Privacy
Your data stays yours
MyFitnessPal's ToS lets them share your logs with advertisers and third parties. Nourish won't. Here's exactly what we store and what we'll never do with it.
What stays private — always
•Your meal log, workouts, weight history, and body-fat entries.
•Your profile (name, stats, targets, goal, notes).
•Your pantry items by default — they only leave your account if you explicitly tap “Share” on one.
•Your chat history with the AI. Messages are stored so the conversation persists across devices, but nobody else sees them and we don't train models on them.
•Your API keys. Encrypted at rest (AES-256-GCM) with a key we can't read from the database. They're only decrypted per-request to make the call your provider.
•Photos you attach to chat. Stored with the message so they stay visible when you scroll back, but never sent to third parties and dropped from all subsequent AI requests after the turn they belonged to.
The one thing that's public — only if you opt in
When you tap Share on a pantry item, you're submitting that food's public nutrition info (name, brand, serving size, macros, micronutrients, ingredient list) to the community database for review. That's it — no personal info, no log, no quantity, no timestamp. It's the same data that would be on the back of the package. Approved entries help other users log the same food faster without re-scanning or re-typing it. You can unshare by deleting the pantry item or rejecting it if the reviewer sends it back.
What we'll never do
•Sell your data to advertisers or anyone else.
•Hand it to third parties for marketing, profiling, or insurance scoring.
•Train AI models on your meal log or chat history.
•Show ads. Nourish is user-funded (you bring your own API key for the AI features; we're not paying OpenAI/Anthropic on your behalf).
•Track you across the web. No Google Analytics, no Segment, no session replay. Operational logs (errors, auth, rate limits) only.
What we do store, and why
•Google account email + name — to sign you in and tie your data to your account.
•Your logs, pantry, profile, chat history — on Neon (Postgres), scoped to your user id, so the app works across devices.
•Encrypted API keys — so you don't have to paste them on every device.
•Feedback you submit — stored so we can reply. Nothing else.
•Operational logs — Vercel's default server logs (errors, response codes). No content logging.
Delete your data
You own everything. Clear your chat from the chat header (trash icon). Delete meals, workouts, weight entries, pantry items, or memories from their respective pages. For a full account wipe, send a request from feedback and I'll purge the row plus any linked community submissions.
Questions? Send feedback — I read everything.