‹ Back to Nouriq
Privacy Policy
Effective July 23, 2026 · Nouriq, operated by Eisen Labs (eisenlabs.io)
Nouriq ("the app", "we") helps you log food, track calories and macros, review connected-health
context, and receive general consumer-wellness coaching. This policy explains what data we handle and
why. We keep it minimal: most data starts on your device, and cloud features are used only when you
sign in or connect an external service.
What we collect
- Account sign-in: when you use email, Google, Apple, or a passkey to sign in, the selected
provider supplies the account identifiers and profile details needed to authenticate you. Depending
on your choice, this may include your name and email address. We use this information for protected
AI calls, sync, billing status, and health-data access controls.
- Food, meal, and glucose data: foods you log, meals you save, glucose readings you enter,
favorites, trusted corrections, portions, targets, and metabolic profile settings are stored in
your browser and may be synced if you enable signed-in cloud sync.
- Health metrics: if you connect Apple Health or Health Connect, Nouriq can read user-granted
weight, body composition, blood pressure, pulse, and glucose readings. Future integrations may include
CGM data. Health observations are tagged by source
where possible so the app can show provenance and source-level sharing controls.
- AI coaching requests: when you request coaching, the relevant food, meal, glucose, and profile
summaries may be sent to our AI provider (Anthropic). Connected-health context is excluded unless
you opt in from the app's AI data sharing controls, and any enabled health context is minimized to
bounded aggregates for the requested insight.
- Barcode lookups: barcodes you scan or enter are sent to Open Food Facts to retrieve product
information. No personal information is sent.
- Cross-device sync: when signed in, your app data is stored server-side in Postgres and
Upstash, keyed to an internal Nouriq account identifier so it can sync across devices. Supported
browser features can remain local unless you sign in or export them.
- Purchases: when you subscribe, Stripe, Google Play, or Apple's App Store handles payment
details. Nouriq receives product and transaction identifiers, subscription status and dates, store
region, and an account-linking identifier. We store the signed store token encrypted so we can
verify access, restore purchases, prevent one purchase from being claimed by another account, and
respond to renewals, cancellations, billing issues, refunds, and revocations. We do not receive your
full payment-card number from an app store.
- Product analytics: we record allowlisted event names and coarse context—such as page type,
broad search source, signup method, and whether a calculator result was low, medium, or high—to
understand whether public pages and core features work. These events exclude food names, health
readings, free-text notes, email addresses, and search queries.
Connected health
Health Connect and Apple Health data is read only inside the native mobile app after OS permission approval,
then sent as normalized observations without provider tokens. Health readings may be displayed on Today, trend screens, and coaching
summaries. Source-level privacy controls let you disable supported health sources, and connected-health
context is excluded from AI unless you opt in.
Service providers
We rely on these processors to run the app: Google and Apple (sign-in and app-store billing),
Anthropic (AI generation),
Upstash (rate-limiting, caching, and sync storage), Vercel (hosting), Stripe
(web subscription billing), Postgres (account and app-data storage),
Apple Health and Health Connect (connected health metrics), USDA FoodData
Central (nutrition data), and Open Food Facts (product data). Each processes data only as
needed to provide its part of the service.
How long we keep it
- If you enable sync, your stored app data is kept until you change it or delete it. Settings →
Delete synced data erases the synced copy from our server.
- Native health permissions are managed by the operating system. You can revoke access in Apple Health
or Health Connect at any time.
- Rate-limit counters use an account or privacy-protected network identifier and expire after their
configured protection window.
- Generated AI guidance is cached keyed to the food (not to you) and expires within 30 days.
- After a deletion request completes, encrypted backup snapshots can retain a deleted copy for
up to 30 days before automatic expiry. A minimal deletion audit containing a hashed identifier,
deletion scope, record count, and timestamp may be kept for security and compliance; it contains
no name, email address, food log, or health readings and cannot restore an account.
- Anthropic's, Google's, Upstash's, Apple's, Stripe's, Vercel's, USDA's, and Open Food Facts'
handling of data are governed by their own policies.
What we don't do
We do not sell your data, share it for advertising, or use it to track you across other sites.
Your choices
Supported public and browser-local features may be used without signing in. A Nouriq account
is required for the native app and subscription status. An active Nouriq Plus trial or membership is
required for protected AI calls, cloud sync, and connected health. You can sign out at any time from
within the app.
Export and deletion
Settings includes local export/import, server account export, synced-data deletion, and full
server-account deletion. Server export includes synced app data, entitlement records, audit entries,
signed-in consent metadata, and connected-health token metadata without exposing token secrets. Full
server deletion removes synced app data, entitlement records, consent metadata, and user-specific
connected-health tokens where available. Step-by-step deletion instructions are available on the
support page.
Children
Nouriq is not directed to children under 13 and we do not knowingly collect their data.
Not medical advice
Nouriq is a consumer wellness app. It provides general educational information, estimated glycemic
values, and coaching suggestions. It is not a substitute for professional medical advice, diagnosis, or
treatment, and it is not intended to be used as a HIPAA-regulated clinical service. Always consult a
qualified healthcare provider about blood sugar and metabolic health.
Changes
We may update this policy; the effective date above reflects the latest version.