1. Overview
Nishi is an AI nutrition companion operated by Mirae Ventures LLC ("we," "us," or "our"). Nishi helps people (especially those on GLP-1 medications) understand how the food they eat, the data their wearables report, and how they feel fit together. We do this through a mobile app on iPhone and Apple Watch, and through our website at meetnishi.com.
This Privacy Policy explains what we collect, how we use it, who we share it with, and the choices you have. We've tried to write it in plain English. If anything here is unclear, email support@meetnishi.com.
Nishi handles information about your body, your food, and how you feel, categories of data that deserve real care. We've designed Nishi around three commitments:
- We don't sell your data. Not to advertisers, not to data brokers, not to anyone.
- We don't use your data to train AI models. Your conversations with Nishi, your food logs, and your health data are not used to train third-party AI systems or our own.
- You can leave with your data. You can export it. You can delete it. Both are one-tap actions in the app.
2. What we collect
Account information
When you create a Nishi account (required to use the app), we collect:
- Email address, or your Apple ID / Google account identifier if you use Sign in with Apple or Google
- Display name and profile photo, if you provide them
- Authentication tokens, stored only on the device's secure keychain
Food and kitchen content
- Food items, meals, and ingredients you log by voice, photo, text, barcode, receipt scan, or menu scan
- Nutrition estimates (calories, macros, micronutrients) derived from your logs
- Grocery receipt content, processed on-device or via our backend depending on the flow; we describe details below
- Photos of meals or menus you take inside the app, if you use those features
Health, biometric, and wellness data
If you grant Nishi access to Apple Health (iOS) or Health Connect (Android), Nishi reads selected metrics so it can interpret your nutrition in context. The specific metrics we may read include:
- Body measurements: weight, body fat percentage, BMI
- Activity: steps, active and resting energy, workouts
- Heart: heart rate, resting heart rate, heart rate variability
- Sleep: time asleep, time in bed, stages
- Cycle tracking, if you share it
- Blood glucose from a connected continuous glucose monitor (CGM)
You choose which categories to share at the iOS or Android permission prompt and can revoke any of them at any time in your device settings.
GLP-1 medication and treatment context
If you choose to share that you are on a GLP-1 medication (e.g., Ozempic, Wegovy, Mounjaro, Zepbound), we may collect:
- Medication name, dose, and injection schedule (only what you enter)
- Side effects and symptoms you log (for example, nausea, fullness, hunger, energy, mood)
- Notes you write about how you're feeling
You can use Nishi without disclosing any of this. If you do share it, we treat it as sensitive health data per Section 3.
Voice agent interactions
If you use Nishi's voice interface, we process your spoken audio so Nishi can transcribe what you said and respond. We describe the third parties involved in Section 6. We do not retain raw audio beyond what is needed to complete a request, and we do not use your voice to train voice models.
Subscription and purchase information
If you subscribe to Nishi Premium, your subscription is processed by Apple's App Store, Google Play, or Stripe depending on where you signed up. We never see or store payment card details. We receive only the subscription state (active, trialing, canceled, expired) and an identifier needed to associate the subscription with your account.
Diagnostic and analytics data
- Anonymous app usage events (which features are used, screen views, performance metrics)
- Crash and error reports
- You can opt out of analytics in Settings → Privacy at any time
We do not collect contact lists, advertising identifiers, or precise location.
3. Health and biometric data: extra commitments
Health data is the most sensitive category Nishi handles, and we treat it with extra care.
- HealthKit data stays out of advertising and analytics. Per Apple's HealthKit rules, we do not share any data read from HealthKit with third parties for advertising or data-broker purposes, and we do not use it in our product analytics in personally identifiable form.
- No sale of health data. We do not sell, license, or rent health, biometric, or symptom data. Ever.
- No use for model training. Health data is not used to train our own models, our AI providers' models, or any third party's models.
- Encrypted in transit and at rest. See Section 8.
- You can disconnect Apple Health, Health Connect, or CGM at any time. When you do, Nishi stops reading new metrics. Previously-read values remain in your Nishi data until you delete your account or specific entries.
If you live in California, your health data may be subject to additional protections under the Confidentiality of Medical Information Act (CMIA). If you live in Washington, the My Health My Data Act gives you specific rights over consumer health data. See Section 10 for how to exercise them.
4. How we use your information
We use what we collect to:
- Run the core product: log food, parse receipts and menus, generate observations about your patterns, answer your questions, sync across your devices
- Interpret nutrition in the context of your wearable data, medications, and how you've been feeling
- Send local reminders and observations on your iPhone and Apple Watch
- Process your Premium subscription and entitlements
- Diagnose crashes, fix bugs, and improve performance
- Improve Nishi using aggregate, de-identified analytics
- Communicate with you when you contact us, or about meaningful changes to the service
We do not use your data for advertising, lead generation, or to build profiles for sale.
Legal bases for processing (UK and EEA users)
If you are in the United Kingdom or the European Economic Area, the UK GDPR and EU GDPR require us to have a legal basis for each use of your personal data. We rely on:
- Your explicit consent for special-category data: health, biometric, and GLP-1 or other medication and symptom data. We process this only after you choose to share it (for example, when you connect Apple Health or Health Connect, or enter medication or symptom details). You can withdraw consent at any time by disconnecting those sources or deleting the data, without affecting processing already carried out.
- Performance of a contract, to provide the core features you sign up for: logging food, syncing across devices, generating observations, and managing your subscription.
- Our legitimate interests, to secure the service, prevent abuse, diagnose and fix problems, and improve Nishi using aggregate, de-identified analytics, balanced against your rights and freedoms.
- Legal obligation, where we must retain or disclose data to comply with the law.
5. Sharing and disclosure
We share data only in these limited situations:
- Service providers who help us run Nishi (listed in Section 6). They process data on our behalf under contracts that restrict their use of it.
- Care partners you choose to share with. If you generate a doctor visit summary, household summary, or shared report, you control who receives it and what's in it. We don't share these to anyone you don't invite.
- Legal compliance. If we are legally required to (subpoena, court order, regulatory request), we may disclose specific information. We will push back on overbroad requests where we can, and notify you where the law allows.
- Business transfer. If Nishi is acquired or merges with another company, your data will transfer subject to this Privacy Policy (or a successor at least as protective). We'll notify you in the app and by email if you've signed in.
We do not share data with advertisers, marketers, or data brokers.
6. Third-party services
Nishi relies on a small, deliberately chosen set of services to operate. Each is contractually restricted in how they may use your data.
- Supabase: authentication and encrypted database storage for your account. US-region hosting. Row-level security ensures only you can access your data.
- Apple App Store, Google Play, and Stripe: subscription billing and entitlement.
- OpenAI and Anthropic: for nutrition reasoning, receipt and menu parsing, observation generation, and voice agent responses. We send the minimum context needed to answer your question, typically text from your logs, not raw photos. Per OpenAI and Anthropic's API terms, your inputs and outputs are not used to train their public models.
- Speech-to-text and text-to-speech providers: for the voice agent. Audio is processed transiently to produce a transcript or a spoken response and is not retained for training. The specific providers may change as we improve voice quality; the current list is available on request to support@meetnishi.com.
- Apple HealthKit: on-device only; HealthKit itself does not transmit data to us. We read specific values from HealthKit only with your explicit permission.
- PostHog: privacy-respecting product analytics, anonymous and opt-out via Settings.
- Apple Push Notification Service and Firebase Cloud Messaging: to deliver app notifications you've opted in to.
We work to share only the minimum data each service needs. None of these services receives your data for advertising.
7. Device permissions
Nishi asks for permissions only when they're needed for a feature:
- Microphone: for the voice agent, when you press to talk
- Camera: for scanning receipts, menus, or food labels
- Photo Library: to pick existing photos for receipt or meal logging; limited and full access both work
- Notifications: for reminders and observations you've enabled
- Apple Health / Health Connect: only the specific data categories you toggle on
- Apple Watch background data: to refresh observations on your wrist
- Face ID / Touch ID: optional, only if you turn on biometric app lock
You can change any permission at any time in your device's settings. Revoking a permission disables the related feature; the rest of Nishi keeps working.
8. Storage and security
- Cloud-stored data lives on Supabase infrastructure in the United States, protected by row-level security so only you and parties you explicitly invite can read it.
- All network traffic between Nishi and our backend uses TLS encryption.
- Authentication tokens are kept in the iOS Keychain or Android Keystore.
- Local data on your device is stored in Apple or Android secure storage primitives.
- We use administrative, technical, and physical safeguards consistent with industry practice for health-adjacent applications. No system is perfectly secure, but we work to keep yours safe and treat security as an ongoing practice rather than a checklist.
International data transfers
Nishi is operated from the United States, and our cloud infrastructure and several of our service providers are located there. If you use Nishi from the United Kingdom, the European Economic Area, Australia, New Zealand, or anywhere else outside the United States, your personal data is transferred to and processed in the United States and in other countries where our providers operate.
Where we transfer personal data out of the UK or EEA, we rely on appropriate safeguards recognised under the UK GDPR and EU GDPR, including the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum in our agreements with processors, and/or providers certified under a recognised framework such as the EU-U.S. and UK-U.S. Data Privacy Framework. For transfers from Australia and New Zealand, we take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles and the New Zealand Privacy Act 2020. You can request more detail about these safeguards at support@meetnishi.com.
9. Retention and deletion
We keep your data for as long as your account is active.
- In-app: Settings → Account → Delete Account. Deletion is immediate and permanent.
- By email: write to support@meetnishi.com from the address tied to your account; we'll process within 30 days.
Deleting your account removes your food and health data, voice transcripts, observations, analytics identifier, and authentication. To stop subscription billing, also cancel via the App Store, Google Play, or your Stripe customer portal. Those billing systems are separate.
We may retain limited data when required by law (for example, receipts for tax purposes, or records under legal hold).
10. Your rights
Wherever you live, you can:
- Access the data Nishi stores about you, in-app or by email request
- Export your data
- Correct or update any information you've entered
- Delete your account and all associated data
- Opt out of analytics in Settings → Privacy
Depending on where you live, you may have additional rights under laws including:
- UK GDPR and the Data Protection Act 2018 (United Kingdom): rights to access, rectification, erasure, restriction of processing, data portability, and to object to processing. Where we process your data based on consent, you can withdraw it at any time. Mirae Ventures LLC is the data controller for your personal data (contact details in Section 14). You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.
- EU GDPR (European Economic Area): the same access, rectification, erasure, restriction, portability, objection, and consent-withdrawal rights, and the right to complain to your local data protection supervisory authority.
- Privacy Act 1988 and the Australian Privacy Principles (Australia): rights to access and correct your personal information and to complain about how it is handled. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
- Privacy Act 2020 (New Zealand): rights to access and correct your personal information and to raise a concern. You can also complain to the Office of the Privacy Commissioner at privacy.org.nz.
- CCPA / CPRA (California): right to know, delete, correct, opt out of sale or sharing (we do neither), and limit use of sensitive personal information
- Washington My Health My Data Act: rights over consumer health data including the right to confirm collection, withdraw consent, and request deletion
- CMIA (California): protections specific to medical information
- Similar rights under state and national privacy laws elsewhere
To exercise any of these, email support@meetnishi.com from the address tied to your account. We will respond within the timeframe required by the applicable law.
11. Health disclosures and limits
- We are not your doctor or pharmacist. Nishi does not prescribe medication, manage GLP-1 dosing, or adjust treatment.
- We are not a HIPAA-covered entity. Nishi is a consumer wellness application. We are not a healthcare provider, health plan, or healthcare clearinghouse, and we do not enter into Business Associate Agreements. That said, we treat your health data with care designed to meet or exceed industry expectations for health-adjacent apps.
- Nutrition information is an estimate. Macronutrient and micronutrient values are derived from public food databases and AI estimation. They are not laboratory measurements and should not be relied on for clinical decisions.
- AI can be wrong. Nishi's observations, suggestions, and answers are produced by AI systems that can make mistakes. Use your own judgment, and discuss anything important with your healthcare provider.
- Talk to your doctor before significant changes during GLP-1 therapy. Big changes to your diet, exercise, or supplement routine while on a GLP-1 medication can interact with how the medication affects you. Run material changes by your prescribing clinician.
12. Children's privacy
Nishi is not intended for children under 13, and you must be at least 18 (or the age of majority in your jurisdiction) to create a Nishi account. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with information, please contact us and we will delete it.
13. Changes to this policy
We may update this Privacy Policy as Nishi evolves. When we do, we'll post the updated version here with a new "Last updated" date. For material changes (especially anything that expands what we collect or who we share with), we'll notify you in the app and by email if you've signed in, before the change takes effect.
14. Contact
Questions about this policy or how we handle your data? We'd rather hear from you than have you wonder.
Email: support@meetnishi.com
Mail: Mirae Ventures LLC, c/o Nishi Privacy, United States