Privacy Policy
Last updated: 25 March 2026
CalorieX ("we", "our", "us") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights.
1. Information We Collect
We collect the following categories of information:
- Account data: Email address used to create your account.
- Nutrition targets: Your calculated daily calorie goal and macro targets (protein, carbs, fat). Your age, weight, height, sex, and activity level are entered locally on your device to generate these targets; they are never transmitted to or stored on our servers. However, the computed nutrition targets derived from these inputs are stored securely on our servers to power the app's tracking features.
- Food & meal logs: Meals, foods, and nutrition entries you log within the app.
- Goal history: Snapshots of your nutrition targets over time, so historical meal logs are compared against the correct goals.
- Photos: Images you optionally submit for AI food recognition (Pro feature). Photos are processed and not stored beyond the immediate request.
- Usage data: Anonymous usage statistics via a third-party analytics service.
- Subscription data: Purchase and subscription status managed by a third-party subscription provider (we do not store payment card details).
2. How We Use Your Information
- To provide and personalise the app's calorie tracking and AI features.
- To calculate your daily nutrition goals and display progress.
- To send meal reminder notifications (only if you enable them).
- To manage your subscription and entitlements.
- To understand aggregate app usage and improve the service (anonymous analytics).
3. Legal Basis for Processing
Under the UK General Data Protection Regulation (UK GDPR), we process your data on the following lawful bases:
- Contractual necessity: Account data, meal logs, nutrition targets, and subscription data are processed to provide the service you signed up for.
- Legitimate interest: Anonymous analytics to understand usage patterns and improve the app.
- Consent: Ad personalisation (you can opt out via your device's tracking settings), optional photo analysis for food recognition, and meal reminder notifications.
4. Data Storage & International Transfers
Your data is stored securely in a cloud database hosted in the EU (Google Cloud), encrypted at rest and in transit. Biometric data (age, weight, height, sex, activity level) is stored only on your device and is never uploaded to our servers.
When you use AI-powered features (meal estimation, photo analysis, chat), your data is processed by Google's Gemini AI service, which may involve transfer to Google servers outside the EU/UK. Google operates under Standard Contractual Clauses (SCCs) and appropriate safeguards for international data transfers in accordance with UK GDPR requirements.
5. Third-Party Services
CalorieX uses the following third-party services, each governed by their own privacy policies:
- Google: We use Google's cloud infrastructure for account authentication, secure data storage, anonymous analytics, and AI-powered features. Messages you send to the AI assistant and photos submitted for analysis are processed by Google to generate responses; we do not store your chat messages.
- Google AdMob: We display ads to free-tier users via Google AdMob. On iOS, we request your permission via Apple's App Tracking Transparency (ATT) framework before any ad-related tracking occurs. If you grant permission, Google may collect device identifiers for ad personalisation. You can change this at any time in your device settings. No ad data is stored by CalorieX.
- RevenueCat: In-app purchase tracking and subscription management. We do not store payment card details.
- Open food database: Barcode scanning uses an open-source community food database. No personal data is shared.
6. AI-Generated Content & Accuracy
CalorieX uses AI models to estimate calorie and nutritional content from text descriptions and food photos. These estimates are generated by third-party AI services and are not verified for accuracy. Barcode nutritional data is sourced from a community-driven database (Open Food Facts) and may be incomplete or outdated. We do not guarantee the correctness of any nutritional data displayed in the App.
7. We Do Not Sell Your Data
We do not sell, rent, or share your personal information with third parties for marketing purposes.
8. Data Retention
Your data is retained for as long as your account is active. You can delete your account and all associated data directly within the app (Profile → Settings → Delete Account). Deletion is permanent and removes all your data from our servers, including meal logs and nutrition targets. Biometric data (age, weight, height, etc.) is stored only on your device and is removed when you uninstall the app or delete your account. Anonymised transaction records may be retained by payment processors for legal and financial compliance.
9. Children's Privacy
CalorieX is not directed at children under 13. We do not knowingly collect personal data from children under 13. Additionally, the app requires all users to confirm they are at least 18 years old before creating an account, as calorie tracking features are intended for adults.
10. Your Rights
Under UK GDPR, you have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of inaccurate personal data.
- Erasure: Request deletion of your personal data. The primary way to do this is to delete your account directly within the app (Profile → Settings → Delete Account).
- Restriction: Request that we limit how we process your data in certain circumstances.
- Data portability: Request your data in a portable format.
- Objection: Object to processing based on legitimate interest.
- Withdraw consent: Where processing is based on consent (e.g. ad personalisation), you can withdraw it at any time via your device settings or by contacting us. Withdrawal does not affect the lawfulness of prior processing.
To exercise any of these rights, contact us at rojanthomas@gmail.com. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's supervisory authority for data protection.
11. Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes through the app or by email.
12. Contact Us
For any privacy-related questions, please contact:
rojanthomas@gmail.com