Effective: May 8, 2026 ยท Last updated: May 8, 2026

Privacy Policy

This policy describes what data NutriAI Pro (https://ai-nutri.net and Telegram bot @botnutraibot) collects, why, how we store it, and how you can manage it. Aligned with GDPR (Art. 13-22) and Russian Federal Law 152-FZ.

1. Data Controller

Data controller: NutriAI Pro (individual entrepreneur โ€” registration in progress). Email: [email protected]. Telegram: @botnutraibot.

2. What We Collect

CategoryFieldsPurpose
IdentifierstelegramId, name from Telegram, languageAuth, addressing you
Contact (optional)emailRecovery, retention pings (consented)
Anthropometricsage, gender, weight, heightDaily kcal target (Mifflin-St Jeor)
Goalsweight goal, activity level, target weightAI personalisation
Special category (health)allergies, chronic conditions, pregnancy, diet notesSafety warnings in AI analysis
Activityfood logs (name + macros), weight history, analytics eventsHistory, progress, product analytics
Paymentsamount, provider, transaction statusSubscription billing
TechnicalIP via Cloudflare, User-Agent, timestampsSecurity, anti-abuse, debugging

๐Ÿ’ก Food photos are NOT stored. The image is forwarded to AI for real-time analysis and discarded after the result is received. Only the result (dish name, macros, AI text) is saved.

3. Legal Basis

4. Cross-Border Transfer

โš  Important: Food photos and context (goals, allergies, conditions) are sent to Google Gemini API (servers in the US/EU). This is a cross-border transfer under GDPR Art. 44-49 and 152-FZ Art. 12. The transfer is pseudonymised to Google (UUID, not your name). By accepting this Policy you consent to this transfer.

Third-party recipients:

5. Retention

DataPeriod
Profile, food logs, weight historyUntil account deletion or 3 years of inactivity
Health data (allergies, conditions)Until consent withdrawal or account deletion
Payments5 years (accounting requirement)
Analytics events90 days (auto-TTL)
AI request logs (no photo content)60 days (auto-TTL)
IP in server logs30 days

6. Your Rights

7. What We Don't Do

8. Data Security

9. Children

Service not intended for users under 14. If you notice data of a minor processed without parental consent, contact us โ€” we remove within 24 hours.

10. Policy Changes

Material changes announced 14 days in advance via Mini App and bot. Version date in header reflects current state.

11. Contact