Skip to content
Nutrition MCP
How it works Install Tools Examples Live stats0 new food logs since you opened FAQ
EN
EnglishEN DeutschDE EspañolES FrançaisFR NederlandsNL PolskiPL ItalianoIT УкраїнськаUK 日本語JA
Connect
How it works Install Tools Examples Live stats0 new food logs since you opened FAQ
Language
EN DE ES FR NL PL IT UK JA
Theme
Connect

October 2, 2026

Privacy Policy

How Nutrition MCP handles your data: what we store, how it is used, where it lives, and how to delete your account and everything in it at any time.

Privacy Policy Terms of Service
  1. 01What we collect
  2. 02How we use it
  3. 03Where it's stored
  4. 04How long we keep data
  5. 05Data deletion
  6. 06Contact and your rights
  7. 07Terms of Service
Privacy Policy
  1. 01What we collect
  2. 02How we use it
  3. 03Where it's stored
  4. 04How long we keep data
  5. 05Data deletion
  6. 06Contact and your rights
  7. 07Terms of Service
01

What we collect

When you register, we store your email address and a securely hashed password via Supabase Auth. If you sign in with Google instead, we ask Google only for your email address, and receive it together with Google's account identifier for you, which Supabase Auth keeps so it can recognise your next Google sign-in. We never see a Google password. Accounts that signed in with Google before September 27, 2026 may also still hold the name and profile picture Google sent back then; nothing in the service reads or shows them except your data export, and they are deleted with your account.

When you use the service, we store:

  • Meal logs — description, meal type, calories, macros, fiber, total sugar, grams of alcohol, milligrams of caffeine, notes, and timestamps. Food photos are interpreted by your AI assistant and are never uploaded to or stored by us.
  • Water logs — amount, notes, and timestamps.
  • Body weight logs — weight, notes, and timestamps. This is health data, and it is treated exactly like the rest of your logs.
  • Goals — your daily calorie, protein, carb, fat, fiber, sugar, alcohol, caffeine, and water targets, and your target weight.
  • Profile settings — your IANA timezone, preferred weight unit, whether alcohol tracking is switched on and which standard drink it is shown in, whether in-chat widgets are enabled, and the language in-chat widgets are shown in.
  • Tool-usage telemetry — for each MCP tool call, which tool ran, whether it succeeded, how long it took, a coarse error category when it failed, the span in days of any date range you asked for, the MCP session id, which revision of the MCP protocol your AI app connected with, and the name and version that app reports for itself (for example “claude-ai/1.0”) when it sends them. It is linked to your account id. It never includes the content of your logs.
  • Server runtime log — for each request to the server: the method, path, response status and response time, your IP address with its last part removed, and for MCP requests the protocol revision and the name and version your AI app reports. For each tool call it also records the tool's name, whether it succeeded, how long it took and, when it failed, a short reference code and the error message — which can repeat back a value your AI app sent, such as an invalid date. When your AI app signs in or renews its connection, it records the outcome, the random identifier your AI app was given when it registered with our sign-in service, and the site it asked to be sent back to (for example claude.ai). It is written to our hosting provider's runtime log, does not contain your account id or email address, and is kept only briefly: that log is a rolling buffer that overwrites older lines as new traffic arrives.

Alcohol is health data too, and of a more sensitive kind than a calorie count, so it works differently from everything above. Alcohol tracking is off by default, and we only ever record alcohol when it comes from you — a drink you log, or a column in a file you import. Nothing infers it on your behalf. Switching the setting off does two things: the bulk importer stops reading the alcohol column out of files you upload, and everything else stops showing alcohol in the meals, goals, progress and widgets you see. It is not a delete switch. Alcohol you logged directly is still recorded whether the setting is on or off, anything already stored stays in the database, and all of it still appears in the meals file of any export you take. To actually remove an alcohol figure, delete the meal it belongs to, or delete your account.

We also keep the OAuth access and refresh tokens and authorization codes that let your AI assistant stay connected to your account; how long each one lasts is under “How long we keep data”. They are stored only as one-way hashes.

02

How we use it

Your meal, water, weight, and goal data is used solely to provide the nutrition tracking service and, in anonymous aggregate form, the public statistics on the home page. We never sell it, never share it with third parties, and never use it for advertising or feed it into any ad or profiling system.

The home page and the public statistics feed behind it show anonymous site-wide totals — how many meals have been logged, their calories and macros, the water logged and the net weight lost across all accounts — and the timezones set in profiles, which the home page draws as a world map. A timezone appears on the map only once at least three profiles use it, and no figure is linked to a person.

When you or your AI assistant look up a barcode, our server sends only the barcode digits to Open Food Facts — never your account, email or logs — and keeps the product data it returns in a shared cache that is not linked to any user.

Two kinds of analytics do exist, and neither touches the content of your logs:

  • Website analytics. With your consent, these pages load Google Analytics, which gives us aggregate traffic statistics — page views, referrers, rough geography, device type — and Microsoft Clarity, which records how visitors use the site — clicks, taps, scrolling, mouse movement — as session replays and heatmaps, so we can see where the pages confuse people. Neither loads until you accept in the cookie banner; if you reject, neither loads at all, and if your browser sends a Global Privacy Control signal, neither loads unless you opt in yourself from the footer. Accepting grants analytics storage only: advertising storage and Google signals stay off. Google receives your IP address with each request but, according to Google, does not log or store it for visitors from the EU, Switzerland or the UK, and uses it only to derive an approximate location. Clarity masks what you type into forms and also receives your IP address and browser details. Neither runs on the sign-in page. You can withdraw at any time with “Cookie settings” in the footer, which also deletes the analytics cookies set on this site; your choice is kept in your browser's local storage for up to 6 months.
  • Server telemetry. Every MCP tool call writes one row of usage telemetry — which tool ran, whether it succeeded, how long it took, which MCP protocol revision and which AI app (by the name and version it reports) made the call — linked to your account id but not to what you logged. We use it to find slow and broken tools. It is not shared with anyone, and it is deleted along with everything else when you delete your account.

Because the site loads fonts and icons from Google Fonts and jsDelivr, visiting these pages exposes your IP address to those providers. The project's GitHub star count is fetched by our server, not your browser, so GitHub never sees your visit.

03

Where it's stored

All data is stored in Supabase (PostgreSQL) in the EU, in AWS’s Ireland region (eu-west-1). Authentication and export storage are handled by Supabase in the same region. The server runs on DigitalOcean in Frankfurt, Germany. Requests to the site and the server pass through Cloudflare’s network (used by our hosting provider), which decrypts the connection and so handles everything sent to and from the service in transit, including your IP address, and may set a strictly necessary bot-protection cookie (__cf_bm, 30 minutes).

04

How long we keep data

Your meal, water and weight logs, goals, profile settings, and tool-usage telemetry are kept for as long as your account exists — none of them has a separate expiry date or a scheduled purge. When you delete your account, all of it is deleted immediately and irreversibly, as described below. The only traces left are the telemetry row for the deletion itself, recorded without your account id; the short-lived server runtime log described above, which never carries your account id; our database provider's own operational logs, kept for a limited period (up to 7 days on our plan); and its rolling backups, which age out on their own schedule.

Sign-in credentials are short-lived by design. The sign-in page's session lasts 10 minutes and is held in the server's memory; it is tied to your browser by a strictly necessary cookie that holds only a random value, expires after the same 10 minutes and is deleted when sign-in finishes. To check your password or Google sign-in we use Supabase Auth, which creates a Supabase sign-in session each time; we never use it and end it immediately. The one-time authorization code handed to your AI app expires after 10 minutes and is deleted as soon as it is used. An access token is valid for 24 hours (the few issued on or before September 27, 2026 expire no later than October 6, 2026); a refresh token is valid for 90 days, and it is deleted the moment it is used to get a new pair. Expired tokens and codes are deleted automatically within an hour. Deleting your account removes all of them immediately.

Export archives are short-lived. Each new export overwrites the previous one, and the file is deleted automatically once its 60-minute download link has expired — a cleanup runs every ten minutes, so an archive normally stays in storage for no more than about 70 minutes.

05

Data deletion

You can delete your account and all associated data at any time by asking your AI assistant to delete your account while connected to the Nutrition MCP server. This action is immediate and irreversible. It removes your meals, water and weight logs, goals, profile settings, any export archive still in storage, your tool-usage telemetry, your access tokens, and the account itself. That includes every alcohol figure you ever logged, whether or not alcohol tracking was switched on.

06

Contact and your rights

Nutrition MCP is run by [YOUR NAME], an individual developer, who is the controller of your personal data for this service. For anything about your data or this policy, email your@email.com.

Why we are allowed to process it:

  • Your account and logs — to provide the service you signed up for (performance of a contract). Meals, weight and alcohol are health data, so we process them on the basis of your explicit consent, given when you create your account and each time you sign in (for an app connected before the sign-in page asked for this consent, by logging the entries until you next sign in), which you can withdraw at any time by deleting the entries or your account.
  • Tool-usage telemetry and the server runtime log — our legitimate interest in keeping the service working, fast and secure (finding broken tools, rate-limiting abuse). Neither contains the content of your logs.
  • Website analytics — your consent, given in the cookie banner and withdrawable at any time with “Cookie settings” in the footer.

Your rights, and how to use them — most need no email at all:

  • Access and portability — ask your AI assistant to export your data. You get a ZIP of CSV files with everything we store about you: your meal, water and weight logs, your goals, your settings, your account record (email address, sign-in methods and sign-in dates, and any name or picture Google sent), your tool-usage telemetry, and the connections that keep your AI apps signed in — without the tokens themselves. Not in it: the values we keep only as one-way hashes for security (your password and your connections’ tokens), internal bookkeeping such as duplicate-detection keys, the server runtime log, which does not contain your account id, and our providers’ own short-lived logs and rolling backups.
  • Rectification — ask your AI assistant to correct or delete any meal, water or weight entry, or to change your goals and settings.
  • Erasure — ask your AI assistant to delete your account, which removes everything at once.
  • Objection and restriction — email us.
  • Complaint — you can complain to the data protection authority where you live or work. We would appreciate the chance to fix it first.

Everything we store stays in the EU region named above. Whatever your AI assistant reads through the tools is sent to that assistant's provider, which may be outside the EU; that happens under your own agreement with them, not ours. Cloudflare (the network every request passes through), Google and Microsoft (website analytics, Google Sign-In) and Google and jsDelivr (the font and icon requests described above) are outside the EU too; where they receive personal data from outside the EU, they rely on the European Commission's standard contractual clauses or the EU–US Data Privacy Framework.

The service is not meant for anyone under 16, and the Terms of Service require you to be at least 16. If you believe someone younger has created an account, email us and we will delete it.

If this policy changes, the date at the top changes with it.

07

Terms of Service

Use of the service is also governed by our Terms of Service, which cover acceptable use, the fact that nothing here is medical advice, and the absence of any warranty — the service is provided as-is, free of charge, with no guarantees of availability, accuracy, or fitness for any purpose.

Back to home Terms of Service
Nutrition MCP
Tools Troubleshooting Alternatives Privacy Policy Terms of Service

Free and open source. Nutrition figures are estimates, not medical advice.