Welcome to NexuSelf! This Privacy Policy explains how NexuSelf ("we," "us," or "our") collects, uses, discloses, and protects your information when you use our mobile application and related services (collectively, the "Service"). By using NexuSelf, you agree to the collection and use of information in accordance with this policy.
Related Documents: Please also review our Terms and Conditions for information about your rights and responsibilities when using our Service.
1. Information We Collect
1.1 Account Information
When you create an account with NexuSelf, we collect the following information through third-party authentication services:
- Google Sign-In (Android & iOS): Email address, name, and profile picture
- Apple Sign-In (iOS): Email address, name, and profile picture (or anonymized identifiers if you choose "Hide My Email")
We do not collect or store your Google or Apple account passwords. Authentication is handled securely by Google and Apple.
1.2 Personal and Health Information
To provide personalized fitness and nutrition recommendations, we collect the following information that you provide during onboarding and app usage:
- Basic Information: Age, gender
- Physical Measurements: Height, current weight, target weight
- Fitness Goals: Fitness objectives (e.g., weight loss, muscle gain, maintenance)
- Activity Preferences: Workout frequency, diet preferences
- Health Context: Self-reported obstacles or challenges
1.3 Food and Nutrition Data
When you use our food tracking features, we collect:
- Food Logs: Manually entered meal information, including food names, quantities, and nutritional details
- Barcode Data: Scanned barcode information from packaged foods, which we store along with related food entries to maintain your nutrition history
1.4 Device Permissions
The NexuSelf app requests the following device permissions:
- Camera: To capture food photos, scan barcodes, and take progress photos
- Photo Gallery/Library: To upload existing food photos or progress photos from your device
These permissions are only used when you actively initiate features that require them (such as logging a meal with a photo or scanning a barcode). You can revoke these permissions at any time through your device settings.
1.5 Information We Do NOT Collect
For transparency, we want to clearly state that we do NOT collect:
- Device information (device model, operating system version, unique device identifiers)
- IP addresses
- Usage analytics or app behavior data
- Location data or GPS coordinates
- Cookies or tracking technologies
- Contacts or address book information
- Microphone or audio data
2. How We Use Your Information
We use the information we collect for the following purposes:
2.1 To Provide and Improve Our Service
- Create and manage your account
- Generate personalized workout plans and nutrition recommendations
- Track your fitness progress and health metrics
- Maintain your food diary and meal history
- Calculate calorie targets and macronutrient recommendations based on your goals
2.2 To Communicate With You
- Send you important service updates and notifications
- Respond to your support requests and inquiries
- Notify you about changes to our terms or privacy policy
- Send subscription-related information (renewal reminders, payment confirmations)
2.3 To Process Payments
Process subscription payments through Apple App Store or Google Play Store. Manage your subscription status and billing cycle.
Note: We do not directly collect or store your payment card information. All payment processing is handled securely by Apple and Google through their respective in-app purchase systems.
2.4 To Ensure Security and Compliance
- Detect and prevent fraud, abuse, or security incidents
- Comply with legal obligations and enforce our Terms of Service
- Protect the rights, property, and safety of NexuSelf, our users, and the public
3. How We Store and Protect Your Information
3.1 Data Storage
Your data is stored securely on servers operated by DigitalOcean, located in California, United States. We use MongoDB as our database system to store and manage your information.
3.2 Security Measures
We take the security of your data seriously and implement industry-standard security measures, including:
- Encryption in Transit: All data transmitted between your device and our servers is encrypted using HTTPS (SSL/TLS) protocols
- Password Security: Your passwords are securely encrypted using industry-standard hashing algorithms before being stored in our database
- Authentication: We use JSON Web Tokens (JWT) to securely manage user sessions and access control
- Access Controls: Only authorized administrators have access to user data, and all access is monitored and logged
- Regular Security Audits: We regularly review and update our security practices to protect against emerging threats
3.3 Data Retention
We retain your personal information for as long as your account remains active or as needed to provide you with our services. Specifically:
- Account Data: Retained while your account is active
- Health and Fitness Data: Retained while your account is active to provide tracking history and personalized recommendations
- Deleted Account Data: When you delete your account, your data is retained for 45 days to allow for potential account recovery. After this period, all personal data is permanently deleted from our systems
- Legal Requirements: Certain information (such as financial records) may be retained longer as required by law
4. How We Share Your Information
4.1 Third-Party Services
We use the following third-party services to provide and improve our Service:
Authentication Services:
- Google Sign-In: For user authentication on Android and iOS. Google's Privacy Policy applies to their authentication service
- Apple Sign-In: For user authentication on iOS. Apple's Privacy Policy applies to their authentication service
Payment Processing:
- Google Play Billing: For subscription payments on Android devices. We do not receive or store your payment information; Google processes all payments securely
- Apple In-App Purchase: For subscription payments on iOS devices. We do not receive or store your payment information; Apple processes all payments securely
Food Database Services:
- OpenFoodFacts: A public food database used to retrieve nutritional information based on scanned barcodes. We only share the barcode or product identifier—no personal user data is transmitted to OpenFoodFacts
- USDA FoodData Central: A public nutritional database used to provide accurate food and nutrition information. No personal data is shared with USDA
Infrastructure Services:
- DigitalOcean: Cloud hosting provider for our servers (California, USA). Your data is stored on DigitalOcean's secure infrastructure
- MongoDB: Database management system used to store and organize your data securely
4.3 We Do NOT Share Your Data With Third Parties
Except for the specific services mentioned above that are necessary for app functionality, we do not sell, rent, or share your personal information with third parties for their marketing purposes.
4.4 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court order or government agency), including to:
- Comply with legal obligations
- Protect and defend the rights or property of NexuSelf
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of users of the Service or the public
5. Your Rights and Choices
5.1 Access and Update Your Information
You can access and update your personal information at any time through the app:
- Go to Settings → Profile to view and edit your account information
- Go to Settings → Personal Details to update your health and fitness information
- View and manage your food logs and meal history within the app
5.2 Delete Your Account and Data
You have the right to delete your account and all associated data at any time:
- In the app, go to Settings → Account → Delete My Account
- Alternatively, contact us at Contact Support to request account deletion
When you delete your account:
- All your personal data, including account information, health data, and food logs, will be permanently deleted
- Data deletion occurs immediately from active systems, with a 45-day grace period before permanent removal from backups
- Some financial records may be retained as required by law
- This action cannot be undone after the 45-day grace period
5.3 Data Portability
At this time, we do not provide an automated option to download or export your data. If you would like to receive a copy of your personal information, please contact us at Contact Support, and we will work with you to provide your data in a readable format.
5.4 Marketing Communications
We currently do not send marketing emails or promotional communications. You will only receive essential service-related communications.
5.5 Rights Under GDPR (EU Users)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR):
- Right to Access, Rectification, and Erasure
- Right to Restrict Processing and Data Portability
- Right to Object and Right to Withdraw Consent
To exercise any of these rights, please contact us at Contact Our Team.
5.6 Rights Under CCPA (California Users)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA):
- Right to Know categories and specific pieces of information collected
- Right to Delete your personal information
- Right to Opt-Out and Right to Non-Discrimination
To exercise these rights, please contact us at Contact Support.
6. Children's Privacy
NexuSelf is intended for users aged 13 and above. We do not knowingly collect personal information from children under 13. If you are under 18, you must have your parent or guardian's permission to use our Service. If you believe we have collected information from a child under 13, please contact us at Contact Privacy Team.
7. International Data Transfers
Your information is stored on servers located in California, United States. By using NexuSelf, you consent to the transfer of your information to the United States and acknowledge that U.S. law may not provide the same level of data protection as the laws in your jurisdiction.
8. Data Breach Notification
In the event of a data breach that affects your personal information, we will notify affected users via email within 72 hours and inform relevant regulatory authorities as required by applicable law.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date and notify you via email or through an in-app notification at least 30 days before changes take effect.
10. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: Contact Support
- Support: Available through the app under Settings → Support
- Grievance Officer: Contact Grievance Officer
- Response Time: We aim to respond within 7 business days
11. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), we process your personal data based on Consent, Contract necessity, Legal Obligation, and Legitimate Interests (e.g., improving algorithms, preventing fraud).
12. Your Consent
By using NexuSelf, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and sharing of your information as described herein. If you do not agree with this Privacy Policy, please do not use our Service.