Skip to content

Privacy Policy

Last updated: 15 September 2026

Nutly helps you understand what's in the food you scan. This policy explains, in plain language, what information we collect, why, the legal bases we rely on, and the choices and rights you have.

Nutly is operated by Yehor Hunko, a private entrepreneur (ФОП) registered in Ukraine, who is the controller of your personal data. Using Nutly also means agreeing to our Terms of Service. We try to collect as little as possible, to keep your data safe, and to be clear about who processes it on our behalf.

What we collect

Account — the app creates a random account ID on your device the first time you open it, automatically: no sign-up, no email, no name, no password. It's what your subscription, usage limits, and any health profile you set up live against. It's kept in your iCloud Keychain, so it carries over to your other Apple devices and survives a reinstall, and you can erase it at any time in Settings ('Erase my data').

Scans — the barcodes you scan and when. This is kept as your history, on your device and, if you have iCloud enabled, synced privately across your own Apple devices through iCloud — we never receive it or store a copy of it ourselves.

Label photos — when a product isn't found, you can take a photo of its ingredients label so we can read it. We send the photo for text recognition and keep only the recognised text; the photo itself is never stored. See 'Photos of labels' below.

Usage and device data — we record pseudonymous usage events. They are designed to minimise identifiability and carry no direct personal details (for example, only the first three digits of a barcode rather than the whole code, the source of a result, and how confident our reading was), but they are linked to your account ID so we can understand how Nutly is used and improve it. Because of that identifier this data is pseudonymous, not fully anonymous. Analytics stay off until you turn them on, and you can turn them off again at any time in Settings.

Technical error reports — if something breaks, our error-monitoring provider (Sentry) receives a diagnostic report. We remove personal and sensitive details — your IP address, email, name, barcodes, ingredients text, and any image data — before the report leaves your device or our servers, and these reports never contain label photos.

Health profile — only if you choose to set one up. It can include health information such as allergies, intolerances, chronic conditions, and life stages (for example pregnancy or breastfeeding), plus optional basics like age range, sex, height, and weight. This is special-category (sensitive) data, which we collect only with your explicit consent and use only to generate your personal analysis; you can delete it at any time in Settings.

Preferences — your language and app settings are stored on your device.

Photos of labels

When you upload a photo of an ingredients label, we send it to a text-recognition service to read the ingredients (see 'Who we share it with'), then save the recognised text with the product. We do not need to keep the photo itself to do this.

We do not store label photos. A photo is processed only to read its text and is discarded immediately afterwards — it is not kept in any database, bucket, or file storage. Product reports are text-only and never include a photo.

How we use your data

To provide the core service — looking up products, reading labels, and scoring ingredients.

To improve accuracy and fix problems — including reviewing low-confidence text readings.

To understand how features are used so we can make Nutly better.

To keep Nutly secure and reliable, and to detect and fix faults.

To provide personalized analysis when you set up a health profile — comparing a scanned product against the health information you gave us.

We do not sell your personal data, and we don't use it for advertising.

Our legal bases

Where the EU/UK GDPR or Ukraine's data-protection law applies, we rely on the legal bases below.

Providing the core service and your account — performance of our contract with you once your device's account is registered (this happens automatically, moments after you first open the app), together with our legitimate interest in operating Nutly for the rare request that reaches us before that finishes, or while you're offline.

Product analytics and usage measurement — your consent. Analytics are off until you turn them on; we keep this data pseudonymous and minimised, host it in the EU, and you can withdraw your consent at any time in Settings.

Error monitoring, security, and fault diagnosis — our legitimate interest in keeping Nutly safe and working.

Your health profile and personalized analysis — your explicit consent. Setting up a health profile is optional; we ask for your consent when you create it, process this special-category data only to generate your personal analysis, and you can withdraw consent at any time by deleting your profile in Settings.

Product reports — our legitimate interest in improving the quality and accuracy of product data.

Who we share it with

We rely on a small number of trusted providers (sub-processors) to run Nutly. They process data only on our behalf, under contract, and only as needed:

PostHog — product analytics, hosted in the European Union (pseudonymous usage events).

Sentry — error monitoring (diagnostic reports, with personal data, IP address, and images removed).

Cloudflare — application hosting, the global edge network, and short-term caching of product data.

Neon — our database for products, and for everything listed above that we keep under your account: your health profile, usage limits, subscription state, and reports.

RevenueCat — subscription management: it receives your account ID from the moment you open the app, and the purchase and renewal events the App Store or Google Play reports for your subscription, so we know which plan you are on. It never receives your health profile or your scans.

Google (Gemini) and Anthropic — text recognition and ingredient extraction/verification: when a label photo or product needs reading, the image or text is sent to Google's Gemini (our primary provider) or, as a fallback, to Anthropic, to transcribe and interpret it. We use these providers' paid business APIs, under which your inputs are not used to train their models, and neither we nor they retain this data afterwards. When you request a personalized analysis, your health profile is also sent to this provider, together with the product's data, to generate that analysis, under the same business API terms. Both process it in the United States (see 'International data transfers').

To identify products, we also look them up by barcode in external databases. Ukrainian products (barcodes starting with 482) are looked up via GS1 Ukraine (GEPIR). Other products are looked up in the public Open Food Facts database; Ukrainian 482 barcodes are never sent to Open Food Facts. In every case only the barcode is sent — no personal details.

International data transfers

Some providers process data outside your country, including outside the EU/EEA. In particular, Google (Gemini) and Anthropic process label images and text in the United States; Cloudflare, Sentry, Neon, and RevenueCat may process data in regions outside the EEA depending on configuration.

Where data leaves the EU/EEA or Ukraine, we rely on the European Commission's Standard Contractual Clauses (SCCs) and equivalent safeguards, alongside each provider's technical and organisational measures.

Where your data lives

Your product data is stored in our database and on our cloud provider's network. Your history stays on your device and, if you have iCloud enabled, in your iCloud — never on our servers. Usage analytics are processed in the European Union. Some providers may process data elsewhere under the safeguards described in 'International data transfers'.

How long we keep it

Your account data — health profile, usage limits, subscription state, and reports — is kept for as long as your account exists; you can erase it at any time in Settings. Your scan history never reaches our servers in the first place — see 'Where your data lives' above.

Your health profile is kept until you delete it, or erase your data, in Settings.

We do not store label or report photos — they are never retained in the first place.

Pseudonymous analytics and error-monitoring data are kept for up to 24 months, or each provider's standard period if shorter.

Deleting your data

'Erase my data' in Settings erases your scan history on all your devices, and deletes your health profile, saved reports, usage counters, and subscription record; you're then given a brand new, empty account. Your personal analyses aren't tied to your account directly: each is stored against a secure fingerprint of the health profile that produced it, shared by anyone with an identical profile, and is removed automatically within a day of no profile needing it any more.

Erasing your data does not cancel a subscription you bought through the App Store or Google Play. That billing relationship is with the store, and only you can end it — from your subscription settings in the App Store or Google Play.

How we protect your data

We use encryption in transit (HTTPS) for data moving between your device, our servers, and our providers, and we limit access to personal data to what each part of the service needs.

We minimise what we collect, strip personal and sensitive details — including your IP address and any images — from error reports before they reach our monitoring provider, and do not store label or report photos.

No system is perfectly secure, but we work to protect your data and to fix problems quickly when we find them.

Your choices and rights

You're never asked to register or provide your name or email to use Nutly. You can erase your data, and change or clear your on-device settings, at any time in Settings. You can also turn product analytics off whenever you like.

You can ask us to access, correct, delete, export, or restrict the processing of your personal data, and to object to processing we base on our legitimate interests.

Where we rely on your consent — for example, product analytics — you can withdraw it at any time; for analytics, simply switch it off in Settings.

If you're in the EU/EEA, the UK, or Ukraine, you have these rights under applicable data-protection law.

You also have the right to lodge a complaint with a supervisory authority. As Nutly is operated from Ukraine, the lead authority is the Ukrainian Parliament Commissioner for Human Rights (Ombudsman); if you are in the EU/EEA or the UK, you may also contact your local data-protection authority.

To make a request, contact us at the address below.

Children

Nutly isn't directed at children under 16, and we don't knowingly collect their data.

Who is responsible for your data

The controller of your personal data is Yehor Hunko, a private entrepreneur (ФОП) registered in Ukraine. You can reach us about your data at the contact below.

Because we operate from Ukraine and process only a limited amount of personal data, we have not appointed an Article 27 EU representative; we will appoint one if and when our processing requires it.

Changes to this policy

If we make material changes, we'll update this page and ask you to review and accept the new version the next time you open Nutly.

Contact us

Questions or requests? Email us at privacy@nutly.cc.