CalAlly is an AI calorie tracker. To do its job it processes information about your body, your meals, and your goals. Under the GDPR that is health data, a special category that gets the strongest protection in EU law. This page explains exactly what we collect, why, who we send it to, and how you delete it.
Who we are and how to reach us
CalAlly is the data controller for the personal data described on this page.
For any privacy question, to exercise your rights, or to request a copy of the safeguards we use for international transfers, write to support@calally.com. We answer within 30 days.
What data we collect
Account data. Your email address and the name you sign up with. If you sign in with Apple or Google, we receive the identifier those services return to us.
Health data (special category, GDPR art. 9). This is the core of the app and we want to be blunt about it:
- Weight, height, age, and sex
- Body measurements you enter
- Your goal (lose, maintain, gain) and your target
- Dietary preferences and food restrictions. These can indirectly reveal a religious belief or a medical condition, which is exactly why they get art. 9 protection
- Photos of your meals and of nutrition labels
- Progress photos of your body, if you choose to save them
- Step count from Apple Health, if you connect it
Apple Health (HealthKit). Connecting Apple Health is optional and you control which data you send us. The data you share from HealthKit is never used for marketing or advertising, and is never transferred to third parties for marketing or advertising purposes. We use it only to make your calorie targets more accurate. You can revoke the permission at any time in the iOS Health app, and what you share with HealthKit is also governed by Apple's own terms and privacy policy.
Usage data. The meals you log, the questions you ask the AI coach, and its answers.
Technical data. Security and error logs needed to keep the service running and to detect abuse.
We do not use advertising trackers, we do not run an ad network, and we do not sell anything to data brokers. CalAlly is a native iOS app: it does not use cookies. Our website, calally.com, uses one cookie to remember your language, and loads the help center only if you open it. See the Cookie Policy.
Why health data needs special protection
Health data is a special category under GDPR art. 9, which is why we describe it in full above and keep the list of who receives it short and named. We process it on the basis of art. 6(1)(a), consent and art. 6(1)(b), performance of the contract you enter into when you create an account and ask the app to build your nutrition plan.
In practice: when you sign up you accept the Terms and this Privacy Policy, and the app then processes the body, meal, and goal data you enter in order to deliver the nutrition plan, the meal analysis, and the AI coach. Those features are the service itself, so they cannot run without that data. If you do not want this processing to happen, do not create an account, or delete the one you have. See how to stop the processing below.
Legal bases
| Purpose | Legal basis |
|---|---|
| Account creation and user management | art. 6(1)(b), performance of a contract |
| Nutrition plan, meal analysis, AI coach | art. 6(1)(a), consent and art. 6(1)(b), performance of a contract |
| Sharing data with the AI providers listed below | art. 6(1)(a), consent and art. 6(1)(b), performance of a contract |
| Security, abuse prevention, technical logs | art. 6(1)(f), legitimate interest |
Who we share your data with
CalAlly does not build its own AI models or its own database. We use named providers. The table below lists every provider that receives your data. No one else does.
| Provider | What it receives | Where |
|---|---|---|
| Supabase | All stored account and health data | United States (infrastructure hosted on AWS) |
| Meal descriptions and photos, coach messages, profile context | United States | |
| Groq | Voice recordings, for transcription only | United States |
| Langfuse | Technical traces of AI features, with a pseudonymous identifier | European Union |
| PostHog | App usage events, device information, pseudonymous identifier | European Union |
| RevenueCat | Subscription status, and an app user identifier | United States |
| Sentry | Crash and error reports, with your user identifier | United States |
| Resend | Email address and transactional email content | European Union |
| Expo | Push notification token | United States |
| Apple, Google | Sign-in authentication only | United States |
| ImprovMX | Email sent to support@calally.com | European Union |
| Featurebase | Support requests you send us | United States |
| Open Food Facts | Barcode number only, no personal data | European Union |
Each of these providers acts as a processor on our instructions, under a data processing agreement. They are not allowed to use your data for their own purposes.
Data transferred outside the EU
Our database sits in the United States, and several providers above are US-based: Supabase, Google, Groq, RevenueCat, Sentry, Expo, Apple, and Featurebase. We do not hide this.
The general safeguard we rely on is the Standard Contractual Clauses adopted by the European Commission, incorporated into the data processing agreement we have with each of these providers. This is the mechanism that covers Supabase, which stores your account and health data, and it is also the mechanism in Groq's data processing addendum.
Some providers are additionally self-certified under the EU-US Data Privacy Framework. Google is one of them. The Data Privacy Framework is a voluntary certification that each company joins individually, so it does not cover US providers as a group, and we only name it for those that are actually on the list. Where a provider is not certified, the Standard Contractual Clauses apply on their own.
You can ask us for a copy of the safeguards that apply to your data by writing to support@calally.com.
How long we keep your data
Meal photos and voice recordings are not stored. They are sent for processing, analysed, and discarded. We do not keep an archive of them.
Account data, health data, progress photos, and coach conversations are kept for as long as your account is active. When you delete your account from inside the app, this data is deleted immediately. When you ask us to delete it by email, we do it within 30 days.
Technical and security logs are kept for 1 day and then rotated out. The pseudonymised traces of the AI features stored in Langfuse are kept for 30 days.
How to stop the processing and delete your account
There is no separate switch that turns off health data processing while keeping your account. The nutrition plan, the meal analysis, and the AI coach are the service, so the way to stop the processing is to delete your account:
- Open the CalAlly app.
- Go to the Profile tab, scroll to Account Actions and tap Delete Account. This deletes your profile, your health data, your meals, your progress photos, and your coach conversations. It is immediate and it cannot be undone.
If you prefer, write to support@calally.com and we do it for you, within 30 days.
Deleting your account stops the processing from that moment on. It does not undo processing that already happened while the account was active.
The full procedure, including how to delete specific data without deleting your account, is on the account deletion page.
Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Rectify data that is wrong or incomplete
- Erase your data, the "right to be forgotten"
- Restrict processing in certain circumstances
- Data portability, receiving your data in a machine-readable format
- Object to processing based on our legitimate interest
- Withdraw consent at any time, by deleting your account as described above
- Lodge a complaint with a supervisory authority. In Italy that is the Garante per la protezione dei dati personali (www.garanteprivacy.it)
To exercise any of these, write to support@calally.com.
Children
CalAlly is not intended for children. You must be at least 16 years old to create an account, which is the age of digital consent in Italy. If we learn that we hold data belonging to someone below that age, we delete it.
Changes to this policy
We update this page when the way we handle data changes, for example when we add or remove a provider. The date at the top always reflects the last revision. If a change is significant, we tell you in the app before it takes effect.