1. Scope
This policy applies to the Noury iOS app and this legal website. We do not sell personal data or use health data for advertising.
2. Data we process
- Profile and goals: age, sex, height, weight, activity level, nutrition goals, dietary focus, units, and reminder settings.
- Food content: meal photos and food descriptions you choose to submit, meal type, food names, portions, nutrition estimates, edits, and favorites.
- Logs and reports: weight logs, goal changes, trends, and weekly reports.
- Health data: with your permission, weight, steps, active energy, and workouts read from Apple Health, plus weight entries you explicitly ask Noury to write.
- Membership and technical data: subscription status, product identifiers, a random installation identifier, app version, system language, and basic operational information needed for security and troubleshooting.
- Product analytics and diagnostics: a separately generated pseudonymous analytics identifier, feature-use events, event times, app version, device class, OS version, language and region, plus crash stacks and basic device and runtime state when a crash occurs. Product analytics excludes meal names, meal photos, weight values, raw Apple Health samples, and free-form text.
- Support communications: messages and attachments you send to our support email.
Apple processes payments. Noury does not receive your card number or complete payment credentials.
3. How we use data
We use data only as needed to provide and maintain features: generating food and nutrition estimates; saving and displaying logs, trends, and reports; connecting to Apple Health or syncing across devices when you choose; validating membership and usage quotas; analyzing onboarding, food-logging, and purchase flows to improve the product; monitoring crashes and stability; preventing abuse and troubleshooting; responding to requests; and complying with legal obligations.
4. AI food recognition
The content is sent to Noury's recognition service and processed by AI services provided by Alibaba Cloud to generate food names, portions, and nutrition estimates. Requests may also contain language, a random installation identifier, membership status, and device-integrity proof for service security and quota enforcement.
Data read from Apple Health is not sent to the food-recognition AI. Noury does not use submitted meal photos or text to train its own models. AI results may be inaccurate; review them before saving and do not use them as medical diagnosis or treatment advice.
5. Apple Health
With your permission, Noury may read weight, steps, active energy, and workouts to show trends and support calculations. It may write a weight entry only when you explicitly save it in Noury. You can manage access at any time in Apple's Health app or system settings.
Health data is not sold, used for advertising, or sent to the food-recognition AI, PostHog, Firebase Crashlytics, or RevenueCat. Features that depend on it may stop updating after permission is withdrawn.
6. Cross-device sync
If enabled, Noury uses Apple's private cloud services to sync data saved in the app. Raw data read from Apple Health is not uploaded.
8. Retention and deletion
- On-device records normally remain until you delete them in the app or uninstall it. Random identifiers stored in the system keychain may survive reinstallation.
- Cloud data remains until deleted through Noury or Apple; disabling sync alone does not delete existing copies.
- AI service operational information is retained only as long as needed for recognition, quota management, security, troubleshooting, and legal obligations.
- Product analytics events are retained for the necessary period configured in our PostHog project. You may request deletion of data associated with your pseudonymous analytics identifier through our support email.
- Firebase Crashlytics generally begins deleting crash stacks and associated identifiers from live and backup systems after 90 days.
- Subscription, transaction, security-incident, or dispute records may be kept longer where required by law or platform rules.
Some data required for legal, fraud-prevention, security, or dispute purposes may not be deleted immediately, but its use will be restricted.
9. Your choices and rights
You can manage Health permissions, notifications, AI consent, cross-device sync, and subscriptions in Noury or system settings. Depending on applicable law, you may also request access, correction, deletion, restriction, withdrawal of consent, or a copy of your data.
To request action on server-side data linked to a random installation identifier or pseudonymous analytics identifier, email us. We may perform risk-appropriate verification to prevent impersonation.
10. Children
Noury is not designed specifically for children. Anyone below the age of independent consent in their location should use it only after a parent or guardian has reviewed and agreed to these terms. Guardians who believe a child submitted data without appropriate consent should contact us.
11. Policy changes
We may update this policy as features, providers, or laws change and will update the date above. Where required, material changes to data types, purposes, or AI recipients will be explained in the app and consent obtained.
12. Contact
Email: support@noury.top
Suggested subject: Noury privacy request