Skip to content
Nutrify.AI
Features How it works Pricing Waitlist FAQ
Get notified

Privacy Policy

Nutrify.AI, operated by DevX Group LLC

Last updated: August 30, 2026

Effective date: 2026-08-30

Last updated: 2026-08-30

Operator: DevX Group LLC ("DevX Group", "we", "us")

Contact: privacy@devxgroup.io

App: Nutrify.AI (Apple App Store ID io.devxgroup.nutrifyai)

This is the per-app addendum to the shared DevX Group corporate privacy policy at devxgroup.io/privacy. The corporate-wide sections (who we are, governance, cookie practices, your global rights) live on the parent page; this addendum covers what is specific to Nutrify.AI.

1. Plain-language summary

Nutrify.AI is a personal nutrition, exercise, sleep, and lab-data assistant. We collect what you tell us and what you log (and, only if you connect it, sleep and workouts from Apple Health or Health Connect), store it in your account, send a bounded slice to third-party AI providers when you ask the AI for help, and use it to generate personalized recommendations only inside your account. We also use first-party product analytics (PostHog) to see how people use the app so we can fix problems and improve it. Analytics records that you opened a screen or created a log, tied to your account ID. It never records the contents: not the food, not the number on the scale, not a lab value, not a journal entry. Analytics also includes session replay on the paywall screens only, with all text and images masked, so we can see where the purchase flow confuses people without ever capturing your health or nutrition content; it runs under the same analytics toggle. Because knowing that you uploaded a lab report is itself health information, we treat these events as health data too: they stay first-party, they are never used for advertising, they are never shared with an advertising or data-broker network, and you can turn them off in Settings then Support. We do not sell your data. We do not use your data for advertising and we do not use it to train third-party AI models. Every AI request is processed for that single response and not retained for training by our providers under their commercial API terms. You can delete everything from inside the app at any time.

2. What we collect

CategoryExamplesSource
Account identifiersEmail, Apple/Google sign-in subject ID, Supabase user IDYou, when you sign up
ProfileName, age, sex, height, weight, goals, dietary preferences, activity levelYou, during onboarding & in Settings
Health logsMeals (text + photos), workouts (sets, reps, weight, RPE, duration, extras), sleep (duration, quality, factors), supplements, body weight historyYou, in the app
Connected health platforms (optional)Sleep sessions and workouts, including ones recorded by an Apple Watch or another device that saves to Apple Health or Health Connect. Details in section 2a.Apple Health (iPhone) or Health Connect (Android), read-only, only after you connect in Settings
Lab resultsPDF/image uploads of blood-work reports + structured analyte values extracted by AI OCRYou, when you upload
Personal Notes / JournalFree-form text, biomarkers, symptoms, mood entries you type into the JournalYou
Subscription stateActive / inactive Pro tier, RevenueCat anonymous user IDRevenueCat (our payments processor)
Usage / Product interactionWhich screens you open, when you create a log, when you view or start a subscription, paired with your account ID. Never the health or nutrition values you enter. Also includes an approximate location (country, region, city) that PostHog works out from your IP address; PostHog then discards the IP address itself.PostHog (our product-analytics processor)
DiagnosticCrash logs, error stack traces (no PII)Sentry
Local-only signalsStreak counts, app preferences, cached AI responsesOn-device only (SharedPreferences)

We do NOT collect: precise location, contacts, browsing history outside the app, microphone audio (the speech-to-text feature converts voice to text on-device or via Apple SpeechFramework before any text leaves the device), social-graph data, or anything from Apple Health or Health Connect beyond the sleep and workouts in section 2a, and those only after you connect.

Notifications. If you allow them, we send reminders and nudges through Apple Push Notification service (Android will use Google's push service when the Android app ships). The notification text never contains a lab value, a weight, or anything else you logged, so nothing sensitive shows on your lock screen. Turn them off any time in your device settings or in Settings then Notifications inside the app. Notifications are optional and the app works without them.

2a. Apple Health and Health Connect (optional)

Nutrify.AI can read sleep and workouts from Apple Health on iPhone, or from Health Connect on Android. This is off until you turn it on in Settings, then Wearables, then Connect, and confirm on the permission screen your phone shows. Data from an Apple Watch, or from any other watch or ring that saves to Apple Health or Health Connect, arrives the same way. This feature shipped in app version 1.4.0.

What we read.

  • Sleep sessions: when you went to bed, when you woke up, how long you slept, and the minutes of light, deep, and REM sleep when your device records them.
  • Workouts: the type, the start and end time, the duration, the calories your device counted, and the ID your phone gave the workout, so we never import the same one twice.

What we do not read. Heart rate, steps, location, medical records, or anything else in Apple Health or Health Connect. We never write anything back into either one.

What happens to it. When you connect, we read the last 30 days. After that we read new entries each time you open the app or tap Sync now. Imported sleep and workouts are stored in your account on Supabase next to what you log by hand, marked as imported, and every section of this policy treats them as health data. They show in your charts and, like anything you log, they can be part of the bounded slice sent to Google Gemini (or Anthropic Claude on failover) when the coach, the sleep insights, or the morning brief run for you. They are never used for advertising or marketing, never sold, never given to a data broker, never used for data mining, never stored in iCloud, and never shared with anyone except the processors in section 4. Apple and Google do not receive your Nutrify.AI data through this feature: the read happens on your phone.

Turning it off. Settings, then Wearables, then Disconnect stops new imports. You can also take away Nutrify.AI's access inside the Apple Health app or the Health Connect app. Sleep and workouts already imported stay in your history until you delete them one by one or delete your account.

3. How we use your data

Most of what you log with Nutrify.AI is health data. Under the GDPR that is "special category" data and it gets extra protection, so we ask for your explicit consent before we process any of it, separately from your agreement to the Terms. You give that consent at sign-up and you can withdraw it at any time by emailing privacy@devxgroup.io or by deleting your account in Settings. Withdrawing stops all future processing. It does not undo processing we already did while your consent was in place.

If you withdraw consent, Nutrify.AI cannot do the thing it exists to do, so withdrawing also ends your ability to use the health features.

PurposeLegal basis (GDPR)Data used
Provide the core service: log + chart + summarize your health dataArt. 6(1)(b) contract + Art. 9(2)(a) explicit consentAll health logs, profile
Generate personalized AI recommendations (chat replies, daily actions, meal plans, sleep insights, supplement advice, workout plans, lab summaries)Art. 6(1)(b) contract + Art. 9(2)(a) explicit consentA bounded user-context slice + your prompt; sent to Gemini (Google) and, on quota failover, Anthropic Claude. The slice can include sleep and workouts imported from Apple Health or Health Connect (section 2a)
Extract structured analyte values from uploaded lab PDFs/imagesArt. 6(1)(b) contract + Art. 9(2)(a) explicit consentThe uploaded file; sent to Gemini
Bill subscriptionsArt. 6(1)(b) contract performanceApple/Google receipt (handled by Apple StoreKit + RevenueCat)
Detect, fix, and prevent crashesArt. 6(1)(f) legitimate interestStack traces, device model, OS version
Understand how people use the app so we can fix problems and improve itArt. 6(1)(a) consent in the EEA and UK; Art. 6(1)(f) legitimate interest elsewhereProduct-usage events (screens opened, logs created, subscription views) tied to your account ID; never your meals, weight, sleep, or other logged values
Comply with App Store, GDPR, CCPA, and applicable consumer-protection lawArt. 6(1)(c) legal obligationWhatever the law requires

We do NOT use your data for: advertising, cross-app or cross-company tracking, behavioral profiling that follows you outside Nutrify.AI, model training (third-party or our own), or sale to data brokers. We do use first-party, in-product analytics (PostHog) to understand how people use the app and improve it; that data stays first-party, is never used for advertising, and is described in the rows above and §4.

4. Third-party processors

We share data only with the processors strictly required to operate the app, each under a written data-processing agreement.

ProcessorRoleRegionData sent
Supabase Inc.Authentication, database, file storageUnited StatesAccount + health data + lab files
Google LLC (Gemini API)LLM inference, embeddings, OCRUnited StatesPer-request user-context slice + prompt
Anthropic, PBC (Claude API)LLM inference fallback when Gemini is rate-limitedUnited StatesSame per-request slice as Gemini
Apple Inc.App Store sign-in, push notifications, StoreKit subscriptionsRegion of user's Apple accountApple-managed identifiers
Google LLC (Sign-in with Google)OAuth sign-inUnited StatesGoogle account ID, email
RevenueCat Inc.Subscription management abstractionUnited StatesAnonymous user ID, Apple/Google receipt
PostHog Inc.First-party product analytics (US Cloud, us.i.posthog.com)United StatesEvent names and timestamps that describe what you did (opened a screen, created a log, uploaded a report, viewed the paywall) plus your account ID, and masked session replay of the paywall screens only. Never the contents of anything you log. PostHog also turns your IP address into an approximate location (country, region, city, postal code, and coordinates) and stores that location on your analytics profile; it discards the IP address itself right after. We use this only to see which countries and regions use Nutrify.AI, never for advertising, and never shared outside PostHog.
Resend, Inc.Transactional email, meaning the emails the app has to send you, such as your account deletion confirmation and our replies to your support messagesUnited StatesYour email address and the text of that email
Functional Software, Inc. (Sentry)Crash + error reportingUnited StatesStack traces, device model, app version
Vercel Inc.Hosting for our in-app feedback relay (form-relay, operated by DevX Group)United StatesYour email, feedback message, app version, and a short-lived link to a screenshot if you attach one
DevX Group LLCOperator (us)United StatesAll of the above, scoped to your account

Sub-processors of these vendors (e.g., AWS, GCP) operate under each vendor's published sub-processor list. We update this table whenever a primary vendor changes.

Apple Health and Health Connect are not processors. When you connect them (section 2a), the read happens on your phone. Apple and Google never receive your Nutrify.AI data through that connection.

Food databases. When you scan a barcode or log a food, our server looks up nutrition facts in the U.S. Department of Agriculture's FoodData Central and in Open Food Facts. The request carries only the barcode number or food description, never your name, account ID, or any other personal data.

5. Where your data is stored

Primary storage is Supabase US-East. Processing for AI inference happens on the AI vendor's infrastructure (Google US, Anthropic US). Crash diagnostics live on Sentry US. By using Nutrify.AI you consent to international transfer of your data, including, where applicable, transfer outside the European Economic Area, the United Kingdom, or other jurisdictions, under the EU Standard Contractual Clauses or equivalent legal mechanism.

5a. EU and UK residents: Article 27 representation

DevX Group LLC is established in the United States and offers Nutrify.AI to users in the European Economic Area and the United Kingdom, so Article 27 of the GDPR and of the UK GDPR applies to us and we treat it as binding.

Write to privacy@devxgroup.io for our current Article 27 representation arrangements, and for anything you would otherwise raise with a representative: access, correction, erasure, objection, restriction, portability, withdrawal of consent, or a complaint. Requests from the EEA and the UK are handled by us directly, on the timelines in §7, so nothing is lost in a hand-off.

None of this narrows your rights. You can always complain to your own supervisory authority (in the EEA, your national data protection authority; in the UK, the Information Commissioner's Office) without contacting us first.

6. How long we keep your data

DataRetention
Account + all health logs + journal entries + lab filesUntil you delete your account. Deletion is immediate, hard-delete (cascade), and permanent in the live database. Residual copies inside encrypted backups age out within 90 days (see Backups below)
Sleep and workouts imported from Apple Health or Health ConnectSame as your other health logs. Disconnecting stops new imports but does not delete what was already imported; delete those entries one by one in the app, or delete your account
Analytics events at PostHogTied to your account lifecycle: deleted when you delete your account, and we stop collecting them the moment you turn analytics off in Settings
AI inference logs at our vendorsPer vendor terms (Google: ≤ 24 hours abuse-monitoring buffer; Anthropic: ≤ 30 days under its commercial API terms; neither uses your data to train models)
BackupsOur database host takes automatic daily backups that it keeps for 7 days. On top of those we take our own encrypted backups, kept for up to 90 days, stored on access-controlled devices and an access-controlled private cloud account under DevX Group control. Backups exist only for disaster recovery; we never read individual accounts out of them, and deleted accounts age out of them within 90 days
Crash diagnostics90 days at Sentry, then auto-deleted
Subscription receipts7 years (tax/audit obligation)

7. Your rights

Regardless of jurisdiction, you can:

  • Export your data: Settings → Support → "Export My Data" gives you a JSON archive of your data on the spot, right in the app. You can also email privacy@devxgroup.io from the address on your account and we will send the archive within the windows described under "How long we take" below.
  • Correct your data: edit any log directly in the app; the underlying row updates immediately
  • Delete your data: Settings → Account → "Delete Account". This hard-deletes your row in auth.users and cascade-deletes every child table including journal entries, lab files, and chat history within minutes (your analytics identity is erased at PostHog in the same pass; other vendor copies expire on their documented windows)
  • Disconnect Apple Health or Health Connect: Settings → Wearables → "Disconnect", or take away Nutrify.AI's access in the Apple Health or Health Connect app. New imports stop right away (section 2a)
  • Object / restrict / portability (GDPR / UK GDPR): email privacy@devxgroup.io
  • Opt out of sale (CCPA, CPRA): we do not sell. There is nothing to opt out of.
  • Turn off analytics: Settings → Support → "Share anonymous analytics". Flip it off and we stop collecting product-usage events right away.
  • Children's data: Nutrify.AI is not directed to children under 16. We do not knowingly collect data from anyone under 16. If you believe a child has provided data, email us and we will delete it.

If you live in the EEA, UK, or Switzerland, you may also lodge a complaint with your national data-protection authority.

How long we take. We confirm we got your request within 10 days and answer it within 45 days. If it is complicated we may take another 45 days, and we will tell you before the first 45 are up. There is no charge unless a request is repetitive or excessive, and we will tell you before charging anything.

Someone acting for you. You can authorize another person or a service to make a request on your behalf. Send us written proof that you authorized them. We may still check with you directly before acting.

If we say no. We will tell you why in writing. You can appeal by replying to that email with the word "appeal". A different person reviews it and answers within 45 days. If we still say no, you can complain to your state attorney general, or, in the EEA, UK, or Switzerland, to your national data-protection authority.

No retaliation. We will never give you a worse price, a worse service, or a worse experience because you used one of these rights.

7a. Washington and Nevada consumer health data

If you live in Washington State or Nevada, you have extra rights over the health data you give us. We publish those rights in a separate Consumer Health Data Privacy Policy, linked from the home page and from Settings inside the app, as those laws require.

The short version: we collect your consumer health data only after you agree to it at sign-up, we never share or sell it, and you can ask us to delete it by emailing privacy@devxgroup.io or by deleting your account in Settings. We respond to a deletion request within 30 days: your live data is hard-deleted immediately, your analytics identity and events are erased at PostHog, and remaining processor copies expire on their documented windows (Sentry diagnostics and our encrypted backups within 90 days). Nobody at DevX Group can access your health data except to fix a problem you have reported to us or to keep the service running, and that access is logged.

8. Security

In transit: TLS 1.2+ on every API call. Authentication: Supabase Auth + Apple/Google OAuth + Sign-in-with-Apple. Authorization: Postgres row-level security: every read/write is scoped to your auth.uid(); this is enforced in the database, not the application. Storage: Apple-managed iCloud-encrypted on device; Supabase-managed encryption at rest in the cloud (AES-256). API secrets: never embedded in the app binary; all AI keys live server-side in Supabase Edge Function environment variables.

We are a small team. We will not promise SOC 2 today; we will tell you the truth: we follow the same practices SOC 2 demands (least-privilege access, encrypted at rest and in transit, audit logs, password rotation, deny-by-default RLS) but we are not externally audited yet.

8a. If something goes wrong

If your health data is ever exposed to someone who should not have it, whether through a security incident or through a disclosure we did not have your permission to make, we will email you at the address on your account without unreasonable delay and no later than 60 days after we find out. The notice will say what happened, what data was involved, what we have done about it, and what you can do. Where the law requires it we will also notify the US Federal Trade Commission, the relevant data-protection authorities, and, for large incidents, the media.

9. Health-data disclaimer

Nutrify.AI is not a medical device. The advice, summaries, and recommendations the app produces are general wellness information, not medical diagnosis or treatment. Always consult a licensed clinician before changing your diet, exercise, supplementation, or medication.

HIPAA does not apply here. DevX Group LLC is not a HIPAA covered entity and not a business associate of one. Nutrify.AI is a consumer wellness app, not a healthcare provider, health plan, or clearinghouse. The lab reports and health data you put into it are not protected health information under HIPAA. They are protected by this policy, by the state and national privacy laws described in §7 and §7a, and by the security measures in §8, but not by HIPAA. If you want your doctor's copy of your records to stay under HIPAA, keep it with your doctor.

10. Children and parental control

The app is rated 16+ on the App Store given the scope of AI conversations on health topics. We do not market to children and do not collect data from anyone under 16.

11. Changes to this policy

If we materially change how we collect or use data, we will (a) update this Markdown file, (b) update the hosted copy, (c) bump the "Last updated" date, and (d) announce the change prominently in the app before it takes effect. Non-material clarifications (typo fixes, layout changes) update silently.

Recent changes. 2026-08-30: added Resend, Inc. to the processor table (it sends the account deletion confirmation and support replies), matching the in-app policy screen. 2026-08-30: disclosed that PostHog derives an approximate location (country, region, city, postal code, coordinates) from your IP address for country-level product statistics, and that PostHog discards the IP address itself right after. 2026-08-27: added section 2a for the optional Apple Health and Health Connect import that shipped in app version 1.4.0, and removed the earlier line that said Apple HealthKit was not integrated. 2026-08-08: disclosed masked paywall session replay and the in-app feedback relay.

12. Contact

privacy@devxgroup.io. Typical response within 5 business days.
DevX Group LLC, PO Box 5010, PMB 76, Rancho Santa Fe, CA 92067
Nutrify.AI
Terms Privacy Consumer Health Data Support

© 2026 Nutrilogical.co. All rights reserved.

Developed by DevX Group LLC