NutriApexa Privacy Policy

NutriApexa Privacy Policy

Effective date: 2026-06-20

Last updated: 2026-07-25

This Privacy Policy explains how Claudio Torrens, an individual developer based in Pointe-Claire, Quebec, Canada ("Claudio Torrens", "we", "us", or "our"), collects, uses, discloses, retains, and protects personal information when you use the NutriApexa mobile application (the "App"), and the choices and rights you have in relation to that personal information. References to "we", "us", and "our" mean Claudio Torrens acting as the individual developer and operator of NutriApexa, not a corporation.

This Policy applies in addition to our Terms of Use. It is written in plain language wherever possible, with the formal disclosures required by Canadian, U.S. (California), European (GDPR), and U.K. data-protection laws set out in dedicated sections below.

We've built NutriApexa to keep your nutrition, weight, and health data on your devices and in your private iCloud — never on our servers, never shared with advertisers, never sold.

1. Who we are and how to contact us

Data controllerClaudio Torrens, individual developer, Pointe-Claire, Quebec, Canada
Emailclaudio.torrens@gmail.com
Postal addressAvailable on written request to the email above
Subject line for privacy inquiriesPrivacy Request

If you contact us about privacy, please tell us the country or province you are writing from so we can apply the rights of your jurisdiction.

2. Summary — what we collect, in plain words

  • You tell us: your Apple ID identifier via Sign in with Apple, the profile data you enter, and the content you log, including food entries, photos, voice transcripts, weight measurements, water entries, exercise entries, saved foods, favourite recipes, and notes.
  • Apple HealthKit gives us, with your consent per category: steps, active energy burned, basal energy burned, body weight, body mass index, workouts, and dietary energy consumed. HealthKit data stays on your device and never leaves through us.
  • We use your data to: run the App for you. Period.
  • We don't use your data to: sell, advertise, profile, train AI, or otherwise commercialise it.
  • Where it lives: locally on each device you install the App on; in your private iCloud CloudKit container; and, for AI features only, transiently with our AI subprocessor while it processes the single text, voice transcript, or photo you submitted.

3. Personal information we collect

3.1 Account information from Sign in with Apple

When you create your account using Sign in with Apple, we receive your Apple-issued user identifier, your name only if you choose to share it, and your email address only if you choose to share it. You may choose Apple's private email relay address. We never receive your Apple ID password.

3.2 Profile and goal information entered by you

  • Sex assigned at birth or selected for calorie calculation, used to apply the correct Mifflin-St Jeor equation;
  • Year of birth, height, weight, activity level, goal type, target weight, target pace, daily calorie and macronutrient targets, display name, and preferences.

3.3 Logging information entered by you or generated from your input

  • Food log entries, including food name, brand, barcode, serving size, quantity, calories, macronutrients, fiber, sugar, sodium, meal type, date, time, source, AI confidence score, and AI assumptions text;
  • Photos submitted for meal photo or label scan analysis;
  • Voice transcripts produced on-device by Apple's Speech framework;
  • Weight, water, and exercise entries;
  • Saved foods, favourite recipes, achievement badges, and app settings such as notification preferences, units, AI consent state, photo retention preference, and selected interface language.

3.4 Information we read from Apple HealthKit with your consent

CategoryWhy we read it
Step countDisplay in the daily dashboard
Active energy burnedOptional inclusion in daily calorie balance
Basal energy burnedDisplay only
Body mass (weight)Show on the weight chart without duplicate entry
Body mass indexShow in the profile card
WorkoutsDisplay in the daily dashboard
Dietary energy consumedAvoid double-counting on the daily dashboard

HealthKit data is read on demand and is not transmitted off your device. It is not copied into your iCloud CloudKit container, is not sent to our AI subprocessor, and is not retained by the App beyond the current display refresh.

3.5 Information we write to Apple HealthKit with your consent

We write body mass, dietary water, and dietary energy consumed only when you explicitly save or confirm the value in the App. We never write derived or estimated values without your action.

3.6 Information we do not collect

  • Precise or coarse location, contacts, calendar, or photo library beyond the specific photos you choose to submit;
  • Browsing history, search history outside the App, or app usage outside the App;
  • Advertising identifiers, financial information, government IDs, biometrics, sexual orientation, religion, political opinions, trade-union membership, ethnic origin, or genetic information.

3.7 Information collected automatically

The App does not include analytics SDKs, crash-reporting SDKs, attribution SDKs, or telemetry SDKs. We do not log custom events. If you opt in to share diagnostics and usage with Apple system-wide, Apple may share anonymised crash reports with us through App Store Connect; those reports contain no personal information.

4. How we use personal information

PurposeCategories usedLegal basis where required
Operate core featuresAll categories in Section 3Performance of a contract; consent for HealthKit categories
Compute personalized calorie and macronutrient targetsProfile and goal informationPerformance of a contract
Provide AI-assisted featuresThe specific input you submit plus localeConsent; you may decline AI features
Sync across Apple devices via private CloudKitLogging information, profile, badges, settingsPerformance of a contract
Mirror confirmed entries back to Apple HealthKitThe specific entry you confirmedConsent per HealthKit write category
Resolve food and recipe lookupsSearch query onlyPerformance of a contract
Respond to support requestsEmail content and identity providedPerformance of a contract; legitimate interests
Comply with legal obligations and enforce TermsAs requiredLegal obligation; legitimate interests

We do not use personal information for marketing or advertising, profiling or automated decisions producing legal or similarly significant effects, training or evaluating any AI model, selling or licensing to third parties, or cross-context behavioural advertising.

5. Where your information is stored

5.1 On your device

All food logs, weight history, settings, badges, saved foods, recipe favourites, and caches are written to the App's private storage on each device where you have NutriApexa installed. This storage is sandboxed by iOS so other apps cannot read it.

5.2 In your private iCloud

With iCloud enabled, the same data is synced to your iCloud account using Apple's CloudKit private database for NutriApexa's private iCloud container. This data is accessible only by you, on your Apple ID. Neither Claudio Torrens nor any third party, other than Apple as iCloud operator under Apple's own privacy practices, has access to your private CloudKit container.

5.3 At our AI subprocessor

When you use AI text parsing, voice parsing, photo analysis, recipe generation, or label parsing, the specific input you submitted plus your device locale is transmitted to our AI subprocessor for processing. The subprocessor returns a response, the App parses it into a draft you confirm, and the request is complete.

5.4 No developer-operated user-data server

Claudio Torrens does not run a back-end server that stores user data. There is no developer-operated database holding your food logs, weight history, profile, or other personal information. The only servers involved are Apple, the AI subprocessor transiently, and public food or recipe lookup services for the search query alone.

6. AI features — exactly what we send and how

FeatureWhat we sendWhat we do not send
Describe with textThe text you typed and your device localeYour name, email, weight, age, goals, history, identifiers, or location
Describe with voiceThe on-device speech-to-text transcript and localeRaw audio or the personal data listed above
Take meal photoA compressed photo copy, optional hint, and localeProfile, history, identifiers, location, or HealthKit data
Scan nutrition labelOn-device OCR text, a compressed label photo, and localeProfile, history, identifiers, location, or HealthKit data
Generate recipeYour prompt, selected dietary constraints, and localeProfile, history, identifiers, location, or HealthKit data

We do not transmit your Apple ID, name, email, weight, age, height, activity level, goals, history of past entries, location, contacts, installed apps, advertising identifier, or HealthKit data alongside AI requests.

Meal and label photos are resized on-device to at most 1568 pixels on the longer edge and re-encoded as JPEG at quality 0.7. EXIF orientation is baked into the pixel buffer before transmission, while GPS, camera serial, and other EXIF metadata are stripped. We never send the original full-resolution photo.

For voice logging, we never send raw audio. Apple's Speech framework converts speech to text on your device, and only the transcript is sent to the AI subprocessor.

By default, the App does not retain photos submitted for meal analysis. If you enable "Save meal photos" in Settings, the App retains the photo locally and in your private iCloud with the corresponding food entry.

We use OpenAI as the current AI subprocessor. OpenAI is used for three purposes: (1) parsing text, voice transcripts, and meal photos into structured nutrition estimates; (2) generating a stylised food image when no curated food photo is available for the identified item (via OpenAI's image-generation API — the App sends only the plain food name, e.g. "grilled salmon fillet", and receives a generated PNG that is stored in your private App cache); and (3) generating on-demand recipes when a search returns no results. Under OpenAI's API terms in effect as of the effective date of this Policy, inputs and outputs submitted through the API are not used to train OpenAI's models. OpenAI may retain inputs and outputs transiently for abuse-monitoring for a limited period in accordance with OpenAI's stated retention policy, currently up to 30 days and subject to OpenAI's current terms at https://openai.com/policies.

The App asks for explicit AI consent before any AI feature is used. You can review or withdraw consent at any time in Me → Settings → AI & privacy → AI consent. AI output is informational only and requires explicit confirmation before any food log entry is saved.

7. Third-party services and subprocessors

PartyRolePersonal data processedPurposePrivacy policy
Apple Inc.ControllerApple ID identifier, name/email if shared, private CloudKit contents, HealthKit data on-device onlyAuthentication, iCloud sync, distribution, HealthKitApple Privacy
OpenAIAI subprocessorThe specific text/transcript/photo you submit plus locale; for image generation, only the plain food name identified from that inputAI-assisted nutrition parsing, food image generation, and recipe generationOpenAI Policies
Open Food FactsIndependent controllerBarcode or food name search query, request IPPackaged-food and barcode lookupPrivacy policy
U.S. Department of AgricultureIndependent controllerFood name search query, request IPFoodData Central nutrition dataU.S. federal privacy practices
Health CanadaIndependent controllerFood name search query, request IPCanadian Nutrient File dataCanada privacy
Spoonacular by inFoodSphere LLCIndependent controllerRecipe filter/search terms, request IPRecipe catalogue and imagesPrivacy policy
Wikipedia / Wikimedia CommonsIndependent controllerFood name search query, request IPStock food imagesPrivacy policy

We do not transmit identifying information about you to these third-party services beyond the search query and your IP address, which the service receives automatically as part of any network request.

8. International data transfers

Your information may be processed in Canada, the United States, and other jurisdictions required by Apple's iCloud, Wikimedia infrastructure, or OpenAI's regional processing. For users in the EEA, UK, or Switzerland, transfers outside those jurisdictions are supported by appropriate safeguards, including Standard Contractual Clauses or the UK addendum where required. Quebec residents should treat this Policy and the limited disclosures it identifies as the privacy impact assessment notice required by Article 17 of Quebec's private-sector privacy law.

9. Retention

CategoryRetention period
Account dataUntil you delete your account
Logging informationUntil you delete the entry or your account
Photos if "Save meal photos" is enabledUntil you delete the corresponding food entry or your account
Photos by defaultDiscarded immediately after processing
Voice transcriptsNever persisted by us beyond the AI request
HealthKit dataNot persisted by us; remains in Apple Health on your device
Search queries to food/recipe servicesNot stored by us; third-party retention applies
AI subprocessor logsPer the subprocessor's stated retention policy, currently up to 30 days for OpenAI API
Support correspondenceUp to 24 months after the matter is resolved, then deleted
Legal-hold recordsAs required by applicable law

When you delete your account in the App, your data in your private iCloud CloudKit container is removed by Apple per Apple's policies. Locally cached data is removed when you uninstall the App.

10. Security

  • All network requests use HTTPS/TLS with certificate validation;
  • Sensitive identifiers are stored in the iOS Keychain, scoped to NutriApexa's keychain access group;
  • iOS sandboxing prevents other apps from reading NutriApexa's storage;
  • API keys for third-party services are kept out of public source code repositories and scoped to NutriApexa's bundle identifier;
  • We minimize data by sending only what is strictly needed for each feature;
  • We do not maintain a backend server that stores user data.

No system is perfectly secure. Vulnerability reports can be emailed to claudio.torrens@gmail.com with the subject "Security report". We aim to acknowledge security reports within 5 business days.

In the event of a personal-information breach that poses a real risk of significant harm, we will notify you and the appropriate regulator(s) without undue delay, in accordance with applicable law.

11. Your rights — general

Subject to applicable law and to the limits of what we actually hold, you can ask us to access, correct, delete, restrict, object to processing, withdraw consent, receive a portable copy of data you provided, or lodge a complaint with a supervisory authority. To exercise any right, contact claudio.torrens@gmail.com. We will respond within thirty days or any shorter period required by law, and may request reasonable information to verify your identity.

12. Canada — federal and provincial rights

The App is operated from Pointe-Claire, Quebec, Canada. PIPEDA applies where applicable. Quebec residents have additional rights under the Act respecting the protection of personal information in the private sector, as amended by Law 25, including rights related to automated decision-making and communication in French. A French version of this Policy and of the Terms of Use is available in the App. You may file a complaint with the Office of the Privacy Commissioner of Canada at https://www.priv.gc.ca/ or, for Quebec-specific matters, with the Commission d'accès à l'information du Québec at https://www.cai.gouv.qc.ca/.

13. United States — California, Virginia, and similar state privacy rights

California residents have rights to know, access, correct, delete, limit certain sensitive personal information uses, opt out of sale or sharing for cross-context behavioural advertising, and avoid discrimination for exercising those rights. We do not sell personal information. We do not share personal information for cross-context behavioural advertising, and we do not use sensitive personal information for purposes other than those permitted by California law. Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other U.S. states with comprehensive privacy laws have substantially similar rights, and we treat all such requests under a single procedure.

14. European Economic Area, United Kingdom, and Switzerland

If you are in the EEA, UK, or Switzerland, the GDPR, UK GDPR, and/or Swiss FADP applies. Claudio Torrens is the data controller. You may lodge a complaint with your supervisory authority, the UK Information Commissioner's Office at https://ico.org.uk, or the applicable Swiss authority. Where processing is based on consent, you may withdraw it at any time. Where processing is based on legitimate interests, you may object for reasons specific to your situation. We are not currently required under Article 27 to appoint an EEA/UK representative.

15. Children's privacy

The App is rated 9+ in the App Store and is intended for general audiences age 13 and older, or 16 where required by applicable EU member state law. We do not knowingly collect personal information from children under the applicable minimum age. Parents or guardians who believe a child has provided personal information should contact claudio.torrens@gmail.com. The App does not market to children, does not present age-inappropriate content, and does not advertise.

16. Lead supervisory authority and how to complain

We encourage you to contact us first so we can try to resolve your concern directly.

17. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will notify you by in-App notification, by email where we have one, or by displaying a notice the next time you launch the App, at least fifteen days before the changes take effect or such longer period as required by applicable law. If a change materially expands the categories of personal information we collect, the purposes of processing, or third parties we share with, we will obtain renewed consent where applicable law requires.

18. Contact and accountability

Privacy questions, rights requests, complaints, and any other communications about this Policy should be sent to Claudio Torrens at claudio.torrens@gmail.com with the subject "Privacy Request". We are accountable for personal information under our control and for compliance with this Policy. Where personal information is processed by a subprocessor or third party, we use contractual terms to require comparable protection.

This Policy is provided in good faith as a comprehensive framework for the App. It is not a substitute for advice from a qualified attorney in your jurisdiction. If you are reviewing this Policy in connection with App Store submission in a country with specific privacy or consumer-protection requirements, obtain professional legal review before relying on this Policy as final.

This policy is also available inside the NutriApexa app under Me → Privacy & legal → Privacy policy. The version shown in the app and the version hosted here are kept in sync.