Security
A short, honest summary of how your data is protected — and how to reach us if you find a problem.
Authentication
Sign-in is handled by Supabase Auth, including Sign in with Apple and Google. We don't build our own password storage.
Meal photos
Meal photos are stored in a private storage bucket — not on the public internet. The app accesses them through short-lived signed URLs that expire, so a photo link can't be shared around indefinitely.
In transit
Data moving between the app, our servers, and our service providers is encrypted with TLS.
Payments
Payments are handled by Apple, Google, and Stripe. Your card number never touches our servers — we never see it, so we can't lose it.
Deleting your account
Settings → Delete account removes your stored photos and your data from our database immediately. The details of what gets deleted are on How We Use Your Data.
Responsible disclosure
No system is immune to bugs, including ours. If you believe you've found a security vulnerability in NutriAI, please email support@trynutriai.com with the details. We'll acknowledge your report, investigate, and keep you posted on the fix. Please give us a reasonable window to address the issue before disclosing it publicly.