Nectar

Privacy Policy

Effective: 14 August 2026  ·  Last updated: 20 August 2026

This policy explains what Nectar collects, why, who else sees it, and what you can make us do about it. It covers the Nectar mobile app on iOS and Android.

Nectar is operated by Stefan Cleland, an individual sole proprietor ("Nectar", "we", "us"), based in the State of Florida, United States. Stefan Cleland is the data controller for the personal data described here. For anything in this policy, write to nectarappsupport@gmail.com.

Health information, in plain terms

To score products for you, Nectar asks about your allergies, dietary restrictions, symptoms and health goals. That is health-related information about you, and we treat it as the sensitive data it is.

We do not sell it. We do not use it for advertising. We do not share it with data brokers, insurers, or employers. It exists to score products for you, and for nothing else.

Contents

  1. What we collect
  2. Why we collect it
  3. What we deliberately don't do
  4. What stays on your device
  5. Third parties we send data to
  6. Device permissions
  7. How long we keep it
  8. Your rights and how to use them
  9. Deleting your account
  10. Security
  11. International transfers
  12. Children
  13. Changes to this policy
  14. Contact

1. What we collect

Information you give us

DataWhen
Email addressWhen you create an account. If you sign in with Apple using "Hide My Email", we only ever receive Apple's private relay address, never your real one.
Display name and avatarOptional. Supplied by you, or by Apple or Google at first sign-in.
Health and dietary profile — allergies, dietary restrictions, symptoms, wellness goals, ingredients you want to avoidDuring onboarding, and whenever you change your preferences.
Scan history — barcodes, product names, brands, and the score we calculatedEach time you scan a product.
Saved productsWhen you add something to your pantry.
Product reports — barcode, category, and any note you writeWhen you tell us a product's data is wrong or missing.
Support correspondenceWhen you email us.

Information collected automatically

2. Why we collect it, and our legal basis

PurposeData usedLegal basis (UK/EU)
Scoring products against your needs — the core function of the appHealth and dietary profileYour explicit consent (Art. 9(2)(a))
Creating and securing your accountEmail, authentication dataPerformance of a contract
Syncing your history and pantry across your devicesScans, favouritesPerformance of a contract
Fixing wrong product dataProduct reportsLegitimate interests — accuracy of the service
Preventing abuse and keeping the service secureAccount data, technical dataLegitimate interests — safety and security
Answering your support emailsCorrespondenceLegitimate interests — user support
Meeting legal obligationsAs requiredLegal obligation

Where we rely on your consent for health data, you can withdraw it at any time by clearing those answers in the app or deleting your account. Withdrawing consent doesn't undo processing that already happened, and much of the app stops being useful without it.

3. What we deliberately don't do

Stated plainly, because these are the things people worry about:

4. What stays on your device

A good deal of Nectar works without sending anything anywhere:

Deleting the app removes everything held locally. It does not delete your account — see section 9.

5. Third parties we send data to

The complete list. We add no others without updating this policy.

WhoWhat they receiveWhy
Supabase (database, authentication, hosting) Everything in your account: email, profile, health answers, scans, favourites, reports They host our database. They process this only on our instructions, as our data processor.
Apple — Sign in with Apple Only that you signed in. Apple gives us a token, your email or relay address, and optionally your name. Authentication, if you choose it.
Google — Google Sign-In Only that you signed in. Google gives us a token, your email, name and profile picture. Authentication, if you choose it.
Open Food Facts and Open Beauty Facts The barcode you scanned, plus your IP address as part of the request. Never your identity, account, or health profile. Looking up what the product is.
UPCitemdb, USDA FoodData Central The barcode or product name, plus your IP address. Nothing about you. Filling gaps when a product isn't in the primary database.
Amazon Nothing directly from us. If you tap a "View on Amazon" link, Amazon receives the visit as it would any web visit, and we may earn a commission as an Amazon Associate. Optional shopping links you choose to tap.
Apple App Store / Google Play Purchase and subscription data, handled entirely by them. We never see your card details. Billing, if you subscribe.

We may also disclose information where we are legally compelled to, where it is necessary to investigate fraud or a threat to someone's safety, or to a buyer as part of a merger or acquisition — in which case this policy continues to apply until you are told otherwise.

6. Device permissions

PermissionWhat it's forOptional?
CameraReading barcodes and ingredient labels. Frames are processed on your device to find a barcode. We do not store or upload photographs or video.Required to scan; the rest of the app works without it.
NotificationsReminders you asked for, scheduled on your device.Yes.

You can change any of these in your device settings at any time.

Nectar does not ask for App Tracking Transparency permission, because it does not track you across other companies' apps or websites.

7. How long we keep it

8. Your rights

Wherever you live, you can ask us to:

Email nectarappsupport@gmail.com. We reply within 30 days and never charge for it. We may need to confirm you are who you say you are before acting.

If you are in the UK or EU (UK GDPR / GDPR): the rights above are yours by law, and you may complain to your national data protection authority — in the UK, the Information Commissioner's Office at ico.org.uk. We'd rather you came to us first.

If you are in California (CCPA/CPRA): you have the rights above plus the right not to be discriminated against for exercising them. We do not sell or share personal information, so there is no "Do Not Sell or Share My Personal Information" action to take — but you may still contact us to confirm this. Your health and dietary answers are "sensitive personal information" under the CPRA, and we use them solely to provide the service you asked for, which is a use you cannot be required to opt out of separately.

Other US states — including Virginia, Colorado, Connecticut, Utah and Texas — grant comparable rights. Use the same email address and we will treat your request under whichever law applies to you.

9. Deleting your account

In the app: Settings → Account → Delete account. This is permanent and immediate.

By email: write to nectarappsupport@gmail.com from your registered address and we will delete the account within 30 days.

Deleting your account erases your profile, health answers, scan history, favourites and saved settings from our systems. Backups are purged on their own rotation, within 30 days. Anonymised product reports are handled as described in section 7.

Deleting the app from your phone is not the same thing, and does not delete your account.

10. Security

Your data is encrypted in transit (HTTPS/TLS) and at rest. Access is enforced at the database level by row-level security, meaning each account can only ever read its own rows — this is enforced by the database itself, not merely by the app. We do not store passwords; authentication is handled by our provider using industry-standard hashing.

No system is perfectly secure, and we will not pretend otherwise. If a breach affects your personal data, we will notify you and the relevant regulator as the law requires, without undue delay.

11. International transfers

Our database is hosted in Canada (AWS ca-central-1), and your account data is stored there. If you use Nectar from elsewhere, your data is transferred to Canada. Canada is the subject of adequacy decisions by both the European Commission and the UK government, meaning it is recognised as providing an equivalent standard of protection, so transfers from the EEA or UK rest on that adequacy. Where any transfer falls outside those decisions — for example onward access by our hosting provider’s personnel in the United States — we rely on the UK International Data Transfer Addendum and the European Commission’s Standard Contractual Clauses to protect it.

12. Children

Nectar is for people aged 13 and over. We do not knowingly collect data from children under 13. If you believe a child under 13 has given us information, email us and we will delete it promptly. In some places the minimum age is higher — where local law requires parental consent below 16, that requirement applies.

13. Changes to this policy

If we change anything material, we will update the date at the top and notify you in the app or by email before the change takes effect. Continuing to use Nectar after that means you accept the updated policy.

14. Contact

Stefan Cleland
Florida, United States
nectarappsupport@gmail.com