Privacy Policy

Your privacy is our priority. Learn how we protect your personal health information and give you complete control over your data.

HIPAA Compliant
Apple Privacy Certified
End-to-End Encrypted

Effective Date: July 1, 2025

Last Updated: September 2, 2025

We regularly review and update our privacy policy to ensure transparency and compliance with evolving privacy regulations.

Information We Collect

Health and Wellness Data

  • Mood tracking information (10-point scale ratings and notes)
  • Food and meal logging data including photos
  • Recipe preferences and dietary restrictions
  • Nutrition goals and progress metrics
  • Apple HealthKit data (with your explicit consent only)
  • Location data for grocery store recommendations (optional)

Account Information

  • Email address and authentication credentials
  • Profile information (age, gender, activity level)
  • Subscription and billing information
  • Customer support communications

Usage Data

  • App interaction patterns and feature usage
  • Performance analytics and crash reports (optional)
  • Device information and operating system version

How We Use Your Information

Personalized Experience

  • Generate mood-based recipe recommendations
  • Track your nutrition progress and goals
  • Provide personalized meal planning suggestions
  • Optimize pantry management and reduce food waste

Service Improvement

  • Analyze usage patterns to improve features
  • Identify and fix technical issues
  • Develop new features based on user needs
  • Enhance AI recommendation algorithms

Communication

  • Send important service updates and notifications
  • Provide customer support and respond to inquiries
  • Share optional wellness tips and insights
  • Process subscription and billing information

Data Sharing and Disclosure

We Never Sell Your Data

  • Your personal health information is never sold to third parties
  • We do not share identifiable data with advertisers
  • No data brokers or marketing companies receive your information
  • Your privacy is our highest priority

Limited Sharing Scenarios

  • Service providers (cloud hosting, analytics) under strict data agreements
  • Legal requirements (court orders, regulatory compliance)
  • Protecting rights and safety (fraud prevention, security threats)
  • Business transfers (with equivalent privacy protections)

Your Control

  • Opt out of optional data sharing at any time
  • Control which HealthKit data we access
  • Manage analytics and crash reporting preferences
  • Delete your account and data whenever you choose

Data Security

Encryption and Protection

  • End-to-end encryption for sensitive health data
  • TLS/SSL encryption for all data transmission
  • Secure cloud storage with industry-leading providers
  • Regular security audits and penetration testing

Access Controls

  • Multi-factor authentication for all team access
  • Role-based access controls and principle of least privilege
  • Regular access reviews and deprovisioning
  • Secure development practices and code reviews

Data Minimization

  • Collect only data necessary for service functionality
  • Automatic deletion of temporary processing data
  • Regular purging of unused or expired data
  • Privacy by design in all new features

Your Privacy Rights

Access and Control

  • View all personal data we have collected
  • Export your data in a portable format
  • Correct any inaccurate information
  • Delete your account and all associated data

Consent Management

  • Withdraw consent for data processing at any time
  • Opt out of optional features like analytics
  • Control location services and HealthKit integration
  • Manage notification and communication preferences

Regional Rights

  • GDPR rights for European users
  • CCPA rights for California residents
  • PIPEDA compliance for Canadian users
  • Local privacy law compliance worldwide

Health Information Protection

HIPAA Compliance

  • Business Associate Agreements with healthcare providers
  • Strict controls on health information access
  • Audit trails for all health data processing
  • Staff training on healthcare privacy regulations

Apple HealthKit Integration

  • Explicit user consent required for each data type
  • Granular control over which metrics to share
  • Data stays on your device unless explicitly shared
  • Comply with Apple's strict health data policies

Health Data Special Protections

  • Additional encryption layers for health information
  • Separate storage and access controls
  • Enhanced monitoring and alerting
  • Regular compliance audits and certifications

Privacy Questions?

For questions about this privacy policy or to exercise your privacy rights, contact us at:

legal@nourishmate.app

We respond to all privacy requests within 30 days