Privacy Policy
Last Updated: July 2026 · Contact: [email protected]
1. Overview
Neurolance LLC ("Neurolance," "Company," "we," "our," or "us"), a Virginia limited liability company, operates globally and is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and safeguard your information when you use our mobile application, website, or related services (collectively, "Services").
This policy applies to all users, including those in the European Union, California, Virginia, and other jurisdictions with specific privacy laws. We comply with the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), California Online Privacy Protection Act (CalOPPA), Virginia Consumer Data Protection Act (CDPA), Children's Online Privacy Protection Act (COPPA), and related privacy regulations.
SavorAI is not a medical device. It does not diagnose, treat, cure, or prevent any disease or condition. Nutritional and activity information is provided for general informational purposes only and is not medical advice. Consult a qualified healthcare professional before making decisions about your diet, exercise, or health.
By using Neurolance, you agree to this Privacy Policy.
2. Age Requirements and Parental Consent
Our Services are intended for users aged 13 and older. If you are under 18, you must have permission from a parent or legal guardian to use Neurolance. By using our Services, minors confirm they have obtained parental consent.
We do not knowingly collect personal information from children under 13 without verified parental consent. If we discover such collection, we will delete the data immediately. Parents or guardians may contact [email protected] to request removal of a child's information.
3. Information We Collect
We collect only what is necessary to provide and improve our Services:
Personal Information
- Food images and descriptions: Content you upload for analysis. Images are stored so that you can view the photo associated with a previously logged food entry.
- Nutrition and dietary logs: Foods you log, portions, meal times, and the resulting calorie and macronutrient totals
- Account information (optional): Email address, username, or login credentials if you create an account
- Profile inputs you choose to provide: Information such as height, weight, age, sex, activity level, and goals, used to calculate your personalized calorie and macronutrient targets
- Subscription information: Subscription status, purchase and renewal events, and anonymous purchaser identifiers, processed through Apple, Google, and RevenueCat. We do not access or store your payment card details.
Health and Fitness Data
With your explicit, separate permission, we access a limited set of health and fitness data from Android Health Connect and Apple Health. See Section 4 for full details, including exactly what we access, how it is used, and how to revoke access.
Technical and Usage Data
- Device information: Device type, operating system version, unique device identifiers
- Usage analytics: Anonymized interaction patterns, feature usage, and app performance metrics for service improvement
- Log data: IP addresses, access times, and error reports for security and troubleshooting
Categories of Data (CCPA Disclosure)
We collect the following categories of personal information as defined by California law:
- Identifiers (email, username)
- Commercial information (subscription and purchase history)
- Internet/network activity (usage patterns, device info)
- Visual information (food images)
- Sensitive personal information: Health and fitness data, including dietary logs and, where you grant permission, step counts and active energy burned (see Section 4)
What We Don't Collect
We do not collect:
- Genetic or biometric identifiers
- Racial or ethnic origin, political opinions, religious beliefs
- Sexual orientation
- Precise geolocation data
- Social Security numbers, driver's license numbers, or financial account details
- Medical records, diagnoses, prescriptions, or clinical health information
4. Health and Fitness Data (Health Connect and Apple Health)
SavorAI is a nutrition and calorie tracking application. Some of the information we process is health and fitness data, and we treat it as sensitive. This section explains exactly what we access, why, and how you stay in control.
4.1 What We Access
If you choose to connect Android Health Connect or Apple Health, we request read access only to the following data types:
- Steps: Your daily step count. Step data is read from your device and displayed to you within the app. It is never transmitted to or stored on our servers.
- Active energy burned (calories burned): Energy expenditure recorded by your device or connected fitness apps. A daily total may be sent to and stored on our servers solely to calculate your remaining calorie budget for that day.
We request the minimum data types required for the features described below, and we do not request access to any health data type we do not actively use. We do not access medical records, heart rate, sleep, reproductive health, blood glucose, blood pressure, body temperature, mental health data, or any other health data type.
We may also write your logged nutrition data (calories and macronutrients) back to Health Connect or Apple Health, but only if you separately grant write permission. You may decline this without losing access to any other feature.
4.2 How We Use It
Health and fitness data is used solely to deliver features you have asked for:
- Calorie balance: Incorporating calories burned into your daily calorie budget, so your remaining intake target reflects your actual activity
- Informational display: Showing your steps and activity alongside your nutrition data within the app
We do not use health and fitness data for any other purpose. Specifically, we do not:
- Use it for advertising, marketing, or remarketing of any kind
- Sell it, rent it, or transfer it to data brokers or information resellers
- Share it with any third party for that third party's own purposes
- Use it to train artificial intelligence or machine learning models
- Use it for automated decision-making that produces legal or similarly significant effects
- Use it to determine eligibility for credit, insurance, employment, or pricing
4.3 Consent and Permissions
Access to Health Connect and Apple Health is entirely optional. Before any health permission is requested, we present an in-app disclosure explaining what data we will access and why. Access is granted only after you take an affirmative action, and permissions are granular — you may grant some data types and deny others.
Declining health permissions does not restrict access to SavorAI's core functionality. You may revoke access at any time through Android Health Connect settings, iOS Health app settings, or your device's app permission settings. Revoking access stops all further collection immediately.
4.4 Storage, Sharing, and Retention
We practice data minimization with health data:
- Step data is never stored by us. It is read from Health Connect or Apple Health on your device, displayed within the app, and not transmitted to our servers.
- Active energy burned is stored on our servers only as a daily total, and only for the purpose of adjusting your calorie budget for that day.
Any health data we do store is transmitted over encrypted connections (TLS) and stored encrypted at rest on our infrastructure (AWS and Supabase, United States). Access within our systems is restricted to authorized personnel and protected by access controls and multi-factor authentication.
Health and fitness data is not shared with our AI inference provider and is not included in food image analysis requests.
We retain stored health and fitness data for no longer than 24 months, after which it is deleted or irreversibly anonymized. You may request deletion of all health and fitness data at any time by emailing [email protected] or via Settings > Privacy > "Manage My Data." Deleting your account deletes all associated health and fitness data.
Deleting data within SavorAI does not delete the original records held in Health Connect or Apple Health, which remain under your control on your device.
5. How We Use Your Data
We process your information only for these specific purposes:
- Service delivery: Analyze food images and provide nutritional results
- Personalization: Calculate calorie and macronutrient targets based on the profile information and activity data you provide
- Service improvement: Diagnose errors and evaluate the accuracy of our nutrition estimates using aggregated, anonymized usage data
- Account management: Authenticate users, manage accounts and subscriptions, and provide customer support
- System maintenance: Ensure security, prevent fraud, and troubleshoot technical issues
- Legal compliance: Respond to user rights requests and comply with applicable laws
Legal Basis for Processing (GDPR)
- Contract performance: Providing Services you've requested
- Explicit consent: Processing food images and health and fitness data (Article 9(2)(a)); withdrawable at any time
- Legitimate interest: Service improvement, security, and fraud prevention
We do not use your food images, dietary logs, or health data to train artificial intelligence or machine learning models — neither our own models nor those of any third party.
We do not use your information for:
- Targeted advertising or cross-context behavioral marketing
- Automated decision-making or profiling with legal/significant effects
- Sale or sharing of personal information for monetary or other valuable consideration
Student Data (SOPIPA): If K-12 student data is inadvertently collected, it will not be used for targeted advertising or disclosed without authorization.
6. Data Sharing and Third Parties
We do not sell, rent, or share your personal information for marketing purposes.
Service Providers We Use
We engage limited third-party processors who are contractually obligated to protect your data:
- Google (Gemini API): Processes food images and descriptions to generate nutritional analysis, acting solely as our data processor. Google does not use this data to train its models. See Google's data governance documentation. We remain the data controller. Health and fitness data is never sent to this provider.
- Amazon Web Services (AWS): Cloud infrastructure and encrypted S3 storage (US-East-1 region)
- Supabase: Database and authentication services (utilizing AWS infrastructure)
- RevenueCat, Inc.: Subscription management and purchase validation. Receives subscription status, transaction and renewal events, an anonymized user identifier, and basic device and app information in order to manage your subscription entitlements. RevenueCat does not receive your food images, dietary logs, or health and fitness data. See RevenueCat's privacy policy.
- Google Play / Apple App Store: Payment processing (we do not access payment details)
No other third parties collect data through our Services.
When We May Disclose Information
Limited disclosure occurs only when:
- Legally required: Valid court orders, subpoenas, or legal obligations
- Safety and security: Preventing fraud, protecting rights, or ensuring user safety
- Business transfers: Merger, acquisition, or asset sale (with prior notice and deletion option)
7. Data Retention
We retain information as follows:
- Account information: Deleted within 24 hours of account deletion request
- Step data: Never stored on our servers (see Section 4.4)
- Active energy burned: Retained no longer than 24 months, or until you request deletion or revoke permission
- Food images: Retained for up to 24 months so you can view the photo attached to a logged entry, then automatically deleted. Deleted sooner upon account deletion or on request.
- Dietary logs: Retained while your account is active so you can review your history. Deleted upon account deletion or on request.
- Anonymized analytics: Retained indefinitely (cannot be linked to you)
- Subscription records: Retained as required for billing, tax, and dispute resolution purposes
You may request deletion of any retained data at [email protected]. We will process deletion requests within 30-45 days, except where retention is required by law.
8. Data Security
We implement industry-standard security measures:
- Encryption: Data encrypted in transit (TLS/SSL) and at rest
- Access controls: Limited employee access with multi-factor authentication
- Secure infrastructure: AWS and Supabase enterprise-grade security features
- Private storage: Encrypted S3 buckets accessible only by authorized Neurolance systems
- Regular audits: Ongoing security assessments and vulnerability testing
Data Breach Notification
If a breach compromises your personal information, we will:
- Notify affected users via email without undue delay
- Notify relevant authorities within 72 hours (GDPR requirement)
- Provide breach details, potential consequences, and protective measures
While we employ extensive safeguards, no system is completely secure. We cannot guarantee absolute security but commit to industry best practices.
9. Your Privacy Rights
You have comprehensive control over your data. Rights vary by jurisdiction:
All Users
- Access: Request a copy of your personal information
- Correction: Update inaccurate or incomplete data
- Deletion: Request erasure of your information
- Portability: Receive data in a structured, machine-readable format
- Withdraw Consent: Revoke consent for processing at any time, including health permissions
California Residents (CCPA/CPRA Rights)
- Right to Know: Request categories and specific pieces of personal information collected, sold, or shared in the preceding 12 months
- Right to Delete: Request deletion of personal information (subject to exceptions)
- Right to Correct: Request correction of inaccurate information
- Right to Opt-Out: Opt out of "sale" or "sharing" of personal information (we don't engage in these activities)
- Right to Limit Sensitive PI: Restrict the use of sensitive personal information. We use health and fitness data solely to provide the features you requested, which is a permitted purpose, and never for advertising or inference about you. You may revoke health permissions at any time.
- Non-Discrimination: Exercise rights without discriminatory treatment or pricing differences
California Minors (Under 18): You may request removal of content you've posted. Contact [email protected]
California Minors (Under 16): You or your parent/guardian may opt out of any sale of personal information. We do not sell data.
Virginia Residents (CDPA Rights)
All rights under "All Users" above, plus:
- Right to Opt-Out: Opt out of targeted advertising, sale of data, or profiling (we don't engage in these)
- Right to Appeal: Contest denial of your request (see appeals process below)
EU/EEA Residents (GDPR Rights)
All rights under "All Users" above, plus:
- Right to Restrict Processing: Limit processing under certain circumstances
- Right to Object: Object to processing based on legitimate interests
- Right to Lodge a Complaint: File complaint with your local Data Protection Authority
10. How to Exercise Your Rights
Submit requests via:
- Email: [email protected]
- In-App: Settings > Privacy > "Manage My Data"
Response Timeframes:
- GDPR/CDPA: 30-45 days
- CCPA/CPRA: 45 days (may extend additional 45 days if needed)
Requests are free of charge unless manifestly unfounded or excessive. We may request identity verification before processing.
Appeals Process (Virginia Residents)
If we deny your request, you may appeal within 60 days by:
- Replying to our denial email, or
- Emailing [email protected] with "Appeal" in the subject line
We will respond within 60 days. If unsatisfied, contact the Virginia Attorney General: oag.state.va.us
Additional Resources
- California residents: California Attorney General - oag.ca.gov
- EU residents: European Data Protection Board - edpb.europa.eu
- General inquiries: [email protected]
11. Do Not Sell or Share My Personal Information
We do not sell or share your personal information as defined by the CCPA/CPRA. We do not:
- Sell data for monetary or other valuable consideration
- Share data for cross-context behavioral advertising
- Disclose data to third parties for their own marketing purposes
In the preceding 12 months, we have:
- Not sold any categories of personal information
- Not shared personal information for cross-context behavioral advertising
- Disclosed identifiers, visual information, and subscription information to the service providers listed in Section 6 solely for business purposes
To formally opt out of any potential future sale or sharing, contact [email protected] or use Settings > Privacy > "Do Not Sell My Info."
12. International Data Transfers
Neurolance operates globally through the Apple App Store and Google Play Store. Your data is stored on AWS servers in the United States (US-East-1 region).
If you access our Services from outside the U.S., your information will be transferred to and processed in the United States. We use safeguards including:
- Standard Contractual Clauses (SCCs) for EU/EEA data transfers
- Adequate data protection measures consistent with GDPR Article 46
- Contractual protections with all service providers
13. Automated Decision-Making
Neurolance does not engage in automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals without human oversight.
Our AI provides nutritional analysis for informational purposes only and does not make decisions affecting your legal rights, financial status, or access to services.
14. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be communicated as follows:
- Material changes: Email notification at least 30 days before taking effect
- Non-material changes: Posted here with updated "Last Updated" date
- All changes: Reflected in the "Effective Date" and "Last Updated" fields above
Continued use of our Services after changes take effect constitutes acceptance of the updated policy. We encourage periodic review of this policy.
How you'll be notified: Via email to your registered address. We may also provide in-app notifications.
15. Data Protection Officer
Neurolance LLC's managing members serve as Data Protection Officers for privacy matters. For DPO-related inquiries, contact:
Email: [email protected]
16. Business Information and Jurisdiction
- Operating Entity: Neurolance LLC, a Virginia limited liability company
- Base of Operations: Virginia, United States
- Service Reach: Global via Apple App Store and Google Play Store
- Governing Law: This policy is governed by the laws of the State of Virginia and applicable U.S. federal law
17. Contact Us
For questions, concerns, or requests:
- Privacy & Data Requests: [email protected]
- General Inquiries: [email protected]
18. Legal Compliance Statement
This Privacy Policy complies with:
- General Data Protection Regulation (GDPR) - EU Regulation 2016/679
- California Consumer Privacy Act (CCPA) - Cal. Civ. Code § 1798.100 et seq.
- California Privacy Rights Act (CPRA) - 2020 California Proposition 24
- California Online Privacy Protection Act (CalOPPA) - Cal. Bus. & Prof. Code § 22575-22579
- Virginia Consumer Data Protection Act (CDPA) - Va. Code Ann. § 59.1-575 et seq.
- Children's Online Privacy Protection Act (COPPA) - 15 U.S.C. §§ 6501-6506
- Privacy Rights for California Minors in the Digital World - Cal. Bus. & Prof. Code § 22581
- Student Online Personal Information Protection Act (SOPIPA) - Cal. Bus. & Prof. Code § 22584-22585
- Google Play User Data policy, Health Apps policy, and Health Connect data use requirements
- Apple App Store Review Guidelines § 5.1 (Data Collection and Storage) and HealthKit requirements
Thank you for trusting SavorAI and Neurolance LLC with your privacy.