// Privacy Policy
Kalorii (Калории) — Privacy Policy
Kalorii (Калории) is a nutrition and weight tracking app published by OPTIFLOW LABS LTD. This policy explains what the app records, what stays on your phone, and what leaves it. Your health data stays on your device unless you turn on a feature that needs to send it.
Who we are
Kalorii (Калории) is operated by OPTIFLOW LABS LTD, a private limited company registered in England and Wales under company number 16896823, with its registered office at Flat 41 Albany Park Court, 3 Westwood Road, Southampton, England, SO17 1LA. We are the data controller for the personal data described here.
You can reach us at saf@safarisaev.ai.
Your health data stays on your device
Everything you record in the app — weight, food entries, body measurements, body fat percentage, strength sets and journal notes — is written to a local SQLite database on your phone. By default it is not transmitted anywhere. It stays on the device, and removing the app removes it.
The sections below describe the specific cases where data does leave the device. Each one is either something you switch on yourself, or something you trigger by asking the app to do it.
Cloud sync (optional, off unless you enable it)
If you turn on cloud sync, your records are sent over an encrypted HTTPS connection and stored on Cloudflare infrastructure, tied to your app installation or, if you have signed in, to your Apple account.
This exists so you can restore your history on a new phone. You can delete the cloud copy from inside the app at any time; deleting it does not touch the copy on your device.
Calorie estimation from photos and text
When you ask the app to estimate a meal, the photo or the text description you provide is sent to our server and passed on to the Anthropic API, which returns the estimate to the app.
Neither the photo nor the description is stored on our server after the response is returned. We keep a simple per-installation request counter to limit abuse of the service; it records how many requests were made, never what they contained.
Sign in with Apple (optional)
Signing in is optional; the app works without an account. If you do sign in, we receive an identifier from Apple. Our server converts it into a hashed account identifier and stores only that hash — the original Apple identifier is not stored. If Apple provides your email address, we do not store it.
Apple Health (optional)
Only if you grant permission, the app reads your weight and body fat percentage from Apple Health, and writes weigh-ins you record back to it. This exchange happens on your device, under Apple's permission system, and you can withdraw it at any time in iOS Settings. We do not receive a copy of your Apple Health data.
Product analytics
To understand how the app is used — whether people finish onboarding, which way they log meals, where they stop — the app sends a small set of product events to PostHog, our analytics provider, on its European Union hosting.
What is sent is limited to event names and coarse properties: that the app was opened, that an entry was logged and by which input method, which onboarding step was completed, the interface language.
Events are grouped under an identifier generated at random on your device. It is deliberately separate from the identifier the app uses with our own server, so the two sets of records cannot be joined, and it is connected neither to your Apple account nor to your email address.
We do not use PostHog's SDK. The app posts the events itself, which means the vendor's automatic capture of taps and screens, and session replay, are not merely switched off — they are absent.
Data that never goes to analytics
- —Your weight, and any change in it
- —Food names or descriptions of what you ate
- —Calorie figures
- —Body fat percentage and body measurements
- —Strength training entries
- —Journal notes
None of the above reaches analytics. The app's code carries a catalogue of the properties each event may contain, and any property outside it is dropped before the event is sent — the restriction is a structure in the code, covered by a test, not a promise in this text.
Posting the events ourselves rather than through the vendor's SDK is what keeps that catalogue the only door: nothing gets the opportunity to add to what it allowed.
Subscriptions
Subscriptions are handled through RevenueCat and Apple. Your payment details are processed by Apple; the app never sees them. We receive the subscription status needed to unlock paid features.
Crash reports
If the app crashes, technical diagnostic information about the crash is sent to Sentry so the fault can be fixed. Crash reports do not include your health data.
Legal bases for processing
- —Performance of a contract — operating the app's core functionality, including cloud sync and subscriptions once you use them.
- —Your explicit consent — health data you choose to send off the device: cloud sync, calorie estimation from a photo or description, and Apple Health access. You can withdraw consent by turning the feature off, and by deleting the cloud copy from within the app.
- —Our legitimate interests — product analytics limited to the coarse events described above, and crash reporting, so that the app can be improved and kept working.
How long we keep data
Data on your device stays until you delete it or remove the app. A cloud sync copy is kept until you delete it from within the app. Photos and descriptions sent for calorie estimation are not retained after the response. Analytics events and crash reports are kept no longer than is necessary for the purposes described above.
Your rights
Under the UK GDPR and the EU GDPR you have the right to access your personal data, to have inaccurate data corrected, to have data erased, to receive a copy in a portable format, to restrict or object to certain processing, and to withdraw consent at any time.
Two of these are built into the app rather than being a promise on paper: you can export your entire history to a JSON file from within the app, and you can delete your cloud copy from within the app. For anything else, write to us and we will act on your request.
You also have the right to complain to a supervisory authority — in the United Kingdom, the Information Commissioner's Office (ico.org.uk).
Children
The app is not intended for children under 13, and we do not knowingly collect personal data from them. If you believe a child has provided us with personal data, contact us and we will delete it.
No advertising
The app shows no advertising, uses no advertising identifiers, and takes part in no ad networks. We do not sell your personal data and we do not share it for advertising or profiling.
Changes to this policy
If this policy changes, the updated version is published on this page with a new date at the top. Material changes affecting how your data is handled will also be surfaced in the app.
Contact
Questions about this policy, or a request to exercise any of the rights above: saf@safarisaev.ai. Postal address and registration details are on our legal information page.
saf@safarisaev.ai