Privacy policy
Privacy Policy of NutriConvo AI
Last updated: August 26, 2026
Overview
NutriConvo AI is a voice calorie tracker and AI diet assistant by Useful First. The product uses your account, onboarding state, food logs, body-weight history, nutrition profile, goals, voice-session input, connected-client requests, and billing state only to provide and operate NutriConvo AI.
Information We Collect
When you sign in, log meals, manage your profile, or manage access, Useful First receives information needed to provide the product:
- Email address and name from Apple, Google, or email-and-password sign-in; your Firebase UID, which is stored as the canonical sign-in identity for your NutriConvo account; Apple and Google identity subjects when those methods are linked; and the verified email claim used to validate password sign-in. The backend does not use email matching as an account-ownership identity.
- Profile, goal, onboarding, target, and progress information you enter.
- Meal descriptions, food logs, nutrition estimates, notes, and corrections.
- Food-logging settings, including accuracy mode, food mass and volume unit systems, confirmation behavior, and whether rich food results are shown.
- Persisted account preferences, including body unit system, language, nutrition context such as allergies, intolerances, dislikes, and diet patterns, and the ready, thinking, and ended voice-cue settings and their revision.
- Voice commands, transcripts, voice-session metadata, and generated nutrition summaries.
- Connected-client registration metadata, granted permissions, MCP resource, connection and last-use times, timezone, and locale.
- Connected-capability inputs and bounded results, including onboarding answers and draft plans; account-preference reads and complete voice-cue replacements; searches, diary dates, food descriptions, quantities, meals, clarification answers, confirmations, operation identifiers, and food-logging settings; daily consumed, target, and remaining nutrient totals and logging streaks; body-weight measurements and progress; progress-check windows, bounded evidence, current and proposed nutrition targets, recommendation choices and lifecycle state; plan-change requests, current and draft plan snapshots, selected effective dates, and proposal lifecycle state; current access tier and status, relevant access period, setup prerequisites, capability and managed-assistant availability, and whether management for an existing subscription is available; and first-party account-navigation links.
- Subscription, trial, entitlement, billing status, checkout, and payment-provider identifiers.
- Device, request, error, and operational logs needed to secure and operate the service.
Voice And AI Processing
After you give permission in the app, NutriConvo sends microphone audio or the words you type and the context needed to answer your request to Microsoft Azure OpenAI. Depending on the request, that context may include meal descriptions, corrections, food logs, nutrition estimates, profile and onboarding details, body-weight history, goals, nutrition plans, and recommendations. Microsoft Azure OpenAI processes this information to understand the request and generate the assistant response.
Useful First operates its own LiveKit servers on Amazon Web Services to transport microphone audio, typed messages, transcripts, and assistant responses between the NutriConvo app and its managed assistant. NutriConvo does not use LiveKit Cloud and does not share this session data with LiveKit, Inc. NutriConvo does not start a voice or chat session or send the data listed above to Microsoft Azure OpenAI until you select the in-app permission checkbox and continue. You can decline by signing out without starting a session.
Useful First requires Microsoft Azure OpenAI and its infrastructure providers under their service and data-protection terms to use this personal data only to provide their contracted services and to protect it to the same or an equivalent standard as this policy.
NutriConvo AI keeps available final user and assistant transcript turns for 30 days after each voice or text session. When you choose voice mode, it also keeps your microphone audio for 30 days. Text mode does not capture audio. These fixed periods also apply to copies of this voice-session data.
The voice provider's room-level capture setup may briefly receive other audio tracks before their source is identified. Only the signed-in user's microphone track is eligible for retention; assistant or unexpected tracks are quarantined and erased after they are identified.
Useful First does not use food logs, health-related profile data, voice commands, transcripts, or generated nutrition summaries for advertising.
Connected AI Assistants And OAuth
A compatible AI assistant, MCP client, or CLI may ask you to connect a verified NutriConvo account through OAuth. The authorization screen identifies the client and requested permissions. Setup permissions allow onboarding reads and approved setup changes. Food permissions allow catalog and private diary reads, food logging, clarification, confirmation, receipt access, diary-entry changes, deletion of an identified entry, and reading or changing food-logging settings. The existing food.read permission also lets read_daily_nutrition return one selected day's consumed nutrient totals and logging streak, plus target and remaining totals when an applicable nutrition plan exists. Weight permissions allow body-weight logging and progress reads. A progress read returns the one applicable reference type—a goal, checkpoint, or stability or recomposition anchor—and returns a progress percent only for goal and checkpoint modes; measurement-history results have no reference. Plan permissions are separate: plan.read allows the connected service to review current progress recommendations and plan-change proposals; plan.write allows it to evaluate a due progress check, create or rebase a proposal, acknowledge a no-change result, and submit an explicitly selected accept, reject, or defer decision. Preference permissions are also separate: preferences.read allows the connected service to read the persisted body unit system, language, nutrition context, and voice cues; preferences.write allows it to replace only the complete ready, thinking, and ended voice-cue vector at its exact current revision. Account permissions allow read_account_access to return the bounded access facts listed above and allow open_subscription_management to return or open a first-party NutriConvo page for an existing subscription. After you authenticate and explicitly choose to manage it, that page may open the applicable subscription provider. Account permissions also return links to account management, data export, and whole-account deletion pages; they do not perform those sensitive actions inside the connected service. Connected access tools never return pricing or checkout, start a purchase, change an access tier, or offer an upgrade.
Firebase processes sign-in and returns a verified identity token to NutriConvo. NutriConvo does not receive your password. NutriConvo validates the Firebase UID in every Firebase sign-in token and uses the stored UID to resolve the same internal account whether you use password, Apple, or Google sign-in. Linked provider identities are reconciled only after Firebase proves they belong to that same UID; NutriConvo does not merge accounts merely because email addresses match. A verified identity and current product-policy acceptance and an explicit final Connect action are required to authorize a connection. Requested scopes are granted independently of onboarding and Tools or Full access status; a scope delegates permission but does not confer product access. Completed onboarding and eligible Tools or Full access are checked when you use ordinary food, diary, body-weight, or plan capabilities. Setup, food-settings, and account-preference capabilities remain available before onboarding without Tools or Full access, while account-navigation capabilities require neither. Food-setting operations still require current product-policy acceptance: reading settings requires the delegated food.read permission, and changing them requires food.write. Preference operations require current product-policy acceptance and the applicable delegated preferences.read or preferences.write permission.
The connected service separately handles your conversation under its own privacy terms. NutriConvo receives the bounded tool arguments that service sends and returns the requested setup state and draft plans, account preferences, food-logging settings, catalog matches, private diary facts, daily nutrition totals and logging streaks, body-weight measurements and progress context, bounded progress-recommendation evidence, current and proposed calorie and macronutrient targets, goal and pace facts, rationale and completion estimates, explicitly supplied profile inputs needed to calculate a proposal, operation state, receipts, bounded account-access state, or first-party account links. NutriConvo does not receive the rest of that conversation unless the connected service includes it in a tool argument. The connected service, including OpenAI when you use ChatGPT, is a recipient of the requested results, which may include private diary, profile, preference, onboarding, body-weight, recommendation, or nutrition-plan data. A recommendation or proposal remains a draft until its exact current version is reviewed and explicitly approved. Accepting it can replace the active nutrition plan and targets; rejecting, deferring, or acknowledging it changes only the applicable lifecycle state. Account-navigation results do not include an export archive, do not perform account deletion, and do not include customer IDs, subscription IDs, or product identifiers.
When a compatible host supports component state, ChatGPT may preserve the same validated bounded food-receipt or weight-progress result as widget state so an older chat can restore its view. This creates no new NutriConvo backend record. The connected service controls that copy under its own privacy and retention terms.
Deterministic connected-capability requests are not routed through NutriConvo's managed text or voice agent. The connected service may still use its own AI models to interpret your request and process the result.
How We Use Information
- To create and manage your NutriConvo AI account.
- To interpret voice or text meal descriptions and create food logs.
- To calculate and show targets, summaries, progress, and entitlement state.
- To link authorized clients, enforce granted setup, food-settings, preferences, food, weight, plan, and account permissions, process connected capability requests, and return requested results.
- To support web checkout, mobile store purchases, refunds, access management, and account support.
- To detect abuse, debug failures, maintain security, and operate the service.
Useful First does not sell user data.
Sharing
Useful First shares data only with service providers needed to operate the product:
- Firebase, Apple, and Google for identity and authentication.
- Stripe, the App Store, and Google Play for checkout, subscription processing, refunds, and billing records.
- Microsoft Azure OpenAI for processing the assistant audio, text, and request context described under Voice And AI Processing.
- Amazon Web Services for hosting Useful First's backend, managed assistant, self-hosted LiveKit media transport, and retained voice-session data.
- Food-data, hosting, database, and infrastructure providers used to run NutriConvo AI.
- A connected AI assistant, MCP client, or CLI you authorize, which receives the setup, food-settings, account-preferences, account-access, food, weight, plan, or account-navigation results you request through that service.
Useful First may also disclose information if required by law or to protect the security and integrity of the product.
Security And Retention
Account, profile, preferences, onboarding, food-log, body-weight, nutrition-plan, recommendation, billing, voice-session, and connected-capability requests are sent over HTTPS. The backend verifies Firebase identity tokens and maps them to an internal NutriConvo AI account.
NutriConvo stores one-way SHA-256 digests rather than raw OAuth authorization codes, access tokens, or refresh tokens in its database. A registered confidential client's recoverable client secret is stored encrypted. The connected service separately controls the credentials issued to it.
An OAuth authorization request expires after 10 minutes, an authorization code after 5 minutes, and an access token after 30 minutes. A refresh token expires after at most 30 days. The active service purges expired OAuth credentials when it starts and then checks hourly. A connection record, its granted permissions, and last-use time remain while needed to operate or secure the connection, or until the account-deletion process removes them.
While you maintain an account, Useful First keeps account, profile, preferences, onboarding, food-log, body-weight, nutrition-plan, recommendation, billing reference, support, and operational information, including OAuth connection records and their last-use times, for as long as needed to provide access, maintain billing records, prevent abuse, resolve support requests, and comply with legal obligations. Expired OAuth credentials are removed from the active service under its credential-cleanup process. Voice-session transcripts and voice-mode microphone audio follow the fixed 30-day period described above. Account-deletion requests follow the process described below.
Account Deletion
When an account-deletion request is accepted, access to NutriConvo AI ends immediately. Your live product data becomes eligible for permanent deletion from the active service 30 days after the request. Deletion from the active service proceeds only after Useful First has also verified that live voice-session data associated with the account has been erased from the active service, so completion may take longer than 30 days if that verification is still pending. This policy does not specify a backup-erasure timeframe.
When permanent deletion from the active service proceeds, the underlying account record is anonymized. Useful First may retain deletion audit records and limited records needed for billing, fraud prevention, security, or legal compliance. Retained payment-provider event records are detached from the anonymized account.
Raw sign-in identifiers stored by NutriConvo—including the Firebase UID and linked Apple or Google identity subjects—are removed. For each persisted sign-in identity, Useful First retains a keyed, one-way identity digest—a protected fingerprint instead of the original identifier—only to prevent a deleted identity from creating a replacement account or receiving introductory access again. It is not used to sign in. The app requests deletion of the Firebase user during identity cleanup; if that cleanup is interrupted, the temporary device checkpoint described below supports retry.
If the account used Sign in with Apple, Useful First may also retain a yes-or-no record of whether Apple authorization revocation was required for the deletion. That record does not track whether revocation was completed and does not contain the Apple identity subject, which is the Apple account identifier used for sign-in.
While deletion is being finalized, the NutriConvo app or website may store a temporary checkpoint on your device containing the sign-in provider, Firebase sign-in UID, internal NutriConvo account ID, and a random deletion-operation identifier, plus the deletion receipt when one is available. This allows cleanup to resume if it is interrupted. The website may disable ordinary sign-in and account creation while that checkpoint requires recovery or support. The checkpoint is cleared after cleanup finishes.
Permanent deletion from the active service also removes OAuth connections and credentials associated with the account. Disconnecting a connected service is not the same as deleting your NutriConvo account. Copies already received by a connected service remain subject to that provider's own deletion and retention terms.
Deleting your NutriConvo AI account does not cancel a Stripe, App Store, or Google Play subscription. Subscriptions must be canceled separately through the billing provider used for the purchase.
Cookie Policy
NutriConvo AI web sign-in, the connected account-management page, and the OAuth authorization flow use Firebase Auth in the browser and may use cookies or local browser storage. Payment processing is handled by Stripe, which may set its own cookies or use similar technologies during checkout. Apple and Google may do the same if you choose their identity services. The account-deletion flow may also keep a temporary non-secret recovery checkpoint in local browser storage until identity cleanup finishes. Those services process data under their own privacy policies.
GDPR Compliance
If you are located in the European Economic Area, the United Kingdom, or another region with similar data protection laws, you may have rights to access, correct, delete, restrict, or object to certain processing of your personal data. You may also have the right to request a copy of your personal data.
Useful First processes account, profile, preferences, onboarding, food-log, body-weight, nutrition-plan, recommendation, billing, and usage data, including connected-client authorization and capability-request data, to provide the service, manage subscriptions, prevent abuse, respond to support requests, and comply with legal obligations. To make a privacy request, contact Useful First at support-nutriconvo@usefulfirst.com.
Changes To This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or industry standards. When we make changes to this Privacy Policy, we will post the updated version on our website and indicate the date of the last update.
Contact
For privacy questions, account support, or deletion requests, contact Useful First at support-nutriconvo@usefulfirst.com.