Privacy Policy
Last updated: June 2025
1. Who we are
NutriFlow AI ("NutriFlow", "we", "our") is an adaptive nutrition planning service. This policy explains what personal data we collect, how we use it, and how we protect it.
2. Data we collect
- Account data: email address and bcrypt-hashed password (we never store plain-text passwords).
- Profile data: age, sex, height, weight, activity level, dietary preferences, and health goals you provide during onboarding.
- Medical data: conditions, medications, and lab values you upload or enter. All sensitive medical fields are encrypted at rest using AES-256-GCM with a per-record salt — they are never stored or transmitted in plain text.
- Meal logs: photos you submit for nutrient analysis, along with timestamps and the macro estimates returned by AI.
- Document uploads: prescriptions or lab reports you upload voluntarily, stored in Vercel Blob (private access, IAD1 region) and linked to your encrypted medical profile.
- Usage data: page views, feature interactions, and session events collected via PostHog for product analytics.
3. How we use your data
- To generate and adapt your daily nutrition plan.
- To log meals and rebalance remaining-day targets.
- To apply medical guardrails (e.g., sodium caps for kidney disease).
- To send transactional emails (account verification, password reset) via Resend.
- To process subscription payments via Razorpay. We never see or store your card details — they are handled entirely by Razorpay's PCI DSS compliant infrastructure.
- To improve the product through aggregated, anonymised analytics.
4. Third-party processors
- Vercel — hosting, serverless compute, Blob storage (IAD1, private).
- Neon (PostgreSQL) — primary database, data at rest encrypted by the provider.
- Google Gemini AI — vision analysis of meal photos and medical document extraction. Images are sent to the Gemini API over TLS and are not retained by Google beyond the request.
- Razorpay — payment processing (PCI DSS Level 1). We store only the payment link ID and confirmation status.
- Resend — transactional email delivery.
- PostHog — product analytics. No medical data is sent to PostHog.
5. Data retention
Your data is retained for as long as your account is active. You may request deletion by emailing us at the address below. Upon deletion, all personal and medical data is permanently removed within 30 days.
6. Security
- Passwords are hashed with bcrypt (12 rounds).
- Medical fields are encrypted at the field level (AES-256-GCM) before database storage.
- All data in transit is encrypted via TLS 1.2+.
- Session tokens are HTTP-only, Secure, SameSite=Lax JWTs with a 7-day expiry.
- Document uploads are stored with private (non-public) access — they cannot be accessed without your session.
7. Your rights
Under applicable law you have the right to access, correct, or delete your personal data. To exercise any of these rights, contact us at the email below. We will respond within 30 days.
8. Children
NutriFlow is not directed at children under 13. We do not knowingly collect data from anyone under 13. If you believe a child has provided data, please contact us immediately.
9. Changes to this policy
We may update this policy periodically. Material changes will be communicated via email or in-app notice at least 14 days before they take effect.
10. Contact
For privacy questions or data requests, email: privacy@nutriflow.ai (or use the in-app support link).