Privacy Policy
regarding the processing of personal data
Effective as of December 21, 2025
1. General Provisions
1.1. This Privacy Policy (hereinafter referred to as the "Policy") is drawn up in accordance with the requirements of the General Data Protection Regulation (GDPR) (EU) 2016/679 and applicable privacy laws of other jurisdictions, and defines the procedure for processing personal data and measures to ensure their security undertaken by Individual Entrepreneur Maxim Dmitrievich Nagovitsin, contact email: support@nodiet.ai (hereinafter referred to as the "Data Controller" or "Operator").
1.2. The Data Controller aims to comply with the rights and freedoms of individuals when processing personal data, including protecting the right to privacy, personal and family secrets.
1.3. This Policy applies to all information that the Data Controller may receive about users of the application located at https://app.nodiet.ai (hereinafter referred to as the "Application"), including web and mobile versions.
2. Basic Definitions
Terms are defined in accordance with the GDPR and common privacy terminology: personal data, processing, anonymization, blocking, cross-border transfer, destruction of data, personal data information system, User, etc.
Personal Data: Any information relating to an identified or identifiable natural person.
Processing: Any operation performed on personal data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction.
Data Subject: The individual to whom personal data relates (also referred to as "User").
3. Purposes of Personal Data Processing
3.1. The Data Controller processes User personal data for the following purposes:
- registration and authentication in the Application;
- performance of contracts and provision of services to the User;
- processing payments, generating and sending receipts in accordance with applicable tax legislation;
- establishing feedback (notifications, responses to inquiries, technical support);
- improving the quality of the Application and personalizing recommendations;
- sending notifications about new features, products, and special offers (with User consent).
3.2. The User may unsubscribe from mailings at any time by sending an email to: support@nodiet.ai with the subject "Unsubscribe from notifications."
3.3. Anonymized data (including cookies and analytics data) are used for statistics, behavior analysis, and improving user experience.
4. Legal Bases and Categories of Processed Data
4.1. Processing of personal data is carried out on the following legal bases:
- Consent: User consent (by acceptance during registration or authorization);
- Contract Performance: Performance of the agreement for the use of the Application;
- Legitimate Interests: For improving our services and ensuring security, where such interests are not overridden by your rights.
4.2. Categories of personal data processed by the Data Controller:
- last name, first name;
- email address (when purchasing paid services for sending receipts);
- Telegram nickname and profile photo (when authorizing via Telegram);
- height and weight information (when provided by the User);
- anonymized technical data (cookies, IP address, device identifiers, interaction statistics).
4.3. The email address is provided by the User when purchasing paid services and is used to send electronic receipts in accordance with applicable tax legislation. The Data Controller may use the email address to inform the User about the status of their payments and subscription.
4.4. Height and weight information is considered health data and is processed only with the separate consent of the User, expressed through the Application interface.
5. Your Rights Under GDPR (EU Residents)
If you are a resident of the European Economic Area (EEA), you have the following rights:
- Right of Access: You have the right to request access to your personal data and obtain a copy of the data we hold about you.
- Right to Rectification: You have the right to request correction of inaccurate or incomplete personal data.
- Right to Erasure ("Right to be Forgotten"): You have the right to request deletion of your personal data under certain circumstances.
- Right to Restriction of Processing: You have the right to request restriction of processing of your personal data under certain circumstances.
- Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
- Right to Object: You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority in your country of residence.
To exercise any of these rights, please contact us at support@nodiet.ai.
6. Your Rights Under CCPA/CPRA (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know: You have the right to request information about what personal information we collect, use, disclose, and sell about you.
- Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions.
- Right to Opt-Out of Sale: We do not sell your personal information. If this changes, you will have the right to opt out of such sales.
- Right to Non-Discrimination: You have the right not to be discriminated against for exercising your CCPA/CPRA rights.
- Right to Correct: You have the right to request correction of inaccurate personal information.
- Right to Limit Use of Sensitive Personal Information: You have the right to limit the use and disclosure of sensitive personal information.
To exercise any of these rights, please contact us at support@nodiet.ai or submit a verifiable consumer request.
7. Personal Data Protection Measures
7.1. The Data Controller takes necessary organizational and technical measures to protect personal data from unlawful or accidental access, destruction, modification, blocking, copying, distribution, as well as from other unlawful actions by third parties.
7.2. Protection is ensured through encryption, access control to information systems, and storing data with reliable hosting providers.
8. Data Retention and Deletion
8.1. Personal data are stored until the purposes of their processing are achieved or until the User withdraws consent.
8.2. The User has the right to withdraw consent to the processing of personal data at any time by sending a request to support@nodiet.ai. Upon receipt of the request, the Data Controller will delete the data within 30 calendar days, unless otherwise required by law.
8.3. Specific retention periods:
- Account data: Until account deletion or consent withdrawal
- Payment records: As required by tax legislation (typically 5-7 years)
- Analytics data: Up to 26 months in anonymized form
9. Cross-Border Transfer of Personal Data
9.1. Transfer of personal data to foreign countries is carried out only if adequate protection of the rights of data subjects is ensured.
9.2. When transferring data to countries that do not provide such protection, the Data Controller obtains separate written consent from the User or relies on appropriate safeguards such as Standard Contractual Clauses.
9.3. Your data may be processed by our service providers in various jurisdictions. We ensure that appropriate safeguards are in place for any such transfers, including:
- Transfers to countries recognized as providing adequate data protection;
- Use of Standard Contractual Clauses approved by relevant authorities;
- Other legally approved transfer mechanisms.
10. Cookies and Third-Party Services
10.1. The Application uses cookies and third-party analytics technologies to analyze traffic and improve performance.
10.2. Types of cookies we use:
- Essential cookies: Required for the Application to function properly;
- Analytics cookies: Help us understand how users interact with the Application;
- Preference cookies: Remember your settings and preferences.
10.3. The User may disable the use of cookies in browser settings, which may limit the functionality of the Application.
10.4. Third-party services we use may include analytics providers. These services have their own privacy policies governing their use of your data.
11. Children's Privacy
11.1. The Application is not intended for use by individuals under the age of 18 (or the age of majority in their jurisdiction).
11.2. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete that information.
12. Final Provisions
12.1. The User may obtain clarification on issues related to the processing of personal data by sending a request to support@nodiet.ai.
12.2. This Policy is effective indefinitely until replaced by a new version.
12.3. The current version of the Policy is publicly available at: https://nodiet.ai/en/privacy-policy
Contact Information
Data Controller:
Individual Entrepreneur Maxim Dmitrievich Nagovitsin
Business Registration: 325665800292355
Tax ID: 668602006513
Contact email: support@nodiet.ai