NULOR
Privacy Policy
Last updated: 8 September 2026 Applies to: NULOR private beta (version 0.1.0)
NULOR is an AI nutrition coach. This policy describes what the app actually stores and what it sends where. It was written against the code, not from a template, and every claim below corresponds to something in the architecture.
This is a private beta. NULOR is not publicly available, is not a medical device, and does not provide medical advice.
Who we are
NULOR is built by Dossdan Group. For anything in this document, contact contact@dossdangroup.com.
What NULOR stores about you
Everything below is stored in NULOR's database (hosted by Supabase, in the United States) and is readable only by you. Access is enforced at the database level with row-level security, so one account cannot read another's rows.
Your account
- Email address
- An encrypted password, or an authentication token if you signed in another way
Your profile
- Preferred name, date of birth, sex for metabolic calculation, height
- Timezone, preferred language, and unit preferences (kg/lb, cm/ft, kcal)
What you record
- Weight entries, with the date you recorded them
- Body-composition entries you have entered, including body-fat percentage and
- how it was measured
- Your goal (fat loss, muscle gain or maintenance) and any target weight
- Meals and their food items, with the date eaten
- Nutrition plans calculated for you
Health information you chose to disclose
During onboarding NULOR asks about circumstances that change what advice is safe — for example pregnancy, breastfeeding, or certain medications. If you disclose one, NULOR records it in order to withhold weight-loss targets and deficit advice.
This information is never sent to an AI provider. When it applies, the AI coach is told only that targets are unavailable. It is never told why.
Your conversations with the coach
- The messages you send and the replies you receive
- Preferences you explicitly ask NULOR to remember, such as a disliked food
Diagnostics
- App version, build number, platform, operating-system version
- Which screen an error occurred on, the error type, and a stack trace
The diagnostics table has **no field capable of holding an error message, your meals, your weight, your health information, or your conversations**. That is a property of the database schema, not a policy we apply afterwards.
What NULOR sends to AI providers
NULOR uses external AI providers to understand what you type and photograph.
| When | What is sent | To |
|---|---|---|
| You describe a meal in words | The words you typed | Google (Gemini) |
| You photograph a meal | The photo, resized | Google (Gemini) |
| You photograph a nutrition label | The photo, resized | Google (Gemini) |
| You talk to the coach | Your recent messages in that conversation, your remembered preferences, and the results of NULOR's own lookups | OpenAI |
What is never sent to a provider: your email address, your name, your date of birth, your user id, your health disclosures or the reason for them, your weight history, or your full food history.
Provider retention. These are paid API tiers, not consumer chat products. NULOR sends coach requests with the OpenAI API's store: false parameter, which instructs OpenAI not to retain the request. Providers may retain data briefly for abuse monitoring under their own API terms.
Photographs
When you photograph a meal or a nutrition label:
- The image is resized on your device before it is sent
- Location data (EXIF) is removed on your device before it is sent
- The image is sent to the AI provider to be read
- The image is never stored by NULOR, on your device or on our servers
What is kept is the result — the foods and numbers that were read out of it — because that is what your diary needs.
Barcodes
Barcodes are decoded on your device. Only the barcode number is sent, to look the product up. NULOR does not build a record of your shopping.
What NULOR does not do
- No advertising, and no data shared with advertisers
- No selling or renting of personal information
- No third-party analytics or tracking SDKs
- No location tracking
- No access to your contacts, calendar, or health app data
- No notifications
Feedback you send
If you use "Send feedback", NULOR receives what you typed, along with the app version, build number, platform, and the screen you came from. **Your food diary, weight history and coach conversations are not attached** — the app says so on that screen, above the send button.
Deleting your account
You can delete your account from Profile → Delete account inside the app.
Deletion removes your account and everything attached to it: profile, weight entries, body-composition entries, goals, plans, meals and food items, coach conversations and remembered preferences, health disclosures, diagnostics and feedback. This cascades at the database level and is not reversible.
Children
NULOR is not intended for anyone under 18 and does not knowingly collect information from children.
Changes
This is a private beta and the product is changing. Material changes to this policy will be communicated to beta participants directly, since we know who you are — there are only a handful of you.
Contact
contact@dossdangroup.com