemetry SDKs. We do not log custom events. If you opt in to share diagnostics and usage with Apple system-wide, Apple may share anonymised crash reports with us through App Store Connect; those reports contain no personal information.
4. How we use personal information
| Purpose | Categories used | Legal basis where required |
|---|---|---|
| Operate core features | All categories in Section 3 | Performance of a contract; consent for HealthKit categories |
| Compute personalized calorie and macronutrient targets | Profile and goal information | Performance of a contract |
| Provide AI-assisted features | The specific input you submit plus locale | Consent; you may decline AI features |
| Sync across Apple devices via private CloudKit | Logging information, profile, badges, settings | Performance of a contract |
| Mirror confirmed entries back to Apple HealthKit | The specific entry you confirmed | Consent per HealthKit write category |
| Resolve food and recipe lookups | Search query only | Performance of a contract |
| Respond to support requests | Email content and identity provided | Performance of a contract; legitimate interests |
| Comply with legal obligations and enforce Terms | As required | Legal obligation; legitimate interests |
We do not use personal information for marketing or advertising, profiling or automated decisions producing legal or similarly significant effects, training or evaluating any AI model, selling or licensing to third parties, or cross-context behavioural advertising.
5. Where your information is stored
5.1 On your device
All food logs, weight history, settings, badges, saved foods, recipe favourites, and caches are written to the App's private storage on each device where you have NutriApexa installed. This storage is sandboxed by iOS so other apps cannot read it.
5.2 In your private iCloud
With iCloud enabled, the same data is synced to your iCloud account using Apple's CloudKit private database for NutriApexa's private iCloud container. This data is accessible only by you, on your Apple ID. Neither Claudio Torrens nor any third party, other than Apple as iCloud operator under Apple's own privacy practices, has access to your private CloudKit container.
5.3 At our AI subprocessor
When you use AI text parsing, voice parsing, photo analysis, recipe generation, or label parsing, the specific input you submitted plus your device locale is transmitted to our AI subprocessor for processing. The subprocessor returns a response, the App parses it into a draft you confirm, and the request is complete.
5.4 No developer-operated user-data server
Claudio Torrens does not run a back-end server that stores user data. There is no developer-operated database holding your food logs, weight history, profile, or other personal information. The only servers involved are Apple, the AI subprocessor transiently, and public food or recipe lookup services for the search query alone.
6. AI features — exactly what we send and how
| Feature | What we send | What we do not send |
|---|---|---|
| Describe with text | The text you typed and your device locale | Your name, email, weight, age, goals, history, identifiers, or location |
| Describe with voice | The on-device speech-to-text transcript and locale | Raw audio or the personal data listed above |
| Take meal photo | A compressed photo copy, optional hint, and locale | Profile, history, identifiers, location, or HealthKit data |
| Scan nutrition label | On-device OCR text, a compressed label photo, and locale | Profile, history, identifiers, location, or HealthKit data |
| Generate recipe | Your prompt, selected dietary constraints, and locale | Profile, history, identifiers, location, or HealthKit data |
We do not transmit your Apple ID, name, email, weight, age, height, activity level, goals, history of past entries, location, contacts, installed apps, advertising identifier, or HealthKit data alongside AI requests.
Meal and label photos are resized on-device to at most 1568 pixels on the longer edge and re-encoded as JPEG at quality 0.7. EXIF orientation is baked into the pixel buffer before transmission, while GPS, camera serial, and other EXIF metadata are stripped. We never send the original full-resolution photo.
For voice logging, we never send raw audio. Apple's Speech framework converts speech to text on your device, and only the transcript is sent to the AI subprocessor.
By default, the App does not retain photos submitted for meal analysis. If you enable "Save meal photos" in Settings, the App retains the photo locally and in your private iCloud with the corresponding food entry.
We use OpenAI as the current AI subprocessor. OpenAI is used for three purposes: (1) parsing text, voice transcripts, and meal photos into structured nutrition estimates; (2) generating a stylised food image when no curated food photo is available for the identified item (via OpenAI's image-generation API — the App sends only the plain food name, e.g. "grilled salmon fillet", and receives a generated PNG that is stored in your private App cache); and (3) generating on-demand recipes when a search returns no results. Under OpenAI's API terms in effect as of the effective date of this Policy, inputs and outputs submitted through the API are not used to train OpenAI's models. OpenAI may retain inputs and outputs transiently for abuse-monitoring for a limited period in accordance with OpenAI's stated retention policy, currently up to 30 days and subject to OpenAI's current terms at https://openai.com/policies.
The App asks for explicit AI consent before any AI feature is used. You can review or withdraw consent at any time in Me → Settings → AI & privacy → AI consent. AI output is informational only and requires explicit confirmation before any food log entry is saved.
7. Third-party services and subprocessors
| Party | Role | Personal data processed | Purpose | Privacy policy |
|---|---|---|---|---|
| Apple Inc. | Controller | Apple ID identifier, name/email if shared, private CloudKit contents, HealthKit data on-device only | Authentication, iCloud sync, distribution, HealthKit | Apple Privacy |
| OpenAI | AI subprocessor | The specific text/transcript/photo you submit plus locale; for image generation, only the plain food name identified from that input | AI-assisted nutrition parsing, food image generation, and recipe generation | OpenAI Policies |
| Open Food Facts | Independent controller | Barcode or food name search query, request IP | Packaged-food and barcode lookup | Privacy policy |
| U.S. Department of Agriculture | Independent controller | Food name search query, request IP | FoodData Central nutrition data | U.S. federal privacy practices |
| Health Canada | Independent controller | Food name search query, request IP | Canadian Nutrient File data | Canada privacy |
| Spoonacular by inFoodSphere LLC | Independent controller | Recipe filter/search terms, request IP | Recipe catalogue and images | Privacy policy |
| Wikipedia / Wikimedia Commons | Independent controller | Food name search query, request IP | Stock food images | Privacy policy |
We do not transmit identifying information about you to these third-party services beyond the search query and your IP address, which the service receives automatically as part of any network request.
8. International data transfers
Your information may be processed in Canada, the United States, and other jurisdictions required by Apple's iCloud, Wikimedia infrastructure, or OpenAI's regional processing. For users in the EEA, UK, or Switzerland, transfers outside those jurisdictions are supported by appropriate safeguards, including Standard Contractual Clauses or the UK addendum where required. Quebec residents should treat this Policy and the limited disclosures it identifies as the privacy impact assessment notice required by Article 17 of Quebec's private-sector privacy law.
9. Retention
| Category | Retention period |
|---|---|
| Account data | Until you delete your account |
| Logging information | Until you delete the entry or your account |
| Photos if "Save meal photos" is enabled | Until you delete the corresponding food entry or your account |
| Photos by default | Discarded immediately after processing |
| Voice transcripts | Never persisted by us beyond the AI request |
| HealthKit data | Not persisted by us; remains in Apple Health on your device |
| Search queries to food/recipe services | Not stored by us; third-party retention applies |
| AI subprocessor logs | Per the subprocessor's stated retention policy, currently up to 30 days for OpenAI API |
| Support correspondence | Up to 24 months after the matter is resolved, then deleted |
| Legal-hold records | As required by applicable law |
When you delete your account in the App, your data in your private iCloud CloudKit container is removed by Apple per Apple's policies. Locally cached data is removed when you uninstall the App.
10. Security
- All network requests use HTTPS/TLS with certificate validation;
- Sensitive identifiers are stored in the iOS Keychain, scoped to NutriApexa's keychain access group;
- iOS sandboxing prevents other apps from reading NutriApexa's storage;
- API keys for third-party services are kept out of public source code repositories and scoped to NutriApexa's bundle identifier;
- We minimize data by sending only what is strictly needed for each feature;
- We do not maintain a backend server that stores user data.
No system is perfectly secure. Vulnerability reports can be emailed to claudio.torrens@gmail.com with the subject "Security report". We aim to acknowledge security reports within 5 business days.
In the event of a personal-information breach that poses a real risk of significant harm, we will notify you and the appropriate regulator(s) without undue delay, in accordance with applicable law.
11. Your rights — general
Subject to applicable law and to the limits of what we actually hold, you can ask us to access, correct, delete, restrict, object to processing, withdraw consent, receive a portable copy of data you provided, or lodge a complaint with a supervisory authority. To exercise any right, contact claudio.torrens@gmail.com. We will respond within thirty days or any shorter period required by law, and may request reasonable information to verify your identity.
12. Canada — federal and provincial rights
The App is operated from Pointe-Claire, Quebec, Canada. PIPEDA applies where applicable. Quebec residents have additional rights under the Act respecting the protection of personal information in the private sector, as amended by Law 25, including rights related to automated decision-making and communication in French. A French version of this Policy and of the Terms of Use is available in the App. You may file a complaint with the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca/ or, for Quebec-specific matters, with the Commission d'accès à l'information du Québec at https://www.cai.gouv.qc.ca/.
13. United States — California, Virginia, and similar state privacy rights
California residents have rights to know, access, correct, delete, limit certain sensitive personal information uses, opt out of sale or sharing for cross-context behavioural advertising, and avoid discrimination for exercising those rights. We do not sell personal information. We do not share personal information for cross-context behavioural advertising, and we do not use sensitive personal information for purposes other than those permitted by California law. Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other U.S. states with comprehensive privacy laws have substantially similar rights, and we treat all such requests under a single procedure.
14. European Economic Area, United Kingdom, and Switzerland
If you are in the EEA, UK, or Switzerland, the GDPR, UK GDPR, and/or Swiss FADP applies. Claudio Torrens is the data controller. You may lodge a complaint with your supervisory authority, the UK Information Commissioner's Office at https://ico.org.uk, or the applicable Swiss authority. Where processing is based on consent, you may withdraw it at any time. Where processing is based on legitimate interests, you may object for reasons specific to your situation. We are not currently required under Article 27 to appoint an EEA/UK representative.
15. Children's privacy
The App is rated 9+ in the App Store and is intended for general audiences age 13 and older, or 16 where required by applicable EU member state law. We do not knowingly collect personal information from children under the applicable minimum age. Parents or guardians who believe a child has provided personal information should contact claudio.torrens@gmail.com. The App does not market to children, does not present age-inappropriate content, and does not advertise.
16. Lead supervisory authority and how to complain
- Canada: Office of the Privacy Commissioner of Canada — https://www.priv.gc.ca/
- Quebec: Commission d'accès à l'information du Québec — https://www.cai.gouv.qc.ca/
- EEA: the supervisory authority in your country of residence.
- United Kingdom: Information Commissioner's Office — https://ico.org.uk/
- California: California Privacy Protection Agency — https://cppa.ca.gov/; also the Attorney General — https://oag.ca.gov/privacy
- Other U.S. states: the Attorney General of your state of residence.
We encourage you to contact us first so we can try to resolve your concern directly.
17. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify you by in-App notification, by email where we have one, or by displaying a notice the next time you launch the App, at least fifteen days before the changes take effect or such longer period as required by applicable law. If a change materially expands the categories of personal information we collect, the purposes of processing, or third parties we share with, we will obtain renewed consent where applicable law requires.
18. Contact and accountability
Privacy questions, rights requests, complaints, and any other communications about this Policy should be sent to Claudio Torrens at claudio.torrens@gmail.com with the subject "Privacy Request". We are accountable for personal information under our control and for compliance with this Policy. Where personal information is processed by a subprocessor or third party, we use contractual terms to require comparable protection.
This Policy is provided in good faith as a comprehensive framework for the App. It is not a substitute for advice from a qualified attorney in your jurisdiction. If you are reviewing this Policy in connection with App Store submission in a country with specific privacy or consumer-protection requirements, obtain professional legal review before relying on this Policy as final.