Privacy Policy
Last updated: July 23, 2026
What we collect
When you register, we store your email address and a securely hashed password via Supabase Auth. If you sign in with Google instead, we receive your email address from Google and never see a password at all.
When you use the service, we store:
- Meal logs โ description, meal type, calories, macros, notes, and timestamps. Food photos are interpreted by your AI assistant and are never uploaded to or stored by us.
- Water logs โ amount, notes, and timestamps.
- Body weight logs โ weight, notes, and timestamps. This is health data, and it is treated exactly like the rest of your logs.
- Goals โ your daily calorie, protein, carb, fat, and water targets, and your target weight.
- Profile settings โ your IANA timezone, preferred weight unit, and whether in-chat widgets are enabled.
- Tool-usage telemetry โ for each MCP tool call, which tool ran, whether it succeeded, how long it took, a coarse error category when it failed, the span in days of any date range you asked for, and the MCP session id. It is linked to your account id. It never includes the content of your logs.
We also keep the OAuth access and refresh tokens and authorization codes that let your AI assistant stay connected to your account.
How we use it
Your meal, water, weight, and goal data is used solely to provide the nutrition tracking service. We never sell it, never share it with third parties, and never use it for advertising or feed it into any ad or profiling system.
Two kinds of analytics do exist, and neither touches the content of your logs:
- Website analytics. These pages load Google Analytics, which gives us aggregate traffic statistics โ page views, referrers, rough geography, device type. It runs on every page, including this one, and there is currently no consent banner and no IP anonymization, so Google receives your IP address as part of the standard measurement. If you would rather not be measured, a tracker blocker or your browser's “do not track”-style protections will stop it.
- Server telemetry. Every MCP tool call writes one row of usage telemetry โ which tool ran, whether it succeeded, how long it took โ linked to your account id but not to what you logged. We use it to find slow and broken tools. It is not shared with anyone, and it is deleted along with everything else when you delete your account.
Because the site loads fonts and icons from Google Fonts and jsDelivr, and the home page fetches the project's star count from the GitHub API, visiting these pages exposes your IP address to those providers.
Where it's stored
All data is stored in Supabase (PostgreSQL). Authentication is handled by Supabase Auth. The server is hosted on DigitalOcean.
Data deletion
You can delete your account and all associated data at any time by asking your AI assistant to delete your account while connected to the Nutrition MCP server. This action is immediate and irreversible. It removes your meals, water and weight logs, goals, profile settings, any stored CSV export, your tool-usage telemetry, your access tokens, and the account itself.
Terms of Service
Use of the service is also governed by our Terms of Service, which cover acceptable use, the fact that nothing here is medical advice, and the absence of any warranty โ the service is provided as-is, free of charge, with no guarantees of availability, accuracy, or fitness for any purpose.