On this page
1. Scope
Calo. is developed and operated by Mini Labs FZ-LLC ("Calo", "we", "our", or "us"). This policy explains how the Calo. iOS app and its supporting services handle information. The current app requires iOS 18 or later.
2. Data in the App
You can provide or create the following information in Calo.:
- Profile information, including your name and an email address if you use Sign in with Apple
- Goals, nutrition targets, food logs, recipes, habits, meal plans, and coach history
- Food preferences, dietary restrictions, allergies, cooking preferences, selected activities, and weekly workout frequency
- Body information, including age, height, weight, target weight, and medication mode
- Weight entries, check-ins, and progress photos
Calo stores the app records listed above in a SwiftData store on your device.
3. On-Device Storage
Your profile, food logs, nutrition targets, goals, preferences, allergies, habits, recipes, meal plans, coach history, health profile, body information, weight history, HealthKit-derived records, check-ins, medication details, and progress photos remain stored on your device. An image attached to a saved food log also remains on your device.
4. AI Processing
Calo routes AI requests through a Calo server hosted on Vercel and then to the Google Gemini API. AI-powered features include photo and text food analysis, voice transcription, meal suggestions, meal plans, and the Calo Coach.
- A food scan can send a food photo, typed description, barcode result, and food preferences.
- Voice input sends a short voice recording for transcription.
- Meal-plan and suggestion requests can include nutrition targets, dietary preferences, allergies, cuisine choices, and cooking preferences.
- Depending on the feature, an AI request can include your selected activities and weekly workout frequency so Calo can tailor nutrition guidance.
- Coach requests send the question you enter plus the context described in Section 6.
Our proxy does not intentionally retain the raw request photo or audio file after it completes the request. Google processes prompts, files, and responses under the Gemini API terms, which describe Google's own retention practices. Raw food photos and voice recordings are not written to Supabase. An image attached to a saved food log remains on your device, as described in Section 3.
5. Nutrition Quality Records
To evaluate and improve nutrition estimates, Calo can store server-side food observations and food corrections in private Supabase tables:
- Food observations: scan source, identified food or barcode result, nutrition estimates, AI or food-database response, interface language, model name, latency, timestamp, and a random device identifier used for service controls
- Food corrections: original and corrected food names and macro values, source, locale, timestamp, observation reference, and the same random device identifier
These quality records do not include your raw food photo, raw voice recording, name, email address, RevenueCat account identifier, medication details, symptom check-ins, body weight, or HealthKit data. The app does not contain a Supabase client key. Only the server can write or read these tables, and database permissions deny app clients direct access.
Food observations and corrections do not currently have a fixed automatic expiry. We retain them for nutrition-quality analysis until they are no longer needed, removed through maintenance, or deleted in response to an applicable request.
6. Coach Context and Consent
Every Coach request can include the question you enter, today's meal names and macros, daily totals and targets, recent logging summaries, streak information, food preferences, dietary restrictions, selected activities, and weekly workout frequency.
Only after you consent, Calo can also send a medication-mode flag and a general wellness summary derived on your device from check-ins. This helps the Coach adjust food suggestions. If you decline or revoke consent, Calo removes those two fields before it builds the request.
- Your name
- Medication names, drug types, schedules, or dosage
- Body weight or weight history
- Raw symptom scores, check-in notes, or side-effect details
- HealthKit data
You can change Coach wellness consent in Calo Settings.
7. Apple HealthKit
If you enable Apple Health, Calo requests read-only access to steps, active calories, workouts, and body weight. It uses this information to show activity and weight context alongside your nutrition. Calo does not write nutrition or other data to Apple Health.
- Calo processes HealthKit records on your device
- Calo does not send HealthKit records to our servers, Gemini, or Supabase
- Calo does not use HealthKit data for advertising or sell it
- You can revoke HealthKit access at any time in iPhone Settings → Privacy & Security → Health → Calo.
8. Location
Calo asks for location access only when you tap Find Nearby for a meal. Calo passes your current location and a restaurant search query to Apple Maps to return nearby places. We do not store your location in Calo or our server databases. You can deny or revoke location access in iPhone Settings and continue using the rest of the app.
9. Support, Diagnostics, and Subscriptions
- Support: the current iOS app opens your email app with Calo's support address. It does not upload a support form. You decide what message, attachments, and device details to send. Your email provider and our support mailbox process that correspondence.
- Subscriptions: RevenueCat processes an app user identifier, product, entitlement, purchase, and subscription status. Apple processes payment details. Calo does not receive your payment card number.
- Service controls: Calo sends a random device identifier, request timestamp, nonce, and subscription identifier where needed for authentication, rate limits, and entitlement checks.
- Food-search logs: food search terms sent to USDA FoodData Central or Open Food Facts pass through Calo in URL search parameters. Vercel runtime logs can record those parameters with request metadata and retain them for up to 30 days, depending on our service plan and logging settings. Calo uses these logs to operate, secure, and diagnose the lookup service.
- Diagnostics: Sentry can receive crash reports and technical diagnostics, associated with a random diagnostic identifier and a coarse goal setting. Vercel logs limited request and feature-event information needed to operate and protect the service.
- Usage analytics: Calo uses PostHog, hosted in the EU, to count pseudonymous product events, such as a meal being logged or a paywall being viewed. Events carry a random analytics identifier and limited app or device context. They do not carry food names, nutrition values, weight, medication details, names, or email addresses. PostHog person profiles are disabled, and an on-device filter removes properties outside a fixed allowlist before sending. You can turn this off at any time in Settings → App → Anonymous analytics.
10. Retention and Deletion
- On-device app data: remains on the device until you delete it in Calo Settings, remove individual records, or uninstall the app.
- Nutrition quality records: follow the retention described in Section 5.
- Food-search logs: Vercel runtime logs containing request search parameters remain available for the logging period described in Section 9, then expire under Vercel's retention controls.
- Support email: correspondence can remain in the support mailbox while needed to resolve, secure, or document the request, meet legal obligations, or establish and defend legal claims.
- Provider records: subscription, crash, hosting, analytics, email, and AI providers apply their own retention periods under their privacy policies and service settings. Deleting your account does not promise immediate deletion of provider diagnostics, pseudonymous analytics, runtime logs, or support correspondence.
Deleting your account
The fastest way to delete your account and linked Calo service records is in the app: Settings → Account → Delete Account. This deletes device-linked server records, including nutrition-quality observations, corrections, rate limits, and subscription lookups; deletes your verified identity from our subscription-management provider; disconnects Sign in with Apple; and then erases app data stored on your iPhone. Support correspondence, runtime logs, provider diagnostics, or pseudonymous analytics may remain under the retention terms above. Account deletion does not cancel an active App Store subscription. Manage the subscription in your Apple account settings.
If you no longer have access to the app, email support@caloapp.co and we will delete your server-side records for you. We may need information that lets us locate the relevant record and verify the request. You can also use that address to request access to your server-side records.
11. Third-Party Services
- Apple: App Store, Sign in with Apple, HealthKit, and Apple Maps. See Apple's Privacy Policy.
- Google Gemini: AI processing. See the Gemini API terms and Google Privacy Policy.
- Vercel: API hosting and operational logs. See Vercel's Privacy Policy.
- Supabase: private nutrition-quality database. See Supabase's Privacy Policy.
- Upstash: Redis rate limits, entitlement state, deletion state, and other temporary service controls. See Upstash's Privacy Policy.
- RevenueCat: subscription management. See RevenueCat's Privacy Policy.
- Sentry: crash reporting. See Sentry's Privacy Policy.
- PostHog (EU): pseudonymous usage analytics, with an in-app opt-out. See PostHog's Privacy Policy.
- USDA FoodData Central and Open Food Facts: food and nutrition lookup services.
12. Security and Data Use
Calo sends network requests over HTTPS/TLS. Server-side nutrition tables use row-level security and restricted service credentials, and the iOS app has no direct database credential. Requests use signed headers, nonces, and rate limits to reduce abuse.
We do not sell personal data, use personal data for advertising, share HealthKit data with advertisers, or track you across other companies' apps and websites for advertising.
13. Your Choices
You can review and edit app records, export local health data, delete your account and all data in Settings (see Section 10), decline or revoke Coach wellness context, revoke HealthKit and location permissions in iPhone Settings, and manage subscriptions in your Apple account. You can also contact us about access, correction, or deletion rights that apply where you live.
14. Children's Privacy
Calo. is not directed to children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child provided personal information.
15. Changes to This Policy
We may update this Privacy Policy. We will notify you of significant changes through the app.
16. Contact Us
Email: support@caloapp.co
Developer: Mini Labs FZ-LLC
Location: Dubai, UAE