Privacy policy
Last updated: August 2026
Data controller
Techbyte OÜ, registry code 16817909, with registered address at Ruunaoja tn 3, Lasnamäe linnaosa, 11415 Tallinn, Harju maakond, Estonia, is the controller for personal data processed by Nutria (nutriaplans.com). Contact: info@nutriaplans.com.
What we process
Account data: email, name and password (stored hashed with bcrypt, never in plain text).
Profile data you or your nutritionist enter to compute targets: sex, birth date, height, weight and activity level.
Health data you or your nutritionist choose to enter: answers to anamnesis questionnaires (free text that may include pathologies, allergies and intolerances or other clinical history), your dietary requirements and preferences, and the clinical notes and directives your nutritionist writes about you. We process it only with your explicit consent (art. 9.2.a GDPR) and only to provide the service.
Content you create: plans, menus, custom foods, meal photos, guides, notes and preferences.
Minimal technical data: IP addresses in server logs and rate limiting (abuse protection).
Why we process it
To provide the service: composing plans, computing nutrients and energy targets, sharing content between nutritionist and client where an accepted connection exists.
Security: authentication, brute-force and abuse prevention.
We never sell data or use it for advertising. There are no third-party trackers.
Legal basis
Contract performance (art. 6.1.b GDPR) for the service; legitimate interest (art. 6.1.f) for security; and consent (art. 6.1.a) for the health-related data you choose to enter, processed by you or your nutritionist within the service (art. 9.2.a).
Who it is shared with
Processors under contract: DigitalOcean (servers, database and file storage in the EU, London/Amsterdam region depending on the service), Stripe (payment processing and billing), Sentry (error monitoring, hosted in its EU region), Cloudflare (bot protection on registration via Turnstile), Google Firebase (push notification delivery in the mobile apps) and, when you use AI features, the corresponding model provider.
Your nutritionist or clients only see what the accepted connection allows. Recipes and foods you mark as public are visible to other users with your name.
International transfers
We run the service from the EU and pick European regions whenever the provider allows it. Even so, some providers (Stripe, Cloudflare, Google and, depending on the case, the AI provider) are global companies and may process certain data outside the European Economic Area. Those transfers rely on GDPR safeguards: standard contractual clauses approved by the European Commission and, where the provider is certified, the EU-US Data Privacy Framework (arts. 46 and 45 GDPR).
Retention and erasure
We keep your data while the account is active. When you delete your account from your profile, deletion is immediate and permanent: your identifying data is anonymized, your health data (profile, anamnesis answers, clinical notes and preferences) and personal content are deleted, your sessions are closed and any active subscription is cancelled.
Only the essential remains: plans a professional created for their clients (unlinked from you), content you shared with other users (attributed to an anonymized profile, without your name) and the billing records required by accounting and tax law, for the applicable legal period. The details are on the Delete account page.
Your rights
Access, rectification, erasure, objection, restriction and portability: write to info@nutriaplans.com. You can also complain to your supervisory authority (AEPD in Spain, AKI in Estonia).
