Legal
Privacy Policy
Last updated: July 22, 2026
This Privacy Policy explains how CalorieAI ("the app", "we", "us") handles your data. CalorieAI is a calorie- and nutrition-tracking app. Questions? Email us at privacy@foodcounter.app.
Summary
We do not show ads, we do not sell your data, and we do not use third-party analytics or trackers. Your data is stored on your device and — when you sign in — synced to our database hosted in the European Union (Frankfurt), so you never lose it when you switch phones. Data leaves this environment only where needed to provide a feature, such as analysing a meal photo or looking up a product.
Your account
AI features and cloud sync require a free account. You can sign in with an email and password or with your Google account. We store your email address and, for password sign-in, a securely hashed password with our authentication provider, Supabase (EU region). If you sign in with Google, Google verifies your identity and shares your email address with us — we never receive your Google password. We use your email only for account purposes (sign-in, password reset, account notices) — never for marketing, unless you separately opt in.
Data we store (on your device and in the cloud)
The following is stored locally on your device and, when signed in, synced to our EU-hosted database linked to your account:
- Profile: optional name and photo, age, height, weight, sex, activity level, workouts per week and goal (used to calculate your calorie and macro targets).
- Food diary: logged meals and products, daily notes, weight entries, saved products, favourite meals and saved recipes, including small thumbnails of photos you analysed.
- Usage metering: a count of your AI analyses (used for the free tier and fair-use limits) and technical logs of AI requests (model, tokens, cost, success) — not the content of your meals.
- Settings: your chosen language and preferences (stored on the device only).
You can delete individual items in the app at any time, or delete your entire account and all associated cloud data (see "Your rights" below).
Data sent off your device
- Meal photos & text descriptions you submit for AI analysis are sent over an encrypted connection to our server (hosted on Vercel) and forwarded to the AI provider (OpenAI) solely to estimate the foods and their nutrition. Our server does not retain the photos.
- Barcodes and search terms are sent to OpenFoodFacts and, if enabled, the USDA FoodData Central database, to look up product information.
- Recipe searches are forwarded by our server to Spoonacular to find recipes and their nutrition.
- Food images shown in the app are loaded from Pexels; your device requests them directly.
Subscriptions and payments
CalorieAI Pro subscriptions are sold through Google Play. Google processes the payment; we never see your payment details. We receive and store only what is needed to activate your subscription: the plan, its expiry date and a purchase token that we verify with Google.
Third parties (processors)
Depending on the features you use, data may be processed by Supabase (database & authentication, EU region), Vercel (our server), OpenAI (privacy policy), OpenFoodFacts, USDA FoodData Central, Spoonacular, Pexels, Google Sign-In (optional login) and Google Play (payments). These parties process data on our behalf or as independent services; please refer to their policies for their own processing.
AI estimates are not advice
Nutrition values produced by the app are AI-generated estimates with a margin of error. They are not medical or dietary advice and are not a substitute for reading product labels or consulting a professional.
Children
The app is not directed at children under 16. We do not knowingly process data from children.
Your rights (GDPR)
Under the GDPR you have the right to access, correct, export and delete your data. In the app you can export all your data (Settings → Back-up) and delete your account including all cloud data (Settings → Account). You can also request deletion by emailing privacy@foodcounter.app from your account email address; we will complete the deletion within 30 days.
Retention
Your account data is kept for as long as your account exists. When you delete your account, all associated cloud data is deleted. Technical server logs are kept briefly for security and abuse prevention.
Security
All connections use encryption (HTTPS). Cloud data is protected with row-level security so it is only accessible from your own account. Sensitive values on your device are stored in encrypted storage.
Changes
We may update this policy; the date at the top reflects the latest version.