Privacy Policy
Effective Date: August 30, 2026 | Version: 0.9.8 | Contact: privacy@mainnutrition.app
Table of Contents
1. Introduction & Scope
Welcome to Main Nutrition ("we", "our", "us", or "Main Nutrition Platform"). We are committed to protecting your personal data, biometric insights, and privacy rights. This Privacy Policy governs our web application (mainnutrition.app), mobile interfaces, background synchronization engines, and related services (collectively, the "Service").
By creating an account, accessing the application, or utilizing any of our meal analysis and health tracking features, you acknowledge that you have read, understood, and agreed to the practices outlined in this Privacy Policy.
2. Information We Collect
We collect information you provide directly, data generated through your use of the Service, and metrics synced from authorized third-party health ecosystems:
A. Account & Authentication Data
- Identity Information: When you sign in using Google OAuth or Firebase Authentication, we collect your unique account identifier (UID), full name, email address, and profile picture avatar.
- User Profile Parameters: Target body weight, biological sex, birth year/age, height, baseline physical activity levels, dietary preferences (e.g., keto, vegan, Mediterranean, omnivore), and daily caloric or macronutrient targets.
B. Dietary, Meal & Image Data
- Meal Photographs & Scans: Images of food and beverages submitted for AI vision recognition and macronutrient breakdown.
- Meal Logs & Notes: Dish names, estimated portion weights (grams, pieces, volumes), ingredients, timestamps, and personal culinary notes.
- Hydration & Fasting Logs: Water consumption logs, liquid type classifications (water, coffee, tea, isotonic), and intermittent fasting interval windows.
- Barcode & Ingredient Scans: Barcode numbers (EAN/UPC) and packaging ingredient lists parsed through the Safe Choice radar and E-Decoder database.
C. Health & Biometric Data (With Explicit User Consent)
- Physical Activity & Energy Expenditure: Daily step counts, active energy burned (kcal), and workout intervals synced via Google Fit or Apple Health.
- Biometric Vitals: Body weight trends, resting and active heart rate recordings, blood pressure, fasting blood glucose, and custom biomarker entries entered or synced.
D. Technical & Device Information
- Browser user-agent, operating system, IP address, approximate geographical region (for local store and food database relevance), crash logs, and localized theme configurations (Light, Dark, S.T.A.L.K.E.R., Cyberpunk).
3. Google API Services User Data Policy & Limited Use Disclosure
Main Nutrition's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When you choose to connect Google Fit with Main Nutrition, we request specific OAuth permissions to deliver biometric sync and calorie reconciliation:
- https://www.googleapis.com/auth/fitness.activity.read — Used strictly to read daily steps and active caloric expenditure to balance your real-time nutritional budget.
- https://www.googleapis.com/auth/fitness.body.read — Used strictly to import body weight and composition logs to track weight goals.
- https://www.googleapis.com/auth/fitness.nutrition.read & fitness.nutrition.write — Used to synchronize recorded meal calories and macros with your central Google Fit journal.
- https://www.googleapis.com/auth/fitness.heart_rate.read — Used to monitor cardiovascular response and metabolic demand.
Our Strict Commitments Regarding Google User Data:
- No Advertising: Google user data is NEVER used or transferred for serving advertisements, including retargeted, personalized, or interest-based advertising.
- No Sale or Monetization: We NEVER sell, rent, or lease Google user data to data brokers, advertising networks, or any commercial third parties.
- No Model Training: Google user data is NEVER used to train or fine-tune generalized artificial intelligence (AI) or machine learning (ML) models without explicit user consent.
- Human Review Restrictions: No human employees or contractors are permitted to read your raw Google Fit user data, except:
- When you provide explicit consent to investigate a specific technical support request;
- When strictly necessary for security purposes (e.g., investigating abuse or system vulnerabilities); or
- When required to comply with applicable statutory laws or binding judicial orders.
4. Gemini AI Meal Vision & Multimodal Processing
Main Nutrition utilizes Google Cloud's enterprise Gemini Multimodal Vision API to recognize dishes, estimate portion sizes, and calculate macro/micronutrient compositions from uploaded meal photographs.
- Secure Server-Side Proxy: All AI inference requests are routed through authenticated server-side API proxies (/api/analyze-meal). Your personal API keys and direct account tokens are never exposed in browser clients.
- Ephemeral Vision Inference: Images submitted for nutritional parsing are processed transiently for visual inference and are not retained by Google Cloud base models for third-party foundation training.
- User Storage Control: Stored meal photos in your personal history log are encrypted within Google Cloud Firestore and Firebase Storage under your isolated user ID container.
5. How We Use Your Information
We use your information exclusively to operate, maintain, and enhance the Main Nutrition platform, specifically:
- Calculating personalized basal metabolic rates (BMR), total daily energy expenditure (TDEE), and dynamic calorie surpluses/deficits.
- Analyzing meal photos and calculating protein, carbohydrate, healthy fats, dietary fiber, sodium, caffeine, and micronutrient amounts.
- Screening processed foods and additives against your personal medical and lifestyle exclusions using the Safe Choice radar and E-Decoder.
- Generating intelligent grocery restock shopping lists via the autonomous Nutri-Agent based on detected dietary deficiencies.
- Powering gamified streaks, habit milestones, and longevity biomarkers.
- Managing billing, invoices, and active subscriptions through Stripe.
- Maintaining offline resilience via local IndexedDB and localStorage synchronization.
6. Data Sharing & Third-Party Service Providers
We do NOT sell, trade, or rent your personal health data to third parties. We share information only with trusted cloud infrastructure providers bound by strict confidentiality and data protection agreements:
- Google Cloud & Firebase: Provides secure authentication, Cloud Firestore database storage, and hosting. (Compliant with ISO 27001, SOC 1/2/3, and GDPR).
- Stripe, Inc.: Processes payment card transactions, subscription management, and customer portal sessions. Payment card details are tokenized and processed directly by Stripe (PCI-DSS Level 1 certified); we never store raw credit card numbers.
- Legal & Regulatory Authorities: We may disclose data if legally compelled by a valid subpoena, court order, or applicable legal obligation to protect against fraud or imminent harm.
7. Data Storage, Security & Retention
Your data is stored in the us-west1 Google Cloud / Firestore multi-region cluster with enterprise-grade AES-256 encryption at rest and TLS 1.3 encryption in transit.
- Role-Based Access: Access to Firestore collections is strictly governed by authenticated Firebase Security Rules enforcing user-level isolation (request.auth.uid == userId).
- Retention Policy: We retain your meal history, biometric logs, and profile records for as long as your account remains active. If you delete your account, your data is scheduled for permanent purging across primary and subcollection stores within 30 days.
8. Your Rights (GDPR & CCPA / CPRA)
Depending on your jurisdiction, you possess specific statutory rights regarding your personal information:
- Right to Access: You have the right to request a complete export of your personal data, meal logs, and synced records in a structured, machine-readable JSON format.
- Right to Rectification: You can edit or update inaccurate meal logs, profile metrics, or weight entries directly within the application at any time.
- Right to Erasure ("Right to Be Forgotten"): You have the right to request the permanent deletion of your account and all associated Firestore documents.
- Right to Restrict Processing: You can disconnect wearable health sync (Google Fit / Apple Health) at any moment in the Settings panel.
- Non-Discrimination: We will never discriminate against you, alter service tiers, or deny functionality because you exercised your privacy rights.
9. Account Deletion & Revocation Instructions
You maintain complete control over your account and data:
- In-App Deletion: Navigate to Settings & Goals → Account → Delete Account. Confirming deletion immediately wipes your profile, meal history, water logs, biomarker metrics, and local cache.
- Google Permissions Revocation: You can disconnect Main Nutrition's access to your Google Fit account at any time by visiting Google Account Security Permissions.
- Manual Erasure Request: Send an email from your registered account to privacy@mainnutrition.app with the subject line "Data Erasure Request". We will process and confirm your request within 7 business days.
For dedicated step-by-step guidance, please review our Data Deletion Instructions.
10. Children's Privacy
Main Nutrition is not directed to children under the age of 13 (or under 16 in the European Union). We do not knowingly collect or solicit personal data from children. If we become aware that personal information has been collected from a child without verified parental consent, we will promptly delete that data from our servers.
11. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect enhancements in our architecture, regulatory updates, or new Google API requirements. When changes are made, we will revise the "Effective Date" at the top of this page. Significant modifications will be announced via an in-app banner or email notification.
12. Contact & Data Protection Officer
If you have questions, feedback, or concerns regarding this Privacy Policy or our data handling practices, please contact our Data Protection team:
Email: privacy@mainnutrition.app
Support Desk: support@mainnutrition.app
Official Website: https://mainnutrition.app