Consumer Health Data Privacy Notice
CONSUMER HEALTH DATA PRIVACY NOTICE
NutriMotion LTD · Version 2026-09-12
Publication date: 12 September 2026 · Last updated: 12 September 2026
This notice supplements our main Privacy Policy, which explains NutriMotion's broader personal-information practices.
1. Who we are and when this Notice applies
NutriMotion LTD is registered in Scotland under company number SC838276. Our registered office is Clyde Offices, 2nd Floor, 48 West George Street, Glasgow, Scotland, G2 1BP, United Kingdom. Contact us about consumer health data at [email protected].
This Notice describes consumer health data processed through NutriMotion, its Apple Watch and Wear OS companions, optional authorised Garmin Connect integration and related services. It applies where your information is protected by the Washington My Health My Data Act, Nevada's consumer-health-data provisions in NRS Chapter 603A, or another applicable consumer-health law. It supplements, but does not replace, our Privacy Policy. This version is published and takes effect on 12 September 2026; it does not retrospectively authorise an undisclosed use. Garmin-specific processing applies only when the connection is available and you authorise it, not merely because this notice is published. A more protective applicable statutory rule prevails over an inconsistent statement.
Relationship to Scottish and UK law. NutriMotion is established in Scotland and its UK data-protection duties continue to apply as described in the main Privacy Policy. Scots law remains the chosen law of our account and service contract. This Notice supplies regional statutory disclosures where the relevant consumer-health law applies; it does not make United States law the general governing law of that contract, constitute an additional submission to United States courts or enlarge a statute's territorial scope. Statutory jurisdiction, remedies and regulatory powers are not restricted by this clarification.
Consumer health data can include information used to learn about, assess, measure or improve health, not just a formal medical diagnosis. Nutrition and exercise information, body measurements, related photographs and health-related inferences can qualify when connected or reasonably linkable to a consumer. Encryption or replacing your name with an account identifier does not necessarily remove those protections.
2. Categories, sources and purposes
| Category we process when the relevant feature is used | Sources | Purposes |
|---|---|---|
| Body measurements and fitness profile, including weight, height, age, biological sex, activity level and goals | You; your authorised health-platform connection | Personal tracking, progress, calorie and training calculations |
| Food, drink, nutrition, meal, recipe and diary information, including amounts, calories and macronutrients | You; selected food databases; your logged AI estimate | Nutrition logging, targets, summaries and requested sharing |
| Exercise, steps, workout, performance, injury/discomfort feedback, sleep and heart-recovery information | You; phone, Apple Watch or Wear OS sensors; Health Connect or Apple Health; recorded Garmin activities or supported files where authorised | Activity recording, recovery estimates, training recommendations and synchronisation of records that the relevant feature stores; raw phone workout-coach recovery readings are processed on-device as described in the main Policy |
| Progress photographs and associated dates, account association and storage metadata | Photographs you select or capture; application processing | Private storage, synchronisation, comparison, display and export |
| Food images, descriptions, barcode information, candidate food/nutrition matches, AI observations and estimates | You; recognised product information; selected food databases; Google Gemini's processing | Optional cloud Food Scan, including follow-up selection requests, and the diary entry you choose to save |
| Precise locations, time-stamped exercise routes, route choices and location-revealing metadata | Your device; your selected origin or waypoints; map and route interactions | Planning, nearby preparation, navigation, recorded activity and a share you request |
| Health- or fitness-related inferences and recommendations | Calculations using the above information | Personal progress, calorie, training and recovery feedback |
| Garmin connection identifiers, permissions, authorisation credentials and transfer records linked to fitness information | Your requested account link; Garmin's authorisation process; integration-service operations | Maintain or revoke the authorised connection, export selected courses, import authorised activities and prevent duplicate or unwanted transfers |
| Health information in messages, reports, shared lists, support attachments and feature-use records | You; another participant; application events and support or security interactions | The requested interaction, support, rights handling, necessary security and authorised service measurement |
An account identifier or purchase record can become health-related when linked to these activities. We process only what is appropriate for the feature or purpose. We do not deliberately collect genetic data, identify people through facial or voice biometric templates, or infer visits to a healthcare provider for advertising. If you put additional sensitive facts into free text or an image, they may become part of the material submitted for that function.
3. How information is processed and disclosed
Information is entered or measured, processed on the device and, where needed for the selected function, transmitted to the relevant service, stored, synchronised, displayed or used to produce an estimate. Progress-photo image payloads are encrypted on the device before Cloudflare R2 upload; their Firestore metadata is separate. The progress-photo bucket has the Western Europe (WEUR) location setting. This does not by itself establish Cloudflare's separate EU jurisdictional restriction or EU-only processing of all associated information. Private saved-route detail payloads are encrypted, but route names, area identifiers and other searchable metadata are not all protected by that client-side encryption. Food Scan inputs are readable by the selected AI processor. A public route contains readable route geometry for the intended audience.
The following recipient categories receive the stated information as needed for the disclosed purpose:
| Recipient category | Information and reason |
|---|---|
| Cloud database, authentication and application-service providers, principally Google/Firebase | Account-associated health, nutrition, activity and route records and technical metadata needed to operate the account and features; encrypted payloads remain encrypted where that scheme applies |
| Object storage and delivery provider, Cloudflare R2 | Encrypted progress-photo files and associated request/storage information |
| AI processing provider, Google Gemini through Firebase AI Logic | Food image, optional description, barcode/product evidence, candidate nutrition records, AI observations, generated estimate and relevant request information for the analysis you request |
| Garmin, operating Garmin Connect and the authorised APIs | When the connection is available and authorised: selected course data, account-link and transfer information, and the recorded activities exchanged for the functions described in the main Privacy Policy |
| Apple Health / HealthKit and Health Connect | Authorised health-platform exchanges, including an Apple Watch workout and route recorded in Apple Health where supported and permitted |
| Food-database services, including Open Food Facts and our cloud search services | Barcode or food-search queries, including terms inferred from Food Scan, and necessary technical request information; not the source image simply to perform a database lookup |
| Map, routing-data and geocoding service operators, including OpenFreeMap for map resources | Geographic resource requests, search text and search area, with relevant network information; we do not send a full private health diary simply to obtain a map |
| Service diagnostics and analytics providers, including relevant Firebase services | Appropriate technical or feature-use information, only under the permissions and other conditions required by law; not private image payloads or full diaries for unrelated advertising |
| App stores and subscription-administration providers, including RevenueCat | Purchase, entitlement and account information needed to supply the purchased service, rather than an automatic copy of your health records |
| People and external destinations you choose | The particular record, message, list, photograph or route that you instruct us to share, with the audience selected for that feature |
| Professional advisers, public authorities and a lawful business successor | Only information necessary and legally permitted for the specific legal duty, claim, incident or transfer; a business transaction does not permit an undisclosed new health-data use |
Providers acting as processors are restricted by the applicable processing arrangements; other recipients may have independent legal responsibilities. We do not disclose consumer health data to corporate affiliates under the processing described in this Notice. If a relevant affiliate recipient is introduced, the notice and any required consent must identify it before the disclosure.
We do not sell consumer health data, offer it to advertisers, employers or insurers for their independent decisions, or permit third parties to collect it through our Services over time and across unrelated websites or services for independent behavioural advertising. We do not use healthcare-facility geofences to identify or track people seeking care or send health-related targeted messages. Ordinary user-requested route planning is not permission to create such a tracking system.
Public and link-shared material can be copied by recipients. A route link is not a private encrypted record. Review locations and audiences before sharing. Removing a private saved route and removing its separately shared copy are different actions.
A Garmin export creates a record within Garmin Connect; it does not itself publish the route in NutriMotion. Garmin manages that record under its own settings and Garmin Connect Privacy Policy. Incoming Garmin activities are stored with your NutriMotion account under the protections for the relevant workout and route fields. The exchange is readable to the services carrying it out and is not represented as end-to-end encrypted against those services. NutriMotion does not send Garmin activities to Gemini or use them for general-purpose AI-model training. An Apple Health workout is likewise a separate copy, not erased merely by removing a NutriMotion or watch-queue record.
4. Consent and stopping processing
We obtain the consent required for collection and for sharing, with separate sharing consent where the law requires it. A narrow exception for processing necessary to provide a product or service you actually request applies only within its lawful scope. We do not treat a general acceptance of Terms of Service, a broad purpose such as improvement, or camera permission alone as consumer-health-data consent.
Where consent is sought, the request must identify the relevant information, purpose, recipient categories and method of withdrawal. For cloud AI, you must be informed before submission that an image and description go to Google. General permission to store a progress photograph is not permission to analyse it with Gemini. A Garmin account link, course export, activity import and any optional public share are limited to their disclosed purposes and applicable permissions; authorising one is not unrestricted permission for all of them.
You may withdraw consent to future collection or sharing by [email protected] or an available working feature control. Stop cloud submissions by not using Food Scan; revoke health or location access in the relevant device/platform settings to prevent future access under those permissions. Those actions do not necessarily delete information already stored. For Garmin, revoke NutriMotion's access through Garmin's connected-app settings or an available NutriMotion disconnect control, or contact us. We stop future exchanges and remove or invalidate the connection credentials and pending bodies. Request deletion of retained imports as well when that is the outcome you seek, subject to any applicable requirement for automatic or earlier deletion.
A feature requiring the information cannot continue without it, but we do not unlawfully penalise you for a privacy choice. For example, declining cloud photo analysis does not prevent manual food logging. Any new category, recipient or purpose requiring additional notice and affirmative consent must be addressed before that processing starts.
5. Your requests and rights
Email [email protected] and identify the request, the account contact information necessary to find the records, and the relevant content where you are requesting a particular item. Do not send a password or recovery phrase. An existing authenticated account or another proportionate method may be used to verify authority; creating a new account is not required solely to exercise a right.
Covered rights include confirmation of relevant collection, sharing or sale; access or recipient information as the applicable law provides; withdrawal or cessation of covered processing; and deletion. Washington requests can include the list of third parties and affiliates with whom your consumer health data was shared and an active contact mechanism for those recipients. You may review and correct supported entries within the application and ask us to correct other inaccurate information we hold.
We authenticate promptly and request only information reasonably necessary to protect against disclosure to the wrong person. We ordinarily provide responses free of charge; any exception for a manifestly unfounded, excessive or repetitive request must satisfy the applicable law and be explained. We do not discriminate unlawfully for exercising rights.
For Washington, we respond without undue delay and within 45 days of receiving the request, including prompt authentication within that period. A single additional 45 days is used only where permitted and with timely notice and reasons.
For Nevada, the ordinary response deadline is 45 days after authentication, subject to the permitted extension and notice. Deletion has its own shorter rule: we delete covered information from our active records and notify downstream recipients within 30 days after authentication, except where a specific lawful exception applies. A notified recipient's corresponding deletion duty is governed by the statute; an ordinary response extension does not automatically extend the deletion deadline.
Where more than one applicable law protects the same request, we apply the requirements that govern it rather than use a less protective period to avoid another duty.
6. Retention, deletion and downstream recipients
Private records, including retained Garmin imports, are normally held while you keep them in an active account, subject to the general Privacy Policy and any earlier removal required by law or applicable provider terms. Temporary automatic Garmin import bodies are limited to the transfer window in section 1.12 of the main Policy, rather than retained as a second permanent activity archive. Watch transfer queues, local Apple Health reconciliation files and independent Apple Health or Garmin records have the separate handling described there. A valid deletion request covers information we control across the relevant storage and records, not only the sign-in account. We notify the processors, affiliates and other recipients as the law requires and take the steps required to give effect to the request.
Core database recovery copies are encrypted at rest and access-restricted, with 28-day weekly-backup and 7-day point-in-time recovery schedules. These do not describe every service provider. Temporary retention in a backup must satisfy the law; a statute's outer limit is not a reason to extend our shorter routine schedule. Deleted information must not be returned to ordinary use after a recovery operation.
Google separately publishes a 55-day abuse-monitoring period for Gemini prompts, context and outputs, including possible authorised review of flagged material. That disclosure is not a claim that a provider policy overrides your statutory deletion rights. Where a request requires earlier removal or a different processing arrangement, we must satisfy the applicable requirement or not use that arrangement for the covered data. We do not claim an approved zero-retention configuration unless it has actually been approved and applied.
Other service-provider deletion cycles, including Firebase Authentication and installation identifiers, are described in section 8 of the main Privacy Policy. A provider's routine maximum does not displace a shorter applicable legal deadline or remove our obligation to initiate and follow up required downstream deletion.
Limited retention for a binding legal obligation is permitted only to the extent the relevant law allows. We explain a refusal or limitation where required. We cannot guarantee recall of copies a person independently made from a share, but this does not remove downstream notification or other legal duties concerning a valid deletion request.
7. Appeals and complaints
To appeal a refusal, reply to the decision or email [email protected], identifying the original request and the reason you disagree. The route is the same as for the original request and does not require a paid subscription. We communicate the action or decision, with reasons, within 45 days after receiving an appeal where Washington or Nevada law sets that period.
If the appeal is denied, we provide the applicable attorney general's complaint contact. You may also contact the Washington State Attorney General through atg.wa.gov or the Nevada Attorney General through ag.nv.gov, as appropriate. A complaint or appeal does not waive another right or remedy.
8. Changes and contact
We give appropriate prominent notice of material changes before they affect the relevant processing and obtain fresh affirmative consent where required. An updated notice cannot retroactively authorise a previously undisclosed purpose or disclosure. The version and last-revised date identify this text; any separate date for changed processing is stated in the relevant notice.
For questions, consent withdrawal, access, correction, deletion or an appeal: [email protected], or write to NutriMotion LTD, Clyde Offices, 2nd Floor, 48 West George Street, Glasgow, Scotland, G2 1BP, United Kingdom.
A consent withdrawal, rights request or complaint to an authority is not conditional on agreeing to arbitration. Any civil dispute provision in the Terms of Service applies only within its valid scope and does not waive the protections in this Notice.