In short. Nourish stores your plans and progress on your device. If you create an account (or use the automatic anonymous session), a copy is synced to your own private cloud record so you can restore it on another device. We collect health-related information you enter yourself — such as weight, goals and allergies — because the app cannot build a plan without it. We do not sell your data, we do not show ads, and you can delete your account and all of your data from inside the app at any time.
1. Who we are
Nourish — Meal Planner (“Nourish”, “the app”) is developed and published by Abazzo d.o.o, a company registered in Beograd (Belgrade), Republic of Serbia. Abazzo d.o.o is the data controller responsible for the personal data described in this policy.
You can reach us at any time:
- Email: contact@abazzodigital.com
- Phone: +381 64 2633400
- Post: Abazzo d.o.o, Beograd, Republic of Serbia
2. Data we collect
2.1 Account data
The first time you open Nourish, the app signs you in anonymously through Firebase Authentication. This creates a random user identifier (a “UID”) that is not linked to your name or email address; its only purpose is to give your data a stable home so it can be backed up and restored.
If you choose to create a permanent account so you can sign in on another device, we additionally process:
- your email address;
- a password, which is transmitted to and stored by Firebase Authentication in hashed form — neither we nor the app ever see or store your password in readable form;
- the account creation and last sign-in timestamps kept by Firebase Authentication.
When an anonymous session is upgraded to a permanent account, the same UID is kept, so nothing you have already recorded is lost.
2.2 Health and nutrition data
Nourish is a nutrition app, so most of what it holds is information you enter about your body, your diet and your daily routine. Under the GDPR some of this qualifies as data concerning health (a special category of personal data) and we treat all of it with that level of care. It includes:
- Profile: the name or nickname you type, age, gender, height, current weight, target weight, your goal (lose / maintain / gain), activity level, diet type (e.g. balanced, keto, vegan), allergies, foods you like, foods you want to avoid, meals per day and how long you like to cook.
- Calculated targets: your daily calorie, protein, carbohydrate, fat and water targets, derived from the profile above. Your BMI is computed on the fly from your height and weight for display.
- Meals and plans: the meals planned for each day, meals you mark as eaten, meals you add or swap, and their nutrition values.
- Trackers: water intake logs, your weight history over time, and your daily habit check-ins.
- Engagement data: streaks, experience points, achievements, favourite recipes, recipe ratings (your “taste preferences”) and which shopping-list items you have ticked off.
This information is stored on your device. When Firebase is available it is also synced to your private cloud record so you do not lose it (see section 7).
2.3 Usage and analytics data
Nourish uses Google Analytics for Firebase to understand, in aggregate, which parts of the app are used and where people get stuck. The app logs product events such as: onboarding started / step completed / finished, profile generated, meal created, completed or swapped, recipe viewed, favourited or rated, water logged, weight logged, habit toggled, streak increased or frozen, XP awarded, achievement unlocked, paywall viewed or dismissed, premium purchased or restored, purchase restored, AI coach opened or prompted, premium feature blocked, reminder opened, notification tapped, and screen views.
The parameters attached to these events are limited to app-usage values — for example the onboarding step number, the screen name, your goal type, your calorie target, the amount of water logged or the surface a feature was opened from. Analytics events do not carry your name, your email address or the free text you type into the app.
In addition, the Firebase Analytics SDK itself automatically collects standard measurement data, including a pseudonymous app-instance identifier, device model, operating system version, app version, language, approximate region derived from IP address, and first-open / session timings.
2.4 Diagnostics and crash data
Nourish uses Firebase Crashlytics so that crashes and fatal errors can be found and fixed. If the app crashes, Crashlytics sends a report containing the stack trace, the exception type, the app version, the device model and operating system version, device state at the time (such as available memory or whether the device was rooted), and a Crashlytics installation identifier. Crash reports are not used to profile you.
2.5 Subscription status
Premium subscriptions are managed through RevenueCat, which records your subscription state so the app knows whether Premium is active. RevenueCat receives your Firebase UID as its app user identifier, together with the product purchased, purchase and expiry dates, trial and renewal status, and the store transaction identifiers supplied by Google Play, plus basic device and country information.
2.6 Push notification token
If you turn on daily reminders, Nourish requests notification permission and may obtain a Firebase Cloud Messaging registration token for your device installation, so that reminders and service messages can be delivered. Mealtime reminders themselves are scheduled locally on your device. You can switch reminders off at any time in Settings or in your device's system settings.
3. What we do not collect
- No payment details. All purchases are processed by Google Play. Nourish and Abazzo d.o.o never see or receive your card number, bank details or billing address.
- No advertising and no data sales. Nourish shows no third-party ads. We do not sell, rent or trade your personal data, and we do not share it with advertising networks or data brokers.
- No contacts, photos, precise location, microphone or health-platform data. The app does not request access to your contacts, camera roll, GPS location, microphone, or Apple Health / Google Fit.
- No AI processing outside the coach chat. Meal planning, insights, forecasts and the shopping list run entirely on your device against a built-in recipe catalogue. Nothing you log — meals, weight, water, habits — is sent to an AI provider. Only the coach chat uses an external model, and only when you type into it; see section 3a below.
3a. The coach chat and Anthropic
When you send a message in the in-app coach, that message is transmitted to Anthropic PBC and answered by their Claude model. This is the only feature in Nourish that sends anything you write to an external provider, and it only happens when you actively send a message — the coach never runs in the background.
What is sent with each message: the text of your message, up to the last ten messages of that conversation for context, and a summary of your profile so the answer fits you — your first name, age, gender, height, weight, target weight, goal, activity level, diet type, allergies, liked and avoided foods, and your calculated daily calorie, macro and water targets.
What is never sent: your email address, your account identifier, your meal logs, your weight history, your streaks or habit data, your payment information, or any device identifier.
How Anthropic handles it: Anthropic processes the message on our behalf as a processor under their commercial terms. They do not use API inputs or outputs to train their models. They retain API traffic for a limited period for trust-and-safety purposes and then delete it.
If you would rather not use it, simply do not open the coach chat — every other feature in Nourish works without it, and nothing is sent unless you send a message. The coach is a nutrition-information feature, not a medical service; it does not provide medical advice, diagnosis or treatment.
4. How we use your data
| Purpose | Data used |
|---|---|
| Calculate your calorie, macro and water targets and build your daily meal plan | Profile and health data (2.2) |
| Respect your diet, allergies and disliked foods when suggesting meals and swaps | Profile and health data (2.2) |
| Show your progress: charts, weight trend, streaks, habits and achievements | Trackers and engagement data (2.2) |
| Back up your data and restore or sync it on another device | Account data (2.1) and health data (2.2) |
| Unlock Premium features and restore previous purchases | Subscription status (2.5), account UID |
| Send the reminders you asked for | Notification token and reminder settings (2.6) |
| Improve the app: understand which features are used, fix crashes and prevent abuse | Usage and analytics (2.3), diagnostics (2.4) |
| Answer your support requests and honour your privacy rights | Your email and the content of your message |
| Comply with legal obligations (e.g. accounting, responding to lawful requests) | Transaction and account records |
We do not use your data for automated decision-making that produces legal or similarly significant effects on you. The nutrition targets the app calculates are simple, transparent formulas based on the numbers you provide.
5. Legal bases
We process personal data under the Serbian Law on Personal Data Protection (Zakon o zaštiti podataka o ličnosti), which closely mirrors the EU General Data Protection Regulation (GDPR), and — where it applies to you — under the GDPR itself. Our legal bases are:
- Explicit consent (GDPR Art. 9(2)(a)) for health-related data. You give it by entering that information into the app; you can withdraw it at any time by deleting your account, which erases the data.
- Performance of a contract (Art. 6(1)(b)) to provide the app, your account, cloud sync and your subscription entitlements under our Terms of Service.
- Legitimate interests (Art. 6(1)(f)) to keep the app stable and secure, to fix crashes, to prevent fraud and abuse, and to understand aggregate product usage so we can improve Nourish. We balance these interests against your rights, which is why analytics events carry no names, emails or free text.
- Consent (Art. 6(1)(a)) for push notifications, which are only sent if you enable reminders and grant the system permission.
- Legal obligation (Art. 6(1)(c)) where we must retain records, for example for tax and accounting purposes.
6. Third-party processors
We keep the number of third parties deliberately small. The following providers process data on our behalf, under contract and only for the purposes described above:
| Provider | Services used | Data involved | Privacy information |
|---|---|---|---|
| Anthropic PBC | Claude API — generates the in-app coach chat replies | The message you send, the last ten messages of that conversation, and the profile summary listed in section 3a. No email address, account identifier, logs or device identifiers. | Anthropic Privacy Policy Commercial Terms |
| Google Ireland Ltd. / Google LLC (Firebase) | Authentication, Cloud Firestore, Analytics, Crashlytics, Cloud Messaging | Account data, synced health and nutrition data, analytics events, crash reports, notification token | Firebase Privacy & Security Google Privacy Policy |
| RevenueCat, Inc. | Subscription and entitlement management | App user ID (Firebase UID), purchase and entitlement status, store transaction IDs, device and country data | RevenueCat Privacy Policy |
| Google Play (Google LLC) | App distribution and subscription billing | Your payment details and billing records — held by Google as an independent controller; we receive only the resulting purchase status | Google Privacy Policy |
7. Where your data is stored
Nourish is offline-first. Your profile, plans, logs and settings are written to your device's own app storage, which is sandboxed by the operating system and removed if you uninstall the app.
When you are signed in and Firebase is reachable, a snapshot of your app state is also written to Google Cloud
Firestore in a single private document at users/{your-uid}. The synced snapshot contains your onboarding
status, profile, meals, water log, weight log, habits, favourite recipes, streak state, gamification state, shopping
list check state and taste preferences. Device-only settings such as your light/dark theme choice are deliberately
excluded and never leave your device.
Our Firestore security rules allow a document under users/{uid} to be read, written or deleted
only by the authenticated user who owns it. No other user of the app can reach your record.
8. International transfers
Our processors are global providers and may store or process data on servers outside the Republic of Serbia and outside the European Economic Area, including in the United States. Where data leaves Serbia or the EEA, the transfer is protected by the safeguards those providers make available — primarily the European Commission's Standard Contractual Clauses, together with additional technical measures such as encryption in transit and at rest. You can request more information about these safeguards using the contact details in section 15.
9. Data retention
- Your account and synced data: kept for as long as your account exists. When you delete your account in the app, the cloud document is deleted immediately and the local copy is wiped from the device.
- Local data: removed when you delete your account, use “Reset & delete account”, clear the app's storage, or uninstall the app.
- Analytics data: retained by Google Analytics for Firebase for the retention period configured for our project (by default, event-level data is kept for up to 14 months, after which only aggregated reporting remains).
- Crash reports: retained by Firebase Crashlytics for approximately 90 days.
- Subscription records: retained by RevenueCat and Google Play for the life of the subscription and afterwards as required for billing, dispute-resolution, tax and accounting obligations.
- Support correspondence: kept for up to 24 months after your request is resolved.
10. Your rights
Under the Serbian Law on Personal Data Protection and, where applicable, the GDPR, you have the right to:
- Access — obtain confirmation of whether we process your data and receive a copy of it;
- Rectification — have inaccurate or incomplete data corrected (most profile fields can be edited directly in the app);
- Erasure — have your personal data deleted (“right to be forgotten”);
- Restriction — ask us to limit processing while a dispute about accuracy or lawfulness is resolved;
- Data portability — receive the data you provided in a structured, commonly used, machine-readable format (we supply your synced state as a JSON file) and have it transmitted to another controller where technically feasible;
- Objection — object at any time to processing based on our legitimate interests, including analytics;
- Withdraw consent — withdraw your consent to health-data processing or to notifications at any time, without affecting the lawfulness of processing carried out before withdrawal;
- Lodge a complaint — with the Serbian Commissioner for Information of Public Importance and Personal Data Protection, or with the supervisory authority in your country of residence.
To exercise any of these rights, email contact@abazzodigital.com from the address associated with your account, or call +381 64 2633400. We respond within 30 days. We may ask for information that lets us match your request to your account (for example the email address you signed up with) so that we do not disclose or delete someone else's data by mistake. Exercising your rights is free of charge.
11. Deleting your data
You can delete everything yourself, in the app. Open Settings → Reset & delete
account and confirm. This permanently deletes your cloud document at users/{your-uid}, deletes your
Firebase authentication account, and wipes your profile, plans, logs, streaks and preferences from the device.
The action cannot be undone.
If the app tells you the cloud step could not be completed — for example because a long-lived sign-in needs to be refreshed first — sign in again and repeat the deletion, or email us and we will remove the record for you.
Deleting your Nourish account does not cancel a subscription that is billed by Google Play. Cancel the subscription in the Google Play Store to stop future charges — see our Terms of Service.
12. Children's privacy
Nourish is not directed at children. The app is intended for adults aged 18 and over, and setup will not accept an age below 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact contact@abazzodigital.com and we will delete the account and its data without undue delay.
13. Security
- All traffic between the app and our processors is encrypted in transit with TLS; Firebase encrypts data at rest.
- Firestore security rules restrict every user record to its owner; the shared recipe catalogue is read-only to clients and the subscription mirror is write-protected server-side.
- Passwords are handled entirely by Firebase Authentication and stored only as salted hashes. We have no access to them.
- Data on your device is held in the operating system's sandboxed app storage.
- Access to production consoles is limited to the people at Abazzo d.o.o who need it, and is protected by multi-factor authentication.
No system can be guaranteed perfectly secure. If a personal data breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours and inform affected users without undue delay.
14. Changes to this policy
We may update this policy as the app evolves or as the law requires. The current version is always published at this address, with the “Last updated” date at the top. If a change materially affects how we use your data, we will give notice in the app before it takes effect, and — where the law requires it — ask for your consent again. Continuing to use Nourish after an update takes effect means you accept the revised policy.
15. Contact
Questions, requests or complaints about privacy are handled by:
Abazzo d.o.o
Beograd (Belgrade), Republic of Serbia
Email: contact@abazzodigital.com
Phone: +381 64 2633400