Privacy Policy

Last updated: September 24, 2026

Calometric keeps most tracking on your device, with optional iCloud sync. It sends only feature-specific data when you use a feature that needs it: a photo you choose to scan or a barcode lookup. Firebase is initialized at every launch before any consent screen to help protect cloud requests; that setup fact does not by itself mean a cloud packet is sent at launch.

Data We Process

Calometric does not require an account, sign-up, advertising identifiers, or tracking pixels. Optional usage analytics are processed by TelemetryDeck and collect a random identifier created on your device when you turn analytics on, deleted when you turn them off, plus coarse location derived from a masked IP address and device/app metadata. Nothing is sent before you make that choice. Crash reports, which are enabled by default and can be disabled in Settings, are processed by Sentry and contain technical diagnostics. When analytics are on, your subscription and purchase events are also linked to them through a pseudonymous identifier so we can understand which features lead to a subscription; that linkage is forwarded by RevenueCat’s servers, so turning analytics off stops future events but cannot recall events already sent. Neither telemetry path includes meal content, nutrition values, photos, barcodes, Health data, a user ID, an advertising identifier, or raw error descriptions. It processes local meal logs and goals, optional iCloud sync, and feature-specific network data: barcode lookups sent to Open Food Facts, and consented photo scans sent for cloud analysis. Purchase, scan-credit, subscription, and app-integrity records are also processed to authorize and protect paid cloud features. We do not receive your name or email from the app. The purchase identifier used by the cloud service is pseudonymous and Calometric cannot itself resolve it to a person.

Meal Data and Saved Photos

Meal logs, food entries, goals, notes, and saved-meal templates are stored locally in the app. If you enable iCloud sync, they may also sync through Apple's CloudKit infrastructure to your iCloud account. When you save a reviewed photo meal, a separate downsampled copy can be stored with that local meal record and may sync through iCloud. Calometric does not upload your meal history as part of photo analysis, and we cannot access your CloudKit data.

HealthKit Integration

Calometric can read from and write nutrition data to Apple HealthKit with your explicit permission. HealthKit data is handled on your device and is not included in cloud photo requests. You can revoke HealthKit access at any time in Settings → Privacy & Security → Health.

Photo Scanning & AI Food Recognition

When you choose to scan a meal photo, cloud-photo consent, an active Calometric Pro subscription or remaining legacy scan credits, and network availability are required. Before upload, Calometric corrects orientation, removes EXIF and location metadata, and resizes the image to a maximum long edge of 960 pixels. The resulting JPEG is sent through Firebase callable Functions to Cloud AI for a nutrition estimate. The request also carries the signed App Store transaction material and a stable request identifier needed to authorize the scan and prevent duplicate charging. Your meal history, HealthKit data, and non-photo entries are not included. When you save the reviewed meal, a separate downsampled photo may be stored locally and synced through iCloud. No exact cloud retention or deletion period is promised here because production settings have not been verified.

Nutrition Coach (no longer available)

The Nutrition Coach is not available in the app. If you used it before, Calometric may still hold the pseudonymous entitlement and usage records it kept for quota, billing, abuse prevention, and cost control, such as counters and token and cost totals. Your conversations were kept in your device's memory, not stored by Calometric; messages you sent were processed by Cloud AI under the applicable service terms. To export or delete the Coach records Calometric holds, contact hello@calometric.app.

Barcode Scanning

Barcode scanning uses your device's camera to read product codes. Images are never stored or transmitted. To fetch nutrition facts, Calometric sends the barcode number along with your device's language and country to Open Food Facts, a community-maintained food database, plus the technical details any web request carries, such as an app-identifying User-Agent and your IP address. No photos, meal history, or other identifying information is included. You can add products locally when one is missing or you're offline.

iCloud Sync

If you enable iCloud sync, your data is synced across your Apple devices using Apple's CloudKit. CloudKit uses Apple's Standard Data Protection, including encryption in transit and at rest; end-to-end encryption applies only if you have enabled Apple's Advanced Data Protection. The data is associated with your iCloud account, not with us, and we cannot access your CloudKit data.

Third-Party Processing

Calometric links Firebase for cloud features, RevenueCat for subscriptions and the paywall, TelemetryDeck for optional usage analytics, and Sentry for crash diagnostics. Firebase is initialized at every app launch, before any consent screen. App Check helps protect callable cloud requests by checking app integrity; it is not an identity check, and source code does not establish that an attestation packet is sent at launch. Firebase carries the consent-gated cloud feature: selected meal photos sent to Cloud AI for analysis. Analytics stays off until you enable it, and the analytics SDK is not started before then; crash reports are enabled by default and can be disabled in Settings. We do not use advertising SDKs. Barcode lookups go directly to Open Food Facts.

Voice Logging

Voice logging uses Apple's SpeechAnalyzer/SpeechTranscriber and DictationTranscriber on your device. There is no server-recognition fallback: unsupported device or language combinations fail closed. Calometric does not send your audio to a server or store it; the resulting transcript is matched to local nutrition data.

Widgets

Home screen and lock screen widgets display your calorie data locally. No network requests are made by widgets.

Children's Privacy

Calometric does not ask for, verify, or store your age and has no age gate. It does not require an account. If a person uses a consent-gated cloud feature, the supplied photo is processed as described above; parents or guardians with questions about a child's data can contact us at hello@calometric.app.

Changes to This Policy

If we ever change this policy, we'll update this page. But our commitment to privacy is fundamental to Calometric. We built it this way on purpose.

Contact

If you have questions about this privacy policy, contact us at hello@calometric.app.