Privacy Policy
1. Introduction
This Privacy Policy explains how Intuitive HB Limited (“we,” “our,” or “us”), a company registered in England and Wales, collects, uses, and protects your personal data when you use our mobile application (“the App”).
We are committed to protecting your privacy and handling your data in accordance with UK data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By using the App, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the App.
2. Who We Are (Data Controller)
- Data Controller: Intuitive HB Limited
- Registered Office: 61 Bridge Street, Kington, HR5 3DJ
- Country: United Kingdom
- Email: nouriche.support+dataprotection@gmail.com
- Data Protection Contact: nouriche.support+dataprotection@gmail.com
- ICO Registration Number: 00013492513
3. What Information We Collect
We collect the following categories of personal data:
3.1 Account Information
- Name and email address
- Authentication credentials (encrypted)
- Account preferences and settings
3.2 Profile and Health Data
- Age, weight, height, gender
- Dietary preferences and restrictions
- Nutrition goals and targets, including calculated metrics such as Basal Metabolic Rate (BMR)
- Meal logs and food intake records, including meal photos you choose to add
- Wellness reflections and personal notes
- Body measurements (if voluntarily provided)
- Short daily wellness check-ins (“Body Signals”), such as sleep quality, hydration, energy, and mood, which you provide with a single tap
3.3 Genie AI Chat Data
- Messages you send to Genie, our in-app AI chat assistant
- Contextual information from your own logged data (e.g. recent meals, goals, wellness check-ins) that we include so Genie can give you relevant answers
- Genie’s replies to you
- Conversations with Genie are stored locally on your device and are not uploaded to our servers or Firebase
3.4 Voice and Audio Data
- If you use voice logging, your microphone audio is captured temporarily to convert your speech into text
- Audio is processed using Apple’s Speech framework, which may transcribe on your device or send audio to Apple’s servers for transcription depending on your device and settings
- We do not retain raw audio recordings after transcription is complete
- Voice logging is entirely optional and can be turned off at any time in Settings
3.5 Technical and Usage Data
- Device type and operating system version
- App usage patterns and feature interactions
- Error logs and diagnostic information (via Firebase Crashlytics)
- IP address (automatically collected)
- Authentication tokens (encrypted)
3.6 Location Data (Optional)
- Approximate location (only if you grant permission)
- Used solely to find nearby healthy food options
- Can be disabled at any time in device settings
4. Legal Basis for Processing
Under UK GDPR, we process your personal data based on:
- Consent - You provide explicit consent when creating an account and using health tracking features, voice logging, or the Genie AI chat assistant
- Contract - Processing is necessary to provide the App services you’ve requested
- Legitimate Interests - We process certain data to improve our services, prevent fraud, and ensure security, where our interests don’t override your rights
You may withdraw consent at any time by deleting your account, disabling a specific feature (such as voice logging) in Settings, or contacting us.
5. How We Use Your Information
We use your personal data for the following purposes:
- Providing and maintaining the App’s core functionality
- Creating and managing your user account
- Delivering personalized nutrition tracking and recommendations
- Powering the Genie AI chat assistant and generating personalized insights, using a third-party AI inference provider (Groq) to process your messages and generate responses
- Converting spoken meal descriptions into text when you use voice logging
- Analyzing usage to improve features and user experience
- Communicating important updates and service notifications
- Detecting and preventing fraud, abuse, and security threats
- Complying with legal obligations
- Processing subscription payments (via Apple App Store)
We will not use your data for purposes beyond those stated without obtaining your consent.
6. Who We Share Your Data With
We do NOT sell your personal data.
We only share your data with:
Service Providers
- Firebase (Google) - authentication, cloud storage, database, and crash reporting services
- Apple - authentication, payment processing, and (for voice logging) speech-to-text transcription
- Groq - AI inference provider that powers the Genie chat assistant
- Cloud hosting providers - data stored in secure servers
Firebase Services Used:
- Firebase Authentication - For secure user account management
- Cloud Firestore - For storing your meal data, nutrition information, and wellness reflections
- Firebase Cloud Storage - For app data synchronization
- Firebase Crashlytics - For crash and error reporting to help us fix bugs
All service providers are bound by data processing agreements compliant with UK GDPR requirements.
Firebase Privacy:
Firebase services are compliant with:
- UK GDPR (General Data Protection Regulation)
- SOC 2 Type II certification
- ISO 27001 certification
For more information: https://firebase.google.com/support/privacy
Groq (Genie AI Chat):
When you use Genie, your messages and relevant context from your logged data are sent to Groq, a third-party AI inference provider, so it can generate a response.
- Groq does not use your messages to train or fine-tune its AI models
- Groq does not retain your messages by default; it may keep short-term logs (up to 30 days) solely to maintain service reliability or investigate abuse
- Groq’s servers are located in the United States
- Your conversation history itself is stored locally on your device, not by us or by Groq
For more information: https://groq.com/privacy-policy
Apple Speech Recognition:
If you use voice logging, your audio may be sent to Apple’s servers to be transcribed into text, governed by Apple’s own privacy practices.
Legal Requirements
We may disclose data if required by law, court order, or regulatory authority, or to protect our legal rights and the safety of others.
Business Transfers
In the event of a merger, acquisition, or sale of assets, your data may be transferred to the new owner, subject to the same privacy protections.
7. International Data Transfers
Some of our service providers (such as Firebase/Google and Groq) may process data outside the United Kingdom. When this occurs, we ensure:
- Transfers are to countries with adequate data protection (as recognized by the UK government)
- Standard Contractual Clauses (SCCs) are in place
- Appropriate technical and organizational safeguards protect your data
Data Storage Locations:
- Firebase/Google Cloud servers (primarily in Europe and United States)
- Groq’s servers (United States) — used only transiently to generate Genie’s responses, not for long-term storage
- All data is encrypted in transit and at rest
- Firebase complies with EU-US Data Privacy Framework
Your data may be processed in the European Economic Area (EEA) and the United States, where our service providers operate secure data centers with industry-leading security standards.
8. How We Protect Your Data
We implement robust security measures to protect your personal data:
Technical Measures
- AES-256 encryption for sensitive data at rest
- TLS 1.3 encryption for all data in transit, including messages sent to Groq for the Genie chat assistant
- Secure credential storage in iOS Keychain
- Multi-factor authentication options
- Regular security audits and vulnerability assessments
Organizational Measures
- Strict access controls and authentication
- Staff training on data protection
- Incident response procedures
- Regular backups with encrypted storage
While we take all reasonable precautions, no system is completely secure. We cannot guarantee absolute security of data transmitted over the internet.
9. Your Data Protection Rights
Under UK GDPR, you have the following rights:
- Right to Access - Request a copy of your personal data
- Right to Rectification - Correct inaccurate or incomplete data
- Right to Erasure - Request deletion of your data (“right to be forgotten”)
- Right to Restrict Processing - Limit how we process your data
- Right to Data Portability - Receive your data in a structured, machine-readable format
- Right to Object - Object to processing based on legitimate interests
- Right to Withdraw Consent - Withdraw consent at any time (doesn’t affect prior processing)
- Right to Lodge a Complaint - Complain to the ICO if you believe your rights have been violated
To exercise these rights, email us at: nouriche.support+privacy@gmail.com
We will respond within one month (extendable by two months for complex requests).
10. How Long We Keep Your Data
We retain personal data only as long as necessary:
- Active Accounts - Data retained while your account is active
- Inactive Accounts - Data may be deleted after 24 months of inactivity (you’ll receive advance notice)
- Deleted Accounts - Data permanently deleted within 30 days of deletion request
- Backup Systems - Data removed from backups within 90 days
- Genie Conversations - Stored only on your own device; deleted when you clear the conversation or delete the App
- Groq Processing Logs - Not retained by Groq by default; may be held for up to 30 days solely for service reliability or abuse prevention
- Legal Obligations - Some data may be retained longer if required by law (e.g., financial records for 6 years)
You can request deletion of your data at any time by contacting us or deleting your account in Settings.
What Data Gets Deleted:
When you delete your account, the following data is permanently removed:
- Firebase Authentication account
- All meal logs and food entries, including meal photos (Cloud Firestore / Firebase Cloud Storage)
- Wellness reflections, Body Signals check-ins, and personal notes
- User profile and preferences
- Nutrition goals and progress data
- Local device storage data (Core Data, UserDefaults), including your Genie conversation history
Deletion Timeline:
- Cloud data (Firebase/Firestore): Immediately upon confirmation
- Backup systems: Within 90 days
- Cached data: Removed from all servers within 30 days
Cannot Be Recovered:
Once deleted, your data cannot be recovered. This action is permanent and irreversible.
11. Children’s Privacy
The App is not intended for children under 13 years of age. We do not knowingly collect personal data from children under 13.
If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at nouriche.support+privacy@gmail.com. We will promptly delete such information.
Users aged 13-17 should seek parental consent before using the App.
12. Cookies, Tracking Technologies, and App Tracking Transparency
We use the following technologies:
Essential Technologies
- Authentication cookies (to maintain your login session)
- Local storage (for app preferences and settings)
Analytics
- Crash reporting (to identify and fix bugs)
We Do Not Track You Across Apps or Websites
We do not use advertising identifiers (such as the IDFA), advertising SDKs, or any third-party tracking or analytics tools that link your data with other companies’ data for advertising purposes. Because we do not engage in this kind of “tracking” as defined by Apple, the App does not display an App Tracking Transparency (ATT) permission prompt — there is nothing to opt in or out of.
We do not use cookies or trackers for advertising or marketing purposes, and we do not sell or share your data with data brokers or advertising networks.
13. Automated Decision-Making and AI Features
The App uses algorithms — including Genie, our AI chat assistant, which is powered by a third-party AI model provided by Groq — to provide personalized nutrition recommendations, wellness insights, and conversational responses.
These are suggestions and observations only and do not constitute:
- Medical advice, diagnosis, or treatment
- Legally binding decisions
- Decisions that significantly affect your rights
Genie may occasionally produce inaccurate or incomplete responses, as is a known limitation of AI language models. You are always free to ignore any recommendation or observation from Genie or the App. The App does not make automated decisions that have legal or similarly significant effects on you, and Genie is designed to encourage you to speak with a qualified healthcare professional rather than to replace one.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements.
How we notify you:
- Prominent notice in the App
- Email notification (if you’ve provided your email)
- Updated “Last Updated” date at the top of this policy
Material changes will be notified at least 30 days in advance. Your continued use of the App after changes take effect constitutes acceptance of the updated policy.
We recommend reviewing this policy periodically.
15. Contact Us and Complaints
For privacy questions or to exercise your rights:
- Email: nouriche.support+privacy@gmail.com
- Data Protection Contact: nouriche.support+dataprotection@gmail.com
- Mail: Intuitive HB Limited Privacy Team 61 Bridge Street, Kington, HR5 3DJ United Kingdom
We aim to respond within 30 days.
To lodge a complaint:
If you’re unhappy with how we’ve handled your data, you have the right to complain to the UK Information Commissioner’s Office (ICO):
- Website: https://ico.org.uk
- Phone: 0303 123 1113
- Mail: Information Commissioner’s Office Wycliffe House, Water Lane Wilmslow, Cheshire SK9 5AF
16. Where Your Data Lives
Your Data Journey:
1. On Your Device (iOS)
- Local cache (Core Data), including your Genie conversation history
- Encrypted Keychain storage
- Session data and preferences
2. In the Cloud (Firebase)
- Authentication: Firebase Auth (encrypted)
- Database: Cloud Firestore (encrypted at rest)
- Location: Europe/US data centers
- Backup: Automated encrypted backups
3. Momentarily, With Groq (Genie AI Chat)
- Your Genie messages and relevant context are sent to Groq’s servers (United States) only to generate a response
- Not retained by Groq for training; short-term reliability/abuse logs only (up to 30 days)
- The conversation itself remains stored on your device, not with Groq or with us
4. When You Delete Your Account
- All cloud data deleted immediately from Firebase
- Local data, including Genie conversation history, cleared from device
- Backups purged within 90 days
- Authentication account permanently removed
Security Throughout:
- TLS 1.3 encryption during transfer
- AES-256 encryption at rest
- End-to-end security from device to cloud
- No data sold or shared with advertisers
This privacy policy is designed to comply with UK GDPR and Apple App Store requirements. Users are encouraged to review this policy regularly for updates.