Nishtu

⚠ Draft — not legally reviewed

This document describes what the software actually does, written from the source code. It has not been reviewed by a lawyer, and the highlighted {{PLACEHOLDER}} markers still need real values (legal entity, address, governing law, contact address, effective date).

Do not rely on it, and do not submit it to an app store, until both are resolved.

Legal

Privacy Policy

What Nishtu collects, where it goes, how long it is kept, and how to get rid of it.

Effective {{EFFECTIVE_DATE}}

1. Who we are

Nishtu is a recipe, nutrition and pantry application. It is operated by {{LEGAL_ENTITY}}, of {{REGISTERED_ADDRESS}} (“we”, “us”). We are the data controller for the personal data described here. This policy covers the Nishtu website at {{DOMAIN}} and the Nishtu Android application.

2. What we collect

Everything below is data you give us by using the app — we do not buy data about you, we do not run advertising, and we do not use third-party advertising or analytics trackers.

CategoryWhat it isWhy
AccountEmail address, display name, and your unit and theme preferences. Your password is held by our authentication provider, never by us.To create and sign you into your account.
Public profileA handle, display name, an optional avatar image and an optional short bio — only if you create a profile.So other members can identify you in shared groups and on public recipes.
RecipesRecipe titles, ingredients, quantities, instructions, tags, servings, notes and any photos you attach; the nutrition figures we compute or you enter manually.The core of the product — this is your recipe book.
PantryThe ingredients you record as being in your kitchen, their quantities and any expiry dates, plus a log of which recipes you marked as cooked and what that deducted.To work out what you can cook now, and to undo a mistaken deduction.
Meal plans and food logsWhich recipes you planned for which day and meal slot, and any ad-hoc food you logged by photo, menu photo, receipt, voice or typed text — including the food label and its estimated nutrition.To show your day, your week, and your progress against goals.
Nutrition goalsPer-nutrient daily targets you set, for example a protein minimum or a sodium maximum.To show attainment against a goal. See §6 — this can be health-adjacent data.
GroupsThe groups you create or join, your role in them, invite codes you generate, and which of your recipes you published to which group.To share recipes with people you choose.
ReportsIf you report a public recipe: the recipe, a reason and an optional note, recorded against your account.Moderation of public content.
BillingWhether you hold a Pro entitlement and when it was granted or revoked, and an append-only ledger row per grant or revocation recording only an account reference, the platform, and a timestamp. We never receive or store your card details.To give you what you paid for, and to keep the records tax and consumer law require.
DiagnosticsServer logs and, where enabled, error reports containing the failing request, a stack trace and your account identifier. Short-lived counters for rate limits and daily scan quotas.To keep the service working and to stop abuse.

3. Camera, photos and microphone

Several features accept an image or an audio recording. Whether the app asks for your camera, photo library or microphone depends on which of these you use, and you can decline any of them and still use the rest of the app.

The result of a scan is saved when you confirm it — for example the pantry item, the food-log entry, or the product facts learned from a barcode. Product facts learned from a barcode are stored against the barcode, not against you, and are shared with other users who scan the same product.

4. Third-party AI providers

Images, audio and text you submit to the scanning, import and voice features are sent to third-party AI providers. Specifically: images and text go to Anthropic (photo, label, menu and receipt extraction; recipe import; ingredient-match adjudication; parsing what you said), and audio goes to OpenAI (speech-to-text). Your account identifier, email and name are not sent with them — but whatever is in the picture, the recording or the text is.

These providers are only called when their API keys are configured for the environment you are using. Where they are not configured, the corresponding features are unavailable rather than silently degraded. We use them as processors, under their commercial terms, to return a result to you.

Barcode lookups also query the public Open Food Facts database. That request contains the barcode only.

5. Who else processes your data

We use the following service providers. Each processes personal data only to provide their service to us.

ProviderWhat forWhere
SupabaseAuthentication and the application databaseEU (eu-west-1)
Fly.ioHosting the application server{{FLY_REGION}}
VercelHosting the websiteGlobal edge network
TigrisObject storage for recipe photos{{TIGRIS_REGION}}
AnthropicAI extraction from images and text (§4)United States
OpenAISpeech-to-text for voice input (§4)United States
StripeCard payments on the webGlobal
Google Play billingSubscriptions bought in the Android appGlobal
SentryError reporting, where enabled{{SENTRY_REGION}}
Open Food FactsPublic barcode lookups (barcode only)EU

Some of these providers are outside the UK/EEA. Transfers rely on the safeguards in those providers’ own data-processing terms — {{TRANSFER_MECHANISM}}.

We do not sell your personal data, and we do not share it with anyone for their own advertising or marketing.

6. Goals, food logs and health data

What you eat and the nutrition targets you set can reveal things about your health. We treat them accordingly: they are visible only to you, they are never published with a recipe, and they are deleted with your account.

Nutrition figures in Nishtu are estimates, derived from food composition data and — for scanned or AI-parsed items — from a model’s reading of an image or a sentence. They are not medical or dietetic advice and must not be relied on to manage a medical condition, an allergy or an intolerance. Always check the packaging.

7. What other people can see

Your pantry, meal plans, food logs, goals and email address are never shown to other users.

8. Cookies

The website sets a small number of strictly necessary cookies: a session cookie and a refresh cookie that keep you signed in (both HTTP-only, so page scripts cannot read them), and a cookie recording your chosen theme so the first paint is not the wrong colour. There are no advertising or analytics cookies, so there is no consent banner to click through.

9. How long we keep it

10. Deleting your account and your data

You can delete your account yourself, from inside the app — you do not need to email anyone and you do not need to ask us.

Deleting your account removes, immediately and irreversibly:

Two things behave differently, and you should know about both before you press the button:

If you are the only administrator of a group that still has other members, deletion is refused until you transfer administration or delete the group — otherwise we would be stranding other people’s shared content. The app tells you which groups and links you to them.

If you signed in through a social provider and want to request deletion without opening the app, email {{CONTACT_EMAIL}} from the address on the account and we will carry out the same erasure. This section is also the data-deletion instructions URL for social login providers that require one.

11. Your rights

Subject to {{JURISDICTION}} data protection law, you have the right to access the personal data we hold about you, to have it corrected, to have it erased, to restrict or object to our processing of it, and to receive it in a portable form. You also have the right to complain to a supervisory authority.

Erasure is self-service (§10). For access, correction or portability, email {{CONTACT_EMAIL}} — there is currently no one-click export in the app, so we fulfil those requests manually.

We process your data to perform our contract with you (providing the service), on the basis of legitimate interests (keeping the service secure and working), to comply with legal obligations (billing records), and — for optional, health-adjacent features such as goals and food logging — on the basis of your consent, given by choosing to use them, which you may withdraw at any time by deleting that data or your account.

12. Security

Traffic between your device and our servers, and between our servers and our database and service providers, is encrypted in transit with TLS. Sign-in tokens are held in HTTP-only cookies. Access to production systems is limited to those who operate the service. Encryption at rest is provided by our hosting and storage providers under their own terms.

No system is perfectly secure, and we do not claim otherwise. If you find a vulnerability, please report it to {{CONTACT_EMAIL}} rather than disclosing it publicly.

13. Children

Nishtu is not directed at children. You must be at least {{MINIMUM_AGE}} years old to create an account. If you believe a child has created one, contact us and we will delete it.

14. Changes

We may update this policy as the product changes. The effective date at the top always reflects the current version, and we will tell you in the app before a material change takes effect.

15. Contact

Questions, requests or complaints: {{CONTACT_EMAIL}}, or write to {{LEGAL_ENTITY}}, {{REGISTERED_ADDRESS}}. See also our Terms of Service.