1. Introduction and Scope
Welcome to CalorieFit AI ("App," "we," "us," or "our"), a dedicated health, nutrition, and fitness application developed to help users track nutritional intake and physical milestones. We are completely committed to protecting your personal information and your right to privacy regarding all biometrics and tracking items.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application available on the Apple App Store and Google Play Store. This policy applies to all users globally and is specifically designed to comply with the Apple App Store Review Guidelines (including Section 5.1), Google Play Store User Data and Health Apps Policies, the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and HIPAA framework alignment where applicable.
By downloading, installing, or using the App, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with these provisions, please do not access or use the App.
2. Information We Collect
2.1 Personal Identification Information
When you create an account, establish a profile, or interact with our authentication interfaces, we collect:
- Full name and profile display name.
- Email address for account lifecycle management and security verifications.
- Date of birth and precise age (required to precisely calibrate caloric baseline algorithms).
- Gender identity (utilized to calculate metabolic baselines and energy expenditure values).
- Profile photograph (optional; processed strictly on-device or via secure cloud storage if synced).
- Account credentials (usernames and passwords), which are explicitly stored in heavily salted, encrypted hash formats.
2.2 Health, Nutrition, and Biometric Data
As a highly specialized fitness and nutrition tracking system, the core operation of the App requires the processing of sensitive metrics that you voluntarily provide or generate via system interactions:
- Physical Biometrics: Height, weight, target weight metrics, and granular body dimensions or structural changes.
- Metabolic & Composition Indicators: Body Mass Index (BMI), estimated body fat percentages, and matching lean mass values.
- Activity & Exercise Metrics: Workout history logs, structural exercise types, durations, physical intensities, movement frequency, step tallies, and overall calories burned.
- Nutritional Intake: Granular daily food logging records, meal time captures, specific dietary intake parameters, localized macronutrient ratios, micro-nutritional indices, and target dietary plans.
- Computer Vision Data: Image snapshots of food items or packaging text captured voluntarily via your device camera to trigger object detection or Optical Character Recognition (OCR) systems for fast item identification.
- Wearable Vital Indicators: Continual heart rate metrics, structural sleep cycles, sleep durations, or cardiovascular data pushed from connected hardware interfaces.
2.3 Device, Telemetry, and Technical Information
To assure software reliability, manage offline syncing parameters, and prevent localized errors, we gather standard technical data during active sessions:
- Device architecture models, exact hardware brandings, and underlying operating system versions (iOS/Android tracking).
- Unique OS-level identifiers (such as IDFA on Apple devices, or Android Advertising ID / Play Services ID).
- Internet Protocol (IP) addresses and macro-level geographic telemetry data (coarse country or regional tiering only).
- App performance telemetry, precise internal session runtimes, explicit crash stack traces, operational error logs, and transactional diagnostic flags.
2.4 Location Telemetry
Subject to explicit system-level runtime permission flags, the App may request access to:
- Precise GPS tracking data to map, display, and log path coordinates for outdoor physical exercises like running, jogging, or cycling paths.
- Coarse location data to serve localized nutritional defaults or regional item matching parameters.
You preserve the right to completely restrict or modify location access models through your device’s core settings at any time without locking basic application code.
2.5 Critical Platform Ecosystem Integrations (Apple HealthKit & Google Health Connect)
You can voluntarily bridge CalorieFit AI with system-level health aggregates including Apple HealthKit (on iOS hardware) and Google Health Connect / Google Fit APIs (on Android systems). Our data handling parameters are subject to rigid restrictions:
- Zero Commercial Exploitation: We explicitly promise that data extracted from Apple HealthKit or Google Health Connect frameworks will NEVER be sold, exchanged, traded, or transferred to third-party data brokers, advertising agencies, tracking aggregators, or marketing companies under any circumstances.
- Strict Use Limitation: Any biometrics, heart rate metrics, step totals, or sleep data derived via these platform-native frameworks is read solely to render charts, populate physical metrics tables, and run local calculation models inside the App.
- Granular Control: Permissions can be individually toggled or fully decoupled dynamically via your system’s default iOS Health settings or Android App Permission panes.
2.6 Payment Processing Telemetry
Premium features and subscription items are transacted exclusively via platform storefronts:
- All payment pipelines are funneled through Apple App Store In-App Purchases (Apple Pay) or Google Play Store Billing infrastructure (Google Pay).
- Our technical architecture never sees, intercepts, or retains raw primary account numbers, credit card strings, or secure banking pin numbers.
- We retain only clean transaction receipt proofs, purchase dates, subscription states, and macro billing references.
3. How We Use Your Information
Every operational use case involving your tracking profiles is tethered to a legitimate legal framework:
- Provision of App Functionality: Establishing accounts, calculating accurate calorie goals, processing food imagery, computing metabolic scores, maintaining offline-first local data structures, and ensuring synchronization across active endpoints.
- System Stabilization & Optimization: Analyzing crash structures, addressing CocoaPods or version dependency compilation breaks, tracking API bottlenecks, running localized performance diagnostic assessments, and testing feature rollouts via isolated code groups.
- Tailored Adjustments: Generating adaptive caloric limits, modifying exercise thresholds, and alerting users via contextual in-app milestones.
- Security and Defensive Protocols: Screening for account takeovers, mitigating malicious cloud injections, protecting server APIs, and maintaining integrity across system backends.
- Regulatory and Legal Compliance: Meeting global enforcement guidelines, archiving mandatory data items, and processing official legal claims.
- App Communications: Issuing high-importance system maintenance alerts, account security statements, synchronization failure warnings, or transactional push notifications.
4. Our Duties and Obligations When Sharing Your Information
4.1 Core Data Stewardship
We approach data distribution with extreme security controls. When third-party mechanisms interact with data, we legally commit to:
- Data Minimization: Limiting exposure strictly to the absolute minimum schema fragments required to complete a technical instruction.
- Vendor Auditing: Screening all third-party processing hubs to confirm they deploy rigorous encryption and data management schemes.
- Enforcement of Data Processing Agreements (DPAs): Forcing all processing parties to enter into binding legal frameworks that permanently restrict them from repurposing user data.
- Breach Communications: Committing to notify affected users and regional data authorities within 72 hours of identifying a verified data security breach.
4.2 Third-Party Service Providers (Data Processors)
We integrate external cloud infrastructure entities to fulfill core features, subject to strict DPAs:
- Cloud & Database Hosts: Secure database storage and backend synchronization infrastructure (such as Azure Cloud Services) to hold encrypted sync targets.
- Telemetry & Analytics Services: Software health trackers and diagnostics tools to isolate bugs, crashes, and rendering delays.
- Notification Conveyors: System networks (like Firebase Cloud Messaging or Azure Notification Hubs) to securely distribute standard background payloads and system push notifications.
4.3 Specialized Health Data Commitments
Because health and physical metrics represent highly sensitive data domains, we enforce distinct safeguards:
- We will NEVER pass health profiles, caloric indexes, or physical measurement values to corporate employers, health insurance groups, financial agencies, or medical screening firms without explicit, independent, written consent.
- We run periodic internal Data Protection Impact Assessments (DPIAs) before changing any code related to data pipeline logic, local storage engines, or vision processing systems.
4.4 Mandatory Legal Disclosures
We may present account logs to legal entities only under valid court orders, binding search warrants, or verified regulatory subpoenas. We commit to actively contesting overbroad discovery requests and will notify users unless legally barred from doing so.
4.5 Corporate Structural Changes
If CalorieFit AI undergoes a business transition, merger, or asset acquisition, users will receive a 30-day advance notification via email or clear in-app popups. Users retain the complete right to permanently wipe their data profiles before any structural transfer completes.
4.6 Aggregated or De-Identified Datasets
We may extract macro-level, completely anonymous statistics for systemic analysis or optimization. These operations use strict modern differential privacy guidelines, completely ensuring that no individual user pattern can ever be re-identified or reversed.
4.7 Transnational Server Routing
Data synchronized out of local device files may travel to servers operating outside your home country. We anchor these pathways using the European Commission's standard contractual clauses (SCCs) and robust security baselines to maintain continuous data protection.
5. Data Retention Parameters
We maintain profiles only for active lifecycle timelines or mandatory archival windows:
- Active Tracker Profiles: Retained for the active duration of your account. Upon a formal account deletion request, all personal records are purged within 30 days.
- Financial Records: Purchase validations and storefront receipts are securely archived for up to 7 years to meet global tax and corporate accounting compliance laws.
- Diagnostic Telemetry: System error tracking records and general server logs are auto-purged on a rolling basis within 12 months.
- Database Backup Archives: Redundant server images are overwritten and cleared within 90 days of an primary deletion event.
6. Data Security Controls
We enforce deep corporate technical guards to shield user metrics:
- Comprehensive AES-256 bit encryption models applied to all persistent data stores at rest.
- Mandatory Transport Layer Security (TLS 1.3 or higher) configurations protecting data in transit.
- Rigidly segmented employee access policies using strict "least-privilege" and "need-to-know" access rules.
- Enforced Multi-Factor Authentication (MFA) requirements protecting all administrative management infrastructure and deployment pipelines.
7. User Rights and Global Controls
7.1 Standard Rights Assured to All Users
Regardless of your geographic location, we provide comprehensive personal data controls:
- Right of Access: You can download a complete structured extract of all physical logs and account data we store.
- Right to Rectification: You can instantly update inaccurate personal profiles or physical tracking metrics.
- Right to Erasure (Deletion): You can execute a total profile wipe via our in-app account options, erasing all records from active production clusters.
- Right to Data Portability: You can export your metric records in standard, machine-readable text or JSON data formats.
7.2 European Union / United Kingdom Protections (GDPR)
If you connect from the EEA or the UK, you retain the right to restrict processing models, object to legitimate interest processing pipelines, revoke voluntary health access parameters instantly, and file compliance escalations directly with your home Data Protection Authority.
7.3 California Privacy Adjustments (CCPA/CPRA)
California residents have the explicit right to inspect exact categories of collected metrics and request structural erasures. We explicitly confirm that CalorieFit AI does NOT "sell" or "share" user metrics as defined under California law.
To exercise any data right, please contact our privacy desk directly at the dedicated email address provided below.
8. Protections for Children
CalorieFit AI is not built for, nor intentionally directed toward, individuals under the age of 13 (or under 16 across the EEA). We do not knowingly compile or ingest records from children. If we discover a profile belongs to a minor under these age constraints without verified parental oversight, we will delete it immediately. Parents can flag unauthorized accounts to our support desk.
9. External Services and Outbound Links
Our screens may display references or outbound links to third-party web domains (such as nutritional research portals or external fitness equipment guides). We do not dictate the behavior or manage the policies of external operators. We recommend reading their separate privacy policies before interacting with them.
10. Platform Ecosystem Compliance Statements
Apple iOS Environment: We comply fully with Apple’s App Store Review Guidelines, App Tracking Transparency framework rules, and App Privacy Nutrition Details. Camera access is strictly limited to scanning barcodes or using vision-based food item logging.
Android Ecosystem: We declare all data collections within the Google Play Store Data Safety Configuration console. We adhere completely to Google Play's User Data Policy, Core Structural Permissions restrictions, and the Health Apps Declaration rules.
11. Policy Modifications and Adjustments
We may adjust this policy document to keep pace with changing privacy laws or new features. When material changes occur, we will post an explicit in-app notification dashboard panel or send an email update at least 14 days before the updated policy goes into effect. Your continued use of the app after that time constitutes acceptance of the new policy terms.
12. Corporate Contacts and Inquiries
For questions, formal compliance notifications, or to exercise your privacy rights, contact us at:
Company: Magn.Obvious Inc.
Email: magn.obvious@gmail.com