Sprout - Nutrition Tracker

Privacy Policy

Effective August 16, 2026 · Last updated August 19, 2026

Nutriguard, published as Sprout - Nutrition Tracker ("Sprout," "we," "us," or "our"), was conceived, designed, and developed by Heeva Alavi, a 17-year-old student developer. Sprout is published and operated by Ali Alavi, who is responsible for the app's privacy practices and serves as its privacy contact. This Privacy Policy explains how Sprout collects, uses, stores, and shares information when you use the Sprout mobile application and related services.

Contact: sproutsupportteam@gmail.com

Educational use: Sprout provides educational nutrition information. It is not a medical service and does not diagnose, treat, cure, or prevent any disease.

1. Scope

This Privacy Policy applies to Sprout's mobile application, anonymous and email-based account features, food and nutrition tracking, meal-photo recognition, optional AI-assisted classification, notifications, support communications, and related backend services. You may use Sprout without providing an email address by choosing Continue without signing in. Sprout is currently offered only to users in the United States.

2. Information We Collect

Anonymous and email-based account information

If you continue without signing in, Supabase creates an anonymous authenticated account with a random account identifier. You do not provide an email address, name, or password for this account. For internal database compatibility, Sprout may associate the anonymous identifier with a system-generated placeholder ending in @sprout.invalid; this is not a real or contactable email address and is not used to contact you. The anonymous account allows Sprout to save your food history, photos, preferences, settings, and AI usage securely under that identifier.

An anonymous session normally remains available on that installation. It is not recoverable on another device or after the app is deleted or its local data is cleared. You can later add an email address and password using Create Account & Keep My Data. This converts the same anonymous account into an email-based account and preserves its existing account identifier and associated Sprout data.

If you create or convert to an email-based account, we collect your email address, account identifier, authentication information managed by our authentication provider, and any optional profile information or settings you provide. Depending on the features you use, those settings may include a display name, age, gender selection, dietary restrictions, disliked foods, preferred cuisines, theme settings, notification preferences, and virtual-pet settings.

We do not receive or store your plaintext account password.

Age-eligibility information

Sprout checks whether a user is eligible to use the app. On supported Apple devices, Sprout may request an age range through Apple's Declared Age Range feature. If that feature is unavailable or does not provide a result, Sprout may ask the user to confirm whether they meet the minimum age. This eligibility check stores only an eligible or ineligible result, how the result was obtained, and the date checked on the device. It does not store a birth date, exact age, Apple Account identifier, or Apple's full response as part of the eligibility check. If you separately enter an age in your profile settings, that profile age is stored with your settings.

Food, nutrition, and health-related information

We collect information that you choose to log, including food names, serving and portion information, food groups, calories, dates and times, nutrition goals, dietary preferences, notes, and classifications or insights generated by the app. Because this information relates to diet and nutrition, it may be considered health-related information in some jurisdictions.

Meal photos and other user content

If you choose photo recognition, Sprout processes the image you select or capture so that foods can be identified. A meal photo may be transmitted through our service providers for AI analysis and may be saved with the corresponding food-log entry. Notes and other text you enter are also user content.

Camera and photo-library access is optional and requested only when you use a feature that needs it. You can change these permissions in your device settings.

Technical and operational information

Our service providers may automatically process limited network and technical information, such as IP address, request time, app or device information, error details, and security signals, to deliver the service, prevent abuse, diagnose problems, and protect accounts. Sprout does not use this information for advertising or cross-app tracking.

Support communications

If you contact us, we receive the email address and information you include in your message. Please do not send meal photos, medical records, or other sensitive information unless it is necessary for your request.

3. How We Use Information

We use information to:

We do not use Sprout data for third-party advertising.

4. AI Processing

AI features are optional. Sprout asks for your choice before first using an AI feature, and you can later enable or disable AI processing in the app's Privacy & AI settings. When AI is disabled, Sprout does not send new food descriptions or meal photos to Anthropic.

When you use AI-assisted food classification or meal-photo recognition, relevant text, food information, and/or a selected meal photo is sent through a Supabase-hosted server-side Edge Function to Anthropic's commercial API. Anthropic processes this content to generate the requested result. Sprout's cancer-risk category indicators are determined separately from a bundled, versioned evidence catalog and deterministic matching rules; Anthropic does not assign those indicators.

Anthropic controls its retention and handling of commercial API inputs and outputs under its own terms and settings. Anthropic states that commercial API inputs and outputs are not used to train its models by default, subject to its terms, customer choices, safety processes, and legal obligations. See Anthropic's commercial data-retention information and model-training information.

AI output can be inaccurate, incomplete, or misleading. Sprout's AI features are for educational assistance and should not be treated as medical advice.

5. Service Providers and Disclosures

We disclose information only as needed to operate, secure, and support Sprout, including to:

We may disclose information if reasonably necessary to comply with law, respond to valid legal process, protect users or the public, investigate fraud or abuse, or establish or defend legal claims. If Sprout is transferred as part of a merger, acquisition, financing, or sale, information may be transferred subject to appropriate notice and legal protections.

6. No Advertising, Sale, or Tracking

Sprout:

If these practices change, we will update this Policy and provide any legally required notice or consent before using information for a materially different purpose.

7. Data Retention

Anonymous and email-based account data

We generally retain anonymous or email-based account information, profile settings, food logs, notes, saved meal-photo thumbnails, and app-generated classifications while the account remains active so that Sprout can provide your history and settings. You can delete individual food-log entries in the app. Anonymous users can choose Delete My Data, and email-based account users can choose Delete Account, in Sprout's Account settings. Either action deletes the authentication account and associated active user data, including user-owned saved photos, from active systems, except where retention is reasonably necessary to comply with law, protect security, prevent fraud or abuse, or establish or defend legal claims.

Deleting Sprout from your device does not by itself send an account-deletion request. If you use Sprout anonymously, use Delete My Data before deleting the app if you want the associated anonymous account data removed. If an anonymous session is lost before deletion, the account generally cannot be recovered because it has no email-based sign-in credentials.

Other records and provider systems

Support communications, security records, and limited operational logs are retained only as long as reasonably necessary for support, security, legal compliance, fraud prevention, and dispute resolution. After deletion from active systems, residual copies may remain temporarily in service-provider backups until those backups are overwritten or expire under the provider's retention practices. We may retain de-identified or aggregated information that cannot reasonably be linked to a user or device.

Anthropic's retention of API inputs and outputs is described in Section 4 and is controlled by Anthropic's commercial service terms and settings.

8. Your Choices and Rights

Depending on your state of residence, U.S. privacy law may give you rights to request access to, correction of, deletion of, or a copy of your personal information; withdraw consent for certain processing; or appeal our response to a request. We will not discriminate against you for exercising an applicable privacy right.

You can:

We may need to verify your identity before fulfilling a request. An authorized agent may submit a request where permitted by law, but we may require proof of authority and identity verification. We will respond within the period required by applicable law. If we deny an appealable request, you may appeal by replying to our decision email with the subject line Privacy Appeal - Sprout.

Consumer health data

Food and nutrition logs, meal photos, dietary preferences or restrictions, profile age and gender selections, nutrition goals, and related app-generated insights may be treated as consumer health data under some U.S. state laws. This information comes from you, your selected device content, and results generated when you use Sprout. We use it to provide the tracking, personalization, photo-recognition, and educational features you request. We disclose it only to the service providers described in Section 5 as needed to provide those features, or as otherwise required by law. We do not sell consumer health data or use it for targeted advertising, and we do not use geofencing to identify or track visits to health-care facilities.

9. United States Availability and Data Processing

Sprout is currently offered only to users in the United States. Information is primarily handled through services selected to operate Sprout for U.S. users, but Supabase, Anthropic, Apple, and other providers may process information in the United States or other countries where they maintain systems or personnel. Their handling of information is also governed by their own terms and privacy practices.

10. Children's Privacy

Sprout is intended for users in the United States aged 13 and older and is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided personal information, contact us so we can investigate and delete it.

Users who are 13 or older but have not reached the age of majority should involve a parent or legal guardian when required by applicable law. Sprout's age-eligibility process is described in Section 2.

11. Security

We use administrative, technical, and organizational safeguards intended to protect information, including authenticated access controls, encrypted network connections, and database access policies. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

12. Changes to This Policy

We may update this Privacy Policy as Sprout's features, providers, or legal obligations change. We will post the updated Policy with a revised date and provide additional notice when required by law. Material changes will not be applied retroactively without appropriate notice or consent where consent is required.

13. Contact

Sprout - Nutrition Tracker was created by:

Heeva Alavi
Original concept, product design, and development

Sprout is published and operated by, and privacy inquiries are handled by:

Ali Alavi
Email: sproutsupportteam@gmail.com

Please use the subject line Privacy Request - Sprout for privacy-related requests.