Privacy Policy
Andri is a nutrition app that reads how your body recovered (sleep, heart-rate variability, activity, and energy) and suggests what to eat, when, and how much. This policy explains what data the app collects, why, who processes it, and the choices you have. It is written to be read, not to hide anything.
Andri is operated by an independent developer ("we", "us"). If you have any question about this policy or your data, contact us at contact@andrinutrition.app.
1. What we collect
Account and identity
- Email address and name, provided through Sign in with Apple when you create an account. If you use Apple's "Hide My Email", we only ever receive the private relay address.
- Account identifiers: an internal user ID and the identifier Apple returns for Sign in with Apple, used to recognise your account on each launch.
Your account
Andri requires an account, created with Sign in with Apple when you first open the app. Apple tells us an identifier for you and, if you allow it, your name and an email address. That address may be a private relay address Apple generates, in which case we never see your real one. Everything described below is stored against that account.
Device identifier
- An identifier we generate the first time you open the app, stored in your device's keychain. It is sent with requests that use our AI features, so we can count the free AI trial per installation rather than per account. Without it, signing out and starting again would reset the trial indefinitely.
- It is also sent with the product events described under “App activity” below. That is what lets us see how many people who open the app finish setting it up, including those who never create an account. Without it, those are unconnected events rather than one journey.
- This is our own identifier, not Apple's advertising identifier. It is never used for advertising, never used to track you across other companies' apps or websites, and never shared for those purposes. Removing the app deletes it from your device.
Profile you enter
- Height, weight, date of birth, and sex (used to calculate your energy needs).
- Activity level, your goal (for example lose fat, build muscle, or maintain) and any target weight or date.
- Optional cuisine preferences, how you eat (for example vegetarian, pescatarian, halal or kosher), and a list of foods you avoid, so meal suggestions fit how you actually eat.
Allergies, intolerances, and foods you avoid
You can tell Andri which foods to leave out, whether that is an allergy, an intolerance, or simply something you would rather not eat. You choose whether to fill this in at all, and you can change or remove any entry at any time.
This is special category data. An allergy or intolerance says something about your health, and a choice such as halal or kosher can reveal a religious belief. Under the UK and EU GDPR both fall under Article 9, which means we may only hold them with your explicit consent. Adding an entry to the list, or choosing how you eat, is that consent. Removing the entry withdraws it, and we then stop using it.
We use this for two things and nothing else: leaving those foods out of the meal plans we generate for you, and flagging food you log when it looks like it contains one of them. Where a flag is produced it is stored on that meal, so the app can show it again when you look back at your day. It is never used for advertising, never sold, never shared for marketing, and never used to make any decision about you beyond what appears on your own plate.
Health and fitness data (Apple Health)
Only if you connect Apple Health, and only the specific types you allow, Andri reads: step count, active and resting (basal) energy burned, walking and running distance, body weight, height, date of birth, biological sex, resting heart rate, heart-rate variability, and sleep analysis. This data is used to size your daily nutrition targets and show your progress. Height, date of birth and biological sex are read once, when you connect, so that you do not have to type them in; they do not change on their own and are not read again. Apple Health access happens on your device and only after you tap Connect and grant permission in the system prompt.
Meal photos
If you log a meal from a photo, the image is sent to our service and to our AI provider (see section 3) to estimate the foods and their nutrition. You choose when to take or select a photo; the app does not access your camera or library otherwise.
Content you create
- Meals you generate or log, weigh-ins, daily check-ins, and the nutrition history built from them.
- Device push token, if you enable notifications, so we can send meal reminders and "plan ready" alerts.
Subscription status
If you subscribe, we record whether your subscription is active, which plan it is, and when the current period ends, so the app knows what you are entitled to. We never receive or store your card or payment details. The purchase itself is made with Apple; our subscription provider (see section 5) tells us only that a purchase happened and what it entitles you to.
Crash reports and diagnostics
When the app or our backend hits an error, we record a crash report: the error and where in the code it happened, the app version, and your device model and iOS version. It is linked to your account identifier so we can tell whether a fault hit one person or everyone. We do not send your health data, meal photos, or profile in crash reports.
App activity
We record the dates on which your account is active (one record per day) so we can understand retention and whether the app is useful.
We also record a small, fixed list of product events: reaching the welcome screen, finishing a setup step, connecting Apple Health, seeing the subscription screen, and starting or completing a purchase. Each carries only the event name, a short label such as which step it was, the device identifier described above, and when it happened. There is no free-text field, and the server discards anything not on that list, so no meal name, message or note can end up here, by accident or otherwise.
We keep this because the app can otherwise only see what people do, never what they abandon. Someone who installs Andri, gets partway through setting up and gives up leaves no other trace, and that is the part we most need to fix.
We also keep a record of subscription changes, such as a purchase, a renewal or a cancellation, so we can understand how the subscription is working. It holds no payment details; those stay with Apple.
Apart from the crash reporting described above, we use no third-party analytics, advertising, or tracking tools, and we do not build advertising profiles.
2. How we use your data
- To create your account and keep you signed in.
- To calculate personalised calorie and macronutrient targets from your profile and recovery data.
- To generate meal suggestions and estimate the nutrition of meals you photograph.
- To leave the foods you avoid out of the plans we generate, and to flag food you log when it looks like it contains one of them.
- To show your progress toward your goal over time.
- To send the notifications you opt into.
- To understand aggregate usage and improve the app.
We do not sell your data, we do not share it for advertising, and we do not use your Apple Health data for anything other than providing these features.
3. AI processing (Anthropic / Claude)
Meal suggestions, photo nutrition estimates and recipes are produced using Claude, an AI service provided by Anthropic. Anthropic processes what we send and returns a result.
What we send, depending on what you asked for:
- Your meal photo, when you log a meal by photo.
- Profile figures used to size the plan: your age, sex, height and weight, your activity level, your goal and any target weight, how you eat, the foods you avoid, and your cuisine preferences.
- Health figures for the day, when you have connected Apple Health: steps, energy burned, hours slept, a sleep score, heart-rate variability, and the recovery level we derive from them. Any workout you have planned is sent too, so the day can be fuelled for it.
- What you type, when you describe a meal or a craving, rename an item in a photo estimate, or enter a meal by hand for us to estimate.
- The meals already on your day, so a new suggestion fits what is left of your targets.
We send only what is needed to produce the result. We do not send your name, your email address, or your weight history. Under Anthropic's commercial API terms, your inputs and outputs are not used to train Anthropic's models, and are retained only briefly for safety and abuse monitoring before deletion.
4. Apple Health
Data read from Apple Health (HealthKit) is used solely to provide Andri's nutrition and progress features. In line with Apple's requirements, we never use Health data for advertising or marketing, never sell it, and never share it with third parties except the service providers strictly needed to run the app (see section 5). You can revoke Andri's access at any time in the iOS Settings › Privacy & Security › Health screen or inside the Health app.
5. Who processes your data
We share data only with service providers who process it on our behalf to run the app. They are not permitted to use it for their own purposes:
- Supabase (database and authentication hosting) stores your account, profile, health, and meal data.
- Anthropic (AI) processes meal photos and plan context as described in section 3.
- Apple provides Sign in with Apple and delivers push notifications (APNs).
- Expo delivers push notifications and app updates.
- Sentry (crash and error reporting) receives the diagnostic data described in section 1, processed on servers in the European Union.
- RevenueCat (subscription management) records that a purchase was made and keeps your subscription status in step with the App Store. It receives your account identifier and the purchase details from Apple, not your payment details, which stay with Apple.
- Contabo (server hosting) rents us the dedicated private server our backend runs on, in France. Every request to Andri passes through it. Contabo provides the machine and does not process your data for its own purposes.
- Netlify hosts these legal pages. It receives only the network request that loads the page you are reading, not any data from the app.
We may also disclose data if required by law, or to protect the rights and safety of our users.
6. Data retention
We keep your data for as long as your account exists so the app can show your history. When you delete your account (section 7), your profile, weigh-ins, meals, plans, health records and sign-in records are deleted from our database. Two things outlive it on purpose. Usage and billing records are kept for accounting, with your account identifier and your device identifier removed, so what remains is a count rather than a person. We also ask RevenueCat, which keeps our subscription records, to delete its record of your purchases; Apple keeps its own record of anything bought through the App Store, under Apple's policies. Deleting your account does not cancel an App Store subscription, so cancel it first in the app (You › Manage my subscription) or in your iPhone's Settings. A tally of how many free AI uses have been made from your device is kept against a device identifier, so that the free allowance cannot be reset by deleting an account and making a new one; it holds no profile, health or contact data. Meal photos sent for estimation are processed to return a result and are not kept as a photo gallery in the app.
7. Your rights and choices
- Access / export: you can export a copy of your data from inside the app (Profile › Export data).
- Deletion: you can permanently delete your account and its data from inside the app (Profile › Delete account). This removes your profile and everything it holds from our database. Section 6 says what is kept afterwards, and why.
- Health access: manage or revoke Apple Health permissions in iOS Settings at any time.
- Notifications: turn off notifications in the app or in iOS Settings.
Depending on where you live (for example the EU/UK under GDPR), you may have additional rights to access, correct, or restrict processing of your data. Contact us and we will help.
8. Security
Connections between the app and our servers use HTTPS. Access to the database is restricted to our backend using secret credentials, and the app never talks to the database directly. No system is perfectly secure, but we take reasonable measures to protect your information.
9. Children
Andri is for adults. You must be at least 18 years old to create an account, and we do not knowingly collect data from anyone under 18. The app asks for your date of birth and refuses to create an account below that age.
10. International transfers
Our backend server is in France, and Sentry processes crash reports in the European Union. Our other service providers are United States companies: Supabase, Anthropic, Apple, Expo, RevenueCat and Netlify. They may process data there or elsewhere. Where that happens, we rely on those providers' safeguards for international data transfers, including the European Commission's standard contractual clauses where they apply.
11. Changes to this policy
We may update this policy as the app evolves. We will change the "Last updated" date above and, for significant changes, notify you in the app.
12. Contact
Questions or requests about your data: contact@andrinutrition.app.
