Last Updated: July 1, 2026 Effective Date: July 1, 2026
1. Introduction
This Privacy Policy describes how Brandon Minch, LLC, a Colorado limited liability company doing business as Nomlog ("Nomlog," "we," "us," or "our"), collects, uses, discloses, and protects your personal information when you use the Nomlog mobile application (the "App"), the nomlog.ai website, and related services (collectively, the "Service").
By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices as described herein, please do not use the Service.
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the revised Privacy Policy within the App, updating the "Last Updated" date, or sending a notification to your registered email address at least thirty (30) days before the changes take effect. Your continued use of the Service after the effective date of the revised Privacy Policy constitutes your acceptance of the changes.
The Service is offered only in the United States and requires users to be at least eighteen (18) years old.
2. Information We Collect
We collect information in the following categories:
2.1 Information You Provide Directly
Account Information. When you create an account, we collect your email address, name, and password (or authentication tokens if you sign in via Google or Apple Sign-In). We also collect your timezone for accurate meal and activity logging.
Profile and Health Information. To personalize the Service, you provide your date of birth, biological sex, height, weight, lifestyle activity level, training frequency and styles, and primary health goal (e.g., weight loss, muscle gain, maintenance, training for an event). This information is used to calculate personalized nutrition targets and calorie recommendations. You may also set preferences such as meal timing, weigh-in cadence, and measurement units.
Meal and Nutrition Data. We collect information about your meals, including text descriptions, meal type (breakfast, lunch, dinner, snack), timestamps, ingredients and servings, and AI-generated nutritional estimates (calories, protein, carbohydrates, fat, and nutrients such as fiber, sugar, sodium, and saturated fat). You may also save favorite meals for quick logging and plan upcoming meals.
Meal Photographs. If you choose to log meals using photos, we collect the images you upload. These photos are processed by our AI systems to generate nutritional estimates and are stored in private cloud storage.
Voice Recordings. If you choose to log by voice, the audio you record is sent to our AI transcription provider to be converted into text, which then appears in the message box for you to review and edit before you send it. While it is being sent, the recording is written to a temporary cache on your own device; the app deletes it as soon as the transcription comes back, or when you discard it. On our side nothing is stored at all — the audio is held in memory only for as long as the request takes, and no recording is written to our databases or cloud storage. Our transcription provider may retain the audio briefly under its own policy for abuse monitoring; see Section 6.
Weight Data. If you use weight tracking, we collect your weigh-in entries (weight and date/time) and compute trends over time.
Activity and Exercise Data. We collect information about your physical activities, including activity type, description, duration, distance, effort level, exercises performed, and estimated calories burned.
Water Intake Data. We collect daily water intake records that you log through the Service.
Chat and Interaction Data. When you interact with the AI chat assistant, we collect your chat messages, the AI-generated responses, and associated metadata (timestamps, thread identifiers, and technical usage telemetry such as token counts used for quota management and service operation).
Recipe Interactions. We collect data about your interactions with recipes, including views, saves, adaptations, and cooking history.
Feedback Submissions. If you submit in-app feedback (bug reports, ideas, or praise), we collect the feedback text, the feedback category, device context (device model, operating system, and app version), and any screenshot you choose to attach. Screenshots are stored in private cloud storage.
Waitlist Information. If you join our waitlist through the nomlog.ai website, we collect your email address and, optionally, your name.
2.2 Information Collected Automatically
Device and Technical Information. We automatically collect device type, operating system and version, app version, and platform identifier (iOS, Android, or web).
Usage Data and Analytics. We collect information about how you use the Service, including features accessed, actions taken (meals logged, activities recorded, photos uploaded, recipes viewed), interaction timestamps, and session data. We use PostHog, a third-party analytics platform, to collect and process this usage data. We do not include your health metrics (such as weight, calorie intake, or body measurements) in analytics events.
Error and Crash Data. We use Sentry, a third-party error monitoring service, to collect crash reports, error logs, and related diagnostic data to help us identify and fix issues with the Service.
2.3 Information from Third-Party Sources
Apple HealthKit (iOS). With your explicit permission, we may read workout and activity data from Apple HealthKit, including workout type, duration, energy burned, distance, and source application. This data is used to automatically log activities within the Service. You can revoke HealthKit access at any time through your device settings.
Third-Party Authentication. If you sign in using Google or Apple Sign-In, we receive basic profile information (such as your name and email address) from the authentication provider, as authorized by you during the sign-in process.
3. How We Use Your Information
We use the information we collect for the following purposes:
Providing and Operating the Service. To create and manage your account, process and display your meal logs, weight entries, activity records, and water intake, deliver personalized nutrition targets, and facilitate recipe browsing, generation, and saving.
AI-Powered Analysis and Features. To analyze meal photographs and text descriptions using artificial intelligence to generate nutritional estimates; to power the AI chat assistant for meal planning, recipe suggestions, and activity logging; to classify user intent in chat conversations; and to generate and adapt recipes. We use OpenAI and Anthropic APIs for these AI capabilities. When we send data to these providers, it is transmitted securely and used in accordance with their respective privacy policies and API data-use terms.
Personalization. To calculate personalized daily nutrition targets based on your profile information, goals, and activity level; to provide relevant recipe recommendations; and to tailor the Service to your preferences.
Age Verification. To verify that you meet the minimum age requirement (18+) using the date of birth you provide.
Push Notifications. To send you meal logging reminders, weigh-in reminders, and other Service-related communications through OneSignal, our push notification provider. You can manage notification preferences in your device settings.
Email Communications. To send transactional and Service-related email (such as waitlist confirmations and account communications) through Resend, our email delivery provider.
Analytics and Improvement. To understand how users interact with the Service, identify trends and usage patterns, diagnose technical issues, evaluate and improve the quality of AI-generated outputs, and improve the Service's features, performance, and user experience.
Feedback and Support. To review, triage, and respond to feedback and bug reports you submit, and to improve the Service based on them.
Safety and Compliance. To enforce our Terms of Service, protect against fraud or abuse, comply with legal obligations, and respond to lawful requests from law enforcement or governmental authorities.
Usage Quota Management. To monitor and enforce usage limits on AI-powered features, including per-user usage quotas on a rolling basis.
4. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
4.1 Service Providers
We share information with third-party service providers that perform services on our behalf, subject to contractual obligations to protect your data:
| Provider | Purpose | Data Shared |
|---|---|---|
| Supabase | Database hosting, user authentication, file storage | Account data, profile data, meal/weight/activity logs, meal photos, feedback attachments |
| OpenAI | AI-powered meal analysis, nutritional estimation, activity burn calculations, intent classification, voice-to-text transcription | Meal descriptions, meal photos, voice recordings, activity descriptions, chat messages, profile context |
| Anthropic | AI-powered recipe generation, chat interactions, meal adaptation | Chat messages, meal/recipe context, dietary preferences, profile context |
| PostHog | Product analytics and usage tracking | Usage events, feature interactions, device information (no health metrics) |
| Sentry | Error monitoring and crash reporting | Error logs, stack traces, device information |
| OneSignal | Push notification delivery | Device tokens, user identifiers, notification content |
| Resend | Transactional email delivery | Email address, name, email content |
| Render | Application hosting | All data processed through our API |
| GitHub | Feedback triage (private issue tracker) | Feedback text, feedback category, device context |
| Apple (HealthKit) | Health data integration (iOS) | Workout data (read/write with user permission) |
If and when paid subscriptions launch, we may additionally share purchase and entitlement information with RevenueCat (subscription management) and receive transaction information from the Apple App Store or Google Play Store. We will update this Privacy Policy before those features take effect.
4.2 Legal Requirements
We may disclose your information if we believe in good faith that disclosure is necessary to: (a) comply with applicable law, regulation, legal process, or governmental request; (b) enforce our Terms of Service; (c) protect the safety, rights, or property of Nomlog, our users, or the public; or (d) detect, prevent, or address fraud, security, or technical issues.
4.3 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be transferred as part of the transaction. We will notify you of any such change in ownership or control of your personal information.
4.4 Aggregated or De-Identified Data
We may share aggregated or de-identified data that cannot reasonably be used to identify you for any purpose, including research, analytics, and business purposes.
5. Apple HealthKit and Google Health Connect Data
We treat health data obtained from Apple HealthKit and Google Health Connect with heightened protections:
- We access HealthKit and Health Connect data only with your explicit, informed consent.
- We do not use HealthKit or Health Connect data for advertising, marketing, or data mining purposes.
- We do not sell or share HealthKit or Health Connect data with third parties for advertising or marketing.
- We do not disclose HealthKit or Health Connect data to data brokers.
- HealthKit and Health Connect data is used solely to provide core Service functionality — specifically, to sync and display your workouts and activity data within the App and to reflect activity in your nutrition picture.
- You may revoke access to HealthKit or Health Connect data at any time through your device's Health or privacy settings. Revoking access will stop future data syncing but will not delete activity data already logged in the Service.
6. AI Data Processing
6.1 How AI Processes Your Data
When you use AI-powered features (meal photo analysis, nutritional estimation, chat interactions, recipe generation, voice input), your inputs are transmitted to third-party AI providers (OpenAI and Anthropic) for processing. This may include:
- Meal photographs and text descriptions
- Voice recordings you make using the microphone button, sent for transcription into text
- Chat messages and conversational context
- Profile information relevant to personalization (e.g., dietary goals, restrictions, nutrition targets)
- Activity descriptions and exercise context
6.2 AI Provider Data Practices
Under the API terms we rely on with OpenAI and Anthropic, data sent to these providers through their APIs is not used to train their general-purpose models. Data processing practices of third-party providers are governed by their own privacy policies and terms, and we encourage you to review them.
6.3 AI Accuracy and Limitations
AI-generated nutritional information, calorie estimates, and other outputs are approximations and are not guaranteed to be accurate. Please refer to Section 6 of our Terms of Service for important disclaimers regarding AI accuracy.
7. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service to you. Specifically:
- Account and profile data is retained until you delete your account.
- Meal logs, weight logs, activity logs, and water intake data are retained until you delete your account or delete specific records.
- Meal photographs are retained until you delete the associated meal log or your account.
- Voice recordings are not retained on Nomlog's servers: the audio is held in memory only for the duration of the transcription request and is never written to our databases or cloud storage. On your own device, the app writes the clip to a temporary cache while it uploads and deletes it as soon as transcription finishes, when you discard it, or once a failed one has been retried — a clip is kept only while a retry is still available to you. Only the transcribed text you choose to send is saved, as part of your chat history.
- Chat history is retained until you delete your account.
- Feedback submissions and attachments are retained until you delete your account, except that feedback content already mirrored to our private issue tracker for triage may be retained in de-identified form.
- Waitlist information is retained until you request removal or we launch and migrate or delete the list.
- Analytics data is retained in accordance with PostHog's retention policies, typically in aggregated or anonymized form.
- Error and crash logs are retained in accordance with Sentry's retention policies, typically around 90 days.
Upon account deletion, we will delete or de-identify your personal information within thirty (30) days, except where we are required to retain it by law, or where it has been incorporated into aggregated, de-identified datasets.
8. Data Security
We implement commercially reasonable technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using TLS/SSL
- Secure authentication using Supabase Auth with JWT tokens
- Protected API endpoints requiring authenticated access
- Row-level security controls scoping data access to the owning user
- Private (non-public) storage buckets for meal photos and feedback attachments
- Access controls limiting access to personal data on a need-to-know basis
However, no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially reasonable means to protect your personal information, we cannot guarantee its absolute security.
9. Your Rights and Choices
9.1 Account Information
You may access, update, or correct your profile information at any time through the App's settings.
9.2 Notifications
You may opt out of push notifications at any time through your device settings. Note that certain transactional or Service-related communications may still be sent via email.
9.3 HealthKit and Health Connect
You may revoke the App's access to HealthKit or Health Connect data at any time through your device's Health or privacy settings.
9.4 Data Export and Portability
You may request a copy of your personal data in a structured, commonly used, machine-readable format through the App's settings or by contacting us at hello@nomlog.ai.
9.5 Data and Account Deletion
You may delete your account and associated personal data through the App's settings or by contacting us at hello@nomlog.ai. We will process deletion within thirty (30) days, subject to any legal obligations requiring us to retain certain information.
10. U.S. State Privacy Rights
10.1 California Residents (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"):
Right to Know. You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which that information was collected, the business or commercial purpose for collecting the information, and the categories of third parties with whom we share it.
Right to Delete. You have the right to request that we delete the personal information we have collected from you, subject to certain exceptions.
Right to Correct. You have the right to request that we correct inaccurate personal information that we maintain about you.
Right to Opt Out of Sale/Sharing. We do not sell your personal information in the traditional sense. However, certain data sharing practices (such as the use of analytics identifiers) may constitute a "sale" or "sharing" under the CCPA. You may opt out by contacting us at hello@nomlog.ai.
Right to Limit Use of Sensitive Personal Information. We collect sensitive personal information, including health-related information (meal data, body measurements, weight history, activity data). We use this information solely for the purposes of providing the Service, and we do not use it for purposes beyond what is necessary to provide the Service.
Non-Discrimination. We will not discriminate against you for exercising any of your CCPA rights.
To exercise your rights, contact us at hello@nomlog.ai. We will verify your identity before processing your request. You may designate an authorized agent to make a request on your behalf.
Categories of Personal Information Collected (Past 12 Months):
| Category | Examples | Collected |
|---|---|---|
| Identifiers | Name, email, user ID | Yes |
| Personal Information (Cal. Civ. Code 1798.80) | Name, physical characteristics | Yes |
| Protected Classifications | Age (date of birth), sex | Yes |
| Commercial Information | Subscription purchase history (when subscriptions launch) | Yes |
| Internet/Network Activity | App usage, feature interactions | Yes |
| Geolocation | Timezone (coarse location) | Yes |
| Sensory Data | Meal photographs, feedback screenshots, voice recordings (transcribed, not stored) | Yes |
| Health Information | Meal data, body measurements, weight history, activity data, HealthKit data | Yes |
| Inferences | Nutritional preferences, activity patterns, personalized targets | Yes |
10.2 Washington Residents (My Health My Data Act)
If you are a Washington State resident, you have additional rights under the Washington My Health My Data Act regarding your consumer health data (including nutrition, weight, and fitness data). These rights include the right to access, delete, and withdraw consent for the collection and sharing of your health data. We will not sell your consumer health data without your affirmative consent. To exercise your rights, contact us at hello@nomlog.ai.
10.3 Other U.S. States
If you are a resident of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive consumer privacy law, you may have additional rights, including the right to access, correct, delete, and port your data, and the right to opt out of targeted advertising, the sale of personal data, and profiling. We do not serve targeted advertising and do not sell personal data. To exercise your rights, contact us at hello@nomlog.ai. You may appeal any decision regarding your request by contacting us at the same address.
11. Users Outside the United States
The Service is offered only to users located in the United States, and the App's store availability is limited accordingly. We do not target or direct the Service to residents of the European Economic Area, United Kingdom, or Switzerland, and we do not intend to process personal data subject to the GDPR or UK GDPR. If you access the Service from outside the United States, you do so on your own initiative; your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from those of your jurisdiction. If we expand availability to additional countries in the future, we will update this Privacy Policy to describe the rights and protections applicable to users in those regions.
12. Children's Privacy
The Service is intended for adults and requires users to be at least eighteen (18) years old. We do not knowingly collect personal information from anyone under eighteen. We verify age using the date of birth provided at onboarding. If we become aware that we have inadvertently collected personal information from a person under eighteen, we will terminate the account and delete such information as promptly as possible. If you believe that a person under eighteen has provided us with personal information, please contact us at hello@nomlog.ai.
13. Third-Party Links and Services
The Service may contain links to third-party websites or services that are not operated by us. This Privacy Policy does not apply to third-party services. We encourage you to review the privacy policies of any third-party services you access through the Service. We are not responsible for the data practices of third parties.
14. Do Not Track Signals
Some browsers offer a "Do Not Track" ("DNT") signal. Because there is no industry-standard interpretation of DNT signals, the Service does not currently respond to DNT signals. We will revisit this policy if a uniform standard is established.
15. Push Notifications
We use OneSignal to deliver push notifications. When you enable push notifications, your device token and user identifier are shared with OneSignal for notification delivery. We may tag users with identifiers to personalize notification content. You can disable push notifications at any time through your device settings. OneSignal's privacy policy governs their processing of your information.
16. Data Breach Notification
In the event of a data breach that compromises the security, confidentiality, or integrity of your personal information, we will notify affected users and relevant authorities in accordance with applicable law, including the Colorado Security Breach Notification Act and other applicable U.S. state breach notification laws.
17. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices — including privacy-specific inquiries and data subject requests — please contact us at:
Email: hello@nomlog.ai Mailing Address: Brandon Minch, LLC d/b/a Nomlog 3034 Quitman Street Denver, CO 80212
This Privacy Policy was last updated on July 1, 2026.