← Back to Home

Security

A short, honest summary of how your data is protected — and how to reach us if you find a problem.

Authentication

Sign-in is handled by Supabase Auth, including Sign in with Apple and Google. We don't build our own password storage.

Meal photos

Meal photos are stored in a private storage bucket — not on the public internet. The app accesses them through short-lived signed URLs that expire, so a photo link can't be shared around indefinitely.

In transit

Data moving between the app, our servers, and our service providers is encrypted with TLS.

Payments

Payments are handled by Apple, Google, and Stripe. Your card number never touches our servers — we never see it, so we can't lose it.

Deleting your account

Settings → Delete account removes your stored photos and your data from our database immediately. The details of what gets deleted are on How We Use Your Data.

Responsible disclosure

No system is immune to bugs, including ours. If you believe you've found a security vulnerability in NutriAI, please email support@trynutriai.com with the details. We'll acknowledge your report, investigate, and keep you posted on the fix. Please give us a reasonable window to address the issue before disclosing it publicly.