Data controller
The controller responsible for processing your personal data is:
You may contact us with any question relating to this policy or to the processing of your data through the email address indicated.
↑ Back to contentsData we process and its source
We process only the categories of data described below. Their source is, in all cases, yourself (the data you enter or provide when signing in) or your browser (technical data generated during use).
Account data
- If you register with email and password: your email address and password, managed through Firebase Authentication.
- If you sign in with Google: email address, name, profile photo and Google account identifier.
- In both cases, a Firebase user identifier (UID) that associates your content with your account.
User content (Cloud Firestore)
We store in Cloud Firestore, under the path users/{uid} associated with your account, the
content you create in the application:
- Pseudonymous patients: only a label or alias chosen by the clinician —never the real name, the medical record number or any identifying data, by design— together with: preterm yes/no (RNPT/RNT), heart condition yes/no, weight in grams and weeks of life.
- Calculations: snapshots of those parameters together with the nutritional intake calculated.
- Custom intakes defined by the user.
The application is designed not to store identifying patient data. Each patient's label is a free alias chosen by the professional; we do not request or expect data that would allow a person to be identified.
Usage analytics
- Usage data via Firebase Analytics, collected only with your explicit consent (cookie banner). Consent is stored locally on your device. Advertising and advertising signals are disabled.
Security
- Firebase App Check with reCAPTCHA v3 (Google), to prevent abuse of the service. It processes interaction signals from your browser to calculate a risk score.
Error reports (optional)
- If you decide to send an error report: the description of the problem, an optional contact email, the app context (pseudonymous data: weight, indicators and list of intakes), the platform, the version and the date.
Hosting
- Standard access logs from Firebase Hosting, generated automatically when serving the application.
NutriNeo does not process payment data, does not include advertising and does not sell personal data to third parties.
Purposes of processing
We process your data for the following purposes:
- Providing the calculator and the associated persistence of content linked to your account (pseudonymous patients, calculations and custom intakes).
- Security and prevention of abuse of the service.
- Improvement of the service through usage analytics —only if you give your consent—.
- Handling of error reports that you send us voluntarily.
Legal bases
Each processing operation is supported by a legal basis under the GDPR:
Specific use of Google data
When you choose to sign in with Google, NutriNeo accesses the basic data of your Google account. In compliance with the Google OAuth user data policy, we detail below how we access, use, store and share that data.
What data we access
- Your email address, name, profile photo and Google account identifier, obtained through signing in with Google.
How we use it
- Exclusively to create and authenticate your account in NutriNeo and identify you within the application, displaying your profile (name and photo) and associating with your account the content you create.
- We do not use this data for advertising or to build profiles.
How we store it
- It is stored through Firebase Authentication (Google) as part of your account. The rest of your content is stored in Cloud Firestore associated with your UID.
How we share it
- We do not share or sell your Google account data to third parties. The only parties involved in its processing are the Google/Firebase services that act as data processors to provide the service (see the following section).
- We do not transfer Google data to third parties other than the data processors mentioned in this policy, we do not use it for advertising and we do not allow people to read it, except with your express consent, when necessary for security reasons or to comply with the law. Nor is it used to train generalised artificial intelligence or machine learning models.
NutriNeo's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. You may revoke NutriNeo's access to your Google account at any time from your Google account settings.
Recipients and international transfers
NutriNeo relies on Google services that act as data processors. We do not disclose your data to other third parties for their own purposes.
| Service | What it is used for | Data involved |
|---|---|---|
| Firebase Authentication | Account registration and sign-in | Email, password or Google account data, UID |
| Cloud Firestore | Storage of your content | Pseudonymous patients, calculations, custom intakes |
| Firebase Analytics | Usage analytics (only with consent) | Usage data; advertising disabled |
| Firebase App Check + reCAPTCHA v3 | Security and prevention of abuse | Browser interaction signals |
| Firebase Hosting | Hosting of the web application | Standard access logs |
| Sign in with Google | Authentication with the Google account | Email, name, photo, Google identifier |
International transfers
These services may involve the processing of data in the United States. Such international transfers are covered by the standard contractual clauses of the European Commission and/or by the applicable adequacy frameworks offered by Google. You may consult the Firebase privacy information and the Google privacy policy.
↑ Back to contentsRetention and account deletion
We retain your account data and your content (pseudonymous patients, calculations and custom intakes) for as long as your account exists. You may delete your account and all your data directly from within the application itself.
When you delete your account, your pseudonymous patients, your calculations and your custom intakes are deleted in a chained manner.
Retention periods for technical logs and analytics
Technical access logs and usage analytics (aggregated and without patient identifiers) follow their own cycle within the Google/Firebase services, according to the following periods:
- The Firebase Hosting access logs are retained for a limited period, in accordance with Google Cloud retention policies.
- Firebase Analytics retains the data according to its retention configuration, for 14 months (default value, configurable in Google Analytics).
Security: App Check and reCAPTCHA
To protect the service against abusive use we employ Firebase App Check with reCAPTCHA v3 from Google. This technology processes interaction signals from your browser to calculate a risk score and verify that requests come from a legitimate application.
Because this is a strictly necessary security measure for the provision of the service, this processing is based on our legitimate interest (art. 6.1.f GDPR) and, therefore, is not subject to the consent of the cookie banner: reCAPTCHA v3 may be loaded and read browser signals regardless of whether you accept or decline usage analytics.
The use of reCAPTCHA is subject to Google's Privacy Policy and Terms of Service.
↑ Back to contentsYour rights and how to exercise them
In accordance with the GDPR and the Spanish Data Protection Act (LOPDGDD), you may exercise at any time the following rights over your personal data:
You may also withdraw your consent to analytics at any time, without this affecting the lawfulness of the prior processing.
How to exercise them
- You may delete your account and your data directly from the application.
- For any other right, write to us at nutrineoapp@gmail.com.
If you consider that the processing of your data does not comply with the regulations, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), www.aepd.es.
Professional use, minors and pseudonymisation
NutriNeo is a calculation support tool aimed at professionals in neonatology. It is not intended for general use by minors or by the general public.
By design, NutriNeo does not store identifying patient data: each patient's label is a pseudonymous alias. The professional is responsible for not entering identifying data (real name, medical record number or others) in those labels.
Changes to this policy
We may update this policy to reflect changes in the application or in the applicable regulations. We will always publish the current version on this page and indicate the effective date. We recommend that you review it periodically.
↑ Back to contentsContact
For any query about this policy or about the processing of your data, you may write to us at:
See also our Terms and Conditions, which form part of the legal framework for the use of NutriNeo.
↑ Back to contents