Privacy Policy
Effective date: 30 September 2026
Kalo ("the App") is a calorie tracker developed by Volodymyr Symonchuk ("we", "us"). It is designed to collect as little data as possible. This policy explains what is handled, where, and by whom.
The short version
- Your food diary, weight, water and profile settings stay on your phone. We never see them.
- Food photos and text descriptions are sent to our server and passed on to Anthropic's Claude API to recognise the food. We do not store the photos or the text.
- The App does not ask for a name, e-mail, phone number or location. There is no account: your phone is identified by a random ID.
- No advertising, no data selling, no analytics or tracking SDKs. Crash reports go to Sentry.
Data kept on your device
Your diary entries, daily goal and macros, profile parameters (sex, age, height, weight, activity level), weight history, water intake, saved products and reminder settings. They live in the App's private storage, protected by your device's security, and are included in device backups you control (iCloud or Google). Settings → "Delete all entries" wipes them; deleting the App removes everything.
Data that goes through our server
When you use photo recognition or "describe in words", the App sends the photo or the text to our server (api.kaloapp.app, hosted by Hetzner in Germany). The server forwards it over an encrypted connection to Anthropic's Claude API, returns the result to you and discards the photo and the text. Anthropic processes the content under its own policy: https://www.anthropic.com/legal/privacy. Anthropic does not use API data to train its models.
For each request the server keeps a technical record: your device's random ID, the date and time, the model used, the number of tokens processed, the calculated cost, the duration and whether the request succeeded. This record contains no photo, no text and no nutrition result. We keep it to enforce the free and Pro limits, to detect abuse and to understand our costs. Records are deleted after 12 months.
Device identifier and subscriptions
On first launch the App generates a random device identifier and registers it with our server. It is not linked to your name, Apple ID or Google account and cannot identify you as a person. It is used to count your free scans and to remember whether Pro is active.
Pro subscriptions are sold through the Apple App Store or Google Play. We never see your payment details. To activate Pro we use RevenueCat, which receives your device identifier and the subscription status from the store. RevenueCat's policy: https://www.revenuecat.com/privacy.
Other services
- Product search and barcodes: the search text or barcode number is sent to Open Food Facts, an open food database. Barcodes are recognised on the device; the camera image is not sent anywhere. Policy: https://world.openfoodfacts.org/privacy
- Crash reports: if the App crashes, a technical report (device model, OS version, stack trace) may be sent to Sentry. It contains no diary data or photos. Policy: https://sentry.io/privacy/
- Reminders and the home-screen widget work entirely on the device.
Permissions
- Camera: only to photograph food for recognition.
- Photos: only to pick a food photo from your library.
- Notifications: only for the reminders you enable.
Your choices
- You can use the App without ever taking a photo: manual entry, barcodes and search do not involve our server or Anthropic.
- To delete the technical records linked to your device identifier, e-mail us the identifier shown in Settings → About, or simply delete the App: the identifier is never reused and records expire after 12 months.
Children
The App is not intended for children under 13. Calorie tracking is not recommended for minors without adult supervision.
Changes
If this policy changes we will update the date at the top and, for significant changes, notify you inside the App.
Contact
vova.symonchuk@gmail.com