1. Overview
This policy explains what Calorie CountAi ("the Service") collects, why it is collected, how long it is kept and what control you have over it. It applies to the Service only. The Adarsh Yadav website has its own privacy policy.
The Service is operated by Adarsh Yadav, an independent software developer working as a sole trader rather than an incorporated company. The guiding principle is simple: collect the minimum needed to make the product work, be explicit about it, and delete it when it is no longer needed.
Your weight, body measurements, meals and photos are health information. They are collected only with your explicit consent, used only to run the app for you, never sold or used for advertising, and you can delete them at any time.
2. What is collected and why
Every category of data handled by the Service is listed below, together with its purpose and retention period.
| Category | Examples | Purpose | Retention |
|---|---|---|---|
| Account | Name, email address, sign-in method (Apple, Google or email) and an account ID | To sign you in and keep your diary with your account | Until you delete your account |
| Body and goal details | Sex, birth year, height, weight, goal weight, activity level, pace, calorie and macro targets | To work out your daily targets and show progress toward your goal | Until you erase your data or delete your account |
| Food diary and activity | Foods and meals logged, calories and nutrients, water, exercise, fasts, planned meals, grocery lists, saved meals | To keep your diary, streaks, badges, reports and widgets | Until you delete an entry, erase your data or delete your account |
| Photos | Meal photos and progress photos you take or choose | To show them in your diary and journal, and to estimate a meal when you ask the AI | Until you delete them, erase your data or delete your account |
| AI requests | A meal photo, a meal description, a food-label photo, Coach messages, and a short summary of today's diary and targets sent with Coach and meal-idea requests | To answer that request, only after you have allowed AI features | Not stored by the developer beyond the answer you save; the AI provider keeps them only as described below |
| AI permission and usage | Whether you allowed AI features and when, and a daily count of AI requests | To respect your choice and apply the fair-use limit | Permission until withdrawn or the account is deleted; counts for a few days |
| Subscription | Whether Pro is active, the plan, renewal date and store transaction IDs | To unlock Pro on every phone signed in to your account | For as long as the store and tax law require |
| Settings and agreement | Units, appearance, reminders, when you accepted these terms | To remember how you set the app up and record your consent | On your phone until changed or the app is deleted |
3. Permissions the app requests
Each permission is requested in context, with an explanation, at the moment it is first needed — never in a burst at first launch. Optional permissions can be declined and the app keeps working without them.
| Permission | Platform identifier | Why | Required |
|---|---|---|---|
| Camera | NSCameraUsageDescription | Optional — photograph meals, food labels and barcodes, and take progress photos. | Optional |
| Photo library | NSPhotoLibraryUsageDescription · NSPhotoLibraryAddUsageDescription | Optional — pick a meal or progress photo, and save a report or comparison to Photos when you ask. | Optional |
| Microphone and speech recognition | NSMicrophoneUsageDescription · NSSpeechRecognitionUsageDescription | Optional — describe a meal out loud. Speech is turned into text on your iPhone where it supports that, otherwise by Apple. | Optional |
| Notifications | UNUserNotificationCenter | Optional — meal, weigh-in, fasting and trial-ending reminders, scheduled on your phone. | Optional |
Any permission can be revoked at any time in your device settings. Revoking a required permission stops the features that depend on it, but does not delete your account or your data.
4. Health information and your consent
Weight, body measurements, meals and photos can reveal things about your health, and laws such as the GDPR treat them as special category data. Calorie CountAi processes them on the basis of your explicit consent, which you give when you tick the agreement on the first screen.
- They are used only to run the app for you: your targets, diary, progress, backup and the AI answers you ask for.
- They are never sold, never used for advertising and never shared with data brokers, insurers or employers.
- You can withdraw consent at any time by erasing your data (Profile → Erase all data) or deleting your account (Profile → your name → Delete account). Withdrawing doesn't affect what was done before.
5. AI features
AI features are part of Pro and need your permission first. Before your first AI request the app asks whether it may send what the feature needs to OpenAI, and you can turn this off at any time in Profile → AI & privacy.
- What is sent: the photo, description or label you chose, your Coach messages, and for the Coach and meal ideas a short summary of today's diary and targets. Your name and email are not sent.
- OpenAI processes requests through its API, which does not use them to train its models. The app asks OpenAI not to store them; OpenAI may keep them for up to 30 days to detect abuse, then deletes them.
- The developer's server checks your account and counts your requests for the daily fair-use limit, but does not keep the photo, text or answer. What you save is kept in your diary.
- If the AI provider ever changes, the app asks for your permission again before sending anything to the new one.
6. Backup and deleting your data
Your diary, body details and photos are backed up to your account automatically so you can restore them on a new phone. Only the app's server, acting for your account, can reach them.
- Profile → Erase all data deletes your diary, weigh-ins, photos and profile from your account and every phone signed in to it.
- Deleting your account removes it together with its backup and AI permission.
- Signing out removes the diary from that phone; it stays in your account until you delete it.
7. What is never done
- Your data is never sold, rented or traded.
- Your content is never used to train machine learning models.
- There is no advertising in the Service and no advertising trackers are embedded.
- No data is shared with data brokers.
- No profile is built about you for any purpose beyond operating the Service.
8. Legal basis for processing
Personal information is handled in line with applicable privacy law wherever you are. Where GDPR-style law applies, processing rests on one of the following bases:
- Contract — processing needed to provide the Service you signed up for.
- Legitimate interests — keeping the Service secure, reliable and free from abuse, balanced against your rights.
- Consent — optional features such as marketing email, which you can withdraw at any time.
- Legal obligation — retaining billing records where tax or accounting law requires it.
9. Service providers
The Service relies on the providers listed below, and only for the purposes described. Each receives only what it needs for that purpose and processes it on the developer's behalf, under its own security and data-protection commitments.
| Provider | Purpose | Region |
|---|---|---|
| Supabase | Stores the backup of your diary, body details and photos, and runs the server that checks your account before an AI request. | India (AWS Mumbai) |
| Clerk | Accounts and sign-in (name, email, sign-in method). | United States |
| OpenAI | Estimates meals from photos, descriptions and labels, and writes Coach replies and meal ideas — only after you allow AI features. Sent without your name or email. | United States |
| RevenueCat | Checks and records whether Pro is active for your account. | United States |
| Apple | App Store payments, Sign in with Apple, and speech recognition when it can't run on your phone. | Global |
| Sign in with Google, only if you choose it. | Global | |
| Open Food Facts | Barcode lookups and food search. Only the barcode or search words are sent. | France / EU (public open database) |
10. Security
- All traffic is encrypted in transit with TLS 1.2 or higher.
- Data at rest is encrypted using provider-managed encryption.
- Access to production systems is restricted, individually credentialed and requires multi-factor authentication.
- Secrets are stored in a managed secret store, never in source control.
- Dependencies are monitored for known vulnerabilities and patched on a regular cadence.
No system is perfectly secure. If a breach affecting your personal data occurs, you will be notified without undue delay, and the relevant supervisory authority within 72 hours where the law requires it.
11. Your rights
Regardless of where you live, you can exercise all of the following:
- Access — request a copy of the data held about you.
- Correction — fix anything inaccurate.
- Deletion — remove your account and associated data.
- Portability — export your data in a machine-readable format.
- Objection and restriction — object to or limit certain processing.
- Withdraw consent — for anything based on consent, at any time.
Most of these are self-service inside the Service. For anything else, email support@adarshyadav.com and it will be actioned within 30 days.
12. Regional privacy rights
The rights above are offered to everyone, everywhere. Some regions add specific rights or wording, set out below. Exercising any of them is free, and you will never be treated differently for doing so.
| Region | Framework | What it adds |
|---|---|---|
| European Economic Area | GDPR | Legal bases as listed above, data portability, objection to processing, and the right to lodge a complaint with your supervisory authority. |
| United Kingdom | UK GDPR & Data Protection Act 2018 | The same rights as the EEA, with complaints directed to the Information Commissioner's Office (ico.org.uk). |
| California | CCPA / CPRA | Rights to know, delete, correct and opt out of sale or sharing. No personal information is sold or shared for cross-context behavioural advertising, so there is nothing to opt out of. Sensitive information is used only to provide the Service. |
| Canada | PIPEDA | Access and correction rights, meaningful consent, and the right to complain to the Office of the Privacy Commissioner of Canada. |
| Brazil | LGPD | Confirmation of processing, access, correction, anonymisation, portability, deletion, and information about data sharing. |
If your region is not listed, the rights in the previous section still apply — email support@adarshyadav.com and your request will be handled the same way.
No authorised agent, verification fee or account requirement stands between you and these rights. Requests are verified only to the extent needed to confirm you are the person the data relates to.
13. Retention and deletion
Data is kept only as long as the purpose in the table above requires. When you delete your account, associated data is removed from production systems within 30 days and purged from encrypted backups within 90 days, except where a legal obligation requires longer retention.
14. International transfers
The providers listed above may process data outside your country. Where personal data leaves the UK or EEA, transfers are covered by Standard Contractual Clauses or an equivalent approved safeguard.
15. Children
The Service is not directed at children under 18. Accounts are not knowingly created for anyone under that age. If you believe a child has provided personal data, email support@adarshyadav.com and it will be deleted promptly.
16. Changes to this policy
If this policy changes materially, the effective date is updated and account holders are notified by email before the change takes effect. Past versions are available on request.
17. Contact
Questions, requests or complaints about privacy: support@adarshyadav.com. If you are not satisfied with the response, you can complain to the data protection authority in your country.