← NutriGoal Check

Privacy Policy

Last updated: 9 August 2026

This policy explains what data NutriGoal Check (operated by Engage Digital Projects Ltd — "we", "us") collects, how it is used, and the choices you have. The short version: your scan history lives on your device and in your own private iCloud, label photos are processed transiently to read the label and are not kept on our servers, and we never sell your data.

1. Data we collect

  • Label photos. When you scan, the photo(s) you capture are sent securely to our server so an AI model can read the nutrition label. Photos are processed transiently and are not stored on our servers after the reading is returned. Copies you choose to keep with a scan stay on your device and, when iCloud is available, are mirrored into your own private iCloud along with the rest of that scan.
  • Scan history and preferences. Your nutrient goals, scan results, and history are stored on your device and, when iCloud is available, in your own private iCloud, which also holds the label photos you choose to keep with a scan. That copy sits in your Apple account, not in a company database, and we cannot read it.
  • Working copies of a reading. When a scan succeeds, the reading our server produced is stored briefly against your device identifier so that a scan interrupted by a lock screen or a dropped connection can be finished without reading the label, or charging you, a second time. Text produced by the optional AI insight feature is stored in two ways: a copy is cached under a key derived from the reading and your goals, so the same insight can be reused without a second AI call, and a second copy is held briefly against your device identifier so a retried request can be answered without generating, or charging you for, the insight a second time. Section 5 gives the retention period for each.
  • No account. NutriGoal Check has no sign-up and no login. The app never asks for your name and never creates an account for you. If you contact support, the form has an optional name field; anything you type there is stored with your ticket (see "Support messages" below). To keep your scans and goals tied to your app between launches and to apply fair-use limits, the app generates a random device identifier. It is held in your device's keychain, which is what makes it survive deleting and reinstalling the app, and it is also mirrored through your own private iCloud key-value storage so a restored or replaced device can pick up the same one. It is pseudonymous: it is not your name, email, or Apple ID, and it is not linked to your real-world identity.
  • Support messages. If you write to us from the Help screen in the app, we store your message together with the pseudonymous device identifier described above, which is what lets us show our reply to you inside the app. An email address is optional there: add one if you would also like the reply by email. On the contact form on this website there is no device identifier, so an email address is required, because otherwise we would have no way to reach you. We also store the name you gave if you chose to give one, and the in-app form attaches your app version, build, device model, and OS version so we can reproduce what went wrong. This is used only to answer you.
  • Product-list email (optional, not currently open). Sign-up is closed and we are not sending it. If you gave us an address before, it is held as described in section 5, never sold, never used for advertising.
  • Abuse-prevention counters. To stop one device or one network flooding the parts of the Service that cost us money, we count requests and store each counter in our database under a name that contains the network address (IP address) the request arrived from, in readable form. This happens when you scan, ask for an insight, ask the coach, answer the coach survey, send a support message, when a purchase is checked, on the product-list pages, and on our own admin and beta sign-ins. If you give us an email address for the product list, a second counter is stored under a name containing that address, which is what caps how many confirmation emails any one address can trigger. One counter, the one that limits how often a device can answer the coach survey, is stored under a name containing the pseudonymous device identifier described above rather than a network address. Section 5 gives how long a counter is kept.
  • Coach survey answers (optional). The Insights screen can offer a short survey asking what you would want to ask an AI coach. If you send it, we store what you typed (up to 500 characters), which of the suggested questions you tapped, and how interested you said you were, against the pseudonymous device identifier described above. Sending it is entirely optional, and the survey asks for nothing else about you.
  • Purchase information. Subscriptions are billed by Apple through the App Store. We receive transaction and entitlement records only — never your payment card details. Your premium access is recognised from that purchase record, not from any account.
  • Usage and diagnostic data. We use PostHog (product analytics, hosted in the EU) and Sentry (crash and error diagnostics) to understand how the app is used and to detect problems. These collect usage signals such as which features are used, device model, and OS version, plus crash reports. Some events are associated with the pseudonymous device identifier described above so we can measure things like feature use over time; they are never linked to your name or advertising data, and never sold. IP addresses are anonymised. We may also record basic service metadata (such as scan counts and timestamps against that device identifier) to enforce fair-use limits and keep the Service secure.

Separately, we keep a reference catalog of non-personal product information, which holds no information about you; the Terms of Use describe it in full.

2. AI processing of your photos

To read a label, your photo is transmitted over an encrypted connection (TLS) to our server, which forwards it to Anthropic's Claude AI to transcribe the nutrition values printed on the label. The result is returned to your device, where the rating against your goals is computed. Your photos and data are not used to train AI models. Optional AI features (insights and the coach) send only the label reading or compact, aggregated statistics about your scans — never a library of your raw photos.

3. How we use your data

  • To provide the Service: reading labels, computing ratings, and recognising premium access from your App Store purchase (contract).
  • To enforce free-tier and fair-use limits and prevent abuse (legitimate interests).
  • To understand feature usage and improve the app via product analytics (legitimate interests).
  • To comply with legal obligations, such as records of purchases (legal obligation).

4. Third-party services

  • Anthropic (Claude) — AI label reading and coaching text; not used to train their models.
  • Apple — App Store billing, and your private iCloud storage that the app syncs to (we cannot read your iCloud data).
  • Supabase — our secure database for fair-use metering, purchase records, support tickets, the optional product list, the abuse-prevention counters described in section 1, the working copy of a reading held so an interrupted scan can be finished, cached AI insight text, and coach survey answers. It holds no account, and no name unless you gave one when you contacted support.
  • Vercel — hosting for our API and this website.
  • PostHog — product analytics, hosted in the EU, with IP anonymisation on. On this website, analytics keep their working data in memory only for the duration of your visit: the site sets no cookies and stores nothing on your device, so there is nothing to accept or clear, and a later visit looks like a new visitor to us.
  • Sentry — crash and error diagnostics.
  • Resend — delivers your support ticket to us, which means it carries your message, any name you gave, and your email address, set as the address a reply goes back to. When we answer a support ticket and you gave an email address, Resend also delivers that reply to it. If you did not give one, the reply appears only in the app and no email is sent.
  • Open Food Facts — optional product lookups. Looking a product up by barcode sends the barcode; searching for a product by name sends the words you typed. Either request goes from your device straight to Open Food Facts, so they receive your device's IP address. We send them nothing else about you.

These providers process data on our behalf under their own data processing terms. We do not sell, rent, or trade your personal data, and we do not use third-party advertising trackers.

5. Data retention

  • On-device data (scan history, preferences, kept photos) stays on the device until you delete it in the app or remove the app. Removing the app does not reach the two copies described in the next bullet: the iCloud mirror, and the random device identifier held in your device's keychain, which is itself on-device data that a reinstall does not clear.
  • Data in your own iCloud. When iCloud is available, your scan history and the label photos you keep are mirrored into your private iCloud, and the random device identifier is mirrored into your private iCloud key-value storage. Deleting the app does not delete either copy, and it does not delete the identifier held in your device's keychain, which is why a reinstall keeps the same identifier. To remove the iCloud copy of your scans and goals, use Delete my data in the app's Settings: it deletes that copy and the one on your device together. The identifier is deliberately kept, so that deleting your data cannot reset the free allowance and so your subscription keeps working. To remove the identifier as well, delete the app's data in the iOS Settings app, under your name, then iCloud, then the screen that manages storage and app data; the keychain copy is removed when you erase the device.
  • Label photos sent for scanning are not retained on our servers after processing.
  • Readings held so an interrupted scan can be finished are deleted 24 hours after the scan. The deletion job runs once a day, at 04:00 UTC, so in practice a reading can be held for up to about 48 hours.
  • Cached AI insight text is deleted 60 days after it is written. That deletion is part of the same once-a-day 04:00 UTC job, and nothing checks an entry's age when it is served, so in practice an entry can be held and reused for up to about 61 days.
  • Insight text held against your device identifier so a retried request can be answered without generating the insight a second time is deleted 24 hours after it is written. That deletion is part of the same once-a-day 04:00 UTC job, so in practice this copy can be held for up to about 48 hours.
  • Abuse-prevention counters (the network address a request came from, for the coach survey, the pseudonymous device identifier, and, for the product list, the email address a sign-up was attempted with) expire after twice their counting window and are then removed by the same once-a-day 04:00 UTC job. The windows run from one minute to a day depending on what is being counted, so a counter with a day-long window, such as the one that caps confirmation emails per address, can be held for up to about three days.
  • Scan counts. Every scan adds one small record to our database, holding the pseudonymous device identifier, the time of the scan, and whether the scan was made on a premium subscription. It holds nothing about the product, the photo, or the reading. These records are how the free tier is counted: each time you scan we count your free scans from today to work out how many are left, and we count every record ever written for that identifier to keep a running total of how many scans it has made. Deleting old records would break that running total, so nothing deletes them. They are kept for as long as we run the Service, and deleting the app does not remove them. This is also a record we will not erase on request: wiping it would set your free allowance back to nothing used, which is exactly what someone working around the free tier would ask us to do. Section 6 sets out how that sits with your right to have data deleted.
  • Free-insight counter. The first few AI insights are free, and to count them our database keeps one small record per install, holding the pseudonymous device identifier, how many free insights that install has used, and when the record was created and last updated. Nothing deletes it, and there is no scheduled deletion: it is kept for as long as the install identifier exists, because erasing it would hand the install a fresh free allowance. For the same reason as the scan counts above, this is a record we will not erase on request; section 6 sets out how that sits with your right to have data deleted.
  • Coach survey answers are kept for as long as we run the Service. Nothing deletes them automatically and there is no scheduled deletion. They are held against the pseudonymous device identifier and nothing else, so we cannot find yours from your name or your email address. If you tell us what you wrote, we can find that answer and delete it.
  • Support tickets (your message, your email address if you gave one, any name you gave, the app details the in-app form attaches, and the device identifier that lets us show you the reply) are kept while we answer you. Ninety days after a ticket is resolved, we remove the personal parts automatically and keep only the reference number, the category and the status, so a reference you quote still resolves without us holding your message or your contact details. Ask us sooner and we will do it on request.
  • Product-list email. You can unsubscribe at any time. We stop emailing you, and your sign-up record is kept and marked unsubscribed rather than deleted, so that the unsubscribe is honoured. That record holds your email address, the country and the goals you chose, when you consented and under which version of the wording, which screen you signed up from, when we last emailed you, and the two tokens the confirm and unsubscribe links use. Sign-ups that are never confirmed are deleted after 7 days.
  • Purchase records may be retained as required for tax and accounting compliance.
  • Analytics are associated only with the pseudonymous device identifier, are used only to improve the Service, and are never sold or used for advertising.

6. Your rights

Depending on where you live (including under UK/EU GDPR and the California Consumer Privacy Act), you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent. The right to have data deleted has limits, and being straight about them matters more than a tidy sentence. When you ask us to delete your data, we will keep the following:

  • The scan-count records and the free-insight counter described in section 5, because they are how the free allowances are worked out. Erasing them would hand back a fresh allowance, which is exactly what someone working around the free tier would ask us to do, so we treat keeping them as necessary to prevent abuse of the Service.
  • Purchase records, where tax and accounting rules require us to keep them, as section 5 says.
  • If you signed up for the product-list emails and unsubscribed, the record that keeps your address unsubscribed, described in section 5, because deleting it would let us email you again.

Everything else we hold about you, we will delete when you ask. Most of this you can do yourself, without asking us: in the app, open Settings, then Your data, then Delete my data. That deletes your scans, goals and achievements from your device, from your iCloud and from our servers in one step, keeping only the records listed above. You can also delete individual scans from your history, and if you subscribed to the product list, every email includes a one-tap unsubscribe. For everything else, including a copy of what we hold, send your request through our contact form or email support@nutrigoalcheck.app, and we will respond within 30 days. There is no self-service export in the app or on this site, so we prepare and send you a copy by hand.

California residents: we do not sell personal information. UK/EU residents may also lodge a complaint with the Information Commissioner's Office (ico.org.uk) or their local supervisory authority.

7. Security

Data in transit is encrypted with TLS. The limited data we hold in Supabase (fair-use metering, purchase records, support tickets, the optional product list) is encrypted at rest and protected by row-level security. No system is perfectly secure, but we design the Service to hold as little of your data as possible in the first place, and to keep no account at all.

8. International transfers

Our service providers may process data in the United States or other countries. Where data is transferred outside the UK/EEA, we rely on appropriate safeguards such as Standard Contractual Clauses or the UK International Data Transfer Agreement.

9. Children

NutriGoal Check is not directed at children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided us personal data, contact us and we will delete it promptly.

10. Not medical advice

NutriGoal Check is a preference-matching tool based on the label text we read. It is not medical, dietary, allergen, or ethical advice — see the Terms of Use.

11. Changes to this policy

We may update this policy from time to time. We will update the "Last updated" date above. For material changes we will also post a prominent notice on this page, and where we already have a way to reach you, such as an email address you gave us for the product list or when you contacted support, we will tell you directly. Continued use of the Service after the effective date constitutes acceptance.

12. Contact

Privacy questions or requests? Send them through our contact form or email support@nutrigoalcheck.app.