Skip to content

Privacy Policy

Last updated: 1 October 2026

Nutly helps you understand what's in the food you scan. This policy covers Nutly's native apps and public website and explains what information we collect, why, and the choices and rights you have.

Nutly is operated by Yehor Hunko, a private entrepreneur (ФОП) registered in Ukraine, who is the controller of your personal data. Using Nutly also means agreeing to our Terms of Service. We try to collect as little as possible, to keep your data safe, and to be clear about who processes it on our behalf.

What we collect

Account — the app creates a random account ID on your device and registers it with Nutly automatically when it connects after onboarding. You do not need to provide a name, email or password. Your subscription, usage limits, reports and any health profile are linked to this ID; it is a pseudonymous account, not a guarantee of anonymity. On iOS, account credentials are kept in iCloud Keychain and can carry over to your other Apple devices and a reinstall. On Android, the account ID is stored locally and account credentials are encrypted with an Android Keystore key and excluded from backup. Android credentials do not sync between devices or across platforms. You can erase your account in Settings ('Erase my data').

Product requests and history — individual lookups send the full barcode to Nutly's servers, together with account and technical request information such as your IP address. The saved history list, including scanned products and scan times, stays on your device and is not uploaded as a history list. On iOS, with iCloud enabled, it can sync across your own Apple devices. Android history may be included in Android backups and device transfers according to your device settings. Individual requests may also appear in the operational records described below.

Label photos — you can upload packaging photos to recognise ingredients or nutrition information, including when a product is missing or its data needs improvement. We process the image and save extracted and derived product information. Temporary device files and AI-provider retention are described under 'Photos of labels'. Product reports contain text, not photo attachments.

Optional app analytics — with your consent, we record pseudonymous feature-usage events, including result sources, recognition confidence and barcode prefixes. Events can be linked to your account and app-session identifiers. Personal-analysis events can include a verdict and counts of allergen matches or concerns; these events use a fresh random identifier rather than your account or session ID and do not include the raw health profile. App analytics are off unless you consent during onboarding or enable them in Settings. You can turn them off at any time; this stops future optional events, rather than automatically deleting earlier events.

Public product-page measurement — the website sends page-view events containing the full product barcode and page path, using a new random identifier for each request. These events do not use an account ID or a persistent browser analytics identifier. This server-side measurement operates separately from the app's analytics setting.

Usage limits and security — we process IP addresses and store account-linked or IP-linked usage counters to apply feature limits and prevent abuse. To count a successful barcode check only once per week, we also store opaque keyed identifiers scoped to your account and that week. These accounting identifiers do not contain the barcode, product name or scan timestamp, but remain account-linked data; they are not a guarantee of anonymity. The daily cleanup removes identifiers for completed weeks, normally within 24 hours after the week ends; a failed cleanup can delay removal. Counter totals remain under the retention rules below. This operational processing continues when optional app analytics are off.

Android barcode scanning — Google ML Kit processes camera images and barcode results on your device. It sends Google installation identifiers, device and app information, performance metrics, API configuration, input/output sizes, feature versions, event types and error codes for diagnostics and usage analytics. This SDK telemetry operates independently of Nutly's analytics setting; ML Kit does not send camera images or barcode results to Google.

Operational diagnostics — our hosting and monitoring services can process request metadata and server error reports independently of optional app analytics. We filter known sensitive fields and barcode-like strings from Sentry reports, but cannot guarantee that every personal detail in arbitrary error text or request metadata is removed. When additional server logging is enabled, logs can include full barcodes, recognised ingredient text, and personal-analysis verdicts or concern counts. AI performance telemetry records task, provider, model, timing, status and token-usage metadata, rather than photo or health-profile contents.

Health profile — only if you choose to save one. It can include allergies, intolerances, chronic conditions and life stages such as pregnancy or breastfeeding, plus optional age range, sex, height and weight. We process this sensitive information to store your profile and provide personal analysis. The profile review screen asks you to agree to this processing when you save it. Optional analytics and operational diagnostics may include the derived measurements described above. You can delete your profile in Settings.

Preferences and correspondence — language and app settings are stored on your device. If you email us, we receive your email address and the information you send so we can respond and handle your request. Please avoid including unnecessary health information or account secrets.

Photos of labels

Uploaded packaging images are sent to Google Gemini to recognise and check ingredients, nutrition and other product information. We save extracted text, structured product information and derived results in the shared product catalogue. This information may appear on public product pages and remain after your account is erased; your health profile is not published with it.

On Android, taking a label photo creates a temporary file in the app's cache. The app attempts to delete that file after the capture is cancelled or the upload finishes, but an interruption can leave it in the cache. Choosing an existing image does not delete the original from your photo library.

Nutly's server handles image bytes temporarily, including for background nutrition processing after an initial response. It does not save uploaded image bytes in its product or report database or object storage. AI providers can retain inputs under their own API terms; processing is not a guarantee of immediate deletion by every provider. Product reports are text-only.

How we use your data

To provide the core service — looking up products, reading labels, and scoring ingredients.

To improve accuracy and fix problems — including reviewing low-confidence text readings.

To understand how features are used so we can make Nutly better.

To keep Nutly secure and reliable, and to detect and fix faults.

To provide personalized analysis when you set up a health profile — comparing a scanned product against the health information you gave us.

We do not sell your personal data, and we don't use it for advertising.

Our legal bases

Where the EU/UK GDPR or Ukraine's data-protection law applies, we rely on the legal bases below.

Providing the app's core service, account, subscription state and usage limits — performance of our contract with you. Account registration happens automatically after onboarding when the app connects.

Optional app analytics — your consent. You can withdraw it in Settings at any time. This control applies to future optional app events; it does not switch off operational processing, public-page measurement or Google's ML Kit telemetry.

Security, abuse prevention, operational diagnostics, product reports and public product-page measurement — our legitimate interests in operating a reliable service and improving product information. Google processes ML Kit telemetry under its own Privacy Policy.

Your health profile and personal analysis — your explicit consent when you choose to save a profile. Saving a profile is optional, and you can withdraw this consent by deleting the profile in Settings. The analytics and diagnostic measurements derived from analysis are described above.

Correspondence — responding to your requests and meeting applicable legal obligations, including handling data-rights requests.

Who we share it with

We use the following services to run Nutly. Providers may also process technical and service metadata under their own applicable terms.

PostHog — optional app analytics and public product-page measurement, through its European Union service. It may also receive operational logs when log forwarding is enabled. These different types of processing are described above.

Sentry — server error monitoring and diagnostic metadata, with filtering of known sensitive fields as described above.

Cloudflare — application hosting, request handling, the global edge network and caching of product data. Requests, including uploaded images, pass through this infrastructure.

Neon — our database for shared product information and account-linked health profiles, usage counters, subscription state and reports, as well as cached personal analyses and IP-linked usage counters.

RevenueCat — where subscription services are configured, its SDK receives your account ID, app and device information, and store purchase or renewal information to manage entitlements. Apple or Google handles store billing and payment details. Nutly does not send RevenueCat your health profile or product lookups. Erasing Nutly data does not automatically delete RevenueCat's or the store's records.

Google Gemini — receives uploaded label images and product text for ingredient and nutrition extraction, verification and quality checks. We use a Cloud Billing-linked paid API project and have optional input/output sharing and training opt-ins disabled.

OpenAI — receives your health profile and product data when you request personal analysis. Optional input/output sharing and training opt-ins are disabled. OpenAI response storage is disabled in our requests. Gemini and OpenAI serve separate tasks without cross-provider fallback. Under their applicable API terms and our settings, these inputs and outputs are not used to train their general models, but providers may retain content for abuse monitoring, caching or legal obligations. Disabling response storage does not guarantee zero retention.

Google ML Kit, Android only — receives the barcode SDK telemetry described above to measure performance, debug, maintain and improve its APIs, and detect misuse under Google's Privacy Policy. This is separate from Gemini and Nutly's optional app analytics.

External product databases — barcodes beginning with 482 are looked up through GS1 Ukraine (GEPIR); other barcodes may be looked up through Open Food Facts. A 482 prefix does not establish where a product was manufactured. These services receive the barcode and normal server-request metadata; Nutly does not send them your account ID or health profile. Barcodes beginning with 482 are not sent to Open Food Facts.

International data transfers

Providers can process data outside your country, including in the United States and other countries outside the EU/EEA. This includes label images and product text processed by Google, Android ML Kit telemetry, and health profiles and product data processed by OpenAI. Cloudflare, Sentry, Neon and RevenueCat can also process data internationally. Using an EU analytics endpoint does not mean that every provider processes all data only in the EU.

International processing is subject to the applicable provider terms and data-processing arrangements. You can contact us to request information about the transfer arrangements and safeguards applicable to your data. Google's ML Kit telemetry is governed by Google's Privacy Policy.

Where your data lives

Shared product information is stored in our database and cloud caches. Your saved history list is stored on your device and, on iOS with iCloud enabled, in your iCloud. Individual product requests and operational records are processed on our servers as described above.

Android history and preferences may be included in backups and device transfers. Account credentials, health profiles and personal-analysis caches are excluded from Android backup. Local health caches use Android Keystore encryption. Server-side health profiles and cached personal-analysis contents are encrypted in our database; they must be decrypted to provide analysis and return results to you.

How long we keep it

Account-linked health profiles, usage counters, subscription state and reports have no automatic inactivity expiry and remain until you delete the relevant data or erase your account. IP-linked usage counters also have no automatic expiry and are not removed by account erasure. Shared product information remains in the catalogue independently of your account.

Encrypted Android health-profile and personal-analysis cache entries stop being used after 30 days. Expired files are removed during app-start cleanup, so they can remain on a device longer if the app is not opened. Deleting your profile or erasing your data also clears the relevant local health caches.

Temporary label-photo files and AI-provider retention are described above. Nutly does not retain uploaded image bytes in its product or report database. Provider copies, abuse-monitoring records and caches follow the provider's applicable retention rules.

Analytics, diagnostic logs and error reports follow each service's configured retention and applicable requirements. Turning off app analytics or erasing a Nutly account does not automatically purge records already held by providers. Google retains ML Kit telemetry under its own Privacy Policy.

If you contact us, correspondence may be retained to handle your request and keep records needed for applicable legal obligations. Copies in device or provider backups may remain under those services' retention and deletion mechanisms.

Deleting your data

With an internet connection, 'Erase my data' in Settings deletes your account, health profile, reports, account-linked usage counters and subscription record from Nutly's active database. The app then starts with a new account. On Android it clears this device's history and local product, health-profile and personal-analysis caches; it does not erase other devices or existing backups. On iOS, history erasure is propagated through iCloud when devices sync.

Personal analyses are cached against a protected fingerprint of the health profile, rather than directly against an account, and can be reused for identical profiles. When no saved profile uses a fingerprint, its analyses are scheduled for removal by daily cleanup. Cleanup failures can delay removal. Shared product information, IP-linked counters and records already held by providers are not automatically deleted by erasing your account.

You can also request deletion without opening the app: email privacy@nutly.cc with the subject 'Nutly data deletion', say whether you use Android or iOS, and describe the data you want deleted. Because your account has no linked email address, we may need information to locate it and verify ownership. Do not send account secrets or health details. If the account cannot be identified or ownership verified, we may be unable to act on that account.

Erasing Nutly data does not cancel a subscription bought through the App Store or Google Play. Cancel it separately in the store's subscription settings to stop future renewals. Store and RevenueCat purchase records follow their own retention rules.

How we protect your data

We use HTTPS for data transferred between your device, our servers and providers. Health profiles and cached personal-analysis contents are encrypted in our database, and Android credentials and local health caches use Android Keystore encryption. These measures do not prevent the processing needed to deliver the service.

We filter known sensitive fields from error reports and avoid saving uploaded image bytes in our product and report database. Diagnostic metadata and temporary files are described above. No system is perfectly secure.

Your choices and rights

You do not need to provide a name, email or password to use the app. You can erase your data, change on-device settings, turn off optional app analytics, and delete your health profile in Settings. App analytics controls do not govern public-page measurement, operational processing or ML Kit telemetry.

Under applicable data-protection law, you may request access, correction, deletion, export or restriction of your personal data, and object to processing based on legitimate interests. These rights depend on the applicable law and any lawful exceptions. We may need information to identify your account and verify ownership.

You can withdraw consent for future app analytics in Settings and for health-profile processing by deleting the profile. Withdrawal does not change the lawfulness of processing before withdrawal.

You can complain to the Ukrainian Parliament Commissioner for Human Rights (Ombudsman) or, where applicable, your local EU/EEA or UK data-protection authority. Contact us at the address below to make a request.

Children

Nutly isn't directed at children under 16, and we don't knowingly collect their data.

Who is responsible for your data

The controller of your personal data is Yehor Hunko, a private entrepreneur (ФОП) registered in Ukraine. You can reach us about your data at the contact below.

Changes to this policy

We publish changes on this page with an updated date. App releases containing a newer legal-document version ask you to review and accept it. An older installed app may not show a new acceptance prompt until it is updated.

Contact us

Questions or requests? Email us at privacy@nutly.cc.