Privacy Notice
Last updated: 6/15/2026
1. Who we are
The Rosewood Group ("we", "us", "our") provides the Nutrition Tracker application (the "Service"). We are the data controller for personal data processed in connection with the Service. You can contact us through the in-app support channel.
2. Personal data we collect
- Account data: name, email address, login credentials.
- Profile & health-related inputs you provide: dietary goals, allergens, medications, nutrient targets.
- Meal logs: photos you submit for AI analysis, barcodes you scan, foods you log, and the resulting nutritional data.
- Support communications: messages you send us.
- Usage and device data: log data, telemetry, device identifiers, IP address, approximate location derived from IP.
3. Why we use it (purposes & legal bases)
- Provide the Service (contract): create your account, analyze meals, store your logs and reports.
- Security and fraud prevention (legitimate interests / legal obligation).
- Service improvement and analytics (legitimate interests).
- Customer support (contract / legitimate interests).
- Marketing communications, only where you opt in (consent).
- Compliance with legal obligations such as tax and accounting records.
4. Who we share it with
- Service providers / subprocessors: hosting, database, AI model providers used for meal photo analysis, analytics, error monitoring, and customer support tooling.
- Merchant of Record (Paddle): Paddle.com Market Limited acts as Merchant of Record for the sale of paid plans, handling checkout, subscription management, payments, tax compliance, invoicing, and refunds.
- Professional advisers such as legal and accounting professionals where reasonably required.
- Authorities where required by applicable law or to protect our rights.
5. International transfers
Some of our service providers are located outside your country, including outside the UK/EEA. Where personal data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses or adequacy decisions.
6. Retention
We retain personal data only for as long as needed for the purposes described above: account and meal data for the life of your account and a reasonable period afterwards; billing records as required by tax and accounting law (typically 6–10 years, held by Paddle as MoR); support communications for up to 3 years. We delete or anonymize data when no longer needed.
7. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Request correction of inaccurate data;
- Request deletion of your data ("right to be forgotten");
- Restrict or object to certain processing;
- Request portability of data you provided;
- Withdraw consent where processing is based on consent;
- Lodge a complaint with your local data protection authority.
To exercise these rights, contact us through the in-app support channel. We will respond within one month.
8. Security
We implement appropriate technical and organisational measures to protect personal data, including encryption in transit, access controls, and the principle of least privilege. No method of transmission or storage is 100% secure, but we work to safeguard your information.
9. Cookies
We use strictly necessary cookies and similar technologies to operate the Service (e.g. session and authentication). Where we use analytics or marketing cookies, you can manage your preferences in your browser settings.
10. Changes
We may update this Privacy Notice from time to time. Material changes will be communicated through the Service.