Privacy Policy
This Privacy Policy describes how NutriAID Nutrition Companion ("we", "our") collects, uses and protects the personal data of users ("you", "the user") within the web application available at nutriaid.eu.
By creating an account and using the application, you agree to the terms of this Privacy Policy.
1. Data we collect
We collect only the data you voluntarily provide or that is necessarily generated through your use of the platform:
- Account data: Your name, email address and password (stored encrypted using a secure hashing algorithm).
- Profile data: Dietary preferences, food intolerances and allergies you set in the application.
- Journal data: Foods consumed, symptoms recorded, their intensity and personal notes.
- Recipe data: Generated and saved recipes, meal plans, shopping lists, and usage history of the Cooking Mode feature.
- AI guidance data: History of AI-generated recommendations and nutritional progress reports, including any PDF exports you request.
- Subscription data: Your active subscription plan (Basic / Pro / Pro+), trial status, start date, and Early Adopter status. Payment card data is processed exclusively by Stripe Inc. and is never stored on our servers.
- Newsletter consent data: Newsletter subscription preference, consent timestamp and consent source (post-registration popup or footer form), only if you have given explicit consent.
- Technical data: IP address, browser type, usage sessions — solely for security and application functionality purposes.
- 2FA security data: TOTP secret key if you enable two-factor authentication (stored encrypted).
We do not collect card numbers, national identification numbers, or other government identifiers.
2. How we use your data
Your data is used exclusively for:
- Providing application features (account management, AI recommendations, journal storage, recipe generation, and meal planning).
- Personalising recipes and nutritional guidance according to your intolerance profile and preferences.
- Managing your subscription and processing payments through Stripe.
- Ensuring the security of your account and preventing unauthorised access (including via reCAPTCHA and 2FA).
- Sending newsletter communications if you have given explicit consent and have not withdrawn it.
- Improving the application based on aggregated and anonymised usage data.
- Necessary technical communications (password reset, security notifications).
- Analysing marketing campaign performance via TikTok Pixel, only if you have accepted marketing cookies.
We do not sell your data to anyone.
3. Legal basis for processing
We process your data on the basis of:
- Consent (Art. 6(1)(a) GDPR): given when creating your account, subscribing to the newsletter, and accepting marketing cookies (TikTok Pixel).
- Contract (Art. 6(1)(b) GDPR): performing the services you request through the use of the application and any paid subscription.
- Legitimate interest (Art. 6(1)(f) GDPR): platform security, fraud prevention, and anonymised usage analysis.
- Legal obligation (Art. 6(1)(c) GDPR): retention of financial records in accordance with applicable tax law.
Health data (Art. 9 GDPR): Food intolerance and allergy data may constitute special category health data under Art. 9 GDPR. We process this data solely on the basis of your explicit consent given when completing your profile.
4. Third-party partners and data processors
We do not sell, rent or share your data with third parties for commercial purposes. We work with the following technical data processors, each acting strictly on our instructions or as an independent data controller:
- Stripe Inc. (USA) — payment card processing. Stripe is an independent data controller for financial information. We do not store card data on our servers. See the Stripe Privacy Policy.
- Google LLC (USA) — reCAPTCHA v3 service for anti-bot protection at login and registration. reCAPTCHA collects behavioural data and browser fingerprints and transfers them to the USA under European Commission Standard Contractual Clauses. See the Google Privacy Policy.
- TikTok Technology Limited (Ireland / Singapore / USA) — TikTok marketing pixel, used to measure advertising performance and analyse audiences. The pixel collects data about page visits, platform events, and IP addresses (partially anonymised). This data may be transferred to and stored outside the European Economic Area (EEA), including in the USA and Singapore. You may withdraw consent for TikTok Pixel at any time via the cookie settings. See the TikTok Privacy Policy.
- Hosting / infrastructure providers: the application and database servers are hosted within the EU or in countries with an adequate level of protection recognised by the European Commission.
- AI model providers: user AI requests are processed via external APIs (e.g. OpenAI, Google Gemini, or compatible endpoints, configurable by the operator). Requests contain only the profile and journal data relevant to generating the response; we do not transmit direct identification data (email, name) to AI providers.
Data may be disclosed to competent authorities only where there is a legal obligation (court order, competent authority request).
5. Data security
We implement appropriate technical and organisational measures to protect your data:
- Passwords are stored encrypted using secure hashing algorithms (bcrypt).
- Communications are protected via HTTPS/TLS.
- Sessions are managed via HttpOnly, secure cookies with no JavaScript exposure.
- Access to user data is strictly restricted (role-based access control).
- Two-factor authentication (2FA/TOTP) is available optionally for all users.
- Automated scheduled backups with encrypted S3-compatible storage.
- We carry out periodic security reviews and code audits.
6. Data retention
Your data is retained for as long as your account is active or as long as necessary to provide the service. Upon account deletion, all personal data (profile, journal, recipes, AI history, newsletter preferences) is permanently removed within 30 days. Billing data may be retained for up to 5 years in accordance with applicable tax law obligations. Aggregated and anonymised data may be retained for internal statistics.
7. Your rights (GDPR)
Under GDPR, you have the right to:
- Access (Art. 15): Request a copy of your personal data — also available via the JSON export feature in the Privacy & GDPR section of your dashboard.
- Rectification (Art. 16): Correct inaccurate or incomplete data in your Profile.
- Erasure (Art. 17): Request deletion of your data ("right to be forgotten") — also available via the account deletion button in your dashboard.
- Restriction (Art. 18): Limit processing of your data in certain situations.
- Portability (Art. 20): Receive your data in a structured, machine-readable format (JSON) — available directly from your dashboard.
- Objection (Art. 21): Object to processing based on legitimate interest or for marketing purposes.
- Withdrawal of consent: At any time, without affecting the lawfulness of prior processing. You can unsubscribe from the newsletter via your dashboard (GDPR section) or via the unsubscribe link in any newsletter email.
To exercise these rights, contact us at contact@nutriaid.eu. We respond within 30 days.
8. Cookies and similar technologies
We use several categories of cookies:
- Strictly necessary cookies: authentication sessions (HttpOnly, secure) — without these the application cannot function. These do not require consent.
- Marketing cookies (optional): TikTok Pixel uses cookies and local storage mechanisms to measure advertising performance. These cookies require your explicit consent before being activated. You may withdraw consent at any time.
Full details in the Cookies Policy.
9. International data transfers
Your data may be transferred outside the European Economic Area (EEA) in connection with the use of Stripe (USA), Google reCAPTCHA (USA), and TikTok Pixel (USA/Singapore). These transfers are carried out on the basis of Standard Contractual Clauses adopted by the European Commission (Art. 46 GDPR) or other adequate transfer mechanisms. Application and database hosting data is stored within the EEA.
10. Policy changes
We may update this policy periodically. We will notify you by email or in-app notification at least 30 days before significant changes take effect.
11. Contact and supervisory authority
For any questions regarding data privacy, contact us:
- Email: contact@nutriaid.eu
You have the right to lodge a complaint with the National Supervisory Authority for Personal Data Processing (ANSPDCP) in Romania — www.dataprotection.ro — or with your national data protection authority.
Other legal documents