1. Who we are
Nishtu is a recipe, nutrition and pantry application. It is operated by {{LEGAL_ENTITY}}, of {{REGISTERED_ADDRESS}} (“we”, “us”). We are the data controller for the personal data described here. This policy covers the Nishtu website at {{DOMAIN}} and the Nishtu Android application.
2. What we collect
Everything below is data you give us by using the app — we do not buy data about you, we do not run advertising, and we do not use third-party advertising or analytics trackers.
| Category | What it is | Why |
|---|---|---|
| Account | Email address, display name, and your unit and theme preferences. Your password is held by our authentication provider, never by us. | To create and sign you into your account. |
| Public profile | A handle, display name, an optional avatar image and an optional short bio — only if you create a profile. | So other members can identify you in shared groups and on public recipes. |
| Recipes | Recipe titles, ingredients, quantities, instructions, tags, servings, notes and any photos you attach; the nutrition figures we compute or you enter manually. | The core of the product — this is your recipe book. |
| Pantry | The ingredients you record as being in your kitchen, their quantities and any expiry dates, plus a log of which recipes you marked as cooked and what that deducted. | To work out what you can cook now, and to undo a mistaken deduction. |
| Meal plans and food logs | Which recipes you planned for which day and meal slot, and any ad-hoc food you logged by photo, menu photo, receipt, voice or typed text — including the food label and its estimated nutrition. | To show your day, your week, and your progress against goals. |
| Nutrition goals | Per-nutrient daily targets you set, for example a protein minimum or a sodium maximum. | To show attainment against a goal. See §6 — this can be health-adjacent data. |
| Groups | The groups you create or join, your role in them, invite codes you generate, and which of your recipes you published to which group. | To share recipes with people you choose. |
| Reports | If you report a public recipe: the recipe, a reason and an optional note, recorded against your account. | Moderation of public content. |
| Billing | Whether you hold a Pro entitlement and when it was granted or revoked, and an append-only ledger row per grant or revocation recording only an account reference, the platform, and a timestamp. We never receive or store your card details. | To give you what you paid for, and to keep the records tax and consumer law require. |
| Diagnostics | Server logs and, where enabled, error reports containing the failing request, a stack trace and your account identifier. Short-lived counters for rate limits and daily scan quotas. | To keep the service working and to stop abuse. |
3. Camera, photos and microphone
Several features accept an image or an audio recording. Whether the app asks for your camera, photo library or microphone depends on which of these you use, and you can decline any of them and still use the rest of the app.
- Recipe photos you attach to a recipe are stored by us, in object storage, until you delete the photo, the recipe or your account.
- Barcode and product-label scans, meal photos, menu photos and receipt photos are sent to our server, forwarded to an AI provider for extraction, and used to produce the result you see. We do not store these images. They are held in memory for the length of the request and then discarded; nothing writes them to our database or object storage.
- Voice input for pantry and food logging is recorded on your device, sent to our server, and forwarded to a speech-to-text provider. The audio is not stored by us. The resulting text is then processed as described in §4.
The result of a scan is saved when you confirm it — for example the pantry item, the food-log entry, or the product facts learned from a barcode. Product facts learned from a barcode are stored against the barcode, not against you, and are shared with other users who scan the same product.
4. Third-party AI providers
Images, audio and text you submit to the scanning, import and voice features are sent to third-party AI providers. Specifically: images and text go to Anthropic (photo, label, menu and receipt extraction; recipe import; ingredient-match adjudication; parsing what you said), and audio goes to OpenAI (speech-to-text). Your account identifier, email and name are not sent with them — but whatever is in the picture, the recording or the text is.
These providers are only called when their API keys are configured for the environment you are using. Where they are not configured, the corresponding features are unavailable rather than silently degraded. We use them as processors, under their commercial terms, to return a result to you.
Barcode lookups also query the public Open Food Facts database. That request contains the barcode only.
5. Who else processes your data
We use the following service providers. Each processes personal data only to provide their service to us.
| Provider | What for | Where |
|---|---|---|
| Supabase | Authentication and the application database | EU (eu-west-1) |
| Fly.io | Hosting the application server | {{FLY_REGION}} |
| Vercel | Hosting the website | Global edge network |
| Tigris | Object storage for recipe photos | {{TIGRIS_REGION}} |
| Anthropic | AI extraction from images and text (§4) | United States |
| OpenAI | Speech-to-text for voice input (§4) | United States |
| Stripe | Card payments on the web | Global |
| Google Play billing | Subscriptions bought in the Android app | Global |
| Sentry | Error reporting, where enabled | {{SENTRY_REGION}} |
| Open Food Facts | Public barcode lookups (barcode only) | EU |
Some of these providers are outside the UK/EEA. Transfers rely on the safeguards in those providers’ own data-processing terms — {{TRANSFER_MECHANISM}}.
We do not sell your personal data, and we do not share it with anyone for their own advertising or marketing.
6. Goals, food logs and health data
What you eat and the nutrition targets you set can reveal things about your health. We treat them accordingly: they are visible only to you, they are never published with a recipe, and they are deleted with your account.
Nutrition figures in Nishtu are estimates, derived from food composition data and — for scanned or AI-parsed items — from a model’s reading of an image or a sentence. They are not medical or dietetic advice and must not be relied on to manage a medical condition, an allergy or an intolerance. Always check the packaging.
7. What other people can see
- Private recipes — visible only to you.
- Group recipes — visible to the members of the groups you published them to, attributed to your profile.
- Public recipes — visible to anyone with the link, including people without an account, attributed to your profile.
- Your profile — your handle, display name, avatar and bio are visible to anyone who can see a recipe you shared.
Your pantry, meal plans, food logs, goals and email address are never shown to other users.
8. Cookies
The website sets a small number of strictly necessary cookies: a session cookie and a refresh cookie that keep you signed in (both HTTP-only, so page scripts cannot read them), and a cookie recording your chosen theme so the first paint is not the wrong colour. There are no advertising or analytics cookies, so there is no consent banner to click through.
9. How long we keep it
- Your content — for as long as your account exists, or until you delete the item.
- Images and audio sent for scanning — not retained by us (§3). Any retention by the AI provider is governed by their terms.
- Billing ledger rows — retained after account deletion, in pseudonymised form, for the statutory retention period: {{BILLING_RETENTION_PERIOD}}. They record only a one-way pseudonym, the platform, whether access was granted or revoked, and when. They never contained your name or email.
- Diagnostics — kept for the retention window of our logging and error reporting providers: {{DIAGNOSTICS_RETENTION_PERIOD}}.
10. Deleting your account and your data
You can delete your account yourself, from inside the app — you do not need to email anyone and you do not need to ask us.
- Web: Settings → Account → Delete my account.
- Android: Settings → Account → Delete my account.
Deleting your account removes, immediately and irreversibly:
- your private recipes, their photos and their nutrition data;
- your pantry, cook history, meal plans, food logs, shopping lists and goals;
- your profile, group memberships and any reports you filed;
- your theme and unit preferences and your entitlement records;
- your sign-in identity, including your email address and password.
Two things behave differently, and you should know about both before you press the button:
- Recipes you published to a group or publicly. You choose what happens to them: keep, anonymised — the recipe stays in the group, permanently detached from you and no longer editable by anyone; or remove entirely — it is unpublished everywhere and deleted. Other members may already have their own copies, which we cannot reach.
- Billing ledger rows are kept, pseudonymised (§9). This is a legal retention obligation, not a choice.
If you are the only administrator of a group that still has other members, deletion is refused until you transfer administration or delete the group — otherwise we would be stranding other people’s shared content. The app tells you which groups and links you to them.
If you signed in through a social provider and want to request deletion without opening the app, email {{CONTACT_EMAIL}} from the address on the account and we will carry out the same erasure. This section is also the data-deletion instructions URL for social login providers that require one.
11. Your rights
Subject to {{JURISDICTION}} data protection law, you have the right to access the personal data we hold about you, to have it corrected, to have it erased, to restrict or object to our processing of it, and to receive it in a portable form. You also have the right to complain to a supervisory authority.
Erasure is self-service (§10). For access, correction or portability, email {{CONTACT_EMAIL}} — there is currently no one-click export in the app, so we fulfil those requests manually.
We process your data to perform our contract with you (providing the service), on the basis of legitimate interests (keeping the service secure and working), to comply with legal obligations (billing records), and — for optional, health-adjacent features such as goals and food logging — on the basis of your consent, given by choosing to use them, which you may withdraw at any time by deleting that data or your account.
12. Security
Traffic between your device and our servers, and between our servers and our database and service providers, is encrypted in transit with TLS. Sign-in tokens are held in HTTP-only cookies. Access to production systems is limited to those who operate the service. Encryption at rest is provided by our hosting and storage providers under their own terms.
No system is perfectly secure, and we do not claim otherwise. If you find a vulnerability, please report it to {{CONTACT_EMAIL}} rather than disclosing it publicly.
13. Children
Nishtu is not directed at children. You must be at least {{MINIMUM_AGE}} years old to create an account. If you believe a child has created one, contact us and we will delete it.
14. Changes
We may update this policy as the product changes. The effective date at the top always reflects the current version, and we will tell you in the app before a material change takes effect.
15. Contact
Questions, requests or complaints: {{CONTACT_EMAIL}}, or write to {{LEGAL_ENTITY}}, {{REGISTERED_ADDRESS}}. See also our Terms of Service.