PRIVACY POLICY

NutriMotion LTD · Version 2026-09-12
Publication date: 12 September 2026 · Last updated: 12 September 2026

For additional information about consumer health data and rights that may apply in certain jurisdictions, see our Consumer Health Data Privacy Notice.

This Privacy Policy is published and takes effect on 12 September 2026. It describes the features below, including the optional Garmin connection when that feature becomes available and you enable it. Publication does not activate an integration, grant a permission or retrospectively authorise previously undisclosed processing. Section 15 explains material changes and new permissions.

This Privacy Policy explains how NutriMotion LTD, a company registered in Scotland under company number SC838276, collects, uses, stores, discloses and otherwise processes personal information in connection with the NutriMotion mobile application, its Apple Watch (watchOS) and Wear OS companion applications, optional connected fitness services including Garmin Connect, and our website, related services, beta testing, communications and support channels that link to this Policy, together the Services.

NutriMotion LTD is the controller of the personal information described here. Our registered office is Clyde Offices, 2nd Floor, 48 West George Street, Glasgow, Scotland, G2 1BP, United Kingdom. Our privacy contact is [email protected].

Scottish establishment and UK data-protection framework. NutriMotion LTD operates from Scotland, United Kingdom. Personal-information processing in the context of that establishment is subject to the UK General Data Protection Regulation and Data Protection Act 2018, as amended, and the Privacy and Electronic Communications Regulations 2003 where applicable. Our account and service contract selects Scots law, as set out in section 19 of our Terms of Service.

The regional provisions below describe additional statutory protections only where the relevant law applies. They do not choose a foreign law as the general governing law of our service contract, constitute an additional contractual submission to foreign courts, or expand the territorial scope of a statute. Equally, they do not restrict any jurisdiction, regulatory power or right that exists independently under applicable law. The dispute provisions of our Terms do not make a privacy request, consent withdrawal or regulatory complaint conditional on arbitration.

This Policy is a notice about our processing, not a request for blanket consent. Accepting our Terms of Service or acknowledging this Policy does not, by itself, authorise every use of health information, every location request, cloud AI processing, advertising or an international transfer. Where consent is required, it must be obtained separately for the relevant processing.

Summary of key points

We process account information and the fitness, nutrition, location and other information needed for the features you use. Health information, progress photographs and detailed activity routes can be particularly sensitive. Features and permissions are optional except where the information is necessary to provide the particular service you request.

Progress-photo image files are encrypted on the device before upload to Cloudflare R2. Associated metadata is stored separately. Private saved-route details also use client-side encryption, but some route metadata remains readable to our systems. Publicly shared routes do not retain the confidentiality of private routes.

Food Scan is different from on-device barcode and label scanning: it sends the selected food image, any accompanying description and relevant food-identification information to Google Gemini through Firebase AI Logic. Analysis can include a follow-up text request using food observations and candidate nutrition records. Google must be able to read the inputs it analyses. Section 6 explains the information involved and provider handling.

Our Apple Watch and Wear OS companions exchange the workout, route-guidance and daily-summary information needed for their functions. The optional Garmin connection, when available and authorised, sends selected routes or courses to Garmin Connect and imports authorised recorded activities into NutriMotion. It does not automatically publish your activities or share your progress photographs. See sections 1.3 and 1.12.

We do not sell personal information or use health information for targeted advertising. You can request access, correction, deletion or withdrawal of consent through [email protected]. Applicable regional rights are explained below. Our separate Consumer Health Data Privacy Notice explains additional protections for covered US consumer health data.

Contents

Feature details: Apple Watch, Wear OS and health platforms · Garmin connection · Progress photographs · Food Scan.

  1. What information do we collect?
  2. How do we process your information?
  3. What legal bases do we rely on?
  4. When, with whom and where do we share information?
  5. Cookies, SDKs and similar technologies
  6. Artificial intelligence and food-photo estimation
  7. Third-party sign-in
  8. Retention and deletion
  9. Security and encryption
  10. Your privacy rights
  11. Privacy signals and tracking choices
  12. Supplement for United States users
  13. Additional regional provisions
  14. Public datasets and licensing
  15. Changes to this Policy
  16. Contact and responsibility for privacy
  17. Reviewing, updating, exporting and deleting your information

1. What information do we collect?

1.1 Account, authentication and contact information

We process your account identifier, email address, display name or username, authentication-provider identifiers, account settings, acceptance records and communications with us. Where you use an available telephone-verification feature, this includes your telephone number and verification information. Email/password authentication involves processing your credentials through Firebase Authentication; we do not receive the password for your separate Apple or Google account.

Support enquiries may contain contact information, correspondence, diagnostic information and attachments you choose to send. Do not include passwords, recovery phrases or unnecessary health information in a support message. Information such as an IP address or an installation identifier can be personal information even without your name.

1.2 Nutrition, fitness, health and personalisation information

Depending on your use, we process date of birth or age, biological sex, height, weight and other body measurements; activity levels; weight and nutrition goals; food and drink entries, serving quantities, calories, macronutrients, recipes and meal plans; exercise selections, sets, repetitions, loads, workout history and training plans; injury or discomfort information, body areas, perceived effort and coaching feedback that you choose to enter; steps and activity totals; and the calculations, progress summaries and recommendations generated from that information.

Information you enter in a note, description or other free-text field may reveal additional health or other sensitive information. Provide only what is relevant to the feature. We do not require information about racial or ethnic origin, religion, political views or sexual orientation to operate ordinary fitness and nutrition tracking.

Health and fitness information can be special-category data under UK and European law and consumer health data or sensitive personal information elsewhere. Precise location is sensitive under some laws even where it is not, by itself, special-category data under UK GDPR.

1.3 Health Connect, Apple Health, Apple Watch and Wear OS

Health-platform access. When you authorise the relevant integration, we obtain the health-data categories covered by your permissions and supported by the feature. These include steps, body weight, sleep sessions and stages, heart rate, resting heart rate and heart-rate variability. They support activity and calorie calculations, progress tracking, recovery estimates and training recommendations. Read and write permissions are separate; authorising one category is not permission to access every record in your health account.

Imported steps and weight can be stored with your NutriMotion account. For the workout-coach recovery function, raw sleep-stage and sleep-session readings, resting-heart-rate readings and heart-rate-variability readings are read and processed on your device; that function does not upload those raw readings to our cloud databases. Your decision to use or ignore an unusual sleep reading, session context and coaching feedback can be retained locally. Workout entries, plans and other results you save can persist with the corresponding records. Heart-rate measurements collected as part of a separately recorded workout can be synchronised with that workout. The available information depends on your device, operating system and permissions.

Apple Watch and Wear OS companions. Our companion applications support the relevant watch workout recording, controls, weight-training entries, rest timers, daily fitness and nutrition summaries, and route guidance. They exchange information needed for those functions with your paired phone using the applicable platform connection. This can include account association, workout identifiers and state, exercise and routine details, sets, repetitions and loads, timer values, calorie and macronutrient summaries and goals, route geometry, guidance and fitness-estimation parameters. Not every field is transferred for every function.

For a supported workout you start on the watch, the watch can record locally even when the phone is not nearby. With the relevant permissions, this includes time-stamped GPS positions, activity type, start and end times, pauses, distance, pace or speed, elevation, heart-rate information, steps, cadence where available and estimated energy expenditure. Active workout recording can continue while the watch display is inactive. Phone-started sessions can instead be mirrored and controlled from the watch. Cloud synchronisation depends on connectivity and on the phone or other relevant service being available; local recording is not proof of a completed cloud save.

Completed workouts are held in the watch's pending-transfer storage until the paired phone confirms that the workout has been saved, after which the pending-transfer record is removed. Failed transfers or cleanup can delay removal. A connection acknowledgement alone is not a saved-workout confirmation. Separate daily-summary caches, active-session snapshots, maps, widgets and complications are not all deleted by that one operation. They can display information outside the main application, including on the watch face, according to your settings.

Apple Health records. For a watch-local Apple Watch workout, the application uses HealthKit to record the workout and, where authorised and supported, its associated activity measurements and route in Apple Health. NutriMotion also synchronises its own workout record with the paired iPhone and account. The Apple Health record is separate from the NutriMotion record. Removing a NutriMotion account, workout or pending-transfer item does not itself guarantee deletion of the Apple Health record. Use Apple Health's controls for that copy. Local HealthKit export or reconciliation records may remain on the watch separately from the pending-transfer queue, including after a phone import, until cleared or the application data is removed.

Permissions and restricted uses. You can manage health, location and sensor permissions in the relevant phone, watch and health-platform settings. Revocation stops future access covered by the permission, but does not itself delete previously imported records or information held independently by the platform. Contact us to delete information we control. We use connected-health and watch information for the requested health and fitness functions, not advertising, data brokerage or general-purpose AI-model training. We do not automatically send this history to Food Scan or export it to Garmin merely because an account is linked. Our use of information obtained from Google APIs is subject to the Google API Services User Data Policy and applicable Limited Use requirements.

1.4 Location, recorded workouts and route planning

Location processing is not limited to a recorded workout. With the relevant permissions, we use a current, last-known or selected location to display your position, find nearby routes, prepare nearby map and routing data, plan or follow a route and search for places. Automatic route-map preparation can run while the application is open, including while you use another screen, according to your preparation settings and device permissions. Preparing nearby routes is not itself a recording of a completed workout.

During a workout or navigation session you initiate, we process time-stamped GPS positions and related measurements to calculate routes, distance, pace, speed, elevation and other activity statistics. Active tracking may continue while the screen is off or the application is not in the foreground, using the relevant platform permissions and service notifications. You can pause or stop an active session.

Route-related information includes starting locations, route geometry, waypoints, route names, activity type, distance and duration estimates, route preferences, saved or downloaded routes, sharing choices and cache information. Map and routing caches may reveal an area you have viewed or used, even when a route has not been recorded as a workout.

Place search sends the search text, language and a search area based on the selected origin to our geocoding service. Map and route-data requests identify the geographic tiles or areas requested. A search area, route name or combination of requests may reveal a location; removing a name or using a regional identifier does not necessarily anonymise it.

1.5 Progress photographs

When you add a progress photograph, we process the selected image to create an application-appropriate version and support display, comparison, storage, synchronisation and user-directed export. The image payload is encrypted on your device before cloud upload to Cloudflare R2, accessed through our authenticated services and signed object URLs. Our progress-photo bucket has the Western Europe (WEUR) location setting. This is not a representation that the bucket has Cloudflare's separate EU jurisdictional restriction or that all associated processing is confined to the EU; see section 4.4.

We store associated information separately in Cloud Firestore, including the photo identifier, account association, date, storage and processing information and usage metadata. Metadata does not necessarily receive the same client-side encryption as the image. Encryption does not make the account association or metadata anonymous.

Progress photographs are private account content, not public posts merely because you upload them. They are not automatically sent to Gemini, used to train general-purpose AI models or licensed for advertising. An image can reveal health information or identify you through your face, tattoos, surroundings or other details. We do not use this feature for facial identification or creation of biometric identification templates.

When you view or export a photograph, it must be decrypted on an authorised device. Copies saved to your gallery, downloaded, included in comparison images or shared with another application are outside the original encrypted cloud object and are subject to the destination's controls. Deleting an application copy does not delete the original image in your device's photo library or copies you have independently shared.

1.6 Food photographs, barcode scanning and label scanning

Food Scan processes a selected or captured food photograph, an optional description, detected product barcodes, relevant product and nutrition matches, AI observations and responses, and the nutrition values you decide to log. Food names or search terms inferred from the photograph can be used for product-database lookups. The application prepares a compressed image and removes EXIF metadata from the image prepared for the AI request. Visible identifying details within the image are not removed by stripping EXIF.

Barcode recognition and nutrition-label optical character recognition use on-device processing. A subsequent product lookup, saved food entry or database submission is a separate network or storage operation; on-device recognition does not mean all subsequent use of the result remains on your device. Section 6 explains the distinct cloud Food Scan processing.

1.7 Social, group and sharing information

Where you use these features, we process profile information, friend and group relationships, messages, shared lists, contributions and the workouts, recipes, routes or other content you choose to share. The audience depends on the particular feature and sharing action, not on a single privacy setting for the whole application. In particular, a setting for exercise-proficiency visibility does not, by itself, make a separately published route private.

Other people may provide information about you in an invitation, message, shared item or report. We use that information to operate the interaction, handle the report and protect users. Contact us about an unwanted disclosure. Do not upload another person's private information without a lawful basis and the rights or permissions required for the intended use.

1.8 Purchases and subscriptions

Apple App Store or Google Play processes the purchase. We use RevenueCat for purchase verification, subscription status and entitlements. The information involved may include account or app-user identifiers, receipt or transaction identifiers, purchase tokens, product and plan identifiers, purchase and renewal dates, cancellation or refund events, and storefront, currency or country information. We do not receive or store your full payment-card number or card security code.

1.9 Technical information and permissions

Our application and service providers process device and operating-system information, application version, installation or service identifiers, IP address, timestamps, request and error information, feature interactions, crash reports and performance information. The amount and purpose depend on the SDK and your applicable choices. AI feature events can include the model, success or failure, latency and meal category; a meal-related event can itself be sensitive when associated with a person.

Camera, photo-selection, location, health, activity/sensor, storage or notification permissions are requested for their relevant functions. A camera permission allows camera access; it is not consent to disclose images to an AI provider. Ordinary food-photo capture does not require microphone recording. Notifications, widgets, device sharing and watch synchronisation can display information outside the main application, including on a lock screen.

1.10 Children and age eligibility

The general Services are not intended for children under 13. Where a higher minimum age or parental authorisation is required, that requirement applies. For users below the age of majority, the Terms of Service require involvement of a parent or guardian. Cloud Food Scan is restricted to adults and may be unavailable where we cannot lawfully and contractually provide it; parental permission does not override an AI provider's restrictions.

We must obtain any required, appropriately verified parental authorisation before processing a child's information in reliance on it. An age declaration or a parent's acceptance of general terms does not replace a legally required consent or safety process. Contact us if you believe a child has provided information without the necessary authorisation. We will assess the report, restrict processing where appropriate and delete information when required. Young users retain applicable privacy rights and can contact us directly for help.

1.11 Beta testing, communications and optional activities

If you participate in an offered beta programme, including Apple TestFlight or Google Play testing, we may receive your tester contact or identifier, build and device details, testing activity, crash information and feedback or screenshots you submit. Test builds may be less reliable than general releases; do not send unnecessary personal information in a bug report.

When you ask for product news or take part in a survey, event, competition or promotion that we actually offer, we process the contact details, responses and participation information necessary for that activity. We provide any additional purpose, organiser, eligibility, publication and retention information when inviting participation. Entering does not authorise unrelated health-data processing or marketing. Required consent is separate, and marketing messages include a means of stopping them. Necessary security, transaction and service notices are not marketing subscriptions.

This Policy describes processing for which NutriMotion is the controller. If a separate, expressly agreed business service makes NutriMotion a processor acting on a business customer's instructions, that arrangement and the customer's notice identify its processing separately. Our responsibilities as controller for individual app users are not transferred to a business customer by that separate arrangement.

1.12 Optional Garmin connection and activity-file transfers

Availability and choice. We are developing an optional connection with Garmin Connect through Garmin's official developer APIs. The processing in this section applies only when the relevant capability is available and you choose to authorise it. This notice does not represent that automatic Garmin syncing is already active for every user, that Garmin has approved an unreleased capability, or that publishing this notice connects an account. Course export and activity import are separate capabilities.

Linking accounts. You sign in and authorise access through Garmin's official authorisation process. NutriMotion does not ask you to give us your Garmin password. The connection uses your NutriMotion account identifier, the Garmin user or connection identifier supplied for the integration, authorisation codes and access or refresh tokens where issued, granted permissions, connection state, and relevant expiry and synchronisation information. Our integration service processes the credentials needed to perform the authorised exchange. They are not public profile information and are not shared with other users. Linking is separate from signing in to NutriMotion.

Routes sent to Garmin. When you choose to send a route or course, we disclose the information required to create it in your Garmin Connect account. This can include the route name and identifier, activity type, ordered coordinates, starting and finishing locations, waypoints or course points, distance, elevation and other supported course instructions. Garmin Connect handles subsequent delivery to your compatible Garmin device under Garmin's settings and services. A successful request from NutriMotion is not a guarantee that a device has downloaded the course. The export does not send your private food diary, progress photographs or unrelated health-platform history.

Activities received from Garmin. With the activity access you authorise, Garmin can supply recorded exercise information through activity files, API responses and transfer notifications. Relevant fields include activity and source identifiers, recording device information, activity name and type, dates and times, elapsed or moving duration, recorded GPS track and elevation, distance, pace or speed, estimated calories, and heart rate, cadence, laps or other recorded activity measurements where provided and supported. We use these to import the workout, display its route and statistics, calculate the fitness summaries you request, retain source attribution, resolve duplicates and maintain synchronisation. Historical imports occur only within the authorised functionality and permissions. The connection described here is not permission to import every category of all-day health information in your Garmin account.

Transfer processing and account storage. The connection communicates through NutriMotion-operated integration services and the infrastructure described in section 4. An authorised activity can reach an integration service after your Garmin device syncs with Garmin Connect, including when the NutriMotion app is closed. Final processing, encryption and saving to your NutriMotion account may wait until your phone is available. Incoming and outgoing information must be readable by the services performing the exchange. Temporary server-side encryption is distinct from encryption using a user-held device key; we do not describe the entire Garmin exchange as end-to-end encrypted against Garmin or our integration service.

Once imported, the workout is held as part of your NutriMotion account using the same account-storage, access-control and applicable sensitive-route encryption arrangements as other recorded workouts. Account, source and synchronisation metadata may be stored separately from encrypted route details. This is not a claim that all imported values or every metadata field use the progress-photo encryption scheme. Temporary import bodies are retained for the transfer and removed following acknowledged processing, disconnection or expiry of the transfer window; the proposed automatic-import service uses a maximum 24-hour transfer window. The durable workout you elect to keep is a separate record governed by section 8.

Unlinking, deletion and Garmin's own processing. You can revoke NutriMotion's authorisation through Garmin's connected-app controls and use an available NutriMotion disconnect control, or contact [email protected]. On disconnection, we stop future authorised exchanges for that connection and remove or invalidate stored connection credentials and pending transfer bodies. A request already completed before revocation may have delivered a record. Disconnection and deletion of saved records are separate unless the applicable law or provider terms require earlier removal; request deletion of imported NutriMotion records as well when that is your intention. We comply with applicable downstream deletion requirements.

Garmin independently operates your Garmin account and the records held there. Deleting a NutriMotion record does not, by itself, erase a Garmin activity or exported course; manage those copies through Garmin. Likewise, removing a Garmin record does not guarantee deletion of every separately imported NutriMotion copy. Garmin's privacy and sharing settings apply to records within Garmin Connect. Review a course's starting point and geometry before export because they may reveal your home or routine. Our handling does not make imported activities public without a separate sharing instruction, and sharing remains subject to applicable provider restrictions. We do not send Garmin activity data to Google Gemini or use it for general-purpose AI-model training.

Garmin explains its own handling, transfers and rights in the Garmin Connect Privacy Policy. We remain responsible for our processing and the transfers we make; directing you to Garmin's policy does not transfer that responsibility.

Manual files. Importing or exporting a supported activity or route file is separate from automatic account linking. We process the file and its included route, timestamps, activity measurements and source metadata to perform the import or export you request. Selecting a file does not give us access to your entire Garmin account. A file you save or send elsewhere is a separate copy, subject to that destination's controls. Only the formats and capabilities actually offered in your version are supported.

2. How do we process your information?

We use information for the following defined purposes:

PurposePrincipal information involved
Create, authenticate and administer accounts; record legal choicesAccount, authentication, settings and consent records
Provide nutrition and fitness logging, calculations, progress tracking and recommendationsProfile, nutrition, fitness and authorised health information and derived estimates
Connect Apple Watch or Wear OS and synchronise supported companion functionsAccount association, workout records and sensor data, daily summaries, guidance, timer and synchronisation information
Link Garmin when available, export selected courses and import authorised activitiesConnection identifiers and credentials, permissions, course geometry, activity files and measurements, source and transfer records
Store, synchronise, compare and export private progress photographsSelected photographs, encrypted payloads, metadata and encryption-related records
Estimate the contents and nutrition of a food photograph you submitPrepared image, optional description, detected barcodes, matched product and nutrition records, AI observations and responses, and request metadata
Display maps, prepare or generate routes, search places, navigate and record workoutsLocation, search information, route preferences and geometry, activity records and relevant technical data
Operate friends, groups, shared lists and user-directed publicationRelationships, contributions, sharing instructions, audience and moderation information
Verify purchases and supply subscription accessPurchase records, subscription status and account identifiers
Answer support and privacy requests and send necessary service communicationsContact details, correspondence and information needed to resolve the request
Operate a beta test or optional survey, event or promotion you join; send product news you requestTester information, contact details, responses and participation records appropriate to that activity; not unrelated private health records
Secure the Services, prevent misuse, diagnose faults and enforce proportionate access controlsAuthentication, integrity checks, request records and relevant incident evidence
Measure service use and improve reliability and usabilityAppropriate technical and usage information, subject to the consent or other conditions described below
Meet legal obligations and establish, exercise or defend legal claimsOnly records reasonably necessary for the particular obligation or claim

Personalisation uses information such as your goals, logged activity and authorised health readings to calculate estimates and recommendations. These results are not medical determinations. Food Scan and other ordinary recommendations are not intended to make decisions with legal or similarly significant effects about employment, insurance, credit or eligibility for healthcare.

We do not use private health records, precise routes or progress photographs for unrelated advertising, data brokerage or general-purpose model training. A materially different use requires advance information and a valid legal basis, including fresh consent where required. A new feature is not permission to repurpose existing private data silently.

3.1 UK and EEA

For processing subject to UK GDPR or EU GDPR, the principal Article 6 grounds are:

ProcessingArticle 6 basis
Account administration, subscriptions and non-sensitive information objectively necessary to supply the service you requestPerformance of a contract, Article 6(1)(b)
Optional health, photo, precise-location and personalised features where we rely on your permissionConsent, Article 6(1)(a)
Optional cloud Food Scan and the associated disclosure requiring your permissionConsent, Article 6(1)(a)
Optional Garmin activity imports, selected course exports, and authorised health-platform or watch-data exchangesConsent, Article 6(1)(a), with explicit consent under Article 9(2)(a) where the information reveals health; necessary technical account-link administration may instead rely on contract under Article 6(1)(b), without authorising further health access after withdrawal
Optional analytics, storage/access technologies or marketing communications requiring consentConsent, Article 6(1)(a)
Administration of a beta programme, event or promotion you requestContract where necessary for agreed participation; otherwise legitimate interests in administering that interaction, with separate consent where required
Proportionate security, fraud prevention, essential fault diagnosis, service administration, ordinary enquiries and narrowly scoped service statistics where lawful without consent, where not covered by contractLegitimate interests, Article 6(1)(f), following consideration of your interests and rights
Tax, accounting, legally required records and compliance with a binding legal dutyLegal obligation, Article 6(1)(c)
Necessary legal-claim handling where no binding duty supplies the basisLegitimate interests, Article 6(1)(f)

Our legitimate interests are protecting users and the Services, maintaining reliable operations, answering communications and protecting legal rights. We do not rely on that basis where your interests or fundamental rights override those interests. A legitimate interest does not displace a separate consent requirement for device tracking or sensitive information.

Where information reveals health or another special category, an Article 6 basis alone is insufficient. For the ordinary health, recovery, progress-photo, connected-watch, Garmin activity and related personalised functions involving special-category information, we rely additionally on explicit consent under Article 9(2)(a). Where strictly necessary for legal claims, Article 9(2)(f) may apply. We do not treat general use of a fitness application as consent to all special-category processing, and we do not rely on a healthcare-provider exemption simply because the application concerns fitness.

Public disclosure of health or location information is a separate choice from private storage. We obtain any required consent to the intended audience and purpose before making the disclosure. We do not treat material made public by another person as your consent.

3.2 Your choices and consequences

You can refuse optional processing and withdraw consent for future processing. Withdrawal does not invalidate processing lawfully carried out before withdrawal. We will not switch to a different basis merely to continue the same processing after withdrawal. A genuinely separate legal obligation or necessary legal-claim purpose may still justify limited retention, which we will explain where applicable.

We cannot supply a feature without the information essential to that feature. For example, declining cloud AI processing prevents Food Scan analysis but does not prevent manual food entry; refusing location access prevents locating you by GPS but does not authorise unrelated collection. Contact us where an in-app control does not support the choice you wish to make. Information and consent choices must be understandable and separate from a requirement to accept these general documents.

3.3 Other jurisdictions

We apply the consent, necessity and other permitted grounds required by the law governing the processing. Canadian express-consent requirements for sensitive information, applicable US consumer-health collection and sharing rules, and Brazil's specific rules for sensitive data are not replaced by the UK contractual or legitimate-interest grounds above.

4. When, with whom and where do we share information?

4.1 Service providers and other recipients

We disclose only information appropriate to the purpose and recipient. The principal recipients are:

RecipientFunction and information involved
Google / Firebase / Google CloudAuthentication, databases, storage, cloud functions, configuration, application integrity and operational services. They process relevant account, application, health, route, imported-workout and metadata records; encrypted payloads remain encrypted where client-side encryption applies.
Cloudflare, including R2Object storage and associated delivery/security for encrypted progress-photo files and related storage/request metadata.
Google Gemini through Firebase AI LogicThe food image, optional description, detected-barcode and candidate food/nutrition information, AI observations, responses and technical request information described in section 6. This is separate from on-device ML Kit recognition.
Garmin, operating Garmin Connect and the authorised APIsWhen you enable the available connection: authorisation and connection information, the courses you export, authorised activity records imported from Garmin, and information necessary to administer, revoke or troubleshoot that exchange. Garmin operates its own account service under its privacy policy.
Apple Health / HealthKit and Health ConnectHealth and workout information exchanged with your device health platform under the particular permissions described in section 1.3, including authorised Apple Watch workout and route recording in Apple Health.
Food-database services, including Open Food Facts and our cloud food-search servicesProduct barcodes and food-search terms, including terms derived from a Food Scan, with technical request information needed to return matching food and nutrition records. Food-database lookup does not itself transmit the original photograph to those database services.
Google Analytics for Firebase, Firebase Crashlytics and Firebase Performance MonitoringUsage, diagnostics and performance information to the extent enabled and lawfully collected. We do not authorise these tools to receive private image payloads or complete health diaries for advertising.
RevenueCat, Apple and Google PlayPurchase verification, subscription entitlements and payment administration. They receive the purchase/account information relevant to those tasks, not a copy of your private photo library or health diary simply because you subscribe.
Apple App Store Connect / TestFlight and Google Play Console / testing servicesApp distribution, testing invitations and participation, build/device information, permitted store analytics, crash information and feedback submitted through those channels.
OpenFreeMap and the infrastructure serving its map resourcesMap-style, tile and related resource requests. Direct requests expose network information and the requested map area to the serving infrastructure.
Our geocoding and routing-data service operatorsPlace-search text, language, search area and geographic data requests necessary to return places, maps and route-network data. These may be relayed through our Google Cloud functions.
Recipients selected by youFriends, group members, shared-list participants, route-link recipients, public-route users and external sharing destinations, according to your particular action.
Professional advisers and legally authorised recipientsLimited information necessary for legal, accounting, security-incident, regulatory or dispute purposes, subject to applicable duties and safeguards.

Processors act on our documented instructions under the applicable processing arrangements and may use authorised subprocessors. Not every recipient acts only as our processor: app stores, sign-in providers and some provider security or service-administration activities involve independent decisions and are governed by the relevant provider's own notice and law. Naming a provider does not authorise it to use any of our users' information for any purpose it chooses.

We do not buy personal information from data brokers. We do not sell personal information or share it for cross-context behavioural advertising. We do not disclose consumer health information to insurers, employers or advertising networks for their independent eligibility or marketing decisions.

Private saved-route detail payloads are encrypted before cloud storage. Route names, search tokens, an area identifier, activity, distance, estimated duration, timestamps and sharing state can remain outside that encrypted payload. Do not assume private storage conceals all location-related metadata from our systems.

Publishing a route creates a separate shared copy containing its route geometry, start location, waypoints, name and other route attributes. A route published to map discovery can be found by other users. A link-only route is not listed for map discovery in the same way, but possession or forwarding of its link can allow access; it is not equivalent to an encrypted private route or individually authenticated recipient list.

Review the full route before sharing. It may reveal a home, workplace, routine or other sensitive place even without your name. We keep uploader/account association information where needed to administer the shared record. Deleting the private saved route is distinct from removing its shared copy: use the unshare/delete-public control or contact us. Removal from our live service cannot recall screenshots or independent copies already taken by recipients, but we will take the further steps required by applicable law.

We may disclose necessary information to comply with a valid legal obligation, protect rights or address a substantiated security or safety incident where permitted by law. We assess the request, scope and lawful basis; a request alone does not justify disclosure of all information we hold.

In a merger, restructuring or transfer of the Services, relevant information may pass to advisers or a successor under appropriate confidentiality and data-protection arrangements. A business transfer does not itself permit a materially different use of sensitive information or remove consent and notice requirements.

4.4 International processing and principal locations

NutriMotion operates from Scotland, United Kingdom. Processing takes place in the United Kingdom and through the providers below. A provider's corporate address, a cloud function's execution region and the storage location of a different service are not necessarily the same place.

ServiceLocation information and scope
NutriMotion administration, support and account operationsUnited Kingdom. Authorised support and administration can involve access to information held by our processors.
Google Cloud Functions used for photo operations, geocoding and related application requestsFrankfurt, Germany, europe-west3, for the regional functions described in this Policy. This does not impose the same region on their upstream services, all logs or provider support operations.
Firebase AuthenticationUnited States, under Google's published service-location information.
Cloud Firestore and other Firebase infrastructure, configuration, integrity, crash and performance servicesThe applicable database or service configuration and Google's service-specific location commitments apply. Global Firebase services can involve the United States and other countries where Google or its agents maintain facilities. We do not represent that the Frankfurt function setting guarantees Germany-only storage for every Firebase service.
Cloudflare R2 progress-photo bucketWestern Europe (WEUR) is the bucket's location setting. It is a geographical designation, not the separate EU jurisdictional restriction. Cloudflare is a US-headquartered provider and its associated operational, security, support and subprocessor processing can involve the United States and other countries.
Google Gemini Developer API through Firebase AI LogicGoogle's provider arrangements allow request data to be processed, transiently stored or cached in countries where Google or its agents maintain facilities, including the United States. No Germany-only or EU-only AI processing commitment is made here.
RevenueCatA United States service provider using its contracted infrastructure and subprocessors for subscription administration. The locations and permitted transfers are governed by its applicable data-processing arrangements.
Apple, Google Play, sign-in providers and testing servicesInternational provider operations, including the United States and the relevant local store/provider entity. Their independent account, transaction and testing processing is described in their own notices. Apple Health records are managed through Apple's health-data controls, separately from NutriMotion's Firebase account records.
Garmin Connect and optional integration processingGarmin's international account and service infrastructure handles the records disclosed to Garmin; its Garmin Connect Privacy Policy explains its arrangements. Our integration and account-processing infrastructure handles authorised transfers and imported records as described in this Policy. The R2 WEUR location setting and Frankfurt cloud-function region are not a representation that Garmin or every integration-server operation is hosted in those locations.
Food-database requests, including Open Food FactsRequests may be handled by the database operator and its hosting infrastructure outside your country. The request identifies a barcode or search term and associated network information, not an automatic copy of your private diary.
Map, routing-data and geocoding deliveryResource requests may be served through international infrastructure. Geocoding requests pass through our regional Google Cloud function; that region does not establish the country of every upstream operator. Search areas and geographic resource identifiers are information disclosed for those requests.

Cloudflare distinguishes a location setting or hint from a jurisdictional storage guarantee. We therefore do not promise EU-only residence on the basis of WEUR alone. Image payload encryption continues to apply independently of the storage location. Metadata, access records and provider service data are not necessarily protected by that same client-side encryption.

Transfer safeguards. For transfers covered by UK or EEA restrictions, we rely on an applicable adequacy decision or regulation where it covers the destination and recipient. Otherwise, the applicable processor arrangements use recognised contractual safeguards, such as the European Commission's standard contractual clauses together with the UK Addendum or another valid UK transfer instrument where needed, and relevant supplementary safeguards. We assess the protection required for the particular transfer. A provider's participation in a data-protection framework is relied on only for processing covered by a valid certification and applicable adequacy arrangement.

Google's Firebase and cloud processing terms, its processor addendum for paid Gemini content, Cloudflare's customer data-processing addendum and RevenueCat's data-processing addendum describe their respective contractual arrangements. Some provider account, security and service-administration data is processed under independent-controller arrangements rather than solely on our instructions. None of these arrangements authorises a provider to use private information for unrelated purposes at will.

Current provider information is available through Firebase privacy and security information, Google Cloud subprocessors, Gemini API terms, Cloudflare's data-processing addendum, Cloudflare R2 location documentation and RevenueCat's data-processing addendum. These links supply supporting provider information; they do not replace our responsibility to explain our processing or obtain required consent.

Contact [email protected] for the recipient and destination information relevant to your data and a copy or description of the applicable transfer safeguards, with necessary security or commercial redactions. Where local law requires more specific country, recipient or transfer information before processing or consent, we provide that information for the relevant feature before relying on that arrangement. Continued use of the app is not blanket consent to international transfers.

5. Cookies, SDKs and similar technologies

The Services use local storage, caches, SDKs and similar technologies for authentication, settings, offline functionality, security, synchronisation, diagnostics and, where enabled, usage measurement. Some operations are strictly necessary for a function you request; others are optional.

We obtain consent before using non-essential storage or access technologies where required. Where a specific legal exception permits narrowly defined statistical processing without consent, we use it only if all its conditions are met, including any required information and simple, free means of objection. The presence of an analytics SDK does not establish that an exception applies.

Device and health permissions can be managed through the operating system. They do not necessarily control Firebase Analytics or all website technologies. We will provide the applicable collection choices directly and you can also contact us. Contact [email protected] to exercise an applicable choice that is not available through your current version's controls. The Services do not use third-party advertising or remarketing cookies under the processing described in this Policy.

6. Artificial intelligence and food-photo estimation

6.1 On-device recognition

Google ML Kit performs barcode and nutrition-label recognition on the device. The recognised text or barcode can subsequently be used for a food lookup or saved entry. That processing is different from the optional cloud Food Scan feature.

6.2 Cloud Food Scan

Food Scan uses Google Gemini through Firebase AI Logic with the Gemini Developer API backend. The information sent for analysis can include the prepared food photograph, a description you supply, information obtained from detected product barcodes, matching food or nutrition records, and instructions needed to produce the estimate. We do not automatically attach your progress photographs, GPS history, Garmin activities or connected-health history to these requests.

The analysis can have more than one step. An image request identifies possible food components and quantities. The application can search food databases using those observations and submit a follow-up text request containing the observations, description, barcode evidence and a short list of candidate foods and nutrition values to help select an appropriate match. The follow-up selection step does not require another copy of the image. Resulting database matches and estimated quantities are combined to calculate the proposed diary entry. A recognised label or a database match does not establish that the portion or final estimate is correct.

Google receives readable request content, not an image that remains encrypted solely for you. Protected transmission is distinct from the provider's ability to analyse an input. Cloud analysis requires separate informed permission; camera permission, acknowledging this Policy and accepting general Terms are not substitutes for that permission. Once the feature is authorised, a photo-only mode can submit immediately after capture or selection. Manual Quick Add remains available without sending a food image to an AI provider.

You can review and edit the result before logging it. The application saves the nutrition entry you choose to log; the food photograph is not automatically added to your progress-photo library. A local preview and temporary camera file may be used for the request. The application attempts to remove temporary camera captures after processing; it does not delete your own gallery original. Technical events may record the model, timing, success or failure and meal category as described in section 1.9.

6.3 Provider use, safety review and retention

Under the Gemini API terms applicable to UK customers, Google's paid-service data-use protections apply, including to unpaid quota covered by that UK provision. Under those protections, Google does not use submitted content or responses to improve its products. This describes the provider's content-handling terms; it does not remove its separate billing, age, territory or access requirements.

Google's published abuse-monitoring period is 55 days for prompts, context and outputs. Flagged material may receive authorised human review and may be used for policy-enforcement models; this is different from general-purpose model training. We do not promise zero retention or absence of all human review. The Gemini API terms and abuse-monitoring information explain that processing.

We do not submit private food images, Garmin records or other connected-health information for optional model-tuning, general-purpose model training or dataset-sharing programmes. Provider safety retention is separate from our diary storage and database backups. Any additional purpose requiring a different permission must be disclosed before it is used.

Avoid including faces, identifying documents, other people's private information or unnecessary medical details in a food photograph or description. You can stop future submissions by not using cloud Food Scan and withdraw the relevant permission through an available feature control or [email protected]. Withdrawal does not recall a request that has already been processed; applicable deletion rights and limited lawful retention are addressed in sections 8 and 10.

7. Third-party sign-in

When you choose Sign in with Apple or Google Sign-In, the provider supplies an identifier and the profile details authorised for the sign-in, such as your name and email address. We use these to authenticate and maintain your account. We do not receive the provider account's password or unrestricted access to unrelated information held by that provider.

Disconnecting or changing a sign-in method does not necessarily delete the NutriMotion account. Maintain another working sign-in method before removing the one you use. The provider's own account processing remains subject to its notice.

8. Retention and deletion

We keep information only for as long as reasonably necessary for its stated purpose, taking into account your account and feature choices, applicable law, security needs and outstanding disputes. Different systems have different retention arrangements; there is no single period applying to every provider and data category.

InformationRetention approach
Account, diary, measurements, workout and saved training recordsNormally retained while your account is active and you keep the record; deleted following a valid record or account-deletion request unless a specific lawful exception applies.
Progress photographs and private saved routesRetained for the storage/synchronisation you request until removed or the account is deleted. Deletion must cover both relevant metadata and stored objects, not only the login account.
Shared records and published routesRetained while shared or needed to operate the relevant shared record. A shared copy may require a separate removal action. Legal deletion obligations also apply to information we control in shared records.
Google Food Scan processingLocal working copies are used for the request and preview; the app attempts to remove temporary camera captures after processing. Logged nutrition results remain with the diary. Google's separate abuse-monitoring retention is described in section 6.
Apple Watch and Wear OS pending-workout storageA queued transfer record is removed after the phone's saved-workout confirmation; failed synchronisation or cleanup can delay removal. Separate caches, Apple Health records and local HealthKit export/reconciliation files are not all erased by that operation.
Garmin connection credentials and temporary transfers, when enabledHeld while necessary to maintain the authorised connection or complete a transfer. Disconnection stops future exchanges and removes or invalidates credentials and pending bodies. Temporary import bodies use the transfer window described in section 1.12; limited source identifiers and acknowledgement/deletion records may remain as needed to prevent duplicate or unwanted re-imports and honour your choices.
Workouts imported from Garmin or a supported fileRetained under the same account-record approach as other workouts, unless you request deletion or an applicable provider or legal requirement requires earlier removal. Garmin's independent originals and exported courses follow its own controls and retention.
Device, map, route, nutrition and coaching cachesRetained for the relevant offline, display, local-decision, synchronisation or performance purpose until replaced or cleared, removed using an available control, or removed with application data. Device or operating-system backups may have separate behaviour.
Purchases and financial compliance recordsRetained as needed for subscription administration and applicable accounting, tax, fraud and dispute obligations. App stores and payment providers also apply their own lawful retention.
Support, consent, privacy-request, security and diagnostic recordsRetained for the relevant enquiry, proof of choices, fault investigation, incident or legal obligation, then deleted or minimised. Sensitive content is not retained indefinitely merely because it appeared in a log or support message.

Core database backups. Our core database backup arrangement is weekly backups retained for up to 28 days, together with a 7-day point-in-time recovery window. These periods apply to the relevant database backup systems, not automatically to R2, Google AI, analytics, app-store records or independently saved device copies. The relevant database backups and point-in-time recovery data are encrypted at rest, access-restricted and used for recovery. Provider-managed backup encryption is different from encryption whose keys are held only on an authorised user device. Where deleted information remains temporarily in a backup, it is kept out of ordinary use and expires under the applicable schedule. Following a restoration, deletion instructions must be reapplied so that erased records do not return to ordinary service.

Other provider retention. Google's published Firebase information gives separate periods for particular services: Firebase Authentication logs IP addresses for a few weeks and states that deletion of other authentication data from live and backup systems can take up to 180 days after deletion is initiated; Firebase Crashlytics generally retains crash traces and associated identifiers for 90 days before starting removal; and Firebase Remote Config states that installation-ID deletion from live and backup systems can take up to 180 days after the relevant deletion call. These periods are not an entitlement for us to postpone sending a required deletion instruction, and deleting a sign-in account does not automatically invoke every installation-ID or analytics deletion operation. Google Analytics and independent store records follow their applicable service settings and lawful retention requirements. Contact us for the arrangements relevant to a particular record.

Provider schedules do not override a statutory deletion deadline or the obligation to use a compatible processing arrangement. Where earlier deletion is legally required, we take the required action with the recipient rather than treating its published maximum as a general exemption.

We may retain a limited subset where law requires it or where necessary and legally permitted for a specific security matter or legal claim. We restrict the purpose and access and explain a refusal or limitation where required. We do not retain an entire health diary merely to prove that an account once existed. Irreversibly anonymised statistics may be retained only where they no longer constitute personal information; encrypted or pseudonymous data is not automatically anonymous.

We act on deletion requests without undue delay and within the applicable legal period. Removal from active systems and expiry from backups are different stages. The special deadlines and downstream-deletion requirements in the separate Consumer Health Data Privacy Notice take precedence where applicable. Deleting your account does not itself cancel a store-managed subscription or delete information held independently by your health platform.

9. Security and encryption

We use technical and organisational measures appropriate to the information and risks, including authentication, access controls, protected network connections, application-integrity controls and encryption for designated sensitive payloads. Progress-photo images and private saved-route details use client-side encryption. Ordinary account data, searchable metadata, public routes, temporary server-side integration processing and information intentionally provided to Google or Garmin are not all protected by that same scheme. Garmin must be able to read an exported course and our integration service must be able to process an incoming activity; that does not give either service access to your device-held progress-photo key.

Encryption-related records can include a protected account key, cryptographic parameters, verification information and a recovery hint. A recovery hint must not contain the recovery phrase itself. Keep your recovery information secure and separate from shared images or support messages. Loss of a necessary key or recovery phrase may prevent decryption on another device; changing an account password is not necessarily a way to recover encrypted content.

No security measure eliminates every risk. This statement does not exclude our legal duties or make you responsible for security failures attributable to us. We assess suspected personal-data breaches and make notifications required by applicable data-protection, consumer-health and other laws. Report suspected compromise promptly to [email protected] without sending your password or recovery phrase.

10. Your privacy rights

Depending on the applicable law, you may request confirmation of processing and access to information; correction; deletion; restriction; a portable copy; information about recipients; withdrawal of consent; and an objection to processing based on legitimate interests. You may object to direct marketing at any time. Applicable law may also protect you from certain solely automated decisions and entitle you to an explanation, human involvement or a challenge.

We do not use ordinary calorie, training or route recommendations to make legally binding decisions about you. Where an automated security measure restricts access, you may contact us to challenge an error. We will provide any legally required review; we do not exclude that right by describing an operation as automated.

Send requests to [email protected] or use the relevant working account control. We may request proportionate information to verify identity or authority, particularly before disclosing sensitive material. We will not routinely demand a copy of an identity document where less intrusive verification is sufficient. An authorised representative may act where the law permits, subject to appropriate verification.

We normally respond to UK/EEA rights requests within one month, with an extension only where the law permits and with the required explanation. Other regional periods apply where required. We do not promise that every request can be fulfilled instantly. Requests are normally free; any refusal or permitted fee must have a lawful basis and be explained. We do not unlawfully discriminate against you for exercising your rights.

You can complain to us and to a competent regulator. For UK data-protection complaints, we acknowledge receipt within 30 days, investigate appropriately, provide required progress information and communicate the outcome without undue delay. That acknowledgement period does not extend a separate deadline for a rights request. You may contact the Information Commissioner's Office through ico.org.uk. EEA residents may complain to their competent national supervisory authority and Swiss residents to the Federal Data Protection and Information Commissioner. This Policy does not restrict other remedies.

11. Privacy signals and tracking choices

Browser Do Not Track signals and legally recognised opt-out signals, including Global Privacy Control where applicable, are not the same thing. We do not currently use browser Do Not Track as a separate setting. We honour legally binding opt-out preference signals for processing within their scope where required by applicable law.

Under the practices described here, we do not sell personal information or share it for cross-context behavioural advertising. Such a signal therefore does not disable necessary account functions or delete an account. Consent and objections for other analytics or device-access processing remain separate choices. No statement about Do Not Track overrides a mandatory opt-out right.

12. Supplement for United States users

NutriMotion remains a Scottish company subject to the UK framework identified above. This section is a regional transparency supplement, not an election of United States governing law or a US forum. A right described by reference to a particular state law applies only where that law covers the processing and the person concerned, taking account of its territorial scope, thresholds and exemptions. Our stated handling commitments elsewhere in this Policy remain effective.

12.1 Categories, sources, purposes and disclosures

The categories processed in connection with the features described in this Policy include identifiers and contact information; account and authentication information; age and other supplied profile characteristics; commercial subscription records; device, network and application activity; geolocation; visual information; health and fitness information; and inferences such as estimated calorie needs, recovery or performance recommendations. Sensitive categories can include health information, precise geolocation and account-access information.

This is not a statement that we collect every example within a statutory category. We do not collect fingerprint or voiceprint identifiers for biometric identification, employment histories or education records as part of ordinary application use. A food photograph and a stored progress photograph have different uses and retention, as described above.

Sections 1 and 2 identify sources and purposes; section 4 identifies disclosures and recipient categories; section 8 explains retention. These descriptions include the relevant processing during the preceding 12 months to the extent the feature was available. We do not sell information, share it for cross-context behavioural advertising, or knowingly sell or share minors' information for those purposes.

12.2 Exercising state-law rights

Where a state privacy law applies, rights may include access, deletion, correction, portability, confirmation of processing, recipient information, an opt-out from sale or targeted advertising, and protections concerning sensitive information or profiling that produces legally or similarly significant effects. California residents may have rights to know and to limit certain uses or disclosures of sensitive information. Some state laws provide a right to a list of particular third parties, not just categories. Applicable thresholds and exemptions affect which provisions apply; this Policy does not assert that every state statute applies to every business regardless of those conditions.

Contact [email protected] to exercise a right or appeal a refusal. We will explain any verification needed, respond within the applicable statutory period, explain a refusal and provide the available appeal or regulator route. An appeal can be sent through the same address, identifying the original request and the reason you disagree. A legally authorised agent may submit a request with appropriate proof of authority. Opt-out requests will not be subjected to identity checks inconsistent with the applicable law.

We do not disclose your information to other companies for their own direct marketing under the practices described here. California residents can also contact us about disclosures covered by California Civil Code section 1798.83.

12.3 Consumer health data

Our separate Consumer Health Data Privacy Notice applies where Washington's My Health My Data Act, Nevada's consumer-health provisions or another applicable consumer-health law protects the processing. Those protections can apply independently of general privacy-law business-size thresholds. That notice identifies health-data categories, sources, purposes, recipients, consent choices, deletion and appeal routes. It is available at Consumer Health Data Privacy Notice and is not replaced by our Terms of Service.

13. Additional regional provisions

Canada, including applicable provincial laws. We obtain meaningful consent appropriate to the sensitivity and use of the information; sensitive uses ordinarily require express consent. You may request access and correction, withdraw consent subject to lawful constraints, and challenge compliance. Our privacy contact receives those enquiries. Processing outside Canada may make information subject to the laws and lawful access powers of the destination. Where Quebec law applies, relevant confidentiality, consent, technology and cross-border assessment requirements also apply; contractual choice of Scots law does not remove them. You may complain to the Office of the Privacy Commissioner of Canada or the competent provincial authority, including Quebec's Commission d'accès à l'information.

Australia. To the extent the Privacy Act 1988 and Australian Privacy Principles apply, we process information for the disclosed purposes, obtain required consent for sensitive information, take the required steps regarding overseas recipients, and provide access, correction and complaint mechanisms. Contact us first so we can investigate; you may also complain to the Office of the Australian Information Commissioner. Not supplying information essential to a chosen feature may prevent that feature, but does not authorise unrelated processing.

New Zealand. Where the Privacy Act 2020 applies, you may request access or correction and complain to the Office of the Privacy Commissioner. We apply the relevant collection-notice obligations, including for information received indirectly, and the applicable protections for overseas disclosures. An independently retained health-platform record is not deleted merely by deleting your NutriMotion account.

Switzerland. Rights under the Federal Act on Data Protection may include information about processing, correction, deletion, data delivery or transfer and remedies against unlawful processing. International recipients and safeguards must be disclosed as required by that law. Contact our privacy contact or the Federal Data Protection and Information Commissioner. A Swiss representative, where legally required, must be identified in section 16.

Brazil. Where the LGPD applies, rights include confirmation and access, correction, portability subject to applicable regulation, anonymisation, blocking or deletion where legally available, information about sharing, consent choices and withdrawal, and review of relevant automated decisions. Sensitive information is processed only on a ground permitted for sensitive data, not merely on the contractual ground in section 3. You may contact our privacy contact or the Autoridade Nacional de Proteção de Dados. Local information, representative or officer and international-transfer requirements must be satisfied where applicable.

South Africa. Where POPIA applies, you may request access, correction or deletion, object to relevant processing and complain to the Information Regulator through its current published complaints process. We apply the relevant protections for special personal information and cross-border processing. Our privacy contact will route requests to the responsible person.

Singapore. Where the Personal Data Protection Act applies, you may contact us about access, correction, consent withdrawal and complaints. We apply the relevant notification, accountability and overseas-transfer requirements. A required data-protection contact must be publicly identified; the controller contact above remains available while an enquiry is routed to the responsible person.

Japan. Where the Act on the Protection of Personal Information applies, you may request the disclosure, correction or cessation of use or provision available under that Act, including relevant third-party provision records. We apply the applicable requirements for sensitive information and provision to foreign recipients. Where foreign-transfer consent is the basis, the required destination and recipient-protection information must be supplied before that consent, not inferred from acceptance of general terms. You may contact the Personal Information Protection Commission.

Republic of Korea. Where the Personal Information Protection Act applies, we follow its requirements for sensitive information, overseas transfers and the information to be provided about recipient, destination, purpose, transferred items and retention. We obtain required legal-guardian consent for children under 14; the general minimum age of 13 does not displace that requirement. Applicable rights to access, correct, delete or suspend processing can be exercised through our privacy contact, without prejudice to complaints to the Personal Information Protection Commission.

India. We apply the Indian data-protection requirements that are in force for the relevant processing, including the Digital Personal Data Protection framework as its provisions become applicable. You can contact us about access to processing information, correction, erasure, consent withdrawal and grievance handling where those rights apply. Any required local-language notice, verified parental consent or grievance procedure must be provided separately where the law requires it; a general age statement in this Policy does not replace those measures.

Other locations. Mandatory local rights apply notwithstanding this Policy. Some markets require additional notices, local-language information, representatives, consent arrangements or restrictions on particular processing. We may restrict a feature or market where those requirements or provider restrictions have not been met. Availability in an app store is not a waiver of those requirements.

14. Public datasets and licensing

The public food-product catalogue made available for food search is licensed as described in section 30 of our Terms of Service, including the Open Database Licence, version 1.0 (ODbL) for database rights we can license. Source-specific rights and attribution also apply, including Open Food Facts and OpenStreetMap where used.

That grant does not make your private food diary, custom private recipes, photographs, health readings, purchase records or personal activity and location history an open database. Creating or saving a private record is not a public-database contribution. Where a function expressly invites you to contribute to the public food catalogue, the notice at that function identifies the public use and contribution terms before submission.

Dataset licences do not remove privacy rights or authorise publication of identifiable personal information. We do not claim that NutriMotion owns every copyright or other right in third-party product images, labels, maps or database contents.

15. Changes to this Policy

We identify updates by version and last-revised date, and state any separate implementation date in the relevant change notice. For material changes, we provide a prominent notice in the Services or another appropriate direct notice before the change takes effect, except where an immediate notice or change is required by law or to address an urgent issue. We explain material changes in a way appropriate to the affected users.

We obtain fresh consent before additional processing where required. Continued use after a notice does not substitute for that consent. A revision does not retroactively legitimise an undisclosed collection or expand a public-content licence over private information. Previous versions and information about a material change can be requested from our privacy contact.

16. Contact and responsibility for privacy

Controller: NutriMotion LTD, registered in Scotland, company number SC838276.
Registered office and postal privacy contact: Clyde Offices, 2nd Floor, 48 West George Street, Glasgow, Scotland, G2 1BP, United Kingdom.
Email for privacy requests and complaints: [email protected].
Website: nutrimotion.app.

Privacy enquiries are handled for the company by its director through this dedicated company contact. This identifies the person responsible for responding on the company's behalf; it is not a statement that a statutory Data Protection Officer, EEA representative or other local representative has been appointed. Any separately required representative must be identified through an applicable regional notice. A UK postal address is not presented as an EEA representative's address.

You do not need to purchase a subscription, create a new account or accept an arbitration agreement to send a privacy request or complaint.

17. Reviewing, updating, exporting and deleting your information

You can edit supported entries through their application screens, manage phone/watch and connected-health permissions in the relevant platform settings, and use available photo, workout, route and account-deletion controls. Review a route's public or link-shared copy separately from its private copy. For Garmin, revoke the connection to stop future transfers and request deletion of saved imports separately where needed; manage Garmin originals, exported Garmin courses and Apple Health records through those platforms. A failed or incomplete in-app operation does not remove your right to contact us.

The in-app export provides the records supported by that export function. It may not contain every category held across object storage, shared records or service providers, and encrypted records may require processing on your authorised device to produce a readable copy. For a complete access or portability request, or a missing category, contact [email protected]. We will identify and provide the information required by law rather than treat an incomplete self-service download as the end of the request.

An account-deletion request covers the account and associated information we control, including relevant cloud objects and associated records rather than only Firebase Authentication, subject to the limited lawful retention described above. Contact us if an in-app deletion appears incomplete so that we can investigate and complete the required removal. We do not promise instantaneous erasure from every active system, backup or independent recipient. We will explain applicable timing and any lawful exception. Export material you wish to retain before deletion and cancel an app-store subscription separately.