Privacy Policy
Last Updated: January 9, 2026
Version: 2.0
1. Introduction and Data Controller
Calibite ("we," "our," "us," or the "Company") is committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard your information when you use our mobile application and website (collectively, the "Service").
Data Controller: Calibite
Denmark
Email: privacy@calibite.app
Support: support@calibite.app
By using our Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our practices, please do not use our Service.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Email address, name, profile photo
- Health & Fitness Data: Weight, height, age, sex, activity level, health goals
- Nutrition Data: Food logs, meal photos, dietary preferences, allergies
- User Content: Notes, custom foods
- Payment Information: Subscription status (payment details processed by Apple/Google)
- Communications: Support requests, feedback, survey responses
2.2 Information Collected Automatically
- Device Information: Device type, model, operating system, unique device identifiers
- Usage Data: Features used, screens viewed, session duration, interaction patterns
- Log Data: IP address, access times, app crashes, error logs
- Location Data: Country/region (not precise location)
2.3 Information from Third Parties
- Apple Health / HealthKit: Steps, active energy, workouts, heart rate (with your permission)
- Google Fit / Health Connect: Steps, calories, activity data (with your permission)
- Authentication Providers: Google/Apple Sign-In profile data
- App Stores: Subscription status, purchase history
2.4 Sensitive Data
We process health and fitness data which may be considered sensitive under certain laws. We only collect this data with your explicit consent and use it solely to provide our core Service functionality.
3. How We Use Your Information
3.1 Legal Bases for Processing (GDPR)
- Contract Performance: Provide core Service, AI-powered nutrition analysis, account management
- Legitimate Interest: Analytics, improvement, security, fraud prevention, customer support
- Consent: Marketing communications, personalized advertising
- Legal Obligation: Complying with applicable laws
3.2 Specific Uses
- Provide and personalize the Service - Generate AI-powered nutrition insights, track progress, deliver recommendations
- Process food photos - Analyze images using AI to identify foods and estimate nutritional content
- Sync health data - Integrate with Apple Health/Google Fit for comprehensive tracking
- Send notifications - Meal reminders, progress updates, and goal achievements (configurable)
- Improve the Service - Analyze usage patterns to enhance features and fix issues
- Ensure security - Detect and prevent fraud, abuse, and security incidents
- Comply with law - Respond to legal requests and enforce our terms
4. Advertising and Analytics
4.1 Advertising (Free Tier Users)
We display advertisements to users on our free tier through Google AdMob. We participate in the IAB Transparency and Consent Framework (TCF) and comply with applicable advertising regulations.
Your Choices:
- Opt out of personalized advertising through your device settings
- Upgrade to Premium for an ad-free experience
- Manage consent preferences in app settings
4.2 Analytics Services
We use analytics to understand how users interact with our Service:
- Firebase Analytics: Anonymous usage events, device info
- Firebase Crashlytics: Crash logs, device state, stack traces
- Firebase Performance: App performance metrics
All analytics data is aggregated and does not identify individual users.
5. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
5.1 Service Providers (Data Processors)
We share data with trusted service providers who process data on our behalf:
- Google Cloud / Firebase: Cloud infrastructure, authentication, database
- Google AdMob: Advertising (free tier)
- OpenAI: AI food analysis (via secure API, anonymized)
- Apple / Google: Payment processing, app distribution
All processors are bound by Data Processing Agreements (DPAs) and are required to protect your data in accordance with this policy and applicable law.
5.2 Other Disclosures
- Legal Requirements: When required by law, court order, or government request
- Safety: To protect the rights, safety, or property of Calibite, our users, or the public
- Business Transfers: In connection with a merger, acquisition, bankruptcy, or sale of assets (you will be notified)
- With Your Consent: When you explicitly authorize sharing
6. International Data Transfers
Your data may be transferred to and processed in countries outside your residence, including the United States.
Transfer Mechanisms
For transfers from the EEA/UK/Switzerland to the USA, we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Data Processing Agreements with all processors
- Supplementary measures including encryption and access controls
7. Data Retention
We retain your data only as long as necessary for the purposes described in this policy.
- Account data: Duration of account + 30 days
- Health & nutrition logs: Duration of account + 30 days
- Food photos: 90 days after processing, then deleted
- Analytics data: 14 months (aggregated)
- Crash reports: 90 days
- Support communications: 2 years
- Legal/compliance records: 7 years
After account deletion: Personal data is deleted within 30 days. Anonymized/aggregated data may be retained indefinitely. Backups are purged within 90 days.
8. Data Security
We implement comprehensive security measures to protect your data:
Technical Measures
- Encryption in transit: TLS 1.3 for all data transmission
- Encryption at rest: AES-256 encryption for stored data
- Authentication: Secure authentication with optional biometric login
- Access controls: Role-based access, principle of least privilege
- Infrastructure: Enterprise-grade cloud security (Google Cloud)
Incident Response
In the event of a data breach affecting your personal data, we will notify affected users within 72 hours (as required by GDPR), notify relevant supervisory authorities as required by law, and take immediate steps to mitigate harm.
9. Your Rights
9.1 Rights for All Users
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate data
- Deletion: Request deletion of your data ("right to be forgotten")
- Export: Receive your data in a portable format (JSON/CSV)
- Opt-out: Unsubscribe from marketing communications
- Withdraw consent: Revoke previously given consent
9.2 Additional Rights for EEA/UK Residents (GDPR)
- Restriction: Request limitation of processing
- Objection: Object to processing based on legitimate interest
- Automated decisions: Not be subject to solely automated decisions with legal effects
- Complaint: Lodge a complaint with your local Data Protection Authority
Supervisory Authorities: Denmark: Datatilsynet (datatilsynet.dk) | UK: Information Commissioner's Office (ico.org.uk)
9.3 Additional Rights for California Residents (CCPA/CPRA)
- Right to Know: Categories and specific pieces of personal information collected
- Right to Delete: Request deletion of personal information
- Right to Correct: Correct inaccurate personal information
- Right to Opt-Out: Opt out of "sale" or "sharing" of personal information
- Non-Discrimination: Equal service regardless of privacy choices
We do not "sell" or "share" your personal information as defined by CCPA/CPRA.
9.4 How to Exercise Your Rights
In-App: Settings → Privacy → Manage My Data
Email: privacy@calibite.app
Response Time: Within 30 days (extendable by 60 days for complex requests)
10. Children's Privacy
Our Service is not intended for children under 16 years of age (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children under 16. If we discover we have collected data from a child under 16, we will delete it immediately. If you believe a child has provided us with personal data, contact us at privacy@calibite.app.
11. Third-Party Links and Services
Our Service may contain links to third-party websites or integrate with third-party services (Apple Health, Google Fit). This Privacy Policy does not apply to those third parties. We encourage you to review their privacy policies.
12. Do Not Track Signals
Our Service does not currently respond to "Do Not Track" browser signals. However, you can control tracking through device advertising settings, in-app privacy controls, and browser privacy settings.
13. Changes to This Policy
We may update this Privacy Policy periodically. When we make material changes, we will update the "Last Updated" date, notify you via email or in-app notification, and obtain consent where required by law. Continued use of the Service after changes constitutes acceptance of the updated policy.
14. Contact Us
General Inquiries: support@calibite.app
Privacy Inquiries: privacy@calibite.app
Location: Denmark
15. Jurisdiction-Specific Disclosures
- EEA, UK, and Switzerland: See Sections 3.1, 6, and 9.2 for GDPR-specific information
- California, USA: See Section 9.3 for CCPA/CPRA rights. We do not sell or share personal information.
- Other US States: We comply with applicable state privacy laws including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), and Utah (UCPA)
- Brazil (LGPD): Brazilian residents have rights similar to GDPR rights described in Section 9.2
This Privacy Policy is provided in English. Translations may be provided for convenience, but the English version governs.