1. Scope
This Privacy Notice describes how NAVU ("NAVU," "we," "us," or "our"), operated by Joseph Cruz, collects, uses, discloses, retains, and protects information when you use the NAVU mobile application, website, and related services (the "Service"). NAVU is operated from Connecticut, United States, and is in beta. The current beta is intended for adults in the United States. Worldwide availability remains a future ambition; this statement alone does not restrict app downloads or network access. The U.S. rights below apply where relevant; mandatory rights under other applicable local laws remain in effect.
2. Information we process
The proposed core app does not require an account or legal name. An optional display name is stored with local preferences and may accompany relevant AI requests. Names or other identifying details can also appear in messages, photos, saved recipes, support mail, or reports you choose to send. Technical identifiers and context may link information to a person. No required name does not mean anonymous use or no personal-data processing.
You may voluntarily report an AI response in the app. Before sending, you can edit the selected response excerpt (up to 4,000 characters), choose a category, and optionally add details (up to 1,000 characters). We receive only that submitted content, your report-consent version, a random case ID, and creation/expiry times. Reports do not automatically attach conversation history, allergy settings, or pantry photos. The excerpt or details may contain health information if you choose to include it.
2.1 Information you choose to provide
- Prompts, questions, instructions, relevant conversation context, and generated responses used to continue your request.
- An optional display name and kitchen or appliance settings you enter for personalization.
- Meal preferences, dietary preferences, allergy or ingredient exclusions, pantry details, serving needs, energy-mode selections, and similar everyday-planning information you choose to provide.
- Meals, lists, preferences, or other items you intentionally save through a private save feature, if enabled.
- Support messages, feedback, or other communications you send to us.
- Pantry photos you select or take for ingredient recognition, and ingredients inferred from those photos. Avoid including people, documents, or unrelated private details.
- Places or locations you type into a request. This draft does not describe automatic GPS collection as an enabled beta feature.
2.2 Information processed automatically
Depending on the platform and configuration, NAVU and its service providers may process limited technical information needed to operate and secure the Service, such as:
- IP address and general network information;
- device, operating system, app/browser version, language, and basic configuration information;
- temporary session credentials and app/device identifiers used for authentication, security, and abuse prevention; these may remain linkable even without a name;
- error, request-status, rate-limit, and performance information processed by NAVU and its cloud infrastructure;
- basic usage events needed to understand whether features work, such as feature invocation, latency, failures, and app stability.
2.3 Information NAVU does not require for core use
NAVU is designed so that core practical help does not require you to provide a legal name, telephone number, or linked bank/financial account. Optional future integrations may have separate disclosures before you connect them.
3. DataWheel shadow mode
NAVU has a curated recipe catalog shipped with the service. Curated means selected and structured for the product; it does not mean medically verified. Using that catalog, generating a response, keeping a private recipe, learning from user feedback, and training an AI model are different activities. The deployed backend disables shared user-feedback learning and reuse of generated recipes in the shared catalog. User-supplied context can still guide the answer you request. This is not training the underlying model.
DataWheel operates in shadow mode during the current beta. Generated meal candidates that enter its evaluation stage are checked against its meal-structure schema in memory; not every generated response goes through that stage. New user-derived candidates are not added to the shared DataWheel library, and the shared generated-meal cache is disabled. This check does not guarantee that a meal is accurate, safe, or suitable for you.
- DataWheel evaluates candidates temporarily in memory and discards them after evaluation. Candidate content is not retained in shared storage, shared caches, DataWheel logs, or DataWheel error reports.
- Private conversation history, identity, session details, and user-specific profile information are not promoted into the shared DataWheel.
- NAVU may retain non-content operational measurements, such as whether a validation passed or failed, failure category, latency, error code, or feature-flag state, so long as those measurements do not contain the underlying user content.
- Private items you intentionally save for yourself remain separate from the shared DataWheel. Shared meal-feedback updates and reuse of historical user feedback for personalization remain disabled in this release.
- Before NAVU enables permanent retention or promotion of eligible user-derived AI content into a shared knowledge library, we will update the applicable disclosures, complete the required implementation and privacy review, and obtain consent where required by applicable law.
These limits apply to DataWheel candidate retention. They do not describe ordinary service request handling, infrastructure logs, or historical records. They do not mean that NAVU saves no data: private device-local meals and history remain separate, and AI and cloud providers still process requests under their applicable terms.
4. How we use information
Joseph Cruz reviews submitted reports to investigate harmful, offensive, or inaccurate responses and improve safety controls. Reporting requires a separate, explicit choice and remains available after you withdraw AI permission. A report is not a new AI request and is not used for model training, DataWheel, or shared meal learning. This is not an emergency service.
- Provide, operate, personalize, and maintain the Service;
- Generate and display requested meal or everyday-planning content;
- Honor saved preferences or private saved items when you choose to use those features;
- Enforce exclusions, safety rules, permissions, and feature availability;
- Detect abuse, fraud, security threats, errors, and service failures;
- Measure performance and improve product reliability;
- Comply with law and protect the rights, safety, and security of users, NAVU, and others.
5. AI and cloud service providers
Provider settings are a separate question. NAVU has not yet verified that the credentials used by its running Gemini connection are linked to the required paid-service and data-sharing settings. We therefore do not promise that every provider excludes all beta content from model improvement. Provider verification is required before personal-data beta use. A request storage setting does not by itself establish zero retention or erase older records.
Submitted reports are stored in a restricted Firebase/Google Cloud collection for review by the operator. The report endpoint does not send report content to OpenAI or Gemini. Separate minimal security processing protects the endpoint from abuse.
NAVU sends the information needed for your request through Google Firebase and Google Cloud infrastructure to OpenAI API services and/or the Google Gemini Developer API. Depending on the request and availability, either AI provider may process text or a selected pantry photo, including fallback processing. Relevant conversation context, preferences, exclusions, and any sensitive details you include may travel with the request. Providers also process technical request information.
NAVU does not collect, use, or sell personal data to train large language models. NAVU does not use user content for model training, fine-tuning, distillation, teacher/student optimization, or training exports. Request generation and temporary meal-structure checks are separate from model training.
OpenAI describes API non-training defaults and retention controls. Google's Gemini API terms distinguish Paid Services from Unpaid Services. A provider's non-training commitment does not mean zero retention or immediate deletion. Service, abuse-monitoring, legal, and account-specific retention may apply. The reviewed release must use appropriate non-training provider settings; this draft does not claim that zero-data-retention controls or any special retention agreement have been approved for NAVU.
NAVU does not add Google Search-grounded results to DataWheel inventory. Email you send to the support address is processed by Google Gmail and your email provider. The informational website is hosted using GitHub Pages; website delivery involves hosting infrastructure and technical connection information.
6. When we disclose information
We may disclose information in the following limited circumstances:
- Service providers and processors that help operate NAVU, subject to appropriate contractual or platform terms;
- Legal and safety disclosures when reasonably necessary to comply with law, court process, or protect rights, safety, security, or the integrity of the Service;
- Business transactions involving a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable law and appropriate notice where required;
- At your direction or with your consent.
7. Sale, sharing, targeted advertising, and universal opt-out signals
NAVU does not currently sell personal data as "sale" is defined by applicable U.S. state privacy laws, and does not currently share personal data for cross-context behavioral advertising or use it for targeted advertising across unrelated services. If our practices change, we will update this Notice and provide any opt-out mechanisms required by law.
Where applicable law requires recognition of a valid universal opt-out preference signal, such as Global Privacy Control (GPC), NAVU will honor the signal for activities to which the legal opt-out right applies.
The informational website uses local interface JavaScript, with no advertising or analytics integration in the reviewed site. Hosting providers still process requests and connection information to deliver the site. A GPC signal does not itself delete your data or submit a privacy request. Contact us to request access, correction, deletion, or to appeal a denied request; identify an appeal as a privacy appeal.
8. Data retention
The proposed report record expires 30 days after submission. Database TTL deletion is asynchronous; expiry is not proof of immediate physical deletion. Deployment of TTL, access restrictions, and the operator review/deletion procedure must be verified before launch. Any legally required preservation must have a recorded reason and period.
The categories below distinguish private device storage, temporary processing, service records, and provider retention. Local deletion does not erase provider records automatically. No category is sold or shared for cross-context behavioral advertising.
| Category and purpose | Location | Period or criteria | Deletion and exceptions |
|---|---|---|---|
| Prompts, replies, and conversation context — answer requests and continue cooking | Device; NAVU request memory; AI/cloud providers | Device history persists until cleared or removed by local history limits. Request memory lasts for request handling. Provider retention depends on service and account controls. | Clear my NAVU data removes local history. Contact NAVU about identifiable server/provider records; an already transmitted request cannot be recalled. |
| Preferences, allergy/exclusion settings, pantry, and grocery lists — honor constraints and plan meals | Device; request memory and providers when relevant to a request | Local settings/lists remain until edited or cleared. Transmitted copies follow request/provider criteria above. | Edit preferences/lists or clear local data. Do not remove an allergy merely to bypass permission. Contact NAVU for external copies. |
| Private saved meals, favorites, and cooking history — reopen and use your meals | Device; providers if included in a later request | Until individual deletion, clearing local storage, or applicable local history limits | Delete recipes in My meals or use Clear my NAVU data. No automatic cross-device sync is described. |
| Selected pantry photos and recognized ingredients — ingredient recognition | Device/photo library; NAVU request memory; AI/cloud providers | Image request handling is temporary in NAVU. Provider copies follow applicable service controls. Your original photo remains subject to your device/photo-library settings. | Deleting a scan or clearing NAVU does not delete your original photo or automatically erase provider copies. |
| Technical identifiers, connection data, session/security records, minimal operational events — delivery and abuse prevention | Device; Firebase/Google Cloud; hosting and AI infrastructure | Session and rate-limit windows. The inspected Google Cloud project's default log bucket retains records for 30 days; its required audit-log bucket retains records for 400 days. These are infrastructure settings, not promises about all records or providers. Expired abuse records use asynchronous database deletion. | Clear local data for local identifiers; submit a request for linkable records. Security/legal exceptions must be assessed for the particular record. Additional exports, provider records, and device backups are not established by these log settings. |
| Permission choices and adult-access confirmation — apply your choices | Device; minimal versioned receipt on permitted requests | Current choice persists until withdrawal, reset, or replacement. No full birth date or identity document is required. | Use privacy controls or contact NAVU. Receipts must not contain conversations or allergy values. |
| Support messages and privacy requests — respond and document resolution | Operator's Gmail and restricted operational records | While resolving the request and meeting specific recordkeeping duties. A concrete post-resolution schedule remains to be approved before publication. | Email NAVU; limited evidence may be retained where required by law, with reason and applicable period explained. |
| DataWheel shadow candidates — temporary meal-structure checks | NAVU request memory | Discarded after evaluation; no permanent shared candidate retention in shadow mode | No new shared record to delete; this does not erase separately processed requests or historical records. |
| Historical records predating current controls — investigate prior processing and fulfill rights | Any existing NAVU/cloud records and backups | Inventory and retention decision pending; switching on shadow mode does not erase prior records. | Submit a request. NAVU must determine what exists, what can be linked, and any lawful exception; no blanket refusal based on device-local design. |
| Voluntary AI safety reports — investigate and improve safety | Restricted Firebase/Google Cloud collection; operator review | 30-day expiry from submission; asynchronous deletion and operational controls must be verified before launch | Use your case ID when requesting deletion. Local clearing does not delete submitted reports. |
Draft publication gate: unresolved log, backup, support, historical, and account-specific provider retention entries must be replaced with verified periods or specific criteria before this notice takes effect.
9. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information. No system can guarantee absolute security. NAVU is designed to minimize unnecessary collection and to separate private user context from shared reusable knowledge.
10. Your choices
Keep your case ID if you want to ask about or delete a report. Contact joseph.devteam@gmail.com; a case ID can help locate the record without resending sensitive content. Clearing local NAVU data or withdrawing AI permission does not delete a previously submitted report. NAVU must assess requests for identifiable external records.
- You can choose what information to include in your prompts. AI permission and any required sensitive-data permission are separate from accepting Terms. Declining or withdrawing permission stops future affected AI requests; local functions remain available where feasible.
- You can choose whether to save supported meals or preferences when optional save features are available.
- You can deny or revoke camera or photo access through the available device controls. The proposed beta does not request automatic location access.
- You may submit a privacy request using the contact method below.
- If NAVU later offers optional account or integration features, those features will include their own controls where appropriate.
11. U.S. state privacy rights
Depending on where you live, whether the relevant law applies to NAVU, and the nature of the information involved, you may have rights concerning your personal data. State privacy laws, including those in California and Connecticut, may provide additional protections. Other laws may also apply to particular data or activities.
Where required by applicable law, these rights may include:
- confirming whether we process your personal data and accessing it;
- correcting inaccurate personal data;
- deleting personal data, subject to legal exceptions;
- obtaining a portable copy of certain personal data;
- opting out of sale, targeted advertising, sharing, or certain profiling where those rights apply;
- withdrawing consent for certain sensitive-data processing where consent is the legal basis;
- appealing a denied privacy request where state law provides an appeal right;
- receiving equal service and not being unlawfully discriminated against for exercising privacy rights.
To submit a request, contact joseph.devteam@gmail.com. We may request information reasonably necessary to verify, locate, and process the request. You do not need a new account, legal name, telephone number, bank connection, or unnecessary identity documents to make a request. We may be unable to link a particular device-local record to you remotely, but will explain the issue, help with available local controls, and review any server or provider records that can reasonably be linked. Absence of a name does not make data anonymous. Where legally permitted, authorized agents may submit requests on your behalf subject to verification.
To appeal a denied request, email joseph.devteam@gmail.com with “privacy appeal” and enough information to identify the decision; that subject is helpful, not required. We will explain our decision and any extension within the applicable deadline. You may complain to the Connecticut Attorney General, Washington Attorney General, Nevada Attorney General, California Privacy Protection Agency, or your relevant regulator.
12. California Notice at Collection and California rights
For California residents, this section supplements the rest of this Notice. The categories, purposes, storage, retention criteria, and deletion methods in section 8 form part of this notice at collection. These notices must be available before the relevant collection in the app, not just on this website. Depending on your use of NAVU, we may collect categories of personal information such as identifiers/technical identifiers, internet or electronic activity information, user-provided content and preferences, photographs you submit, location information you type, sensitive content such as allergy information, and inferences or preference signals used to respond to your request.
We collect these categories for the business and operational purposes described above, including providing the Service, security, debugging, personalization you request, and legal compliance. We do not currently sell or share personal information for cross-context behavioral advertising. California residents may have rights to know/access, delete, correct, limit certain uses of sensitive personal information where applicable, opt out of sale/sharing, and receive non-discriminatory treatment.
13. Sensitive information
NAVU is for everyday planning and general wellness. It can help organize meals and practical steps around preferences, allergies, or a limit you supply, including an instruction from your healthcare professional. It must not derive a treatment target from a diagnosis, interpret medical records to decide care, diagnose, prescribe, or change medication. Nutrition figures are estimates. NAVU is not a medical device and does not diagnose, treat, cure, or prevent a medical condition. Consult a healthcare professional for medical advice, diagnosis, or treatment.
Allergy details, health-related exclusions, and free-text statements can reveal sensitive or consumer health information. Ordinary cuisine preferences, budget choices, and locations are not automatically health data; content, purpose, linkability, and applicable law matter. The separate Consumer Health Data Privacy Policy explains health-data processing and rights.
NAVU provides practical nonmedical help. Processing necessary to honor an allergy does not authorize optional reuse, shared-library publication, or training. Any required sensitive-data permission applies before the relevant collection or transmission, including free-text context and photos. If you decline, NAVU must not silently remove a restriction and recommend food as though it never existed.
14. Age and children
NAVU is intended only for users who are at least 18 years old. We do not knowingly offer the Service to children or knowingly collect personal information from individuals under 18 through the Service. If you believe a person under 18 has provided personal information to NAVU, contact joseph.devteam@gmail.com.
15. International users
The current adult beta is intended for the United States. NAVU's longer-term aim includes worldwide availability, subject to a separate review of local requirements and provider availability. Your information may be processed in the United States and other countries where providers operate. A notice alone does not enforce a territorial restriction or supply any required international-transfer safeguard. Mandatory rights under applicable local laws remain in effect. Contact us if you access NAVU from outside the intended beta territory.
16. Changes to this Notice
We may update this Notice as NAVU changes or as legal requirements change. We will post the updated version with a new effective date and provide additional notice when required by law. A material change to DataWheel from shadow mode to permanent shared-library promotion will be treated as a change requiring updated disclosures before activation.
17. Contact us
Privacy questions and requests: joseph.devteam@gmail.com
Support: joseph.devteam@gmail.com
Website: navu.life
Emergency help
NAVU is not an emergency service. In the U.S., call or text 988 for the Suicide & Crisis Lifeline, or call 911 for immediate danger. Outside the U.S., contact your local emergency service or crisis line.