Privacy Policy
Last updated: August 30, 2026
This policy explains how Nibble handles personal data in the iPhone app, the Nibble website, and the signed-in dashboard. Nibble is local-first: the app can be used for manual and barcode logging without an account, while account, sync, and managed AI features involve additional processing described below.
1. Data controller
The controller is Kristaps Dreija, operating the Nibble app and website.
Freudstraße 1080935 München
Germany
For privacy questions or requests, contact privacy@nibble-food.com.
2. Information we handle
Information you provide
- Profile and account details, including the name or email information made available through Sign in with Apple.
- Age, height, weight, goals, calorie targets, dietary preferences, allergies, cooking preferences, and taste preferences.
- Food logs, nutrition values, saved foods, recipes, water, fasting, weight history, chat messages, and meal photos you choose to save or back up.
- Support messages and information needed to answer them.
Information from device features
- Apple HealthKit: when enabled, Nibble reads active energy and selected body measurements such as weight and body fat. If you choose to sync back to Apple Health, Nibble can write nutrition values and selected body measurements.
- Camera, photos, microphone, and speech: only when you use the related logging or chat feature.
- Barcode scanning: uses Google ML Kit on-device. Barcode images and decoded results are not sent to Google by ML Kit. The SDK independently sends the technical metrics described below.
Technical and service information
The service may process account identifiers, installation identifiers, request status, latency, token counts, charged AI units, request IDs, app version, and security information needed to operate the service, provide support, enforce limits, and prevent abuse. Nibble does not use a third-party advertising SDK or a dedicated product-analytics service. Google ML Kit's barcode-scanning SDK may independently send device information, app and version information, per-installation identifiers not intended to uniquely identify a user or physical device, performance metrics, API configuration, event types, and error codes to Google for diagnostics and usage analytics. These ML Kit metrics are not used by Nibble for advertising or cross-app tracking.
3. Why we use data and the legal basis
- Provide the app, account, and Pro features: processing necessary to provide the service you request, generally Article 6(1)(b) GDPR.
- Optional Apple Health, sensitive cloud sync, and AI features: your consent, generally Article 6(1)(a) GDPR. Where HealthKit or other health-related data is processed, we rely on explicit consent under Article 9(2)(a) GDPR for that optional feature.
- Security, reliability, support, and prevention of misuse: legitimate interests under Article 6(1)(f) GDPR where appropriate, balanced against your rights, including operating reliable services, handling support, preventing misuse, and supporting SDK diagnostics, and legal obligations under Article 6(1)(c) where required.
- Subscriptions and entitlement checks: providing the subscription service and maintaining purchase records needed for access, refunds, and legal accounting requirements. Apple handles payment details for App Store purchases, and Paddle handles payment details for web purchases.
You can withdraw optional AI, HealthKit, or sensitive cloud-sync consent in the iPhone app or web account settings. Withdrawal stops future processing or sync but does not automatically delete records already synced; use the deletion controls or contact us for that.
4. Local storage and cloud sync
Meals and settings are created on your iPhone first. Signing in does not start cloud sync. After a separate explicit choice, you can allow automatic or manual sync to Supabase for restore or dashboard viewing. Synced records can include profile and goal data, nutrition, fasting, weight and body measurements, allergies and food preferences, saved recipes, and chat history. You can withdraw this permission in iPhone Settings or web account settings to stop future sync. Meal photos stay on the iPhone by default and require a separate backup choice before Nibble uploads them to private Supabase storage under your account.
5. Apple Health and health-related data
HealthKit access is optional and controlled by Apple. Nibble uses the selected data to adjust nutrition calculations, show activity and body measurements, and optionally write nutrition or body measurements back to Health. Nibble does not sell HealthKit data or use it for advertising.
Health-related values can remain on the device or become part of synced records if you explicitly sync them. Nibble does not include raw HealthKit samples in the normal phone AI request, but an opted-in AI request may include derived values such as an activity-based calorie budget.
6. AI processing
AI is optional. If you choose food analysis, AI Coach, recipe generation, or another AI feature, Nibble may process the meal photo, meal and nutrition context, goals, dietary preferences, allergies, taste preferences, calorie budget, and the text or voice transcript needed for that request.
Normal phone requests do not send your account name or raw HealthKit samples to the AI provider. Watch or Siri AI interactions, when enabled, may include the context needed for that feature, such as goal, weight, activity-derived budget, recent meals, and dietary preferences. See the full AI processing disclosure.
Nibble does not use solely automated decision-making, including profiling, that produces legal effects or similarly significant effects on you within the meaning of Article 22 GDPR.
7. Providers and sharing
We do not sell personal data and do not share it for advertising. Nibble does not use a third-party advertising SDK or a dedicated product-analytics service. Some providers and SDKs still receive operational or diagnostic data as described below. Depending on the feature you use, Nibble may use:
- Supabase for authentication, explicitly synced records, and optional meal-photo backup.
- Hostinger infrastructure for the Nibble web, API, and server-side AI infrastructure.
- LiteLLM and Google Gemini API (`gemini-3.5-flash-lite` route) for managed server-side AI routing. The route is configured on Nibble's server, not in the iPhone app; Google Gemini API is the current upstream provider. See the AI processing disclosure.
- Apple for Sign in with Apple, App Store subscriptions, and the HealthKit platform. Paddle handles web subscription billing as the merchant of record.
- Open Food Facts for product-search and barcode-lookup requests. Nibble's API receives typed queries, barcode values, and a pseudonymous installation identifier for abuse control; no Nibble account is required and the Open Food Facts integration does not receive your Nibble account identifier.
- RevenueCat for subscription offerings, purchases, entitlement status, transaction metadata, and subscription management. RevenueCat receives either an account-linked app user ID or a pseudonymous anonymous app user ID, plus relevant purchase or entitlement information. Apple and Paddle handle payment details for their respective purchases.
- Google ML Kit for on-device barcode scanning and the SDK diagnostics and usage metrics described above. Barcode images and decoded results are not sent to Google by ML Kit.
These services may process information outside the European Economic Area (for example, in the United States). We rely on the providers' applicable data-protection terms and, where required, on appropriate safeguards for data transfers (for example, EU standard contractual clauses or adequacy decisions). The AI processing disclosure explains how managed routing works.
8. Retention
- Local records remain on your device until you remove them or reset the app.
- Synced records remain in your account until you delete them or request account deletion.
- Nibble's AI API and self-hosted LiteLLM routing service do not retain request or response content after processing. Operational spend metadata such as route, status, latency, token counts, and charged units is retained for up to 30 days.
- AI providers may temporarily process or retain content under the endpoint and provider terms in effect when a request is made. Where a requested model supports it, Nibble uses routes with no training and zero-data-retention controls.
- Support and security records are kept only for as long as needed to resolve the request, operate the service, or meet legal obligations.
- Consent records, including the policy version and when you granted or withdrew consent, are kept as needed to demonstrate your choices and meet legal obligations.
9. Your rights
Depending on your location, you may have the right to access, correct, export, restrict, object to, or delete your personal data, to withdraw consent, and to complain to your local data-protection supervisory authority. Contact privacy@nibble-food.com. You can also use the account-deletion control in the signed-in web dashboard or iPhone app.
10. Children
Nibble is intended only for people aged 18 or older. We do not knowingly collect children's personal data.
11. Changes
We may update this policy when the service or data practices change. We will update the date above and provide an in-app notice for material changes.
