nuvi

Privacy Policy

Last updated September 3, 2026

Nuvi tells you whether a product fits your goal. This explains what we collect to do that, why, how long we keep it, and the choices you have — organized so you can jump to the part you're asking about.

1. Who runs Nuvi

Nuvi is operated by [Nuvi entity — TODO(legal)]. This policy covers the Nuvi app, nuviapp.org, and anything either of them sends to a server. [email protected] reaches us for anything on this page, including the requests in section 9.

2. What we collect

Your account. Signing in with Apple gives us an anonymous identifier and, if you allow it, an email address — often a private relay address Apple generates for you. We never see your Apple password.

Your goal and your measures. The goal you pick, your height, your weight, and the target you set. This is what a scan is checked against. It's not a diagnosis and we don't treat it as medical data.

Your scans and your log. Photos of barcodes and labels you point the camera at, processed to read the product and return a verdict, and the record of what you scanned and when, so the app can show you what you've looked at.

Photos you choose to submit to the catalog. If you submit a product photo — see section 6 of the Terms — we keep it and show it to other people who scan the same product, until you ask us to remove it.

Health data, only if you turn it on. With the permission iOS asks for on your behalf, Nuvi can read your weight from Apple Health to prefill it instead of asking you to type it, and can write a weight you log in Nuvi back to Health. Revoke this anytime in Settings → Privacy & Security → Health on your iPhone; we only ever see what that permission allows.

A device identifier, for App Attest. Apple's App Attest lets our server confirm a request comes from a genuine copy of Nuvi running on real Apple hardware rather than a script. This uses a key generated on your device and an attestation from Apple — nothing more of your device than that.

Your purchase. If you subscribe, Apple or Stripe handles the charge. We receive confirmation that you paid and which plan — never your card number.

Standard technical data. Crash reports, which screens you open, and what any server logs from a request: IP address, device and browser.

3. What we don't collect

No location beyond the country your network reports, used only to price a plan and to answer in your language. No contacts, no health record beyond the weight you explicitly connect through Apple Health, and no data read from another app on your phone.

4. Why we're allowed to process it

Your account, your goal, and your scans: we process these because they're what it takes to give you the answer you're asking for — performance of our contract with you.

A photo you submit to the catalog, and any Health data you connect: only with your explicit permission, which you can withdraw anytime the way section 2 describes.

Technical and analytics data, and measuring whether an ad worked: our legitimate interest in keeping Nuvi working and knowing whether running that ad was worth it, weighed against your privacy — and never for anyone who's opted out where the law requires that choice.

5. Why we collect it

To answer a scan, to remember your goal between sessions, to run your subscription, to keep the product working, and to tell whether the ad that brought you here was worth running.

6. Who sees it

Apple — sign-in, App Attest, and, if you subscribe in the app, the payment.

Stripe — the payment, if you subscribe on the web. Stripe is the merchant of record for that charge and handles it directly.

RevenueCat — whether your subscription is active, regardless of which store sold it.

The vision and language model that reads a scan — currently Google's Gemini. A photo of a barcode or a label goes to it to be read; it doesn't get your account, your goal, or anything else about you along with it.

Cloudflare — serves nuviapp.org, routes traffic to our servers, and stores a photo you submit to the catalog.

PostHog — product analytics: which screens get used.

Meta, TikTok and Google — measuring whether an ad worked, with your device's advertising identifier only where the platform allows it. For anyone we detect in California, Meta gets this data under Limited Data Use, which applies the state's privacy rules to it.

Nobody on this list buys or sells what we send them, and neither do we.

7. Cookies

An anonymous id and which ad brought you here, both kept 90 days, so a purchase days after a click can still be credited to it. The language you chose with the switch on this page, so a reload doesn't send you back to English. Nothing beyond what the analytics and ad pixels in section 6 set on their own.

8. How long we keep it

Your account, your scans, and your log, until you delete your account. A scan taken before you had an account is dropped once that session ends. A photo you submitted to the catalog stays there until you ask us to remove it, or until it's replaced by a better one. Payment records are kept as long as tax and accounting law requires — that period isn't ours to shorten.

9. Your rights

Delete your account anytime from the app — Account → Delete account — which removes what section 8 says we keep until then. You can also ask for a copy of your data, ask us to correct it, or ask us to delete it a different way: write to [email protected].

If you're in the EU, the EEA or the UK, GDPR also gives you the right to restrict or object to some of the processing in section 4, and to complain to your data protection authority.

If you're in California, the CCPA gives you the right to know what we hold and to opt out of its sale or sharing. We don't sell your data, and anyone we detect there gets Limited Data Use applied automatically — you don't need to ask.

10. Children

Nuvi is not for anyone under 16. We don't knowingly collect data from a child, and we remove it if we learn we have.

11. Security

Data moving to and from our servers is encrypted, and access to what's stored is limited to what running Nuvi requires. No system is unbreakable — write to [email protected] if you find a problem.

12. International transfers

Nuvi runs on servers that can be outside the country you're in, including the United States. Where that means data crosses out of the EU, the EEA or the UK, we rely on the transfer safeguards that region's law provides.

13. Changes

We'll update this page and move the date at the top. A change to what we collect, not just how we describe it, gets its own notice in the app.

14. Contact

[email protected]

Privacy · Terms