Privacy Policy
Last Updated: January 2026
Introduction
Welcome to Tummy Tracker (also known as "NutriEdu"). At NutriEdu, we take your privacy and the privacy of your children seriously. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our mobile application ("App") and related services.
By using our App, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, please do not use our App.
Information We Collect
Information You Provide Directly
We collect information that you provide directly to us when you:
- Create an Account:
- For parent accounts: Name, email address, password (stored securely using industry-standard hashing)
- For child accounts: Name, username, age, sex (biological sex for nutritional goal calculations), password (stored securely), and parent account association
- Character name (optional, for gamification features)
- Use the App:
- Food scanning data: Barcodes scanned, food products viewed, and nutritional information
- Daily nutrition tracking: Foods logged, nutritional goals, and progress data
- Gamification data: Achievement badges earned, streaks maintained, collectibles unlocked, and video unlocks
- Custom nutrition plans (if using premium features)
- Subscription information: Subscription tier, billing dates, and payment status
- Contact Us: Support requests, feedback, or other communications
Information Collected Automatically
When you use our App, we automatically collect certain information:
- Device Information: Device type, operating system, and version; App version and build information; Unique device identifiers
- Usage Information: Session IDs and session duration; Features used and screens viewed; App performance and error logs; Analytics events
- Push Notification Tokens: If you enable push notifications, we collect device tokens to send you notifications
Information from Third-Party Services
- Food Data: We use the Open Food Facts API to retrieve nutritional information for scanned products. When you scan a barcode, we query this service, but we do not share your personal information with Open Food Facts.
- Payment Processing: Subscription payments are processed through Google Play Store or Apple App Store. We receive transaction confirmations but do not have access to your full payment details.
How We Use Your Information
We use the information we collect to:
- Provide and Improve Our Services: Create and manage your account, provide personalized nutrition tracking and goal setting, calculate age-appropriate nutritional goals, display progress, achievements, and streaks, deliver educational content and gamification features
- Process Subscriptions: Manage subscription tiers and access to premium features, process payments through app stores, send subscription-related notifications
- Communicate with You: Send in-app notifications about achievements, streaks, and educational content, send push notifications (if enabled), respond to support requests and inquiries
- Analytics and Improvement: Analyze app usage to improve features and user experience, track errors and performance issues, understand how features are used to guide development
- Legal Compliance: Comply with applicable laws and regulations, respond to legal requests and prevent fraud
Data Sharing and Disclosure
We do NOT sell your personal information to third parties. We may share information only in the following circumstances:
Service Providers
We may share information with trusted service providers who assist us in operating our App:
- Hosting and Database Services: To store and manage your data securely
- Firebase/Google Cloud Messaging: For push notifications (if enabled)
- Analytics Services: For app usage analytics (we use our own analytics system, not third-party advertising analytics)
All service providers are contractually obligated to protect your information and use it only for the purposes we specify.
Legal Requirements
We may disclose information if required by law, court order, or government regulation, or if we believe disclosure is necessary to:
- Protect our rights, property, or safety
- Protect the rights, property, or safety of our users
- Investigate fraud or security issues
- Comply with legal obligations
Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, subject to the same privacy protections.
Aggregated and Anonymized Data
We may share aggregated, anonymized data that cannot identify individual users for research, analytics, or educational purposes.
Children's Privacy (COPPA Compliance)
Tummy Tracker is designed for children and families. We are committed to protecting children's privacy and comply with the Children's Online Privacy Protection Act (COPPA) and other applicable children's privacy laws.
Parental Consent
- Child accounts require explicit parental consent for children under 13 (or the applicable age in your jurisdiction)
- Parents must create their own account and link child accounts to their parent account
- We verify parental consent through the parent account association system
Information Collected from Children
For child accounts, we collect: username (not email address), name, age (for nutritional goal calculations), sex (biological sex for nutritional goal calculations), nutrition tracking data, and gamification data (badges, streaks, collectibles).
We do NOT collect: email addresses from children, location data, contact information, or any information beyond what is necessary for the app's functionality.
Parental Rights
Parents have the right to:
- Review their child's personal information
- Request deletion of their child's account and data
- Refuse further collection or use of their child's information
- Revoke consent at any time
To exercise these rights, parents should contact us at martin.doychev.93@gmail.com.
No Advertising
Our App is completely ad-free. We do not show advertisements to children or adults, and we do not use children's data for advertising purposes.
Data Security
We implement appropriate technical and organizational security measures to protect your personal information:
- Password Security: Passwords are hashed using industry-standard bcrypt hashing before storage
- Secure Transmission: Data is transmitted using encryption (HTTPS/TLS)
- Access Controls: Access to personal information is restricted to authorized personnel only
- Regular Security Reviews: We regularly review and update our security practices
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.
Data Breach Notification
In the event of a data breach that may affect your personal information, we will notify you and relevant authorities as required by applicable law, typically within 72 hours of becoming aware of the breach.
Data Retention
We retain your personal information for as long as necessary to provide our services to you, comply with legal obligations, and resolve disputes and enforce agreements.
When you delete your account, we will delete or anonymize your personal information within a reasonable timeframe, typically within 30 days, except where we are required to retain it for legal purposes.
Note: Some information may remain in backup systems for a limited period (up to 90 days) before being permanently deleted.
Your Rights and Choices
Depending on your location, you may have certain rights regarding your personal information:
Access and Portability
- Access the personal information we hold about you
- Request a copy of your data in a portable format
Correction and Updates
- Update or correct inaccurate information through the App settings
- Contact us to request corrections
Deletion
- Delete your account and associated data through the App settings
- Request deletion by contacting us at martin.doychev.93@gmail.com
Opt-Out
- Disable push notifications through your device settings
- Contact us to opt out of analytics tracking (note: this may affect app functionality)
Right to Object and Restrict Processing
- Object to processing of your personal information for certain purposes
- Request restriction of processing in certain circumstances
California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including:
- The right to know what personal information we collect, use, disclose, and sell
- The right to opt out of the sale of personal information (we do not sell personal information)
- The right to non-discrimination for exercising your privacy rights
- The right to request deletion of your personal information
To exercise your CCPA rights, please contact us at martin.doychev.93@gmail.com.
European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR), including:
- Right to access: Obtain confirmation of whether we process your personal data and access to that data
- Right to rectification: Correct inaccurate or incomplete personal data
- Right to erasure: Request deletion of your personal data under certain circumstances
- Right to restrict processing: Limit how we use your personal data
- Right to object: Object to processing of your personal data for certain purposes
- Right to data portability: Receive your personal data in a structured, commonly used format
- Right to withdraw consent: Withdraw consent at any time where processing is based on consent
- Right to lodge a complaint: File a complaint with your local supervisory authority
Legal Basis for Processing: We process your personal data based on:
- Your consent (which you can withdraw at any time)
- Performance of a contract (providing our services)
- Legitimate interests (improving our services, security, fraud prevention)
- Legal obligations (compliance with applicable laws)
To exercise any of these rights, please contact us at martin.doychev.93@gmail.com. We will respond to your request within one month, or within two months for complex requests.
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority. For a list of EEA supervisory authorities, visit https://edpb.europa.eu/about-edpb/about-edpb/members_en.
International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country.
We take appropriate safeguards to ensure your information receives adequate protection, including:
- Using standard contractual clauses approved by the European Commission for transfers from the EEA
- Ensuring service providers are bound by appropriate data protection agreements
- Implementing security measures to protect data during transfer
By using our App, you consent to the transfer of your information to countries outside your country of residence.
Third-Party Links and Services
Our App may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies.
Third-Party Services We Use:
- Open Food Facts: Provides nutritional data for food products (privacy policy)
- Google Play Store / Apple App Store: Process subscription payments (subject to their respective privacy policies)
- Firebase/Google Cloud Messaging: For push notifications (if enabled) (privacy policy)
Cookies and Tracking Technologies
Our mobile App does not use cookies or similar tracking technologies. However, we do collect device identifiers and session information as described in the "Information Collected Automatically" section above.
If you access our website, we may use essential cookies to provide basic functionality. We do not use advertising cookies or tracking cookies on our website.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of any material changes by:
- Posting the updated policy in the App
- Updating the "Last Updated" date at the top of this policy
- Sending in-app notifications for significant changes
- Posting a notice on our website
Your continued use of the App after changes become effective constitutes acceptance of the updated policy. If you do not agree with the changes, you may delete your account and stop using the App.
Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
Email: martin.doychev.93@gmail.com
For Parents: If you have questions about your child's account or wish to exercise your parental rights, please contact us at the email above.
For Data Protection Inquiries (GDPR): If you are located in the EEA and have questions about data protection, you may also contact your local supervisory authority.
We will respond to your inquiry within a reasonable timeframe, typically within 30 days (or within one month for GDPR requests, or two months for complex requests).
Summary for Parents
What we collect:
- Basic account information (name, username for kids, email for parents)
- Age and sex (for nutritional goal calculations)
- Food scanning and nutrition tracking data
- App usage data to improve the service
What we DON'T do:
- We do NOT sell your or your child's information
- We do NOT show advertisements
- We do NOT collect location data
- We do NOT share personal information with third parties except as described in this policy
Your rights:
- You can access, update, or delete your child's information at any time
- You can delete your account and all associated data
- You can contact us with any privacy concerns
- You can revoke consent for your child's account at any time
Children's safety:
- Our App is designed to be safe for children
- We comply with COPPA and other children's privacy laws
- We require parental consent for child accounts
- The App is completely ad-free
This Privacy Policy is effective as of the "Last Updated" date shown above.