Privacy Policy

Last updated: 4 September 2026

1. Who we are

Caly AI is operated by [operator legal name], [address], Sweden ("we", "us"). We are the data controller for the personal data described in this policy. You can reach us at support@kcalai.net.

This policy covers the Caly AI web app and the Caly AI iOS app. It applies together with our Terms of Service.

2. What we collect

Data you give us:

  • Account: email address, name, optional username and avatar.
  • Body & goals: date of birth, sex, height, weight and weight history, goal weight, activity level, pregnancy/breastfeeding status if you choose to set it, and the answers you give during onboarding (goal, pace, diet style, what's been blocking you, where you heard about us).
  • Food & health data: the meals you log (descriptions, photos, estimated nutrition), water and exercise entries, recipes you save, allergies, dietary preferences and dislikes, nutrition targets, and personal goals. Also — each only if you use those features — medication diary entries and reminders you set, body measurements, and menstrual-cycle entries. Progress photos, if you take them, are stored in a private bucket and shown only to your household via short-lived signed links.
  • Household members and guests you add: names, allergies, and dietary needs of the people you cook for. You are responsible for having their permission (or, for your children, parental authority) to enter this.
  • Chat: your conversations with the AI assistant are stored so you can revisit them.
  • Payment details: handled entirely by the Apple App Store. Payment details never touch our servers; we only store your subscription tier, status, and billing period.

Data collected automatically:

  • Strictly necessary: sign-in session cookies, your timezone (so reminders fire at the right hour), push-notification subscriptions for devices where you enable reminders, and app preferences stored on your device.
  • Service telemetry: counts of AI feature usage per household (used to apply usage limits) and error reports if error tracking is enabled.
  • Analytics: anonymous product usage events — which screens are used, where people drop off.
  • Marketing signals: ad-measurement events that tell us which of our ads led to installs.

Analytics and marketing signals depend on where you are: where the law requires an opt-in — the EU/EEA, the UK, and Switzerland — nothing loads until you accept it in the consent banner. Elsewhere they are on by default. In both cases you can turn them off at any time in Profile → Personalisation, and we honour the Global Privacy Control browser signal as an opt-out everywhere.

3. Health data needs your explicit consent

Weight, meals, allergies, and similar entries are health data under EU law (GDPR Article 9). We process them only with your explicit consent, which you give when you create your account and enter this information. You can withdraw that consent at any time by deleting the data or your account (Section 12); withdrawing does not affect processing that already happened.

4. Apple Health (iOS app)

If you allow it, the Caly AI iPhone app reads three things from Apple Health: your step count, your active energy, and your workout sessions. Nothing is read until you grant access in Apple's own permission sheet, and Apple — not us — decides what that sheet offers. We never write anything back to Apple Health.

Steps and active energy stay on your device. They are read at the moment a screen displays them, shown to you, and dropped. We do not copy them to our servers, do not store them in iCloud, do not keep them after you close the screen, do not use them for advertising or marketing, do not include them in analytics, and do not send them to our AI providers or any other third party. Because we never receive them, there is nothing on our side to export or delete.

Workouts are different. A workout you allow us to read is added to your exercise log on our servers, exactly like a workout you enter yourself, so that it counts towards your training week. It is covered by the same handling, retention and deletion rules as the rest of your exercise data (Sections 12 and 13), is used only to provide the Service's features, and is never used for advertising or marketing.

You can withdraw access at any time in the Health app under your profile → Privacy → Apps → Caly AI; the app stops reading immediately. Apple Health data is health data under GDPR Article 9, and the access you grant in Apple's sheet is the explicit consent for it — see Section 3.

5. What we use data for

  • Running the service (contract, GDPR Art. 6(1)(b); explicit consent for health data, Art. 9(2)(a)): computing your calorie and macro targets, tracking your intake, generating suggestions and plans, syncing across your devices and household.
  • Safety: your allergies and dietary restrictions are checked in code against recipes and suggestions. This is a core feature, not optional processing — but it is an aid, not a guarantee (see the Terms).
  • Billing (contract + legal obligation): managing subscriptions and keeping records required by bookkeeping law.
  • Improving the app (in the EU, consent for analytics; legitimate interest for service telemetry and aggregated statistics).
  • Marketing measurement (in the EU, consent): attributing installs to ad campaigns. Ad platforms receive events like sign-up or purchase — never your meals, weight, or other health entries.
  • Security & abuse prevention (legitimate interest): rate limits, fraud prevention, and keeping the service working.

We do not sell your personal data. We may create aggregated or de-identified statistics that no longer identify anyone (for example, how many meals were scanned in a month) and use them for any purpose, including marketing; because they identify no one, they may be kept after you delete your account.

6. AI processing

Caly AI's core features run on large language models. When you scan a plate, a barcode label, or a recipe photo, describe a meal in words, chat with the assistant, or generate a plan, the relevant content — your text, the photo, and the context needed to personalise the answer (targets, preferences, allergies of the people eating) — is sent to our AI service providers, who process it to provide the feature. The specific models and providers may change at any time as we improve the Service.

  • AI outputs (calorie counts, macros, extracted recipes) are estimates. They are stored as part of your log so you can correct them.
  • You can turn off personalised AI content in Profile → Personalisation; the assistant then only receives hard safety constraints (allergies), not your preferences and history.

7. Sharing with your household and other users

Caly AI is built for households. Meals, recipes, plans, chat threads, and member profiles belong to the household and are visible to every account in it. Progress photos and weight history are also household-visible. Only invite people you are comfortable sharing this with.

Social features are optional, and what each one shares with other participants is shown in the feature itself. Anything you share with other users should not be considered private: other participants can see it and could copy it. Leaving a social feature stops the sharing.

8. Public sharing

Nothing is public by default. If you create a share link for a recipe, that recipe (title, photo, ingredients, steps, nutrition — not your name or household data) becomes visible to anyone with the link until you delete the recipe.

9. Who processes data for us

We share data with service providers only so they can perform a job for us, each bound by a data processing agreement. They fall into these categories of recipients:

  • Hosting & data storage — the infrastructure the app and its database run on.
  • AI processing — as described in Section 6.
  • Payments & billing — subscription processing through the App Store; payment details never touch our servers.
  • Error diagnostics — crash reports, can be disabled in Personalisation.
  • Product analytics — runs as described in Section 2.
  • Ad measurement — runs as described in Section 2; receives commerce events only, never health entries.
  • Public data lookups — barcode and ingredient databases that receive the barcode or food name, never your identity.
  • Push notifications — delivery of reminders to devices where you enabled them.
  • Business transfers — if the Service's operator changes (for example moving from a sole trader to a company we form, or a merger or acquisition), your data transfers to the successor under the same protections and this policy. We'll inform you of any change of controller.

The specific providers within these categories may change as the Service evolves. Providers that only run with your consent are named in the consent choice itself.

10. International transfers

Some of our providers process data outside the EEA, including in the United States. Where data leaves the EEA, transfers rely on an adequacy decision such as the EU–US Data Privacy Framework, or on the European Commission's Standard Contractual Clauses.

11. Cookies and device storage

Third-party cookies follow the regional rule in Section 2 — in opt-in countries, none are set before you accept. What lives in your browser or app:

  • Sign-in cookies (strictly necessary) — keep you logged in securely. Set by our authentication provider; no tracking role.
  • App preferences on your device (strictly necessary) — local storage entries holding things like your view settings, tutorial-seen flags, unsent onboarding answers, and your consent choice itself. They stay on the device and are not tracking.
  • Analytics storage — created only while analytics runs for you (Section 2); used to keep usage events pseudonymous and consistent.
  • Ad-measurement storage — created only while ad measurement runs for you (Section 2).

Change your mind anytime in Profile → Personalisation. Clearing your browser storage removes these entries — including your consent choice, so we'll ask again.

12. Retention and deletion

  • Your data is kept for as long as your account exists.
  • You can delete individual entries (meals, weights, photos, recipes, chat threads) at any time in the app.
  • Delete Account (Profile → Account) permanently deletes your household's data — meals, recipes, weight history, photos, chat — cancels billing, and removes your sign-in. This cannot be undone.
  • Records we are legally required to keep (for example under bookkeeping law) are kept for as long as that law requires, and we may keep limited records where necessary to enforce our terms, prevent fraud, or resolve disputes. Residual copies may persist briefly in routine backups before aging out.

13. Your rights

Under the GDPR you can:

  • access the data we hold about you, and get a copy (the app can export a PDF summary of your tracking data; for a full export, email us);
  • correct inaccurate data (most of it is editable in the app);
  • delete your data (in-app, see Section 12);
  • withdraw any consent at any time — the consent banner choices can be changed in Profile → Personalisation;
  • object to, or ask us to restrict, certain processing;
  • receive your data in a portable format;
  • complain to a supervisory authority — in Sweden, IMY (Integritetsskyddsmyndigheten, imy.se), or the authority where you live.

To exercise anything you can't do in the app, email support@kcalai.net. We respond within one month.

14. Children

Caly AI accounts require a minimum age of 13 — and where the country you live in sets a higher age of digital consent (up to 16 in parts of the EU), that higher age applies, because we rely on your own explicit consent for health data (Section 3). Goal plans involving calorie targets require age 16. Adults may record household members of any age (for example a child's allergies so the safety filter protects them); that data is entered and controlled by the responsible adult.

15. Security

Data is encrypted in transit (TLS) and at rest. Access is isolated per household at the database level (row-level security), private photos are served through expiring signed links, and payment data never reaches our infrastructure. No system is perfectly secure — if a breach affects you, we will notify you and the supervisory authority as the GDPR requires.

16. Changes to this policy

We'll update this page when our practices change and revise the date at the top. For significant changes — new data uses, new categories of recipients — we'll tell you in the app and, where the law requires it, ask for consent again.