NutriConvo AIConnected food tools

Privacy policy

Privacy Policy of NutriConvo AI

Last updated: July 23, 2026

Overview

NutriConvo AI is a nutrition diary by Useful First. The connected food-tool service uses your account, food logs, nutrition profile, onboarding state, and connected AI-assistant requests only to provide and operate NutriConvo AI.

Information We Collect

When you sign in, log meals, manage your profile, or manage access, Useful First receives information needed to provide the product:

  • Email address, name, and Firebase identity subject from Apple, Google, or email-and-password sign-in.
  • Profile, goal, onboarding, target, and progress information you enter.
  • Meal descriptions, food logs, nutrition estimates, notes, and corrections.
  • Voice commands, transcripts, voice-session metadata, and generated nutrition summaries.
  • Connected-client registration metadata, granted permissions, MCP resource, connection and last-use times, timezone, and locale.
  • Connected food-tool inputs and bounded results, including searches, diary dates, food descriptions, quantities, meals, clarification answers, confirmations, and operation identifiers.
  • Device, request, error, and operational logs needed to secure and operate the service.

Voice And AI Processing

Voice-session input and meal descriptions may be processed by speech, language-model, and food-data providers so NutriConvo AI can understand your request and convert it into food logs, estimates, and summaries. The product sends only the information needed to process your request and return the requested result.

NutriConvo AI keeps available final user and assistant transcript turns for 30 days after each voice or text session. When you choose voice mode, it also keeps your microphone audio for 30 days. Text mode does not capture audio. These fixed periods also apply to copies of this voice-session data.

The voice provider's room-level capture setup may briefly receive other audio tracks before their source is identified. Only the signed-in user's microphone track is eligible for retention; assistant or unexpected tracks are quarantined and erased after they are identified.

Useful First does not use food logs, health-related profile data, voice commands, transcripts, or generated nutrition summaries for advertising.

Connected AI Assistants And OAuth

A compatible AI assistant or MCP client may ask you to connect your existing NutriConvo account through OAuth. The authorization screen identifies the client and requested permissions. Food-read permission allows catalog search and private diary reads. Food-write permission allows food logging, clarification, confirmation, and receipt access.

Firebase processes sign-in and returns a verified identity token to NutriConvo. NutriConvo does not receive your password. Access eligibility, completed onboarding, and entitlement state are checked when you authorize a connection and use a connected capability.

The connected service separately handles your conversation under its own privacy terms. NutriConvo receives the bounded tool arguments that service sends and returns the requested catalog matches, private diary facts, operation state, or receipt, including nutrition values, totals, estimates, assumptions, and clarification prompts when applicable. NutriConvo does not receive the rest of that conversation unless the connected service includes it in a tool argument. The connected service, including OpenAI when you use ChatGPT, is a recipient of the returned private diary data.

Deterministic connected food-tool requests are not routed through NutriConvo's managed text or voice agent. The connected service may still use its own AI models to interpret your request and process the result.

How We Use Information

  • To create and manage your NutriConvo AI account.
  • To interpret voice or text meal descriptions and create food logs.
  • To calculate and show targets, summaries, progress, and entitlement state.
  • To link authorized clients, enforce granted food permissions, process connected tool requests, and return requested results.
  • To detect abuse, debug failures, maintain security, and operate the service.

Useful First does not sell user data.

Sharing

Useful First shares data only with service providers needed to operate the product:

  • Firebase, Apple, and Google for identity and authentication.
  • Speech, language-model, food-data, hosting, database, and infrastructure providers used to run NutriConvo AI.
  • A connected AI assistant or MCP client you authorize, which receives the food-tool results you request through that service.

Useful First may also disclose information if required by law or to protect the security and integrity of the product.

Security And Retention

Account, food-log, voice-session, and connected-tool requests are sent over HTTPS. The backend verifies Firebase identity tokens and maps them to an internal NutriConvo AI account.

NutriConvo stores one-way SHA-256 digests rather than raw OAuth authorization codes, access tokens, or refresh tokens in its database. A registered confidential client's recoverable client secret is stored encrypted. The connected service separately controls the credentials issued to it.

An OAuth authorization request expires after 10 minutes, an authorization code after 5 minutes, and an access token after 30 minutes. A refresh token expires after at most 30 days. The active service purges expired OAuth credentials when it starts and then checks hourly. A connection record, its granted permissions, and last-use time remain while needed to operate or secure the connection, or until the account-deletion process removes them.

While you maintain an account, Useful First keeps account, profile, food-log, support, and operational information, including OAuth connection records and their last-use times, for as long as needed to provide access, prevent abuse, resolve support requests, and comply with legal obligations. Expired OAuth credentials are removed from the active service under its credential-cleanup process. Voice-session transcripts and voice-mode microphone audio follow the fixed 30-day period described above. Account-deletion requests follow the process described below.

Account Deletion

When an account-deletion request is accepted, access to NutriConvo AI ends immediately. Your live product data becomes eligible for permanent deletion from the active service 30 days after the request. Deletion from the active service proceeds only after Useful First has also verified that live voice-session data associated with the account has been erased from the active service, so completion may take longer than 30 days if that verification is still pending. This policy does not specify a backup-erasure timeframe.

When permanent deletion from the active service proceeds, the underlying account record is anonymized. Useful First may retain deletion audit records and limited records needed for fraud prevention, security, or legal compliance.

Raw Apple and Google sign-in links are removed. Useful First retains a keyed, one-way identity digest—a protected fingerprint instead of the original provider identifier—only to prevent a deleted identity from creating a replacement account or receiving introductory access again. It is not used to sign in.

If the account used Sign in with Apple, Useful First may also retain a yes-or-no record of whether Apple authorization revocation was required for the deletion. That record does not track whether revocation was completed and does not contain the Apple identity subject, which is the Apple account identifier used for sign-in.

While deletion is being finalized, the app stores a temporary checkpoint on your device containing the sign-in provider and internal account ID, plus the deletion receipt when one is available. This allows cleanup to resume if it is interrupted. The checkpoint is cleared after cleanup finishes.

Permanent deletion from the active service also removes OAuth connections and credentials associated with the account. Disconnecting a connected service is not the same as deleting your NutriConvo account. Copies already received by a connected service remain subject to that provider's own deletion and retention terms.

Deleting your NutriConvo AI account does not cancel an App Store or Google Play subscription. Subscriptions must be canceled separately through the store account used for the purchase.

Cookie Policy

These connected-app information pages do not require sign-in. Firebase may use cookies or local browser storage when you authorize a connected client through account sign-in. Apple and Google may do the same if you choose their identity services. Those services process data under their own privacy policies.

GDPR Compliance

If you are located in the European Economic Area, the United Kingdom, or another region with similar data protection laws, you may have rights to access, correct, delete, restrict, or object to certain processing of your personal data. You may also have the right to request a copy of your personal data.

Useful First processes account, profile, food-log, and usage data, including connected-client authorization and tool-request data, to provide the service, prevent abuse, respond to support requests, and comply with legal obligations. To make a privacy request, contact Useful First at support-nutriconvo@usefulfirst.com.

Changes To This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or industry standards. When we make changes to this Privacy Policy, we will post the updated version on our website and indicate the date of the last update.

Contact

For privacy questions, account support, or deletion requests, contact Useful First at support-nutriconvo@usefulfirst.com.