The short version
- We collect and process consumer health data to provide Nurelio. Collection includes access, receipt and inference, even when data is not stored on a server.
- The main diary database stays on your device. Food lookups and AI features can process information off-device.
- We do not sell consumer health data or use it for targeted advertising.
- AI is part of the app and on by default. You can switch it off in Settings at any time.
Who is responsible and who is covered
Dzmitry Tselabionak, operating as Nurelio, is responsible for the practices described here. Privacy contact: privacy@nurelio.app, privacy@nurelio.app.
This separate policy describes consumer health data practices, including rights under Washington’s My Health My Data Act and Nevada’s consumer health data law where applicable. Washington coverage can include residents and people whose consumer health data is collected in Washington. Eligibility and rights differ by jurisdiction; this policy does not reduce applicable rights. Our Privacy Policy provides additional details.
Categories and sources
We collect information you enter, information imported or read with your permission, information generated by your use of Nurelio, and inferences calculated from it. Depending on your features and choices, this includes:
- Meals, food descriptions, photos, barcodes and calculated nutrition.
- Water, weight, height, activity, steps, sleep, workouts and supported heart-related signals from Apple Health.
- Moods, feelings, symptoms, allergies, food avoidances and health conditions you disclose.
- Goals, targets, relevant profile details, coach messages, conversation history and saved memories.
- Scores, patterns and other inferences about nutrition and wellbeing.
- Identifiers, feature usage, subscription and technical information where reasonably linkable to you and revealing your health status or your seeking health-related services.
Sources include you, your device, Apple Health or files you choose to import, food-data services responding to a lookup, subscription services, and Nurelio’s calculations and AI responses.
Purposes and processing
We use information to log and display your entries, calculate nutrition and wellbeing patterns, retrieve food information, deliver AI responses, manage subscriptions, respond to requests, and protect and troubleshoot the service. Optional product analytics measures feature usage without diary values or contact details.
The main diary database is encrypted on your device. Receiving or processing an individual request is still collection, even when we do not save its content in our server database. Food lookup requests can reveal eating habits. Unless you switch AI off, food text or photos and, for the coach and score summary, recent diary and relevant profile context are transmitted through our backend. The AI disclosure explains the inputs and automatic summary requests.
Our production AI requests require OpenRouter endpoints with zero-retention policies and disallow provider data collection for training. These controls concern content, not all operational metadata. They are not a guarantee against security incidents or lawful disclosure. We do not use your health content to train our own models.
Recipients
Depending on your choices, recipients include:
- Cloudflare: backend processing, hosting and security.
- OpenRouter and its model-hosting providers: optional food AI, coach and score-summary processing.
- Food-data providers: information needed to answer food lookups; see Data sources.
- Apple: Health features you enable, app-integrity checks and App Store transactions.
- RevenueCat: subscription identifiers, status and related technical information.
- PostHog EU: consented usage events linked to a random identifier, without diary values.
- Sentry: diagnostics configured to exclude health content, but potentially including app-use and technical information.
- Support providers: information you voluntarily include when contacting us.
We do not assume that removing names or food values necessarily removes information from consumer health data laws. Providers’ legal roles depend on the processing and applicable law. We may make disclosures required or otherwise permitted by applicable law, subject to its safeguards.
Consent and choices
We obtain consent where required for collection or sharing, including separate sharing consent where applicable, unless a statutory exception such as processing necessary to provide a product or service you request applies. Accepting general terms is not consent to optional health-data processing.
AI features are part of the service you request when you use the app, and are on by default. You can switch them off in Settings → Privacy & permissions at any time to stop new AI requests. Product analytics has its own choice. Apple Health permissions are managed separately in Apple’s settings. Withdrawal does not reverse completed processing, and the feature that needs the withdrawn permission may become unavailable.
We do not sell consumer health data and do not seek authorizations for sale. We do not use geofencing around healthcare facilities to identify or track people seeking healthcare or send health-related advertising.
Access, deletion and appeals
Where applicable, you can request confirmation of collection, sharing or sale; access to your data and the required list of recipients and their contact details; withdrawal of consent; and deletion. You can use the app’s export and deletion tools or email privacy@nurelio.app. We may use proportionate verification to protect your information and explain any additional steps needed.
Remote account deletion must complete before the app clears the local account. If it fails, your local data and identifier are kept so you can retry. Unverified marketing addresses are suppressed pending verification for erasure. A deletion request can also require us to notify processors and other recipients and address backups as required by law. You must separately manage your own exports, device backups and Apple Health records.
For Washington requests, we respond within 45 days. If a permitted extension is necessary, we will explain it within that period; the extension is no more than an additional 45 days. If we deny a request, email the same address to appeal. We respond to an appeal in writing within 45 days and explain our decision. If an appeal is denied, you may complain to the Washington Attorney General.
For Nevada requests, we respond within 45 days, with a further 45 days where permitted and explained. You can appeal a refusal at the same email address; we respond to the appeal within 45 days. You may also contact the Nevada Attorney General. Where another applicable law requires an earlier response or additional rights, we follow that law.
We do not retaliate for exercising your rights. Requests are generally free; we will explain any exception allowed by law before applying it.
Retention, security and changes
Local records remain until deleted or replaced. We do not maintain a server-side diary or save AI request content to our server database. Technical, subscription and support records have different purposes and retention criteria, described in the Privacy Policy. Where deletion exceptions apply, we explain the reason and restrict further use as required.
Encryption, access controls and data minimization reduce risk, but do not eliminate it. We assess incidents and provide legally required notifications. We will give appropriate notice of material changes and obtain new consent before new processing where required.