1. Who controls your data
NectariaFit is operated personally by Mihajlo Nikolić, who is the controller responsible for deciding why and how your personal data is processed.
- Service address
- Kijevska 2, Beograd
- Country
- Serbia
- Privacy contact
- nanica71@gmail.com
2. Scope and age requirement
This policy applies to the NectariaFit web application and related account communications. The service is intended only for adults aged 19 or older. We do not knowingly offer it to children.
3. Data we process
- Account data: name, email address, profile image, verification state, account timestamps, and linked Google account identifiers when Google sign-in is used.
- Authentication and security data: password hash, encrypted authentication material, sessions, device/browser information, IP address, two-factor authentication state, recovery-code state, browser installation identifier, and one-time verification records.
- Profile and body data: age, height, weight, calculation basis, timezone, routine activity, goals, targets, and derived estimates such as BMR.
- Tracking history: food, calorie and macronutrient estimates, activity, distance, duration, calculated energy use, weight measurements, personal rules, and generated summaries.
- Chat data: messages you submit, assistant replies, clarifications, safety notices, timestamps, and the selected tracking date.
- AI and operational metadata: model and operation type, token counts, cost estimate, latency, safe provider identifiers, retry identifiers, and failure category. This metadata does not intentionally contain prompts or responses.
- Logs and security events: correlation ID, route template, method, status, duration, safe error code, service version, pseudonymous actor reference, and security-event outcome. Request bodies, chat, credentials, and raw user IDs are not intentionally logged.
- Email-delivery data: recipient address, minimal account/security message content, delivery metadata, and an expiring verification, reset, or deletion link.
Weight, weight history, body measurements, nutrition, activity, goals, and related inferences may reveal information about physical health. We treat them conservatively as sensitive health-related data.
Where the data comes from
- Directly from you: account details, profile values, goals, chat messages, corrections, food/activity records, weight history, and rules.
- From Google, when you choose Google sign-in: the limited identity and account information authorized through Google OAuth.
- Generated during use: sessions, security events, request metadata, calorie and activity calculations, summaries, AI estimates, and usage/cost metadata.
Required and optional information
Account credentials are needed to create and secure an account. The profile values identified during onboarding are needed to calculate personalized estimates and use the core tracking experience. Food, activity, chat, rules, and ongoing weight entries are provided only when you choose to use those features. You may decline optional information, but the related feature may be unavailable or less useful. Withdrawing health-data consent disables processing that depends on it and therefore may make the core tracking service unavailable.
4. Why we process data and our legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Create and operate your account and provide requested tracking features | Account, profile, chat, food, activity, weight, rules, and reports | Performance of our agreement with you |
| Process data that qualifies as special-category health data | Body, weight, nutrition, activity, goals, and health-related inferences | Your explicit consent, collected separately before this processing begins; you may withdraw it at any time |
| Secure accounts, prevent abuse, investigate failures, and maintain service | Sessions, device context, IP address, pseudonymous logs and audit events | Our legitimate interests in security, reliability, and fraud prevention |
| Send verification, reset, deletion, and security messages | Email address, expiring link, minimal message and delivery metadata | Performance of our agreement and account security |
| Meet legal obligations and respond to lawful requests | Only the records required in the circumstances | Compliance with legal obligations |
We do not use your data for advertising, sell it, build marketing profiles, or use your chat content to train a NectariaFit model.
5. AI processing
The service uses OpenAI to screen messages for prohibited sensitive content, interpret supported food and activity language, estimate food values, and write limited report prose. The main assistant may receive the current message, relevant selected-day conversation, selected profile/body values, current and historical summaries, validated rules, and structured instructions.
Clearly medical requests, diagnoses, medications, test results, crisis content, secrets, identity/payment data, and certain third-party information are blocked before the full assistant receives profile or history context. A blocked message is not stored as chat content or added to future conversation context. The initial screening transfer still occurs.
AI output does not directly write the database. The backend validates proposed actions and owns authorization, calculations, totals, targets, and persistence. AI estimates may be wrong; you can inspect, correct, or delete your records. The service does not make legal or similarly significant automated decisions about you.
6. Cookies and local device storage
The service uses strictly necessary cookies for authentication, account security, Google reauthentication, and distinguishing signed-in browser installations. The main authentication credential is an opaque, HttpOnly cookie that browser JavaScript cannot read. These cookies are necessary for signed-in features and cannot be disabled without preventing those features from working.
Application responses are temporarily cached in browser memory while you use the service. Authentication credentials are not intentionally placed in local storage or in page URLs. The current service does not use advertising cookies, cross-site behavioral tracking, analytics pixels, or session replay. Introducing any of those technologies requires this policy and the consent design to be reviewed before deployment.
7. Service providers and recipients
- Vercel: hosts the public marketing website, user portal, and admin web interface and processes ordinary web-delivery metadata such as IP address, user agent, requested path, region, and deployment/runtime metadata. Authenticated health-data API payloads are sent directly from your browser to the Hetzner-hosted API, not proxied through Vercel or the marketing website.
- Hetzner: application, PostgreSQL, backups, and self-hosted logs in Germany/EU.
- OpenAI: message screening, supported chat interpretation, food estimates, and report prose. Requests use
store: false, but this alone does not remove OpenAI's default abuse-monitoring logs, which may contain customer content and are retained for up to 30 days unless a longer period is legally required. - Resend: production transactional account/security emails and associated delivery, bounce, and suppression handling. We do not use those messages for advertising or marketing profiling.
- Google: optional sign-in using the identity scopes needed to authenticate your Google account.
- Authorities or advisers: only where lawfully required or necessary to establish, exercise, or defend legal claims.
Software libraries running inside our own environment are not separate recipients unless they activate an external service.
Your profile, chat, and tracking history are private to your account. The service currently has no public profile, social feed, leaderboard, employer portal, coach access, or feature that shares your records with other users.
8. International transfers
Primary application and database hosting is in the EU. Vercel, OpenAI, Google, and Resend may process personal data in the United States or through international subprocessors. Where required, transfers rely on applicable adequacy decisions, the European Commission's Standard Contractual Clauses, or another lawful safeguard. You may request information about the applicable safeguard using the privacy contact above.
9. Retention and deletion
- Chat, food, activity, weight, and generated report history: three years.
- Completed chat retry/idempotency records: 90 days.
- Abandoned in-progress chat reservations: 24 hours.
- Application and error logs: 30 days.
- Security audit events: 180 days.
- AI usage/cost metadata: three years, then deleted or irreversibly aggregated so it is no longer linked to an identifiable user.
- Legal acceptance and consent records: while the account is active and as needed afterward to demonstrate the agreement or consent history and handle legal claims.
- Expired verification, password-reset, account-deletion, and 2FA-recovery records: no more than 24 hours after expiry.
- Encrypted production backups: 30 days under rotation.
- Transactional email delivery records: for the provider-configured delivery and support period; suppression, security, and legally required records may be kept longer.
Current profile and account information is kept while your account is active. Confirmed account deletion removes active user-owned data immediately, subject to short-lived backup rotation, documented legal-preservation requirements, and processor deletion timelines. Deleted data is not restored into active use without reapplying outstanding deletion instructions.
10. Your choices and rights
Depending on the law that applies, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent without affecting earlier lawful processing; and complain to a data-protection authority. You can already download a machine-readable copy, edit many tracking records, withdraw health-data consent, and delete your account inside the service.
Withdrawal of health-data consent means we must stop the processing that depends on that consent. You can withdraw in Profile or on the consent screen; this deletes active profile and tracking data and disables the core tracker unless you choose to consent and complete onboarding again. Export and account-deletion controls remain available if you decline or withdraw consent. You may also send a request to nanica71@gmail.com. We may need proportionate information to verify that a request concerns your account.
Where the law permits, an authorized representative may submit a request for you. We may require proof of authorization and may still need to verify your identity directly. We will not discriminate against you for exercising a legal privacy right; however, a feature cannot continue if it necessarily depends on data or consent you have withdrawn. Requests are handled within the period required by applicable law.
Serbian users may contact the Commissioner for Information of Public Importance and Personal Data Protection at poverenik.rs. EU users may complain to the supervisory authority in the country where they live, work, or believe an infringement occurred.
11. Security
We use user-scoped access controls, encrypted authentication material, optional authenticator-app two-factor authentication, short-lived verified-email recovery, revocable sessions, transport security, bounded and pseudonymous logs, restricted provider settings, and encrypted backups. Emergency 2FA recovery removes the old authenticator and signs out every device. However, no online service can guarantee absolute security.
12. Changes to this policy
We will update the effective date and version when this policy changes. Material changes will be presented through the service or by email where appropriate. A change that requires new consent will not be treated as accepted merely because you continue using the service.
13. Contact
Privacy requests: nanica71@gmail.com
General support: nanica71@gmail.com