Calzi AI
Legal
Privacy Policy
Last updated: May 25, 2026
This Privacy Policy describes how Calzi AI ("Calzi AI," "we," "us," or "our") collects, uses, and shares information when you use the Calzi AI mobile application (the "App"). By using the App, you agree to the practices described here.
1. Information We Collect
Information you provide
- Profile and goals: name, age, height, current weight, target weight, gender, activity level, dietary preferences, workout frequency, and nutrition goals.
- Food log entries: meals, foods you log, portion sizes, water intake, fasting sessions, exercise entries, weight history, weekly check-ins, and any notes you add.
- Photos for food scanning: images you capture or upload to identify food. These images are sent to our AI providers for analysis (see Section 4) and are not stored on our infrastructure beyond the duration of the request.
- Free-text food descriptions: when you log food using natural language (e.g. "two scrambled eggs and toast"), the text is sent to our AI provider to identify foods and estimate nutrition.
Information collected during sign-in
The App offers two sign-in options:
- Sign in with Apple — we receive your Apple user identifier and, if you choose to share them, your name and email. This data is stored locally on your device in the iOS Keychain. Apple's privacy practices apply.
- Sign in with Google — we receive your Google account identifier, name, and email via Google's Sign-In SDK. This data is stored locally on your device in the iOS Keychain. Google's privacy policy applies to data Google collects during sign-in.
Information collected automatically
- Subscription status: whether you have an active Calzi AI Pro subscription, provided through Apple's StoreKit and RevenueCat. We do not receive your payment card or full Apple ID.
- Network metadata: when the App makes API requests, our server (and third-party APIs) receive standard network metadata such as your IP address and a user-agent string. This is used only to operate the service.
What we do not collect: the App does not currently include any analytics, advertising, attribution, crash-reporting, or behavioral-tracking SDK. We do not maintain a user-account database on our servers — your data lives on your device.
Information from Apple Health (HealthKit)
If you grant permission, the App reads and writes the following HealthKit data on-device:
- Reads: body weight, step count, water intake, dietary energy consumed, dietary protein, dietary carbohydrates, dietary fat, active energy burned, and workouts.
- Writes: body weight, water intake, dietary energy, dietary protein, dietary carbohydrates, dietary fat, active energy burned, and workouts. (Step count is read-only.)
- Background updates: with your permission, the App receives step-count updates from HealthKit in the background so your daily activity and calorie targets stay current. No HealthKit data is transmitted off-device.
Raw HealthKit records are stored in Apple HealthKit on your device. Calzi AI does not maintain a server-side HealthKit database. If you use AI coaching or daily insights, the App may include derived or summarized context in an AI request, such as current weight, weekly weight change, calories burned, or whether a workout was logged today, so the insight matches what you see in the App. You can revoke HealthKit access at any time in Settings → Health → Data Access & Devices → Calzi AI.
Camera and depth sensor (LiDAR)
When you use food scan, the App uses your device camera to capture a photo. On devices with a LiDAR depth sensor (iPhone Pro models from 12 Pro onward), the App also captures depth information to estimate food portion volume. Depth data is processed entirely on-device — only the resulting photo and parsed nutrition estimates leave the device, and only as described in this Policy. No raw depth or 3D scene data is sent to any server.
Location
The App uses your location only when you tap "Find Nearby Restaurants" and only for that session. Location is requested as "When in Use" and is sent to Apple MapKit to return nearby places. It is not stored by us.
2. How We Use Information
- Calculate your daily calorie and macro targets and personalize the experience.
- Identify foods from photos, barcodes, and free-text descriptions and return nutrition estimates.
- Save your food log, weight history, fasting history, and goals locally so they're available across sessions.
- Verify and manage your subscription via Apple StoreKit and RevenueCat.
- Send local notifications you've enabled (meal reminders, hydration nudges, fasting milestones, weekly summaries). Notifications are scheduled on-device using Apple's UserNotifications framework — no third-party push service is used.
- Communicate with you about support requests and important service changes.
3. How Your Data Is Stored
- On-device files: profile, food log, weight history, meals, fasting sessions, exercise log, and weekly check-ins are stored locally in the App's sandbox (Documents directory) with iOS Data Protection enabled (
completeFileProtection).
- iOS Keychain: sign-in identifiers (Apple/Google user ID, your name, your email, sign-in provider) are stored in the Keychain with
afterFirstUnlock accessibility.
- HealthKit: health data stays in Apple HealthKit on your device.
- App Group / Widget: a small subset of your nutrition data (today's calories and macros) is shared with the home-screen widget through an iOS App Group. This data never leaves your device.
- iOS Backup: if you have iCloud Backup or encrypted local backups enabled in iOS, Apple may include the App's local data in those backups. Backups are managed by Apple, not by us, and are governed by Apple's privacy policy.
- Our servers: we do not maintain a user account database. We operate a proxy server that forwards individual API requests to AI and food-database providers. We do not intentionally store request contents after the request is complete, though our hosting and infrastructure providers may process standard operational logs.
- In transit: all data sent to our proxy and third-party APIs is transmitted over HTTPS/TLS.
4. Third-Party Services
The App relies on the following third parties to provide its functionality. Your use of the App is also subject to their privacy practices.
AI providers
The App uses AI models from the providers below to identify foods, estimate nutrition, and generate insights. Specific model versions may change as providers release updates; the data we send to each provider does not.
- OpenAI — receives images and short text prompts for food identification from photos and for generating nutrition insights. Nutrition insight prompts may include food logs, goals, profile details, and summarized activity or weight context. Calls are routed through our proxy. No persistent user identifier is sent.
openai.com/policies/privacy-policy
- Google Gemini — receives images and short text prompts for food identification from photos, cross-checking results, and fallback nutrition insights. Nutrition insight prompts may include food logs, goals, profile details, and summarized activity or weight context. No persistent user identifier is sent.
policies.google.com/privacy
- Perplexity — receives free-text food descriptions you enter (e.g. "two scrambled eggs and toast") and returns parsed foods and nutrition estimates. Routed through our proxy. No persistent user identifier is sent.
perplexity.ai/hub/legal/privacy-policy
Food and nutrition databases
- FatSecret Platform API — receives search queries and barcode numbers to look up foods. Routed through our proxy.
fatsecret.com/privacy
- USDA FoodData Central — receives search queries and barcode numbers; public U.S. government API.
fdc.nal.usda.gov
- Open Food Facts — receives barcode numbers and search queries; public open database.
world.openfoodfacts.org/terms-of-use
- Edamam Nutrition Data — used to parse natural-language ingredient descriptions when configured. Receives the ingredient text only.
edamam.com/privacy
- Nutritionix — optional food-search and natural-language nutrition fallback when configured. Receives food search text or natural-language meal descriptions only.
nutritionix.com/privacy
Apple platform services
- Sign in with Apple — authentication.
- Apple StoreKit — subscription purchases, transaction verification, and restore.
- Apple HealthKit — only reads/writes data you explicitly authorize, on your device.
- Apple MapKit — used for the "Find Nearby Restaurants" feature.
- Apple UserNotifications — local notifications scheduled on-device.
Subscription management
- RevenueCat — manages Calzi AI Pro entitlement status and restore behavior. RevenueCat receives an app user identifier and subscription entitlement/transaction status. Apple handles payment processing.
revenuecat.com/privacy
Google services
We do not sell your personal information, and we do not use it for advertising or third-party marketing.
5. Data Retention
Data stored on your device is kept until you delete the App or use Profile → Personal Details → Delete Account. Photos and free-text descriptions sent to AI providers are processed in real time; we do not intentionally retain them on our infrastructure after the request is complete. Subscription records are retained by Apple and RevenueCat as required by their policies and applicable tax/accounting law.
6. Your Rights and Choices
- Access and edit: you can view and edit your profile, goals, and history directly in the App.
- Delete: use Profile → Personal Details → Delete Account to erase Calzi AI data stored by the App on that device, including sign-in credentials, profile, food log, weight history, fasting and exercise data, saved preferences, and widget-shared data. Deleting the App from your device also removes local app data. These actions do not delete Apple Health data or cancel an Apple subscription.
- HealthKit: revoke specific permissions in iOS Settings.
- Notifications: manage notification permissions in iOS Settings.
- Marketing: we do not send marketing emails. Service emails are limited to support and important policy changes.
- California, EEA, UK, and other regional rights: you may have rights to access, correct, delete, or port your information, or to restrict or object to certain processing. Because we generally do not retain your personal data on our servers (it lives on your device), most of these rights are exercised by managing the App directly. To make a formal request, contact us at Calzisupport@gmail.com.
7. Children's Privacy
The App is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, please contact us and we will delete it.
8. Security
We use industry-standard safeguards including HTTPS/TLS in transit, the iOS Keychain for credentials, iOS Data Protection (completeFileProtection) for stored files, and a server-side proxy so that third-party API keys are not embedded in the App binary. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
9. International Users
The App may be used worldwide. By using the App, you consent to the processing of your information in the United States and other jurisdictions where our service providers operate, which may have different data-protection laws than your own.
10. Changes to This Policy
We may update this Policy from time to time. Material changes will be reflected by updating the "Last updated" date above. Continued use of the App after a change indicates acceptance of the revised Policy.
11. Contact
Questions or requests? Email Calzisupport@gmail.com.