How CaloTecHandles Your Data
The diary stays on your device, but online features use external providers. Meal descriptions are sent to Gemini or DeepSeek for analysis; Firebase handles accounts, analytics and notifications; and Google Mobile Ads displays ads.
Welcome to our Privacy Policy
We are committed to protecting your privacy. This document explains how we collect, use, and protect your information.
Last Updated: August 10, 2026 | Version: 1.2
Our Commitment to Your Privacy
The diary stays on-device
Meals, weight, goals and diary settings are stored locally.
AI analysis on request
A meal description is sent to Google Gemini, with DeepSeek as a fallback, when you request analysis.
Google services
Firebase handles accounts, analytics and notifications; Google Mobile Ads displays ads.
Health Connect: steps only
The app requests read access to step counts. It does not read workouts, sleep or nutrition from Health Connect.
What Data Do We Collect?
This table separates information stored on your device from information processed by an external provider.
| Data Type | Collection | Purpose | Storage | Sharing |
|---|---|---|---|---|
| Meal description and analysis result | Text or transcript submitted by the user | Producing a nutrition estimate | The result is stored in the local diary | Description sent to Gemini or DeepSeek |
| Recording for transcription | Audio while recording, after you tap the microphone | Converting a spoken meal description to text | CaloTec-AI receives the transcript | Android speech-recognition service; processing may be on-device or online, depending on the device and service |
| Step count | Device sensors, Fitness Local Recording, or read access through Health Connect | Displaying steps and estimating calories burned | Stored locally on the device | Not shared with third parties |
| User account, if created | Name, email address and user ID | Authentication and account management | Firebase Authentication and local data | Processed by Firebase |
| Analytics | Screen and usage events when collection is enabled | Finding failures and improving flows | Handled under the Google Analytics for Firebase policy | Sent to Google when collection is enabled |
| Advertising | Interactions, diagnostics, approximate location and device IDs | Advertising, analytics and fraud prevention | Handled under the Google Mobile Ads policy | Processed by Google under available consent choices |
| Notifications | Installation ID, FCM token and language topics | Sending push notifications | Handled under the Firebase Cloud Messaging policy | Processed by Firebase |
When you choose to scan a supplement label, the camera image is sent over an encrypted connection to Google Gemini for analysis. Your profile photo is stored on-device and is not uploaded by CaloTec.
Diary values, profile data and step counts are not sent to Google Analytics. Advertising providers may process diagnostic data under their policies.
Behavioral analytics via Firebase (optional)
CaloTec-AI uses Google Analytics for Firebase to understand how people move through authentication, registration, and app screens, where flows stop, and how to improve app reliability. When analytics is enabled, we collect screen and funnel-step names, continue or stop actions, the names and count of missing fields only, broad calculation source or status categories, session and usage timing, general device category, and technical diagnostic information. As part of the SDK's default operation, Google Analytics for Firebase may also process a pseudonymous App Instance ID, general device information, and coarse location derived from a masked IP address.
Google Mobile Ads may process app interactions, diagnostics, approximate location and device identifiers for advertising, analytics and fraud prevention. CaloTec-AI does not log diary, health or profile values as Analytics events.
Analytics data is sent to Google Analytics over an encrypted connection and is processed under the Google Analytics for Firebase terms and policies.
Analytics is used only to improve the product, is not required for the app's core features, and is not used to make health decisions. You can turn it off at any time at Settings → Privacy & Consent → Analytics. After you turn it off, no new analytics events are sent. Turning collection off does not automatically delete data already processed; for a privacy or deletion request, contact support@calotec.app.
How We Use Your Data?
The local diary is used to display tracking and statistics on your device. Information leaves the device only when an online feature needs it, as described on this page.
- Meal description: nutrition estimate through Gemini or DeepSeek
- Account details: authentication and management through Firebase
- Usage events, when enabled: improving flows through Firebase Analytics
How We Store and Protect Your Data?
The diary is stored in the app's local storage. Information sent to external providers travels over an encrypted connection; its handling is also subject to the provider's security and policies.
- Diary and profile data in the app's local storage
- TLS for requests to external services
- No system can guarantee absolute security
Do We Share Your Data with Third Parties?
We do not sell data. To provide specific features, information is processed by Google Gemini, DeepSeek, Firebase and Google Mobile Ads. The data type and purpose are listed in the table above.
What Permissions Do We Request?
We only request the permissions necessary to provide you with our services. You can control these permissions in your device settings.
- Microphone: transcribe a spoken meal description after you start recording
- Camera: take a profile photo or an image for a supplement entry after you choose the camera option
- Activity recognition: count steps using the device sensors
- Health Connect: read step count only
- Notifications and exact scheduling: show reminders at the selected time; can be disabled in settings
What Are Your Rights?
You can edit or delete the local diary in the app, revoke step permissions in Android and Health Connect, turn off analytics and notifications, and delete an account you created. Contact support with questions about information already processed by an external provider.
- Edit and delete local information
- Delete an account through the app
- Contact: support@calotec.app
How We Protect Your Data?
We use the app's on-device storage and encrypted connections to external services. No system is completely secure.
- Encryption in transit (TLS)
- Food diary and step data stay on the device; a meal description is sent for analysis only when you request it
- Reasonable safeguards; no system is 100% secure
How Long Do We Keep Your Data?
The diary stays on your device until you delete it or clear the app's data. You can delete an account you created from the app. Information already sent to an external provider is handled under that provider's retention policy.
- Delete the diary and local data in the app or Android settings
- Delete an account created in the app
External Provider Policies
Google, Firebase and DeepSeek process information under their own policies and terms. Links to Google and Firebase policies appear on this page; contact support about a personal request.
- Regional ad-consent choices through Google UMP
- Privacy requests: support@calotec.app
How Will You Be Notified of Changes?
We may update this privacy policy from time to time. Changes will be published on this page with the updated revision date.
Is Our App Intended for Children?
Our app is not intended for children under the age of 13, and we do not knowingly collect personal information from children.
Have Questions?
If you have any questions or concerns about our privacy policy, please contact us.
support@calotec.app
When Is This Policy Effective?
This privacy policy is effective as of August 10, 2026.
Legal Commitment
1. Information Collection
Depending on the device and permissions, step counts come from device sensors, Fitness Local Recording, or Health Connect. We read step count only from Health Connect. Your diary, weight and goals stay on-device. If you create an account, Firebase processes your name, email address and user ID. Firebase Cloud Messaging processes an installation ID, token and language topics for notifications.
2. Information Usage
A meal description is sent to Google Gemini for a nutrition estimate, with DeepSeek used if Gemini fails or is unavailable. A supplement-label image is sent to Gemini only when you start a scan. Analytics data, when collection is enabled, is used to review flows and reliability.
3. Information Sharing
We do not sell data. Google Gemini and DeepSeek receive the content required for analysis you initiate. Firebase processes account, Analytics and notification data. Google Mobile Ads may process interactions, diagnostics, approximate location and device IDs for advertising, analytics and fraud prevention.
4. Data Security
Step counts and the diary stay on-device. Requests to Gemini, DeepSeek and Google services are sent over encrypted connections. Handling after transfer is also subject to each provider's safeguards and policies. No system is completely secure.
5. User Rights
You can revoke step permissions in Android and Health Connect, turn off Analytics at Settings → Privacy & Consent → Analytics, disable notifications in Android settings, and manage ad choices in the consent screen available in your region. You can delete an account you created from the app.
Last Updated
This privacy policy was last updated on August 10, 2026
Privacy Questions?
Have questions about our privacy policy? We're here to answer any question