Privacy policy
Last updated July 26, 2026
NIA does not collect information about individual children.
There is no child record in the system. Enrollment is recorded as a monthly count per age group — a number, with no name, date of birth, guardian or address attached. Allergens are recorded against recipes and food items for menu planning, never against a child. The personal information we do hold belongs to adults: your staff, people who ask us for a quote, and people who write to support.
1.Who this applies to
This policy covers Mobile App Development Group(“we”, “us”), which operates NIA at nutritionalassistant.com — both the public marketing site and the application your center signs in to.
Two relationships are covered, and they are different. If you are a child-care organization using NIA, you are our customer, and the operating data you enter is yours. If you are a member of a customer’s staff, your account exists because your organization created it, and your organization — not us — decides who at your center may see what. Requests about a staff account are best made to your own manager first.
2.What we collect
| Information | Where it comes from | Why |
|---|---|---|
| Organization name, contact name, email, phone, number of centers, and anything you write in the message box | The request-a-quote form | To answer your enquiry and to price a quote |
| Staff name, email address and role | Created by your organization’s manager when inviting staff | To give each person an account and the right level of access |
| Your name, email address and the text of your message | The in-app support form | To answer the support request |
| Operating data: inventory counts, suppliers, catalog and prices paid, recipes, menus and scheduled meals, meal service records, monthly enrollment counts per age group, uploaded photos and documents | Entered by your staff as they use the product | It is the product |
| Billing contact and payment history | Stripe, when your organization pays an invoice | To bill the subscription and show you what has been charged |
| Error records: the failing page, the error message and stack trace, and a reference to the organization and user account involved | Automatically, when something in the app breaks | So we can find and fix faults without asking you to reproduce them |
Error records deliberately do not include IP addresses or browser fingerprints. Our web host and email provider keep their own operational logs, which do include IP addresses, under their own retention schedules.
We do not buy personal information about you from data brokers, and we do not enrich what you give us with third-party profiles.
4.What we do not do with it
We do not sell personal information, and we do not share it for advertising or cross-context behavioural advertising. We do not use your operating data — your recipes, prices, suppliers or counts — to train machine-learning models, and we do not share it with other customers. Negotiated pricing and supplier terms are commercially sensitive, and tenant isolation is enforced in the database layer rather than left to careful querying.
5.Who else processes it
We run NIA on a small number of established providers. Each one only receives what it needs to do its job.
| Provider | What it does | What it sees |
|---|---|---|
| Supabase | Database, file storage and sign-in | All application data, and staff email addresses and passwords (passwords are hashed by Supabase; we never see or store them) |
| Amazon Web Services | Hosting, outbound email, DNS and uptime checks | Application traffic, and the contents of emails we send you (invitations, password resets, notifications) |
| Stripe | Subscription billing | Billing contact and payment details. Card numbers are entered on Stripe’s own pages and never reach NIA |
Data is stored in the United States. We may also disclose information if we are legally required to, or where it is necessary to investigate abuse or protect the service.
6.When we look at your data
Support sometimes needs us to see what you are seeing. When that happens we use an impersonation tool that is read-only — it cannot create, change or delete anything in your account — and every session is recorded to an audit log with who opened it, which organization it entered, and when.
Beyond that, access is limited to what running the service requires: fixing faults, restoring backups, and answering the requests you send us.
7.How it is protected
Traffic is encrypted in transit. Each organization’s records are scoped to that organization at the database layer, so a query that forgets to filter by customer fails rather than returning someone else’s rows. Uploaded documents are stored in private storage and served through short-lived signed links; uploaded photos are stored in public storage, so treat a photo as shareable. Access to production systems is limited to the people who operate the service.
No system is perfectly secure. If a breach affects your information we will tell you without undue delay and describe what happened.
8.How long we keep it
Your operating data is kept for as long as your organization has an active subscription, and for 30 days after it ends so that a cancellation can be reversed and an export can be produced. After that it is deleted. Quote enquiries and support messages are kept while they are commercially relevant. Billing records are kept as long as tax and accounting rules require. Error records are kept until they are resolved and then cleared out periodically.
9.Your choices
You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Write to admin@mobileappdevelopmentgroup.com and we will respond within 30 days. If you asked for a quote and would rather we did not keep your details, say so and we will remove the enquiry.
Depending on where you live you may have additional rights — for example under the California Consumer Privacy Act or the Texas Data Privacy and Security Act. We apply the rights described above to everyone rather than checking your address first. We do not sell personal information, so there is nothing to opt out of.
10.Children
NIA is a tool for the adults who run a kitchen. It is not directed to children, it is not used by children, and — as above — it holds no records about individual children. If you believe a member of your staff has entered a child’s personal details into a free text field where they do not belong, tell us and we will help remove them.
11.Changes
If we change this policy we will update the date at the top, and for changes that materially affect customers we will email the account contact. Continuing to use NIA after a change means the updated policy applies.
12.Contact
Questions about this policy, or about the information we hold, go to admin@mobileappdevelopmentgroup.com. Our terms of service cover the commercial side of the relationship.