Google API Services User Data Policy & Limited Use Disclosure
Effective Date: August 30, 2026 | Version: 0.9.8 | Compliance Officer: privacy@mainnutrition.app
Main Nutrition's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Table of Contents
1. Purpose of This Disclosure
This document explains specifically how Main Nutrition accesses, processes, stores, and protects user data received through Google OAuth and Google Fit APIs. It demonstrates our strict compliance with Google's API Services User Data Policy.
2. Google OAuth Scopes Requested & Functional Need
When you enable Google Sign-In or Google Fit wearable synchronization in Main Nutrition, we request access only to the minimum required scopes:
Purpose: Used during initial sign-in to authenticate your identity, display your name and profile avatar, and associate your personalized meal logs with your secure account container.
Purpose: Reads daily step counts and active energy expenditure (calories burned) from Google Fit to calculate your total daily energy expenditure (TDEE) and adjust your real-time caloric balance.
Purpose: Imports body weight logs recorded on smart scales or wearable devices to graph progress against target weight goals.
Purpose: Synchronizes meal calorie and macronutrient records between Main Nutrition and your Google Fit health log, ensuring a unified wellness record across your devices.
Purpose: Reads resting and workout heart rate metrics to gauge cardiovascular demand and calibrate metabolic expenditure.
3. How Google User Data Is Processed
Google Fit data imported into Main Nutrition is utilized strictly within the user-facing application for:
- Dynamic calorie reconciliation (subtracting calories burned from consumed food calories).
- Macronutrient ratio optimization based on physical exertion level.
- Hydration intake target recommendations based on workout volume and sweat loss.
- Visual progress charts and streak gamification.
4. Strict Limited Use Guarantees
Main Nutrition strictly adheres to the four core pillars of the Google Limited Use Policy:
We do NOT use, transfer, or disclose Google user data to serve advertisements, including personalized, retargeted, or interest-based advertising.
We do NOT sell, lease, trade, or transfer Google user data to data brokers, information aggregators, marketing networks, or any third party, except as strictly necessary to host and deliver the application via certified cloud infrastructure (Google Cloud/Firebase).
We do NOT use Google user data to train, fine-tune, or improve generalized or non-personalized artificial intelligence (AI) or machine learning (ML) models without prior explicit affirmative user consent.
No humans are permitted to read raw user Google Fit data unless:
- The user has provided explicit consent to investigate a specific technical support issue;
- It is strictly necessary for security purposes (such as investigating abuse or malware); or
- It is required to comply with applicable statutory laws or binding judicial orders.
5. Data Protection, Encryption & Storage
Google Fit tokens and imported fitness metrics are stored in Firestore under authenticated rules (request.auth.uid == userId) with AES-256 encryption at rest and TLS 1.3 encryption for all data in transit. OAuth tokens are refreshed through secure server proxies and never exposed in browser script logs.
6. How to Revoke Google Fit Access
You can disconnect Google Fit from Main Nutrition at any time through either of two methods:
- Within the App: Go to Settings & Goals → Wearables → Disconnect Google Fit.
- Via Google Account Security: Visit the official Google security portal at https://myaccount.google.com/permissions, locate "Main Nutrition", and click Remove Access.
Revoking access immediately terminates all background synchronizations. You can also wipe previously synced data using the in-app Delete Account button.
7. Verification & Compliance Inquiries
For questions regarding our Google API compliance, security posture, or OAuth verification status, please contact:
Email: privacy@mainnutrition.app
Security Team: security@mainnutrition.app
Domain: https://mainnutrition.app