Privacy Policy
Cal Factor (“we”, “us”) builds an AI-powered nutrition tracking app. This policy explains what data we collect, why we collect it, who we share it with, and the controls you have. We try to keep it short and plain.
What we collect
Account information
- Email address (always)
- Display name (optional)
- Authentication provider tokens (e.g. Google, Apple), if you sign in with them
Profile and health-related information you provide
- Age, gender, height, weight, activity level
- Daily calorie goal and dietary preferences
- Avatar photo, if you upload one
Content you create
- Meal photos and the AI’s analysis of them (ingredients, calories, macros)
- Manual meal logs, recipes, hydration logs, and notes
- Optional thumbs-up / thumbs-down feedback on AI outputs
Diagnostic information
- Crash logs and basic error telemetry, used only to fix bugs
- We do not use third-party advertising trackers or analytics SDKs
How we use it
- To run Cal Factor — e.g. generating a nutrition breakdown from your photo, computing your daily summary, scheduling reminders you’ve enabled.
- To send your meal photo to our AI vision model (currently OpenAI’s GPT-4.1, served through Microsoft Azure’s enterprise API) for ingredient identification.
- To enforce per-account rate limits on AI features.
- To respond to support requests you send us.
- To improve Cal Factor — aggregated, de-identified usage patterns only.
We do not use your data to train AI models. We do not sell your data. We do not share it with advertisers.
Who we share it with
We only share the minimum data necessary with the service providers that make Cal Factor work:
- Supabase — our backend host (database, file storage, authentication, serverless functions).
- Microsoft Azure / OpenAI — processes your meal photo to identify ingredients. Per Microsoft’s terms, photos are not retained for model training.
- Apple / Google — if you sign in with their account, they handle authentication. They receive only the information needed to verify your identity.
We may also disclose information when required by law, to protect our rights, or in connection with a corporate transaction (e.g. acquisition), in which case we’ll notify you in advance where the law allows.
How long we keep it
- Active accounts: We keep your data for as long as your account is active.
- Deleted accounts: When you delete your account from the app, we permanently delete your meals, photos, recipes, hydration logs, and authentication record within 30 days. Backups are purged within 90 days.
- Logs: Operational logs (crash reports, rate-limit counters) are kept for up to 90 days then discarded.
Your rights and choices
- Access & export: You can request a copy of your data by emailing support@calfactor.app.
- Edit: Most personal data (display name, profile, goals) is editable directly in Settings.
- Delete: Settings › Delete Account permanently removes your data. There is no undo.
- Notifications: Settings › Notifications turns reminders and goal alerts on or off. Your device’s system Settings can also revoke permission entirely.
- Region-specific rights (GDPR, UK GDPR, CCPA): You may have the right to object to processing, request restriction, or lodge a complaint with your local data-protection authority. Email us and we’ll help.
Security
Data is encrypted in transit (TLS) and at rest. Database access is restricted by row-level security policies so users can only read and write their own rows. AI credentials are never bundled with the app — they live only in our serverless functions. We do our best, but no system is perfectly secure; if we ever suffer a breach affecting your data, we’ll notify you as required by law.
Children
Cal Factor is not directed at children under 13 (under 16 in the EU/UK). We do not knowingly collect data from them. If you believe we have, contact us and we’ll delete it.
International transfers
Cal Factor is operated from outside the EU. By using the app you understand that your data may be transferred to and processed in countries with different data-protection laws. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses with our subprocessors.
Changes to this policy
We may update this policy. When we do, we’ll change the “Last updated” date above and, for material changes, give in-app notice. Continued use of Cal Factor after a change means you accept the updated policy.
Contact
Privacy questions: support@calfactor.app.