Data and privacy

Privacy Policy

Last updated: July 23, 2026

Data we process

  • Account: email address, optional name, sign-in provider, and verification data.
  • Profile and health-related data: birth date, gender, height, weight, activity level, goal, and calculated calorie and macro targets.
  • App content: food logs, weight history, meal plans, feedback, and AI responses you choose to report.
  • Technical and subscription data: platform, AI usage counts, Premium status, a one-way digest of a random installation identifier used to prevent allowance abuse through account cycling, and an encrypted refresh token used to revoke Sign in with Apple authorization when an account is deleted.
  • AI inputs: with your explicit permission, a selected meal photo or chat message and relevant profile/nutrition context needed to produce a response.
  • Support correspondence: email, contact details, and attachments you voluntarily send to our support address.

Purposes

We process data to provide your account and app functions, calculate goals, scan meals and generate advice, validate subscription rights, maintain security, and troubleshoot. Meal reminders are created locally on your device; CalorieSignal does not collect a remote push token for this purpose.

Service providers

  • Anthropic API: processes AI inputs you explicitly permit to produce scans and advice.
  • RevenueCat, Apple, and Google: process or validate purchases and subscription status.
  • Apple and Google sign-in services: verify your identity when you choose a social sign-in method.
  • Resend: delivers verification and password-reset email.
  • Google Gmail: hosts messages sent to our support address so we can respond to and track requests.
  • Render: hosts the API and database infrastructure.

We do not sell your data. We share only what is needed to provide these services.

Photos, AI, and retention

Scan photos and AI chat history are not saved in the CalorieSignal database; they are processed in memory during the request and transferred to the Anthropic API to produce a response. Under Anthropic's standard commercial API terms, inputs and outputs are normally deleted within 30 days; exceptions may apply for usage-policy enforcement, legal obligations, or a different retention agreement. Anthropic states that commercial API inputs and outputs are not used for model training by default.

Account and app records are kept while your account is active or for a legally or operationally required period. AI output you specifically report to CalorieSignal may be retained with your account for safety and quality review. Account-independent installation usage counters are one-way hashed and retained for no more than 14 days for abuse prevention.

When an account is deleted, deletion of the RevenueCat customer record and revocation of Sign in with Apple authorization are started automatically. If a provider is temporarily unavailable, only the provider identifier or encrypted token required to finish cleanup is kept in a temporary retry record; that record is also deleted after successful completion.

Support email content is not stored in the CalorieSignal database. Messages and attachments are subject to the support retention policy of the Gmail account to which they are sent directly.

Deletion and your rights

You can delete your account and related CalorieSignal data from Settings → Delete Account. If you cannot access the account, use the method on our account deletion page. Store subscriptions must be cancelled separately in the App Store or Google Play. Email the CalorieSignal Support Team for access, correction, deletion, or consent withdrawal requests.

Children and security

CalorieSignal is not directed to children under 13. We use access controls, encryption, and reasonable technical measures, but no internet system can guarantee absolute security.