Privacy policy

Last updated July 26, 2026

NIA does not collect information about individual children.

There is no child record in the system. Enrollment is recorded as a monthly count per age group — a number, with no name, date of birth, guardian or address attached. Allergens are recorded against recipes and food items for menu planning, never against a child. The personal information we do hold belongs to adults: your staff, people who ask us for a quote, and people who write to support.

1.Who this applies to

This policy covers Mobile App Development Group(“we”, “us”), which operates NIA at nutritionalassistant.com — both the public marketing site and the application your center signs in to.

Two relationships are covered, and they are different. If you are a child-care organization using NIA, you are our customer, and the operating data you enter is yours. If you are a member of a customer’s staff, your account exists because your organization created it, and your organization — not us — decides who at your center may see what. Requests about a staff account are best made to your own manager first.

2.What we collect

Categories of information NIA collects
InformationWhere it comes fromWhy
Organization name, contact name, email, phone, number of centers, and anything you write in the message boxThe request-a-quote formTo answer your enquiry and to price a quote
Staff name, email address and roleCreated by your organization’s manager when inviting staffTo give each person an account and the right level of access
Your name, email address and the text of your messageThe in-app support formTo answer the support request
Operating data: inventory counts, suppliers, catalog and prices paid, recipes, menus and scheduled meals, meal service records, monthly enrollment counts per age group, uploaded photos and documentsEntered by your staff as they use the productIt is the product
Billing contact and payment historyStripe, when your organization pays an invoiceTo bill the subscription and show you what has been charged
Error records: the failing page, the error message and stack trace, and a reference to the organization and user account involvedAutomatically, when something in the app breaksSo we can find and fix faults without asking you to reproduce them

Error records deliberately do not include IP addresses or browser fingerprints. Our web host and email provider keep their own operational logs, which do include IP addresses, under their own retention schedules.

We do not buy personal information about you from data brokers, and we do not enrich what you give us with third-party profiles.

3.Cookies

NIA sets two cookies, both of them functional. There are no advertising cookies, no analytics or product-telemetry trackers, and no third-party tags of any kind on this site or in the app.

Cookies set by NIA
CookiePurposeLifetime
SessionKeeps you signed in. Set when you sign in, scoped to nutritionalassistant.com so one session covers your center’s subdomain.Until you sign out or it expires
Demo notice dismissalRemembers that you closed the banner on the public demo, so it does not reappear on every page.Until cleared

4.What we do not do with it

We do not sell personal information, and we do not share it for advertising or cross-context behavioural advertising. We do not use your operating data — your recipes, prices, suppliers or counts — to train machine-learning models, and we do not share it with other customers. Negotiated pricing and supplier terms are commercially sensitive, and tenant isolation is enforced in the database layer rather than left to careful querying.

5.Who else processes it

We run NIA on a small number of established providers. Each one only receives what it needs to do its job.

Service providers
ProviderWhat it doesWhat it sees
SupabaseDatabase, file storage and sign-inAll application data, and staff email addresses and passwords (passwords are hashed by Supabase; we never see or store them)
Amazon Web ServicesHosting, outbound email, DNS and uptime checksApplication traffic, and the contents of emails we send you (invitations, password resets, notifications)
StripeSubscription billingBilling contact and payment details. Card numbers are entered on Stripe’s own pages and never reach NIA

Data is stored in the United States. We may also disclose information if we are legally required to, or where it is necessary to investigate abuse or protect the service.

6.When we look at your data

Support sometimes needs us to see what you are seeing. When that happens we use an impersonation tool that is read-only — it cannot create, change or delete anything in your account — and every session is recorded to an audit log with who opened it, which organization it entered, and when.

Beyond that, access is limited to what running the service requires: fixing faults, restoring backups, and answering the requests you send us.

7.How it is protected

Traffic is encrypted in transit. Each organization’s records are scoped to that organization at the database layer, so a query that forgets to filter by customer fails rather than returning someone else’s rows. Uploaded documents are stored in private storage and served through short-lived signed links; uploaded photos are stored in public storage, so treat a photo as shareable. Access to production systems is limited to the people who operate the service.

No system is perfectly secure. If a breach affects your information we will tell you without undue delay and describe what happened.

8.How long we keep it

Your operating data is kept for as long as your organization has an active subscription, and for 30 days after it ends so that a cancellation can be reversed and an export can be produced. After that it is deleted. Quote enquiries and support messages are kept while they are commercially relevant. Billing records are kept as long as tax and accounting rules require. Error records are kept until they are resolved and then cleared out periodically.

9.Your choices

You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Write to admin@mobileappdevelopmentgroup.com and we will respond within 30 days. If you asked for a quote and would rather we did not keep your details, say so and we will remove the enquiry.

Depending on where you live you may have additional rights — for example under the California Consumer Privacy Act or the Texas Data Privacy and Security Act. We apply the rights described above to everyone rather than checking your address first. We do not sell personal information, so there is nothing to opt out of.

10.Children

NIA is a tool for the adults who run a kitchen. It is not directed to children, it is not used by children, and — as above — it holds no records about individual children. If you believe a member of your staff has entered a child’s personal details into a free text field where they do not belong, tell us and we will help remove them.

11.Changes

If we change this policy we will update the date at the top, and for changes that materially affect customers we will email the account contact. Continuing to use NIA after a change means the updated policy applies.

12.Contact

Questions about this policy, or about the information we hold, go to admin@mobileappdevelopmentgroup.com. Our terms of service cover the commercial side of the relationship.