myNutrition

myNutrition Privacy Policy

Last updated: 22 August 2026

This policy applies to the myNutrition app until superseded. Previous versions are available on request.

Policy URL: https://mynutrition.fitness/privacy/

This policy forms part of our Terms of Use.

This policy explains, in plain English, what myNutrition does with your information. The short version: myNutrition is built to keep your data on your own phone. By default, nothing you log ever leaves your device, and what is stored is encrypted so that only you can read it. We don’t run analytics, we don’t show ads, and we never sell your data.

If you only read one section, read “The short version” below.


The short version


1. Who is responsible for your data (data controller)

myNutrition is operated by:

Halocline Labs Limited, a company incorporated in Hong Kong (company number 80831136), registered office: Unit 2904-05, 29/F, Universal Trade Centre, 3 Arbuthnot Road, Central, Hong Kong.

For any privacy question or request — including a request to access or correct your data — you can reach the data controller in writing:

Halocline Labs Limited (data controller)
Unit 2904-05, 29/F, Universal Trade Centre, 3 Arbuthnot Road, Central, Hong Kong
Email (preferred): support@mynutrition.fitness

For users in the EU, UK, or Hong Kong, the operator above acts as the “data controller” for any personal data we actually process. Note that for almost all data this is just you on your own device — see Section 4 for an honest explanation.

EU / UK representative (Article 27): For users in the EU/UK who enable the optional cloud backup, the personal data we process on our servers is an account email address, a one-way login code, end-to-end-encrypted ciphertext that we have no means to decrypt, and the readable information saved alongside each backup and consent record that is listed in full in Section 6; for everyone else, we process no EU/UK personal data on any server at all. We have assessed that this server-side processing is very small in scale, that the only data identifying you by name is an email address, the remainder being information tied to that account rather than naming you, that the health and nutrition content exists on our servers solely as ciphertext we cannot read, and that the processing is therefore unlikely to result in a risk to your rights and freedoms. On that combined basis we currently consider that an Article 27 representative is not required. We keep this assessment under review and, if the scale or nature of our server-side processing changes, we will appoint a representative and name them here.


2. What myNutrition is (and isn’t)


3. What data the app handles, and where it lives

Everything in this table is stored only on your device unless you specifically enable optional cloud backup. The “user data” categories are encrypted with AES-256-GCM, locked by a key that is derived from your password and only ever exists in your phone’s memory.

WhatExamplesWhere it’s storedEncrypted?
Food & drink logs Item name, amount (g/ml), timestamp, supplement/probiotic servings, your notes, scanned product details On device (AsyncStorage) Yes — AES-256-GCM
Your profile First name, surname, date of birth, biological sex, height, weight, activity level, weight goal, pregnancy status, diet preference, gluten-free / dairy-free toggles On device Yes — AES-256-GCM
App preferences/settings Custom nutrient targets, selected country (sets reference values/units), theme & colors, dashboard layout, custom names/icons, backup settings, warning toggles On device Yes — AES-256-GCM
Planned meals (myPlan) Planned meals with date, ingredients, portions On device Yes — AES-256-GCM
Barcode lookup cache Scanned barcodes and the product results you confirmed (name, brand, nutrients), with short expiry times On device Yes — AES-256-GCM
Account & key material Account email, account ID, biometric/auth preference, wrapped (locked) copies of your encryption key, your recovery code in locked form. Your password is never stored — it only exists in memory to unlock your key. On device, in the OS secure store (iOS Keychain) and AsyncStorage Wrapped/locked by password (PBKDF2 + AES-256-GCM) and/or OS secure store
App preference hint Your theme choice (light/dark/auto), kept so the app looks right at startup On device, OS secure store Protected by OS secure store
Local troubleshooting logs App version, platform, OS version, device model/brand (no device name), navigation screens, barcode-lookup events, performance/error info. No food contents, no profile, no identifiers. On device, plain-text files in the app’s documents folder; kept for 3 days then deleted No (deliberately plain text so the app can log startup/unlock problems before encryption is available)
Particularly sensitive fields. Some profile fields — notably pregnancy status and biological sex — are especially sensitive. They are optional where possible, are stored encrypted on your device only, and are used solely to tailor your nutrient reference values. They are never used for advertising or profiling.
Where product data comes from. Product and nutrient details you add from a scan or search originate from public databases (Open Food Facts and the NIH DSLD). They may be incomplete or inaccurate, and you can edit them in the app at any time.
Important note about your password: your password is never saved anywhere and is never sent to any server. It is used only, in memory, to derive the encryption key that unlocks your data. If you lose both your password and your one-time recovery code, no one — including us — can recover your encrypted data.

4. By default, nothing leaves your device — and who the “controller” really is

When cloud backup is off (the default), all of your personal data stays on your phone, encrypted, and we receive no copy of it. In practical terms, you alone control that data on your own device. We are not processing it on a server, and we have no technical means to access it.

To be honest and precise about the law: until you turn on an optional online feature, the personal data in the app is held locally by you and is not processed by us as a controller on any server. We only become a meaningful “controller/processor” of identifiable account data if and when you enable optional cloud backup (see Section 6), and we facilitate the barcode lookups you trigger (see Section 5), which do not involve your personal data.


5. Barcode and product lookups (the routine internet calls)

When you scan a barcode or search for a product by name/brand, the app contacts public product databases to fetch nutrition information:

ServiceWhat it’s forWhat we sendWhere
Open Food Facts (ODbL, public) Food & drink product lookup The barcode digits only, or product name/brand. No personal data. api.openfoodfacts.org (and regional subdomains)
Open Beauty Facts (ODbL, public) Beauty/personal-care product lookup Barcode digits, or name/brand. No personal data. api.openbeautyfacts.org
Open Products Facts (ODbL, public) General product lookup Barcode digits, or name/brand. No personal data. api.openproductsfacts.org
NIH Dietary Supplement Label Database (DSLD) (US government, CC0 public domain) US supplement lookup Product name, brand, and optionally the barcode digits. No personal data. api.ods.od.nih.gov

These requests are made directly from your device to those services, only when you take an action that needs them, and we cache results on your device to reduce repeat lookups. We do not attach your identity, account, profile or logs to these requests. These third parties have their own privacy practices; the data they hold (product catalogs) is public.


6. Optional cloud backup (off by default, zero-knowledge, EU servers)

Cloud backup is disabled by default and only operates if you explicitly turn it on and agree to it. It lets you keep an encrypted backup of your data off your phone, using Supabase servers in the EU (Ireland).

Who processes your backup. Supabase acts as our processor for the cloud-backup feature and hosts the EU (Ireland) infrastructure on an underlying cloud provider (Amazon Web Services, in the eu-west-1 / Ireland region). A current list of sub-processors is available on request at support@mynutrition.fitness.

How it protects you:

You can turn cloud backup off at any time, and you can delete your cloud account and all backups (see Section 9).

You can also export/import backup files yourself (for example to your own Files app or personal cloud storage) using your device’s file picker — that’s entirely under your control and goes wherever you choose to save it.

If you lose both your password and your one-time recovery code: your encrypted data cannot be recovered by anyone, including us. You can start over by creating a new account on the device, which overwrites the previous account record in the device’s secure store. Any data that was locked under the old password becomes permanently inaccessible.

7. What we do not do

The only “logging” is the local troubleshooting log described in Section 3, which stays on your device for 3 days. If you ever ask us for support, you may choose to attach such a log to an email yourself — nothing is sent unless you do that.

This privacy webpage: it sets no cookies, uses no analytics, and runs no tracking technologies. Its display fonts are served from the page itself, so simply viewing this page does not send your data to any third party. The app itself likewise uses no cookies and no web-tracking technologies of any kind.


8. Legal bases for processing (GDPR / UK-GDPR)

Where GDPR or UK-GDPR applies, our legal bases are:

You are never required to enable cloud backup to use the app.

For Hong Kong users (PDPO): we collect and use personal data only for the purposes described here, in line with the Personal Data (Privacy) Ordinance Data Protection Principles. Supplying personal data to the app is voluntary: it is neither a statutory nor a contractual requirement, you choose which profile details to enter and what food and drink to log, and cloud backup is off unless you turn it on. The only consequence of not providing a particular detail is that the related nutrient personalization will be less precise or unavailable; no feature is withheld for declining the optional cloud backup. We do not use your data for any new purpose not described here without your consent, and we take practical steps to keep it secure. Classes of transferees: your personal data may be transferred to (a) our cloud-backup provider Supabase (and its underlying hosting sub-processor, Amazon Web Services, in the EU / Ireland region) — but only if you enable cloud backup, and then as end-to-end-encrypted ciphertext, your account email, and the readable information listed in Section 6 (see Section 6); and (b) the public product databases used for the barcode/product lookups you trigger (Open Food Facts, Open Beauty Facts, Open Products Facts and the NIH DSLD), to which only a barcode number or product name/brand is sent and no personal data (see Section 5). We do not transfer your personal data to any other class of person. (Separately, the app store through which you obtain the app — Apple — may process limited account or transaction data as an independent controller under its own privacy policy; we do not send your personal data to it: see Section 15.)

Access and correction: you may request access to, and correction of, the personal data we hold about you. The contact point handling such requests is our data-access contact at support@mynutrition.fitness.


9. How to access, correct, export, or delete your data

Because your data lives on your device, you control it directly:

Deleting your cloud account does not automatically erase the copy on your device — use the full local wipe on the unlock screen (“I’ve lost everything — erase the app and start over”), or “Clear all logged data” for just your log entries, if you also want to remove data from the device. Likewise, wiping the device does not delete a cloud backup.

If you need help making a request, or want us to confirm what (if any) account data we hold for you in the cloud, contact support@mynutrition.fitness. Where a request concerns cloud-backup account data, we will take reasonable steps to confirm that you are the account holder — for example by asking you to send the request from, or to confirm, the email address registered to the cloud account — before we disclose, change or delete anything, so that we do not act on a request made by the wrong person. We aim to respond within one month (GDPR/UK-GDPR); for complex or numerous requests we may extend this by up to two further months and will tell you if we do. For Hong Kong requests under the PDPO, we will comply with your data access or data correction request within 40 days of receiving it; if we cannot comply (in whole or in part) within that period, we will tell you in writing before the end of the 40 days, give our reasons, and then comply as soon as practicable afterwards. Because most data is end-to-end encrypted and held only on your device, there may be data we genuinely cannot access or produce — we’ll explain this where it applies.

Your rights


10. Retention (how long data is kept)

We don’t keep server-side personal data beyond what’s needed for the optional cloud backup you enabled.


11. International data transfers

Hong Kong is not covered by an EU or UK adequacy decision. Your account email and encrypted backup are stored on Supabase servers in the EU (Ireland), where our backup provider acts as our data processor. The transfer that needs a safeguard under EU/UK law is our access, from Hong Kong, to that EU-stored personal data (your account email plus unreadable ciphertext). For that access we rely on the EU Standard Contractual Clauses, using the module appropriate to our processor-to-controller arrangement, and, for UK personal data, the UK International Data Transfer Addendum / IDTA — both contained in the data-processing agreement we have entered into with our backup provider. As a supplementary measure, your backup content is end-to-end-encrypted ciphertext that neither we nor anyone in Hong Kong can read; we also assess the risks of this transfer as required before relying on these clauses. As for Hong Kong’s own law, section 33 of the Personal Data (Privacy) Ordinance (which would restrict transfers of personal data outside Hong Kong) is not currently in force, so no statutory Hong Kong cross-border-transfer restriction presently applies; we nonetheless follow good-practice safeguards consistent with the PCPD’s guidance on cross-border transfers. You can request a copy of the relevant clauses at support@mynutrition.fitness.


12. Children

myNutrition is intended for users aged 16 and over. We do not knowingly collect personal data from children under 16. Where local law sets a lower digital-consent age, the app is still aimed at users aged 16 and over.

Please note that the app does not enforce a technical age check at sign-up; the 16+ threshold is a usage requirement, not an automated gate. The app has no behavioral targeting and does not collect data from minors for marketing. Date of birth is optional, is stored only on your device (encrypted), is used only to personalize nutrient reference values, and is not sent to us — not for advertising or any other purpose. For US users, the Children’s Online Privacy Protection Act (COPPA) defines a “child” as a user under 13; in US terms myNutrition is a general-audience app that is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If we learn that we hold, on our servers, personal information (for the optional cloud backup, this would be an account email) provided by a child under 13, we will delete it. If you are a parent or guardian and believe a child under 13 has provided personal information through the app, contact us at support@mynutrition.fitness and we will delete it.


13. How we keep your data secure

No system is perfect, but the design goal is that even we cannot read your data.

If something goes wrong: if a personal-data breach affecting the account data we hold (your email and login code) occurs and is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (GDPR / UK GDPR Article 33), and we will tell affected users directly where the breach is likely to result in a high risk to them (Article 34). Because backups are end-to-end-encrypted ciphertext, a server compromise would not expose your readable data.

For US users (health data and breach notification): Your health and nutrition data is end-to-end encrypted. By default it lives only on your device, and even if you turn on cloud backup it reaches our servers only as encrypted, unreadable ciphertext that we cannot decrypt. The information we hold on our servers is your account email, a one-way login code, and the readable details listed in Section 6 — and only if you enable cloud backup. Your account email is the only part of it that identifies you by name. If a security breach ever affected unsecured identifiable health information, or other personal information of US residents that a US breach-notification law protects, in a way that triggers the US Federal Trade Commission’s Health Breach Notification Rule (16 CFR Part 318) or any other US breach-notification law that applies to us, we will notify affected individuals, and the FTC or other authorities where required, without unreasonable delay and within the time limits those rules set. We are not a HIPAA-covered entity (see Section 2), so HIPAA’s separate breach rules do not apply to us.


14. App permissions we may ask for

You can manage these permissions in your device settings.


15. App stores and what we declare

myNutrition will be distributed through the Apple App Store. Apple applies its own health-data and data-safety rules and may collect information (e.g. for purchases or app health reporting) under its own privacy policy, which is outside our control. myNutrition itself does not send your personal data to the store.

Consistent with this policy, what we will declare on the App Store privacy label is:


16. How to make a complaint

If you have a privacy concern, please contact us first at support@mynutrition.fitness and we’ll try to resolve it.

You also have the right to raise a privacy concern with a regulator or, where applicable, a data protection authority:


17. United States — your privacy rights

A growing number of US states have their own comprehensive consumer privacy laws — for example California (the CCPA/CPRA), Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Jersey, New Hampshire, Nebraska, Minnesota, Maryland, Indiana, Kentucky and Rhode Island. We have looked at whether these laws place obligations on us, and we want to be straight with you about the answer.

Most of these laws probably do not apply to us — because of how small we are, not because of how we treat your data. myNutrition is run by one person, through a Hong Kong company. Most of these state laws only cover a business once it handles the personal data of at least 100,000 residents of that state in a year (or 25,000 residents, if the business also makes more than half of its money from selling personal data). We are far below those numbers. A few states (such as Texas and Nebraska) drop the numeric thresholds but instead exempt small businesses (as defined by the US Small Business Administration) — except that even a small business must get your consent before it sells sensitive data. Because we never sell any of your data — sensitive or otherwise — that exception does not apply to us either. So, as things stand, we do not believe any of these state laws currently require us to do anything.

We do not “sell” or “share” your personal information. Under California law (the CCPA/CPRA) and similar laws in other states, “sell” and “share” have specific meanings; we do neither, for money or otherwise, and we do not share your data for cross-context behavioral (targeted) advertising. We have not sold or shared personal information in the preceding 12 months and have no mechanism to do so, so there is no “Do Not Sell or Share My Personal Information” link to offer — there is nothing to opt out of. We also run no advertising, analytics, tracking, crash-reporting or profiling (see Section 7).

Sensitive information stays under your control. Your health and nutrition data — and profile fields such as biological sex or any health-related details you choose to enter — are treated as sensitive personal information. By default this never leaves your device and is encrypted so we cannot read it (see Sections 3 and 4). We use it only to work out your nutrient targets on your device, never to infer characteristics about you, never for advertising, and never to profile you. Because we do not use sensitive information for any purpose beyond providing the app, the “right to limit the use of sensitive personal information” has nothing to restrict in our case.

Even so, here are the rights we will honor voluntarily. Whether or not a particular law applies to us, and as a courtesy to all our US users, if a state law would give you these rights we will honor them. Because almost all of your data lives only on your own device, you can already do most of this yourself in the app:

How to make a request. Email support@mynutrition.fitness and tell us what you would like. The fastest way to access, correct, export or delete your data is usually to do so directly in the app (see Section 9). For any cloud-backup account data, we may ask you to confirm the request from the email address on your account before we act, so that we do not act on a request made by the wrong person. You may use an authorized agent; we may ask for proof of authorization and may still ask you to verify your own identity. We aim to respond within 45 days; for a complex request we may take up to another 45 days and will tell you why. Because nearly all of your data is encrypted and held only on your device, there may be data we genuinely cannot access or produce — we will explain this where it applies.

How to appeal. If we refuse your request, you may ask us to reconsider by replying to our decision or emailing support@mynutrition.fitness with the word “appeal”. We will review and write back, normally within 60 days, explaining our decision. If you are still not satisfied, you may contact your state Attorney General (or, in California, the California Privacy Protection Agency).

“Shine the Light” (California Civil Code § 1798.83). This separate California law lets consumers ask a business what personal information it disclosed to third parties for those third parties’ own direct-marketing use. We do not disclose your personal information to anyone for their direct-marketing purposes, so there is nothing to report under this law.

US state consumer health data laws (Washington, Nevada, Connecticut)

A few US states have specific consumer health data laws that, unlike the general state privacy laws above, apply to a business of any size if it offers products or services to that state’s residents — there is no revenue or size threshold to fall below. The most important for an app like ours is Washington’s My Health My Data Act; Nevada and Connecticut have broadly similar laws. “Consumer health data” generally means information that is linked or reasonably linkable to you and that identifies your past, present or future physical or mental health; some of what you can record here (for example diet and food logs, and any health-related profile fields you choose to enter) could fall within it. We publish this to be transparent with US users, even though, for the reasons that follow, we believe we hold little or no readable consumer health data about you.

Why we believe we hold little or no “consumer health data” as these laws use that term. myNutrition is local-first and end-to-end encrypted. By default your food logs, profile and plans are stored only on your own device, encrypted with a key derived from your password that we never receive — we have no copy and no way to read them. If you turn on optional cloud backup, what reaches our servers is your account email, an encrypted backup that we cannot decrypt, and the readable details listed in Section 6. We genuinely cannot read your health or nutrition information, so we consider that we do not hold readable consumer health data that identifies your health status to us. These laws are new and broadly worded, so we take a careful approach: we describe our practices openly throughout this policy, we do not sell or share your data and we use no geofencing around health facilities or anywhere else (see Section 7), and we apply the security and access protections described elsewhere in this policy.

Nevada. Nevada has a consumer health data law (SB 370, part of NRS chapter 603A). It has no size threshold but only covers health data that a business actually uses to identify your health status, and it gives individuals no right to sue (only the Nevada Attorney General can enforce it). Because we cannot read your data and do not use it to identify your health, we believe we hold little or no “consumer health data” as Nevada defines it.

Connecticut. Connecticut’s Data Privacy Act treats consumer health data as “sensitive data” and, for that data, applies regardless of business size. As in Nevada, it only covers health data a business uses to identify your health condition or diagnosis, and it gives individuals no right to sue (only the Connecticut Attorney General enforces it). Because our design means we cannot read your data and do not use it to identify your health, we believe we hold little or no consumer health data as Connecticut defines it. If despite this any of your data were treated as sensitive data, we rely on your consent: you choose what to enter, and optional cloud backup happens only if you turn it on and agree.

Other US states. Several other US states have or are considering health-data privacy laws (for example Maryland’s Online Data Privacy Act). Some of these apply only to larger businesses that handle the data of tens of thousands of consumers — thresholds we do not expect to reach — and at least one proposed New York health-privacy law was not enacted. Wherever a US state law does apply to us, we will honor the rights it gives you: in practice you can already view, correct, export and delete your data directly in the app (see Section 9), and you can contact us at support@mynutrition.fitness to ask about, or delete, any account data we hold. We do not sell your data, share it for advertising, profile you, or use geofencing.


18. Governing law

This policy, and any dispute about it, is governed by the laws of the Hong Kong Special Administrative Region, where the operator is based. This does not take away any of the following: (a) the mandatory data-protection rights you have under the GDPR, the UK GDPR or the Hong Kong Personal Data (Privacy) Ordinance, where those laws apply to you; or (b) your right to bring a complaint to, or seek a remedy from, the data protection authority or the courts of your own country of residence (see Section 16). Nothing in this section removes any protection that the law of your country of residence gives you and that cannot be excluded by agreement.


19. Changes to this policy

If we change this policy, we’ll update the “last updated” date at the top and post the new version at https://mynutrition.fitness/privacy/. For significant changes, we’ll provide a clear notice (for example, in the app). Previous versions are available on request. Please check back from time to time.