CaloriePilot iconCaloriePilot
FoodsFeaturesEarly AccessGet Early Access ↗

Policy

Privacy Policy

Last updated: August 14, 2026 · Version 2026-08-14

CaloriePilot provides nutrition tracking, body data tracking, image recognition, and AI-assisted features through its website and mobile application. This Privacy Policy explains what information we process, why we process it, how we share it, and the choices available to you.

This policy is currently provided in English. It applies to CaloriePilot accounts, application features, support interactions, and the public website features that link to it. It does not replace a separate notice that may be shown for a specific feature or permission.

Information we process

Depending on how you use CaloriePilot, we may process the following categories:

  • Account and authentication information: email address, username, internal account identifiers, authentication provider, social-provider identifier, email-verification status, session information, and security events. We store a password in protected form when you create a password account; we do not receive or store your Google or Apple password.
  • Nutrition and body information: meal records, food selections, quantities, nutrition values, body measurements, health goals, favorites, custom foods, and related dates or notes that you choose to provide.
  • User content: photos, text, feedback, AI prompts, conversations, drafts, and AI-generated results that are needed to provide a feature you request. Some of this information may reveal health or dietary information.
  • Subscription information: subscription entitlement, product, transaction reference, store, and status information. Apple and Google process the payment transaction. CaloriePilot does not store full payment-card details.
  • Device, application, and security information: platform, application version, device or installation identifiers where supplied by the platform, IP address, user-agent, request path and status, authentication and abuse signals, and error or crash diagnostics. We use these details to operate, secure, troubleshoot, and improve reliability.
  • On-device information:the application may keep a local cache and queued offline operations so screens can load quickly and actions can be retried. This can include cached meal, body, assistant, and account-related data. It remains on the device until the application clears or overwrites it, you log out or delete the account, or the application is removed. A cache can become stale before its stored copy is physically removed; cleanup is best effort and you should also use the device's normal security controls.
  • Early Access information: if you join an Early Access program, we may process your email, platform preference, primary goal, beta-testing interest, consent time, and limited campaign information such as UTM fields, landing path, and referring page without its query string.

How we receive information

We receive information directly from you, from the device and application you use, from Google or Apple when you choose social sign-in, from Apple or Google and our subscription service for purchase status, and from service providers that process data on our instructions. We may also receive information when you contact support or join Early Access.

How we use information

We use information for the following purposes:

  • create and secure your account, authenticate you, and maintain sessions;
  • provide meal logging, food search, body tracking, image recognition, AI-assisted parsing, summaries, personalized tools, and requested support;
  • calculate or display nutrition and body-management information based on the data you provide;
  • deliver, validate, restore, and protect subscription access;
  • send transactional emails such as verification and password-reset messages;
  • respond to feedback and privacy or support requests;
  • monitor performance, investigate errors, prevent abuse, and protect the service;
  • meet legal, accounting, audit, and dispute-resolution requirements; and
  • administer Early Access invitations, product updates, and beta feedback when you choose to participate.

Legal bases and sensitive information

Depending on your location and the processing involved, we may rely on performance of a contract with you, your consent, our legitimate interests in operating and securing the service, and legal obligations. For optional permissions or communications, you can usually withdraw consent through the relevant setting or by contacting us. Where applicable law treats nutrition, body, or other information as sensitive or health information, we use the additional legal condition required in that location, which may include explicit consent where required.

AI, image recognition, and other processors

When you request image recognition or an AI-assisted feature, we send the minimum content and context needed for that request to the relevant processing service. The current service architecture may use cloud hosting and storage, DeepSeek for text or AI processing, Paddle OCR as the primary OCR service, Baidu OCR as a fallback, Resend for transactional email, RevenueCat for subscription status, Apple or Google for authentication or store services, Sentry for error diagnostics, and Slack for a limited internal registration alert. Optional Redis infrastructure may be used for internal event delivery.

These providers process information to provide their services to CaloriePilot or as otherwise described in their own privacy terms. We do not send payment-card details to our AI or OCR providers. AI and OCR results can be wrong, and you should review them before relying on them.

When we share information

We share information only as needed for the purposes described in this policy. This can include sharing with infrastructure, hosting, storage, AI, OCR, email, subscription, authentication, diagnostics, and security providers acting for us; with professional advisers or a successor in a merger, acquisition, financing, or asset transfer; and when required to comply with law, protect rights and safety, investigate fraud or abuse, or enforce our agreements.

When a new account is created, a limited internal alert may contain the internal user identifier, username, email address, authentication method, and email-verification status. It is sent to a controlled internal operations channel for account and abuse monitoring, not for advertising.

We do not sell personal information and do not use it for interest-based or cross- context behavioral advertising. If this changes, we will update this policy and provide any notice or choice required by law before using information for that purpose.

International processing

CaloriePilot and its providers may process information in countries other than the country where you live. Where a transfer is regulated, we use a lawful transfer mechanism and appropriate contractual, technical, or organizational safeguards as required by applicable law. The available mechanism can depend on the provider, the data involved, and your location. You may contact us for more information about the safeguards applicable to your request.

Retention and account deletion

We keep information for as long as needed to provide the service, maintain account security, satisfy legal or accounting requirements, resolve disputes, enforce our agreements, and protect against abuse. Retention differs by data type and is reduced when information is no longer needed.

You can start account deletion in Settings after reauthentication. We immediately invalidate active sessions and remove account access. Meal logs, body data, custom foods, favorites, and user-visible AI conversations are then made unavailable and associated profile, AI/OCR, and image references are redacted or de-identified where practical. Image objects may not be physically deleted at the exact moment the request is submitted; they are handled through a controlled cleanup process. Restricted subscription, purchase, security, fraud-prevention, and deletion-audit records may be retained where necessary and are not transferred to a newly registered account.

Export files are temporary server-side files. They expire after 72 hours and are subject to controlled cleanup designed to remove them within seven days. Deleting a CaloriePilot account does not cancel an Apple App Store or Google Play subscription; you must cancel it through the applicable store.

Your choices and privacy rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent or complain to a regulator. In the application, Settings → Privacy & Data provides requests for export, access, correction, and specific deletion. You can also contact us directly. We may need to verify your identity and may apply lawful exceptions.

Export files include account profile, goals, meal and body records, custom foods, favorites, user-visible AI conversations, subscription status, and feedback. They do not include passwords, tokens, internal logs, administrator information, another person's data, payment-provider raw payloads, or raw AI/OCR provider responses. We aim to respond to rights requests within the period required by applicable law and generally within 30 days where no shorter period applies.

Additional regional rights

If you are in the European Economic Area, the United Kingdom, or Switzerland, you may also have the right to object to processing based on legitimate interests, request restriction, withdraw consent, and complain to your local data-protection authority. You can ask us for more information about the transfer safeguards relevant to your data.

If you are a California resident, applicable law may give you rights to know or access, correct, delete, and obtain information about the categories of personal information we collect, and to opt out of sale or sharing for cross-context behavioral advertising. We do not sell or share personal information for that advertising. Where applicable, you may also request limits on the use of sensitive personal information and use an authorized agent. We will not discriminate against you for exercising a legal right; we may verify requests and apply lawful exceptions.

Children

CaloriePilot is not directed to children. Do not use the service unless you are legally able to agree to its terms in your location. If local law requires a parent or guardian to authorize use, that authorization must be obtained before using the service.

Security

We use reasonable technical, administrative, and organizational measures designed to protect information against unauthorized access, loss, misuse, or alteration. No internet service or device storage can be guaranteed to be completely secure. Protect your device, credentials, and email account, and contact us promptly if you believe your account has been compromised.

Cookies and advertising

The public website may use cookies or similar technologies that are necessary for site operation, security, preferences, or features you request. We do not use personal information for interest-based advertising. If we introduce optional analytics, advertising, or similar technologies that require additional notice or consent, we will update the applicable notice before using them.

Changes to this policy

We may update this policy when the service, providers, law, or our practices change. We will post the new version and update the date and version number. If a change is material, we will provide additional notice or request a new acceptance where required by law. The current version is always available at this page and from the application legal screen.

Contact

For privacy, legal, or support questions, contact . Please include enough information for us to identify your request, but do not send a password, verification code, or payment-card number.

CaloriePilot

Nutrition tracking and AI-assisted parsing.

PrivacyTermsEarly Access