Caloez Privacy Policy

Last updated and effective: August 30, 2026

Caloez is developed by FlowLab Team ("we", "our", or "us"). This policy explains how we collect, use, share, store, retain, and delete personal information when you use our app and website.

Data retention and deletion: We store your records to provide your account and tracking history. After an account or data deletion request is verified, deletion of the applicable Caloez user data is completed within 90 days, subject to the limited retention exceptions explained in Section 6. Uninstalling the app does not delete your cloud account. You can request deletion in the app or on our Account Deletion page.

1. Information We Collect

2. How We Use and Share Information

We use this information to provide accounts and cloud synchronization; display tracking history and trends; calculate goals and estimates; provide optional AI analysis, meal planning, and reports; deliver reminders and widgets; verify subscriptions and AI usage allowances; resolve support requests; diagnose crashes; understand app usage; and prevent abuse.

We use Google Firebase and Google Cloud for authentication, Firestore storage, photo and attachment storage, server functions, Remote Config, App Check, Analytics, Crashlytics, and website hosting. These providers process the data needed for their functions. App Check uses Apple App Attest/DeviceCheck or Google Play Integrity to help verify legitimate app requests. Google and Apple also process sign-in and purchase information when you use their services. See Firebase privacy and security information, Google's Privacy Policy, and Apple's Privacy Policy.

We do not sell personal or health data, or use health records for advertising, marketing, or data brokerage. We share health information with service providers only to provide the features described here and subject to applicable permissions and consent. We may disclose information where legally required or necessary to address fraud or security incidents. When you choose to share a report or photo through another app, that recipient's privacy practices apply.

3. Apple Health and Android Health Connect

Health integration is optional and requires your device permissions. Depending on your platform and granted permissions, Caloez reads steps, exercise, energy expenditure, distance, sleep, body measurements, hydration, nutrition, menstrual flow, glucose, and blood pressure. It can write supported records you log, including weight, body fat, height/BMI, water, nutrition, menstrual flow, glucose, blood pressure, and activity energy. The system permission screen shows the specific data types available on your device.

Authorized data is used for tracking, synchronization, charts, goals, and the health insights you request. Imported information or derived summaries may become part of your Caloez records and cloud-synchronized history; relevant summaries may be included in an optional AI request as described below.

Our use of Health Connect information adheres to the Health Connect Permissions policy, including Limited Use requirements. We do not use Health Connect or HealthKit data for advertising, data brokerage, or sale.

You can disable health synchronization in Caloez and revoke permissions in Apple Health or Android Health Connect. Revoking access stops future authorized access but does not itself delete previously imported Caloez records. Records in Apple Health or Health Connect must be managed separately through those services.

4. Optional AI Processing

Caloez uses Google Gemini through Google Cloud Vertex AI and our Firebase server functions. AI features include food photo and text analysis, nutrition estimates and advice, recipes, meal planning, exercise analysis, weekly reports, and sleep, glucose, or blood pressure insights.

Depending on the feature, we send the photo or text you submit, relevant dietary preferences and allergens, profile measurements and goals, meal and nutrient records, or relevant activity, sleep, glucose, or blood pressure summaries. We also send the requested response language. Account identity is used by our server to verify access and maintain feature-specific trial and daily usage counters.

AI processing is optional and the app requests consent before use. You can decline and continue using available non-AI features. If you previously agreed, you can stop using AI features and contact us to withdraw consent or request deletion. Do not submit information you do not want processed by the AI provider. AI outputs are estimates and general information, not medical diagnoses or treatment.

Our AI proxy processes prompts and images to return a response; saved records, photos, and reports follow Section 6. Google Cloud may retain request data for safety or abuse monitoring under its applicable terms; this is not a promise of zero retention. See Google Cloud's generative AI data governance information.

5. Storage, Security, and Device Permissions

Caloez stores records and preferences locally and synchronizes account data with Firebase cloud services when signed in and connected. We use encrypted network connections, authentication, access controls, and app integrity checks to protect data. No storage or transmission method is completely secure. Google and Apple may process data in countries other than your own, subject to their applicable data protection terms.

Camera and photo access supports images you choose to capture, upload, import, or save. Notifications support reminders. Health and physical activity permissions support the integrations described above. Widgets and Live Activities can display selected tracking information on your home or lock screen. You can control permissions, notifications, widgets, and lock-screen visibility in your device settings. Locally saved exports and images you share remain under your control.

6. Data Retention and Deletion Policy

We retain user data; we do not operate a no-storage service. The following rules describe what we retain, why, and when it is deleted:

Account, profile, health records, photos, plans, preferences, and saved reports
We retain these records while your account exists to provide synchronization and your tracking history. Inactivity or uninstalling the app does not automatically delete your cloud account. When you delete your account or submit a verified deletion request, the applicable Caloez user data is deleted within 90 days. An in-app deletion may remove active account data earlier. Individual records can also be removed using the available app controls or by contacting us.
AI trial and daily usage records
We retain account-linked counters and feature/date information to administer AI allowances and prevent abuse while your account exists. These counters are included in account deletion. A daily allowance resetting does not itself mean that the previous day's usage record has been deleted.
Feedback, screenshots, and support correspondence
These are stored separately to investigate and resolve support issues. The in-app account deletion process does not automatically erase separately stored feedback and its attachments. Contact us to request their deletion, with or without deleting your account; after verification we complete deletion within 90 days, except for information needed for an unresolved dispute, security investigation, or legal obligation.
Subscription, purchase, refund, and billing audit records
Limited billing records, including transaction identifiers, billing account identifiers, store verification responses, and associated account identifiers, may remain after account deletion to verify purchases, handle refunds and disputes, prevent fraudulent reuse of purchases, and meet applicable accounting or legal requirements. They are not automatically removed by account deletion or subject to the standard 90-day deletion window while these reasons apply. Their retention period is determined by the duration of the relevant purchase/refund or dispute process, applicable legal recordkeeping periods, and necessary fraud-prevention requirements. You may request a review and deletion of records that are no longer needed.
Analytics, crash reports, security logs, and provider backups
These have separate service-specific retention settings and deletion processes; deleting a Caloez account does not instantly erase every provider log or backup. For example, Firebase states that Crashlytics retains crash traces and associated identifiers for 90 days before beginning removal, and that Authentication data removal from live and backup systems can take up to 180 days after deletion is initiated. These provider timelines are distinct from our 90-day Caloez user-data deletion process. See Firebase's current retention disclosures. Google Analytics data follows the service's configured retention settings; contact us for a deletion request or information about the applicable retention period. Information that has been irreversibly aggregated so it cannot identify you may be retained for service statistics.
Copies outside Caloez
Apple Health, Health Connect, app stores, your device backups, exported images, and recipients of shared content maintain their own copies. Deleting a Caloez account does not automatically remove these copies or cancel a subscription. Manage those records, backups, and subscriptions with the relevant provider.

Where a limited retention exception applies, access is restricted to the relevant support, security, financial, or legal purpose. Contact us to ask what information remains and the reason for retaining it. We delete or anonymize information when its retention purpose and any required retention period end.

7. Your Choices and Deletion Requests

In the app, open Profile → Personal Details → Delete Account. You may be asked to sign in again to verify ownership. The account deletion flow removes your account, user records, uploaded user photos, and AI usage counters from active systems and clears app-managed local state on the requesting device, subject to Section 6.

You can also email vitaflowlab@gmail.com or follow the Account Deletion instructions without reinstalling the app. You may request deletion of specific data without closing your account. Send enough information to identify your account and the request; never send your password. We may verify ownership before processing.

Depending on applicable law, you may also request access, correction, a copy of your data, restriction of processing, or withdrawal of consent, and raise a concern with your local data protection authority. Withdrawal does not undo processing already performed. Some features need particular information to function.

8. Changes and Contact

We update this policy when our practices change and revise the date above. Where required, we provide additional notice or request consent for material changes. For privacy questions, retention details, or data requests, contact FlowLab Team at vitaflowlab@gmail.com.