CaliFit is a nutrition and fitness tracker. We collect the minimum needed to run it. Everything you log works offline and lives on your device; if you sign in and enable cloud sync, a copy is kept in our database so you don't lose your history when you change phones. We do not sell your data, and we never use health data for advertising.
When you sign up we receive your email address, and your name if your sign-in provider supplies one. This is held by Google Firebase Authentication on our behalf so you can sign in. If you use Sign in with Apple and choose to hide your email, we only ever see Apple's relay address.
Foods logged, calories and macros, workouts and exercise sets, body weight, body measurements, water and creatine intake, saved meals, goals and plans. This is stored on your device. When you are signed in, a copy is also stored in our Supabase database so it survives a lost or replaced phone. Your rows are isolated to your account by database-enforced row-level security: no other user can read them.
Health syncing is off by default. If you enable it, and only for the metrics you switch on:
Data read from Apple Health or Health Connect is used only to show you your own progress inside CaliFit. It is never used for advertising, never sold, never shared with third parties, and never used for any purpose other than the feature you enabled it for. You can switch any metric off, or revoke access entirely from Apple Health or Health Connect, at any time — CaliFit keeps working without it.
If you use AI photo logging, the photo is sent to our processing function and on to Google's Gemini API to identify the foods. The photo is used for that request and is not stored by us afterwards.
If you subscribe, RevenueCat and your app store (Apple or Google) process the purchase and tell us whether your subscription is active. We never receive your payment card details.
When the app crashes or hits an error it handles internally, we receive a crash report through Google Firebase Crashlytics: the error and its stack trace, your device model, operating system version, app version, and your account identifier so a support request can be matched to the crash behind it. Crash reports contain no food diary, workout, photo or measurement content.
Your Firebase authentication token accompanies AI requests so we can enforce usage limits per account. We log request outcomes without photo contents or personal identifiers.
| Purpose | Lawful basis (GDPR) |
|---|---|
| Creating and securing your account | Performance of a contract |
| Storing and syncing the data you log | Performance of a contract |
| Analyzing meal photos you submit | Performance of a contract |
| Enforcing free-tier usage limits | Legitimate interest (preventing abuse) |
| Managing subscriptions | Performance of a contract |
| Diagnosing crashes and errors | Legitimate interest (keeping the app working) |
Health data is a special category under GDPR Article 9. We process it only on the basis of your explicit consent, given by entering it into the app, and you can withdraw it at any time by deleting your data (Section 7).
Only the processors needed to run the app:
| Processor | What they handle |
|---|---|
| Google Firebase Authentication | Your email/name, for sign-in |
| Google Firebase Crashlytics | Crash diagnostics and your account identifier |
| Supabase | Your synced diary, workouts and body data; hosts the photo-analysis function |
| Google Gemini API | Meal photos you submit, for analysis |
| RevenueCat | Subscription status |
| Apple / Google | Payment processing |
Each acts under contract and may not use your data for their own purposes. We disclose data to authorities only where legally required.
Data you log stays on your device until you delete it or uninstall the app.
Synced copies stay in our database until you delete them. Deleting an item marks it as deleted immediately — it disappears from every device you use — and the remaining record is purged within 90 days. Deleting your account removes your account and all associated rows. Meal photos are not retained after analysis. Crash reports are retained for 90 days by Firebase Crashlytics.
In the app, under Profile → Privacy & security:
If you can no longer sign in, use the account deletion request page and we will delete it for you.
Under GDPR/UK GDPR you also have rights of access, rectification, erasure, restriction, objection, and to lodge a complaint with your supervisory authority. Under the CCPA, California residents have rights to know, delete, correct and opt out of sale — we do not sell data, so there is nothing to opt out of. Email us at the address above and we will respond within 30 days.
Deleting your account does not cancel your subscription. Subscriptions are billed by Apple or Google; cancel in your store account settings.
CaliFit is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.
Data in transit is encrypted with TLS. Data in our database is encrypted at rest and partitioned per account by row-level security policies enforced by the database itself, not by application code. Authentication tokens are held in the platform keychain/keystore. API keys for our processors live only on the server and never in the app. Access to production systems is limited to those who need it. Because a copy of your logged data is also stored on your device, its security there depends on your device passcode and encryption.
Our processors are US-based and may process data outside your country. Transfers from the EEA/UK rely on Standard Contractual Clauses or an adequacy decision.
We will update the date at the top when this policy changes, and notify you in the app for material changes.
Questions or requests: evotechnologiesinnovation@gmail.com