‹ Back to Nouriq
Privacy Policy
Effective July 5, 2026 · Nouriq, operated by Eisen Labs (eisenlabs.io)
Nouriq ("the app", "we") helps you log food after eating, understand glycemic load, and receive
general consumer-wellness coaching for metabolic health. This policy explains what data we handle and
why. We keep it minimal: most data starts on your device, and cloud features are used only when you
sign in or connect an external service.
What we collect
- Google Sign-In: when you sign in, Google provides your name, email address, and Google
account identifier. We use this to verify your account for protected AI calls, sync, billing status,
and health-data access controls.
- Food, meal, and glucose data: foods you log, meals you save, glucose readings you enter,
favorites, trusted corrections, portions, targets, and metabolic profile settings are stored in
your browser and may be synced if you enable signed-in cloud sync.
- Health metrics: if you connect Apple Health or Health Connect, Nouriq can read user-granted
weight, body composition, blood pressure, pulse, and glucose readings. Future integrations may include
CGM data. Health observations are tagged by source
where possible so the app can show provenance and source-level sharing controls.
- AI coaching requests: when you request coaching, the relevant food, meal, glucose, and profile
summaries may be sent to our AI provider (Anthropic). Connected-health context is excluded unless
you opt in from the app's AI data sharing controls, and any enabled health context is minimized to
bounded aggregates for the requested insight.
- Barcode lookups: barcodes you scan or enter are sent to Open Food Facts to retrieve product
information. No personal information is sent.
- Cross-device sync: when signed in, your app data is stored server-side, currently in
Upstash, keyed to your Google account identifier so it can sync across devices. Without signing in,
food logging remains local to your browser unless you export it.
- Product analytics: we record allowlisted event names and coarse context—such as page type,
broad search source, signup method, and whether a calculator result was low, medium, or high—to
understand whether public pages and core features work. These events exclude food names, health
readings, free-text notes, email addresses, and search queries.
Connected health
Health Connect and Apple Health data is read only inside the native mobile app after OS permission approval,
then sent as normalized observations without provider tokens. Health readings may be displayed on Today, trend screens, and coaching
summaries. Source-level privacy controls let you disable supported health sources, and connected-health
context is excluded from AI unless you opt in.
Service providers
We rely on these processors to run the app: Google (sign-in), Anthropic (AI generation),
Upstash (rate-limiting, caching, and sync storage), Vercel (hosting), Stripe
(subscription billing when enabled), Apple Health and Health Connect (connected health metrics), USDA FoodData
Central (nutrition data), and Open Food Facts (product data). Each processes data only as
needed to provide its part of the service.
How long we keep it
- If you enable sync, your stored app data is kept until you change it or delete it. Settings →
Delete synced data erases the synced copy from our server.
- Native health permissions are managed by the operating system. You can revoke access in Apple Health
or Health Connect at any time.
- Rate-limit counters are keyed to your Google account identifier and expire within about 26 hours.
- Generated AI guidance is cached keyed to the food (not to you) and expires within 30 days.
- Anthropic's, Google's, Upstash's, Apple's, Stripe's, Vercel's, USDA's, and Open Food Facts'
handling of data are governed by their own policies.
What we don't do
We do not sell your data, share it for advertising, or use it to track you across other sites.
Your choices
You can use food search, barcode lookup, local logging, and manual export/import without signing
in. Google Sign-In is used for protected AI calls, cloud sync, billing status, and connected health.
You can sign out at any time from within the app.
Export and deletion
Settings includes local export/import, server account export, synced-data deletion, and full
server-account deletion. Server export includes synced app data, entitlement records, audit entries,
signed-in consent metadata, and connected-health token metadata without exposing token secrets. Full
server deletion removes synced app data, entitlement records, consent metadata, and user-specific
connected-health tokens where available.
Children
Nouriq is not directed to children under 13 and we do not knowingly collect their data.
Not medical advice
Nouriq is a consumer wellness app. It provides general educational information, estimated glycemic
values, and coaching suggestions. It is not a substitute for professional medical advice, diagnosis, or
treatment, and it is not intended to be used as a HIPAA-regulated clinical service. Always consult a
qualified healthcare provider about blood sugar and metabolic health.
Changes
We may update this policy; the effective date above reflects the latest version.