Last updated: 14 September 2026
This policy explains what Norra (“we”, “the app”) collects, why, who it goes to, and how to get rid of it. It covers the Norra iOS app and this website.
| Data | Why |
|---|---|
| Account identifier An anonymous ID created on first launch |
To keep your data attached to you without asking you to create an account. If you later sign in with Apple, it links to the same ID. |
| Body measurements Sex, age, height, weight, activity level, goal weight |
To calculate your daily calorie and protein targets. Optional, and stored only on your device. |
| Weight history | To show your trend and correct your target against what your body actually does. Stored only on your device. |
| Food log Items, estimated calories and macros, times |
To show your day and your history. Stored only on your device — we never receive what you ate. |
| Preferences Goal, diet, allergens |
Sent with each analysis so recommendations respect them. |
| Photos you capture | Analysed to identify the food or read the menu. See section 3. |
| Usage events Screens viewed, scans started, purchases |
To understand where the app is confusing or broken. |
| Subscription status | To unlock paid features. Payment itself is handled by Apple — we never see your card. |
When you scan a meal or a menu, the image is resized on your device and sent to our server, which forwards it to an AI vision provider for analysis. The provider returns a description; we return that to your app.
We do not keep the image. It is not written to our database or to any file storage. What we record is the analysis result and technical details of the request — which provider answered, how long it took, whether it succeeded.
A copy of the photo stays on your device so your log has thumbnails. Deleting the entry in the app deletes that copy.
Our AI providers may retain inputs briefly for abuse monitoring under their own policies. We use one or more of: Alibaba Cloud (Qwen), Google (Gemini), OpenAI.
| Service | What they get |
|---|---|
| Supabase Authentication and database | Your anonymous account ID, subscription status, technical records of each scan (which AI provider answered, how long it took — not the food), and any feature suggestion you choose to send us |
| AI vision providers Alibaba Cloud, Google, OpenAI | The photo and your goal, diet and allergens for that request |
| RevenueCat Subscription management | Your account ID and subscription status |
| PostHog Product analytics | Your account ID and usage events |
| Apple | Payment and billing, under Apple’s own privacy policy |
We do not sell your personal data, and we do not share it for advertising.
Your measurements, weight and food log are health-related, and we treat them that way. They are used only to run the app’s features. They are never used for advertising, never sold, and never shared with data brokers.
Norra does not currently read from or write to Apple Health. If that changes, this policy will be updated first.
What is on your device stays there until you delete it or remove the app.
On our side, technical scan records are kept for up to 24 months for abuse prevention and cost monitoring, and your account and subscription record last as long as your account does. Ask us to delete it and it goes within 30 days, apart from anything we are legally required to retain.
You can delete individual meals at any time in the app.
Deleting the app removes your food log, measurements and weight history entirely, because they only ever existed on your device. There is no cloud copy to clean up.
To also remove your account and its server-side records, use Settings → Delete my account in the app. It is immediate and permanent. If that fails for any reason, email support@trynorra.app and we will do it within 30 days.
Depending on where you live, you may have the right to access, correct, export, delete, or restrict processing of your data, and to object to it. If you are in the EEA or UK, our legal bases are: performance of a contract (running the app you signed up for), consent (optional measurements and analytics), and legitimate interests (security and abuse prevention).
If you are in California, we do not sell or share personal information as those terms are defined by the CCPA/CPRA.
Exercise any of these by emailing support@trynorra.app.
Norra is not intended for anyone under 13, and we do not knowingly collect their data. Users under 18 are not given weight-loss targets — the app calculates a maintenance target instead.
Data in transit is encrypted with TLS. Database access is restricted by row-level security so one account cannot read another’s rows. AI provider credentials are held on our server, never in the app. No system is perfectly secure, and we will notify affected users of a breach as required by law.
Our providers operate in the United States and elsewhere. Where data leaves the EEA or UK, transfers rely on Standard Contractual Clauses or an adequacy decision.
If we change this policy materially we will update the date above and notify you in the app before the change takes effect.