Legal

Privacy Policy

How Calometer collects, uses, stores, and protects your meal, health, account, and subscription data.

Last updated: July 2, 2026

1. Scope

This Privacy Policy explains how Calometer collects, uses, stores, discloses, and protects information when you use the iOS app, website, API, account system, AI meal analysis, subscriptions, notifications, and integrations.

We use the current app contact email for privacy requests: support@calometer.app.

2. Information we collect

  • Account data: email address, name, profile image if provided by Apple or Google, sign-in provider identifiers, account timestamps, and verification/session records.
  • Authentication and security data: session tokens, IP address, user agent, device identifiers, device signing keys, request signatures, timestamps, and abuse-prevention signals.
  • Meal and nutrition data: meal photos or base64 image uploads, optional notes, AI estimates, confirmed entries, food names, portions, calories, protein, carbs, fat, confidence, custom foods, barcode lookups, and food-search queries.
  • Profile and goal data: unit system, sex, age, height, weight, activity level, goal, calorie and macro goals, water goal, onboarding state, weigh-ins, and water logs.
  • Subscription data: RevenueCat customer identifiers, entitlement status, purchase state, App Store subscription metadata, and related server checks. We do not receive full payment-card details.
  • Notification data: Expo push token, platform, timezone, notification settings, and reminder logs.
  • Device and app data: app version, platform, locale/timezone, crash or diagnostic context if you send it to us through support, and website/server logs.

3. Photos and AI processing

When you ask Calometer to analyze a meal, the image and optional note are sent to our server and then to our AI provider through OpenRouter to generate a nutrition estimate. We cache a hash and the resulting estimate so repeated analysis of the same photo and note can return faster and reduce provider calls.

If you save an entry with a photo and object storage is enabled, the photo may be uploaded to S3-compatible storage such as Cloudflare R2 and linked from your entry. Account deletion removes stored photo links from entries; provider backups and caches may take additional time to expire.

4. Apple Health

Calometer can read active-energy-burned samples from Apple Health after you grant permission. This is used to show burned calories in the app. In the current app, Apple Health active-energy samples are queried on your device and are not written back to Apple Health by Calometer.

You can change Apple Health permissions at any time in iOS Settings. Apple Health data is subject to Apple’s own privacy controls.

5. How we use information

  • Provide the app, authenticate you, keep sessions secure, register trusted devices, and route signed API requests.
  • Analyze meal photos, save entries, build your diary, calculate totals, show trends, and sync your data.
  • Process subscriptions, check Pro entitlement status, present paywalls, and help you manage billing through Apple.
  • Send reminders and push notifications when enabled, including adapting to your current timezone.
  • Debug, secure, monitor, rate-limit, prevent abuse, respond to support requests, and comply with law.
  • Improve reliability and quality of the service, including reducing duplicate AI requests through caching.

6. Legal bases

Where privacy laws require a legal basis, we process information to perform our contract with you, with your consent for optional permissions such as notifications and Apple Health, for legitimate interests such as security and service improvement, and to comply with legal obligations.

7. Providers we use

  • Apple and Google for supported sign-in flows and platform account services.
  • OpenRouter and underlying model providers for AI meal-photo analysis.
  • S3-compatible object storage, including Cloudflare R2 in production where configured, for saved entry photos.
  • RevenueCat and Apple App Store for subscription entitlement, billing, purchase management, and refunds.
  • Expo Push Service and Apple Push Notification service for push notifications.
  • Open Food Facts for public food-search and barcode fallback data.
  • Hosting, database, logging, and infrastructure providers needed to operate the app and website.

8. When we disclose information

We do not sell your personal information. We disclose information only to service providers that help operate Calometer, when you direct an integration, when needed for security or legal compliance, in connection with a business transfer, or with your consent.

AI and infrastructure providers may process data in countries other than yours. We use commercially reasonable safeguards for cross-border processing where required.

9. Retention

We keep account, meal, profile, weight, water, device, notification, and subscription records for as long as needed to provide the service, secure the platform, comply with law, resolve disputes, and maintain business records.

When you delete your account, we remove sign-in records, sessions, linked auth accounts, device keys, push tokens, notification settings, and provider customer data where supported. Remaining logs may be anonymized so they can no longer reasonably identify you. Backups, provider logs, and legal records may persist for limited periods.

10. Security

We use HTTPS, authenticated sessions, server-side validation, per-device request signing, secure device storage for local credentials, provider access controls, and limited-access infrastructure. No system is perfectly secure, and you should protect your device, Apple/Google account, and email.

11. Your choices and rights

  • Access, correct, export, or delete information by using app features or contacting support@calometer.app.
  • Revoke Apple Health, camera, and notification permissions in iOS Settings.
  • Cancel subscriptions through Apple ID subscription settings. Account deletion does not cancel App Store billing.
  • Opt out of push notifications in the app or device settings.
  • Object to or restrict processing where applicable law gives you that right.

12. Children

The service is not intended for children under 18. We do not knowingly collect personal information from children. If you believe a child used the service, contact support@calometer.app and we will take appropriate action.

13. Changes and contact

We may update this Privacy Policy by posting a new version and changing the “Last updated” date. Material changes will be communicated when practical.

Privacy questions and requests: support@calometer.app. See also our Terms of Service.