Privacy Policy
Last updated:
This Privacy Policy explains how Melomeal, MB, trading under the NutriDetector brand (“NutriDetector”, “we”, “us” or “our”), collects and processes personal data when you visit nutridetector.com, use app.nutridetector.com, create an account, submit a supplement label, use My Stack or Personalized Cautions, subscribe to communications, purchase a paid plan, or otherwise contact us (collectively, the “Service”).
We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation or “GDPR”), the Law on Legal Protection of Personal Data of the Republic of Lithuania, and other applicable data-protection laws.
If a U.S. state consumer-health-data law applies to you or to particular information, please also read our separate Consumer Health Data Privacy Policy.
1. Data Controller
The controller responsible for the processing described in this Privacy Policy is:
Melomeal, MB
Registration code: 306144188
Address: Tiltų g. 19, LT-91249 Klaipėda, Lithuania
Email: hello@nutridetector.com
Website: https://nutridetector.com
2. Personal Data We Process
2.1 Account and authentication data
If you create an account, we process information such as your email address, account and user identifiers, authentication status, account creation and update times, and profile information you choose to provide. Authentication credentials and sign-in sessions are handled by our authentication provider, Clerk. NutriDetector does not receive your full password.
We use this information to create and secure your account, keep you signed in, associate saved features with you, provide account support, and prevent unauthorised access. The legal basis is the performance of our contract with you or steps taken at your request before entering into a contract (Article 6(1)(b) GDPR), and our legitimate interest in protecting the Service (Article 6(1)(f) GDPR).
2.2 Supplement labels, images and analysis data
When you request an analysis, we may process:
- supplement label text, ingredient lists and product information that you paste or type;
- label images that you upload for optical character recognition (OCR);
- text extracted from an uploaded image;
- structured label data, analysis inputs, results and explanatory output;
- request identifiers, timestamps, processing status and limited diagnostic metadata.
We process these data to perform the analysis you request, display and save eligible scan history, support My Stack, troubleshoot failures, protect the Service and maintain billing integrity. The primary legal basis is Article 6(1)(b) GDPR. Security, abuse prevention and the establishment or defence of legal claims may also rely on our legitimate interests under Article 6(1)(f) GDPR.
Please do not include your name, contact details, medical records or other unnecessary personal information in a label submission. NutriDetector is designed to analyse supplement labels, not medical documents.
2.3 My Stack data
If you use My Stack, we may process product names, brands, label or product image links, serving information, dose, frequency, timing, notes, related scan references and a structured snapshot of the saved supplement. We use these data to maintain your stack, show daily totals, identify ingredient overlap and provide the features you request. The legal basis is Article 6(1)(b) GDPR.
2.4 Personalized Cautions and special-category data
If you voluntarily enable Personalized Cautions, you may choose profile tags relating to pregnancy, breastfeeding, specified food allergies, and vegan or vegetarian preferences. Pregnancy, breastfeeding and allergy information may constitute data concerning health and therefore special-category personal data under Article 9 GDPR.
We process these optional data only with your explicit consent under Articles 6(1)(a) and 9(2)(a) GDPR. The selected tags are used to match deterministic caution rules to your results. The tag values are not sent to the supplement analysis engine or to the AI provider and are not logged by value. You may change the profile or withdraw consent at any time. Withdrawing consent does not affect processing that was lawful before withdrawal.
Personalized Cautions are optional and are not medical advice. You may use the core Service without creating this profile.
2.5 Billing and subscription data
If you purchase a paid plan, Stripe processes your payment details. NutriDetector may process your email address, internal account identifier, Stripe customer and subscription identifiers, plan and subscription status, billing-period dates, checkout verification data, payment status and limited transaction metadata. NutriDetector does not receive or store your full payment-card number or card security code.
We use these data to provide paid features, verify checkout, administer subscriptions, prevent fraud, reconcile payments and comply with accounting or tax obligations. The legal bases are Articles 6(1)(b), 6(1)(c) and, where applicable, 6(1)(f) GDPR.
2.6 Communications and newsletter data
If you contact us, we may process your name, email address, message content, attachments and technical metadata associated with the communication. We use these data to respond, provide support, investigate complaints and maintain appropriate records. Depending on the context, the legal basis is Article 6(1)(b) or our legitimate interests under Article 6(1)(f) GDPR.
If you subscribe to a newsletter or promotional email, we process your email address, consent status and subscription activity on the basis of your consent under Article 6(1)(a) GDPR. You can unsubscribe at any time using the link in an email or by contacting us. Service and billing messages that are necessary to operate your account are not marketing communications.
2.7 Device, security and operational data
When you use the Service, we may automatically process:
- IP address and approximate location derived from it;
- browser, device type, operating system, language and screen information;
- requested pages, referrer, timestamps, response status and performance information;
- session, request and pseudonymous or hashed user identifiers;
- security, authentication, rate-limit, fraud-prevention and error information.
We process these data to deliver and secure the Service, prevent abuse, diagnose technical failures and maintain availability. The legal basis is our legitimate interest in operating a secure and reliable service under Article 6(1)(f) GDPR, and Article 6(1)(b) where the processing is necessary to deliver a requested feature.
2.8 Analytics and consent data
With your Analytics consent, Google Analytics 4 may process first-party cookie identifiers, page and event information, device and browser information, traffic source and approximate location. We use these data to understand use of the Service and improve product performance. The legal basis for optional Analytics storage and measurement is your consent under Article 6(1)(a) GDPR. Google Analytics is not loaded in the NutriDetector PWA until Analytics consent is granted.
On the public website, Google Tag Manager may load with Google Consent Mode set to denied by default. Before Analytics consent, Analytics cookies and Analytics storage remain denied. Depending on Google’s tag behaviour, Google may receive the consent state and limited cookieless technical signals. We process the consent state and strictly limited pre-consent technical data to apply your privacy choice and maintain compliant measurement controls under Articles 6(1)(c) and 6(1)(f) GDPR.
On the public website, we also use Ahrefs Web Analytics to understand aggregate website traffic. Ahrefs Web Analytics is configured as cookie-free analytics and does not use persistent visitor identifiers. According to Ahrefs, it does not store raw IP addresses and uses a daily salted hash derived from limited technical data to produce aggregate statistics. We rely on our legitimate interest in measuring and improving the public website under Article 6(1)(f) GDPR. You may object to this processing by contacting us.
CookieYes processes consent choices and related proof, such as a consent identifier, consent status, date and time, country information and limited technical evidence. We use this to store your preferences and demonstrate compliance with consent requirements. The legal bases are our legal obligations and legitimate interests under Articles 6(1)(c) and 6(1)(f) GDPR.
3. AI-Assisted Processing and Automated Analysis
NutriDetector uses OpenAI API services for OCR and for limited explanatory narrative generation. An uploaded label image may be sent to OpenAI to extract visible label text. Label-derived, structured analysis context may also be sent to produce an explanation.
NutriDetector’s scores, safety rules, dose checks, ingredient matching and factual conclusions are determined by server-controlled deterministic logic and curated data contracts. An AI model does not determine the score, make a safety decision or independently establish a factual conclusion. AI-generated explanations may nevertheless contain errors and should be read together with the structured result and cited sources.
NutriDetector does not use automated decision-making that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. The Service is an educational supplement-label tool and does not diagnose, treat or replace professional medical advice.
OpenAI states that API data are not used to train its models unless the API customer explicitly opts in. Under OpenAI’s standard API data controls, content sent to the Chat Completions API may be retained for up to 30 days for abuse monitoring, unless different approved data-retention controls apply.
4. When Providing Data Is Required
Data required to authenticate an account, analyse a submitted label, maintain My Stack or process a subscription must be provided if you want to use the relevant feature. Without those data, we may be unable to provide that feature. Personalized Cautions, newsletter subscriptions and optional Analytics cookies are voluntary and are not required for core access.
5. How We Share Personal Data
We do not sell personal data or share it with data brokers or advertising networks for resale. We disclose personal data only where reasonably necessary to operate, secure and support the Service.
Depending on the feature you use, recipients may include:
- authentication and account-security providers that manage sign-in, sessions and account protection;
- payment and subscription processors that handle checkout, billing, fraud prevention and subscription administration;
- AI and OCR service providers, including OpenAI, used to extract text from submitted supplement labels and generate limited explanatory content;
- hosting, cloud infrastructure, database, storage, logging and security providers that help us deliver and protect the Service;
- consent-management and analytics providers that store privacy choices and help us understand Service usage as described in this Privacy Policy and our Cookie Policy;
- professional advisers and public authorities where necessary for legal advice, audits, legal claims or compliance with a lawful request.
A recipient may act as our processor, sub-processor or independent controller depending on the service and applicable terms. Where required, we use contracts and other safeguards designed to protect personal data. You may contact us for more information about the specific recipients relevant to your personal data.
6. International Data Transfers
Some providers may process personal data outside Lithuania, the European Union or the European Economic Area. Where required, we rely on a European Commission adequacy decision, the European Commission’s Standard Contractual Clauses, supplementary measures, or another transfer mechanism permitted by Articles 44–49 GDPR. You may contact us for further information about the safeguards relevant to your data.
7. Data Retention
We apply the following periods or criteria:
- Raw supplement-label text: retained for no longer than 60 days and then redacted. If an eligible scan is deleted earlier, its raw input is redacted at that time.
- Uploaded label images: processed for OCR in memory and not intentionally stored in NutriDetector’s application database after the request completes. A copy sent to OpenAI may be retained for up to 30 days for abuse monitoring under its standard API controls.
- Analysis results and metadata: retained while needed to provide scan history, My Stack, billing integrity, support, security and legal-claim functions. User-linked scans are deleted when the account-deletion workflow completes, except where a limited record must be retained under a legal obligation or for the establishment or defence of claims.
- My Stack: active records are retained while the item and account remain active. Removing an item or deleting an account removes it from active use. Limited deleted-state records may remain where necessary for data integrity, fraud or dispute prevention, or legal claims, and must be deleted or anonymised when those purposes end.
- Personalized Cautions: retained until you clear the profile, withdraw consent or delete your account, unless retention is required by law.
- Account data: retained while your account is active and then deleted or de-identified, subject to necessary security, billing and legal records.
- Billing and transaction records: retained for the subscription relationship and afterwards for the periods required by accounting, tax, payment-reconciliation and legal-claim obligations.
- Rate-limit identifiers: generally expire within approximately one to ten minutes, depending on the protected endpoint.
- Google Analytics: user-level and event-level retention is configured for 14 months. Standard aggregated reports may remain available for longer under Google’s reporting rules.
- Cookie consent: the CookieYes consent preference cookie is set for one year. Consent evidence may be retained for as long as reasonably necessary to demonstrate compliance.
- Support and other communications: retained while the matter is active and afterwards for a period reasonably necessary for follow-up, record-keeping and legal claims.
- Newsletter data: retained until you unsubscribe or withdraw consent. We may retain a minimal suppression record so that we respect your opt-out.
- Security, error and infrastructure logs: retained for a limited operational period determined by security need, incident status and the relevant provider’s retention schedule.
Where a fixed period is not possible, we determine retention by reference to the duration of your account or requested feature, statutory record-keeping duties, applicable limitation periods, security and fraud risks, active disputes, and whether the data can be safely deleted or de-identified. Anonymised data that can no longer identify an individual may be retained for statistical and service-improvement purposes.
8. Cookies and Similar Technologies
We use necessary cookies and similar technologies for consent preferences, authentication, security, session continuity and checkout verification. These technologies are required for the relevant functions and cannot always be disabled through our banner.
Optional Google Analytics cookies, including _ga and the applicable
_ga_* property cookie, are used only after Analytics consent. We do not currently
use advertising cookies or Google advertising tags.
The PWA may also use browser local storage or session storage for items such as theme and interface preferences, anonymous scan history or My Stack state, installation-prompt state, acknowledgements, checkout or purchase deduplication and authentication completion markers. These are not necessarily cookies, but they store information on your device. You can remove them by clearing the site’s browser data, although doing so may reset features or sign you out.
For the current list of cookies, purposes and durations, see our Cookie Policy. You can review or change optional choices at any time through Cookie Settings. Rejecting or withdrawing optional consent does not prevent access to the core Service.
9. Marketing and Advertising
We send promotional emails only where we have a valid legal basis and provide an unsubscribe method. We do not currently use personal data for personalised advertising, and we do not sell or share personal data with third-party advertising networks for their own advertising purposes. If this changes, we will update this Privacy Policy and request consent where required.
10. Your Rights
Subject to applicable law, you may have the right to:
- receive information about how your personal data are processed;
- access your personal data and obtain a copy;
- correct inaccurate or incomplete personal data;
- request deletion of personal data in applicable circumstances;
- request restriction of processing;
- object to processing based on legitimate interests or to direct marketing;
- receive portable data where processing is automated and based on consent or contract;
- withdraw consent at any time where processing is based on consent;
- lodge a complaint with a competent supervisory authority.
To exercise a right, email hello@nutridetector.com. We may ask for information reasonably necessary to verify your identity. We normally respond within one month. Where a request is complex or numerous requests are received, the period may be extended by up to two additional months as permitted by GDPR, and we will inform you of the extension.
Some rights are not absolute. We may retain or continue processing limited data where required by law or necessary for legal claims, security, fraud prevention or the rights of others.
11. Security
We use proportionate technical and organisational measures designed to protect personal data, including encryption in transit, access controls, authentication protections, input validation, rate limiting, security monitoring, data minimisation and restricted operational access. However, no internet service can guarantee absolute security.
12. Children
The Service is not intended for children under 16. We do not knowingly collect personal data from a child under 16. If you believe that a child has provided personal data to us, contact us so that we can investigate and take appropriate action.
13. Third-Party Links
The Service may link to third-party websites, scientific sources or other services. Their own privacy notices apply to their independent processing. We are not responsible for the privacy practices of third-party sites that we do not control.
14. Changes to This Privacy Policy
We may update this Privacy Policy when our Service, providers or legal obligations change. The updated version will be published on this page with a revised “Last updated” date. If a change materially affects how we process personal data, we will provide additional notice or request new consent where required.
15. Contact and Complaints
For questions, requests or complaints about privacy, contact:
Email: hello@nutridetector.com
You also have the right to complain to the State Data Protection Inspectorate of the Republic of Lithuania (VDAI), L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania, email ada@ada.lt, website https://vdai.lrv.lt/, or to the supervisory authority in the EU/EEA country of your habitual residence, place of work or place of the alleged infringement.
