Privacy Policy
We collect only the data needed to run CalorieVision, self-host our database, and use a small number of named third-party processors listed below (including OpenAI for food-photo and voice-transcript analysis).
1. Who is responsible for your data (data controller)
The data controller is FYArc, a sole proprietorship (jednoosobowa działalność gospodarcza) registered in Ząbki, Mazowieckie Voivodeship, Poland ("FYArc", "we", "us"). As a small business, we have not appointed a formal Data Protection Officer; for any privacy question, contact us directly at [email protected].
2. What data we collect
2.1 Account data
- Name, email address, and password (stored as a salted hash, never in plain text).
- If you use Google Sign-In: your Google account email and profile info as provided by Google's OAuth flow.
- Device identifier/label and authentication tokens (access/refresh), stored securely on your device.
2.2 Food, health, and activity data you provide
- Photos of food and recognized voice transcripts you submit for AI recognition, barcode scans, and manual food entries.
- Journal entries, calorie/macro results, weight entries, water intake, dietary profile (e.g., keto/vegan preferences), favorites, and achievements.
- Data you choose to sync from Health Connect or similar platforms (e.g., steps, active energy burned, nutrition, weight). This sync happens on your device; we only receive the specific values you choose to log or sync into the App.
- Product information you voluntarily submit to our shared barcode database (e.g., barcode, product name, nutritional values). Once reviewed, this data may be shown to other users who scan the same barcode; your identity is never displayed alongside it. See our Terms of Use §9.
For voice input, your device's speech-recognition service may send audio to its provider over the internet, depending on your device and settings. CalorieVision does not receive or store that audio; it receives the recognized text, which you can review and edit before submitting for food analysis.
Food photos, weight, and dietary/health-related data may constitute a special category of personal data ("health data") under Article 9 GDPR. We process this data only with your explicit consent, given by using the relevant feature (e.g., submitting a photo, enabling Health Connect sync, or entering weight/dietary information). You may withdraw this consent at any time by not using the feature and deleting the related entries or your account.
2.3 Subscription and payment data
Purchases are processed by Google Play Billing (mobile) or Stripe/RevenueCat Web Billing (web) via RevenueCat. We do not receive or store your card details. RevenueCat identifies your mobile subscription using an internal account identifier, and your web subscription using your account email, plus purchase/entitlement status.
2.4 Technical and support data
- Error and crash diagnostics (via Sentry), which may include device type, OS version, app version, and the technical context of the error.
- Emails you send us for support, and transactional emails we send you (e.g., password reset codes) via SMTP.
- Support/bug reports you submit in-app: your email, the report category, subject and description you write, up to 5 optional screenshots or screen recordings you choose to attach, plus your device model and app platform.
Reminder notifications (meal, water, weekly summary, supplement reminders) are scheduled and delivered on-device; no third-party push-notification service is involved, and no notification content is sent to us. Separately, if you opt into push notifications in Settings, we use Firebase Cloud Messaging (Google) to deliver occasional product-update and offer notifications ("campaigns"); this registers a device token with Google and shares it with our backend. This is off by default and only activates once you enable it, and you can disable it at any time in Settings.
3. Why we process your data (legal basis)
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and managing your account, providing core App functionality | Performance of a contract (Art. 6(1)(b)) |
| AI food-photo and voice-transcript recognition, health/dietary features, weight tracking | Your explicit consent (Art. 9(2)(a)), given by using the feature |
| Processing subscription payments | Performance of a contract (Art. 6(1)(b)) |
| Error monitoring, fraud prevention, keeping the Service secure | Legitimate interest (Art. 6(1)(f)) |
| Responding to support requests, sending transactional emails | Performance of a contract / legitimate interest |
| Complying with legal obligations (e.g., tax records for paid invoices) | Legal obligation (Art. 6(1)(c)) |
| Showing ads to free-tier (non-premium) users | Consent (Art. 6(1)(a)), obtained via Google's User Messaging Platform where legally required; legitimate interest for basic ad delivery where consent is not required (Art. 6(1)(f)) |
4. Where your data is stored
Our application database, file storage, and caching layer (MongoDB, MinIO, Redis) are self-hosted on infrastructure we operate and control, rather than a third-party cloud database provider. This means your data is not distributed across a commercial cloud vendor's global regions by default; it resides on our own server(s).
5. Who we share data with (sub-processors)
| Recipient | Purpose | Data shared | Location |
|---|---|---|---|
| OpenAI | AI-based food recognition from photos and voice transcripts | Submitted food photo or recognized transcript, optional text hint, language preference | United States |
| Device speech-recognition provider (e.g., Google or Apple, depending on your device) | Converting speech to text when voice input is used | Microphone audio, subject to your device settings and the provider's terms | Depends on provider |
| Google Play Billing / RevenueCat | Subscription purchase, billing, entitlement management | Account email (as identifier), purchase/entitlement status | United States |
| Google Sign-In | Optional login method | Google account email/profile, as authorized by you | United States |
| Sentry | Error/crash monitoring | Technical diagnostic data, no food/health content | United States/EU (per Sentry configuration) |
| Email/SMTP provider | Transactional emails (verification, password reset, summaries) | Your email address, message content | Depends on provider |
| Google (Mobile Ads SDK / AdMob) | Showing ads to free-tier (non-premium) users | Advertising identifier and standard ad-request technical data, subject to your consent choice where required. We never include your food, health, weight, or account data in an ad request. | United States |
Where personal data is transferred outside the European Economic Area (e.g., to OpenAI, Google, or Sentry in the United States), we rely on the recipient's participation in the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses as the transfer safeguard, to the extent applicable. We do not sell your personal data. Free-tier users may see ads served through Google's Mobile Ads SDK (see the table above); we never use your food, health, weight, or account data to select or target ads.
Ads are shown only to free (non-premium) accounts — if you have an active premium subscription, you will not see ads. Before showing a rewarded ad (e.g., to unlock an extra scan), the App asks you to explicitly opt in ("Watch ad" / "Not now"); if you decline, the App does not show the ad and does not reduce your remaining scan allowance because you declined. In regions where consent is legally required for ads (such as the EEA and the UK), the App uses Google's User Messaging Platform (UMP) to request your consent before any ad is requested; if you decline consent, no ads are requested or shown.
6. Data retention and deletion
We retain your account data, food photos, and journal/analysis history for as long as your account is active, so that features such as your food history, statistics, and journal continue to work.
When you delete your account (available in-app or by request to [email protected]), we delete your account record, your food photos, and your associated analysis and journal data. This deletion is completed within 30 days, including removal from routine backups. We may retain limited data beyond that period only where required by law (e.g., financial records related to invoicing, which in practice are held by Google Play rather than by us, since we do not process payment card data directly).
Technical diagnostic logs (e.g., Sentry error events) are retained for a limited troubleshooting period and are not linked to your food or health data.
Support/bug reports you submit (including any attached screenshots or recordings) are retained separately for up to 12 months after submission, even if you delete your account, so we can investigate abuse, bugs, or disputes; they are automatically deleted after that period.
7. Your rights
If the GDPR applies to you, you have the right to: access the personal data we hold about you; request rectification of inaccurate data; request erasure ("right to be forgotten"); request restriction of processing; object to processing based on legitimate interest; request data portability; and withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, contact us at [email protected]. You also have the right to lodge a complaint with a supervisory authority — in Poland, the Prezes Urzędu Ochrony Danych Osobowych (UODO), or the data protection authority of your own EU/EEA country of residence.
7a. California and other US state privacy rights
We are a small business and do not sell or "share" (as defined by the CCPA/CPRA) your personal data for cross-context behavioral advertising, and we do not believe the CCPA's applicability thresholds apply to us. If you are a California (or other US state) resident, you may still contact us at [email protected] to ask what personal data we hold about you or to request its deletion, and we will respond on a best-effort basis consistent with Section 7 above.
8. Security
We use industry-standard measures to protect your data, including encrypted transport (HTTPS/TLS), hashed password storage, secure on-device token storage, and access controls on our infrastructure. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Children's privacy
The App is not directed at children under 16. We do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, contact us at [email protected] and we will delete it.
10. Website cookies and local storage
Our companion website (used for sign-in and subscription management) uses browser local storage/session tokens strictly necessary to keep you signed in and to remember your language preference. We do not use advertising or third-party tracking cookies on the website.
On the account page, we optionally use Google Analytics (GA4) to understand basic usage of that page (e.g., how often the subscription options are viewed). This is off by default and only activates if you click "Allow analytics" in the banner shown on that page; declining or ignoring the banner keeps it off. When enabled, GA4 uses a random, non-identifying browser-generated ID stored in local storage — it is not linked to your account, food, or health data. You can change your choice at any time by clearing your browser's local storage for this site.
In the mobile app, Firebase Analytics is off by default and is a separate choice from ad consent. When you register, you are asked once whether to allow anonymous usage analytics (e.g., feature usage counts); declining keeps it permanently off. This choice is independent of the rewarded-ad consent (UMP) flow described in Section 7 and is never inferred from it.
11. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be notified in-app or by email before they take effect. The "Effective date" above reflects the latest revision.
12. Contact
Questions about this Privacy Policy or your data: [email protected].