Privacy Policy
Who we are
Caloroot is built and operated by Synkify, a sole proprietorship (eenmanszaak) registered in the Netherlands and run by Karam Ghazzi. Synkify is the data controller for the personal data described on this page.
Contact: krmghazzi@gmail.com
Location: Amsterdam, Netherlands
What Caloroot collects
Account information
Your email address, and a password stored only as a salted hash by our authentication provider. If you sign in with Google instead, we receive your email address and Google account identifier. We never see your Google password.
Profile and goals
Your sex, age, height, weight, activity level and weight goal. Caloroot uses these to calculate your daily calorie and macronutrient targets, and stores the calculated targets on your profile so that changing the formula later cannot silently rewrite your history.
Food logs
The foods you log, the quantities, and when you logged them.
Meal photos, if you use AI scanning
This feature is optional, and how your photo travels depends on which of the two modes you are using.
If you use your own API key, the photo goes directly from your device to the AI provider you chose, authenticated with your own key. The photo does not pass through Caloroot’s servers and Caloroot never sees or stores it. What that provider does with the image is governed by their privacy policy, so please read theirs.
If you use a Caloroot subscription, the photo is sent to Caloroot’s servers, which forward it to our AI provider using our key and return the result to you. We use the photo only to produce that one nutrition estimate. It is not stored after the scan completes, not used to train any model, and not linked to your profile beyond the log entry you choose to save.
In both modes the estimate you get back is generated by a third-party AI model and can be wrong. Check it against the label where accuracy matters.
Your AI provider API key
This applies only if you bring your own key. It is stored in your device’s secure keychain under the account that entered it, never leaves your device except in requests you initiate to your chosen provider, and is never transmitted to Caloroot.
Subscription and payment
If you subscribe, the payment itself is handled entirely by Google Play Billing. Caloroot never receives or stores your card number, bank details or billing address. We receive only your subscription status, meaning whether it is active and when it renews or lapses, which is what tells the app whether to allow server-side AI scanning.
Barcode lookups
When you scan a barcode, the barcode number alone is sent to Open Food Facts to look up product information. No account data goes with it.
Advertising
Caloroot shows banner ads supplied by Google AdMob. To serve them, the Google Mobile Ads SDK reads your device’s advertising ID and sends it, together with coarse technical information about the device and the ad request, to Google. That identifier is not linked to your Caloroot account, and your food logs, weight, profile and meal photos are never shared with Google for advertising.
The advertising ID is resettable, and can be deleted entirely, from your device settings under Privacy then Ads. Google explains how it uses data from apps that use its services at policies.google.com/technologies/partner-sites.
What we do not collect
- No analytics or tracking SDKs.
- No location data, contacts, or device fingerprinting.
Where your data is stored
Account, profile and log data is held in a PostgreSQL database hosted by Supabase Inc. Access is enforced by row level security, meaning each account can read and write only its own rows. All data is encrypted in transit using TLS.
Who we share data with
Caloroot does not sell personal data, and never shares your account, profile, food logs, weight or meal photos for advertising. Data reaches these parties only as needed to run the service:
- Supabase for the database and authentication.
- Google for sign-in, if you choose it, for app distribution through Google Play, and, through AdMob, for the banner ads described above, which receive your device’s advertising ID.
- Expo for over-the-air app updates. No account data is involved.
- Open Food Facts for barcode lookups.
- The AI provider you choose, for meal photos only, at your instruction and with your own key, if you bring your own key.
- Our AI provider, for meal photos only, if you scan using a Caloroot subscription. The image is sent for the single purpose of producing your nutrition estimate.
Legal basis for processing
- Performance of a contract for your account and the core tracking features.
- Consent for camera access, photo access and AI scanning. You can withdraw it at any time in Android settings, or simply by not using those features.
- Legitimate interest in keeping the service secure and working correctly, and in showing advertising that keeps the app free. You can limit ad personalisation, or reset the advertising ID, in your Android settings.
How long we keep it
Until you delete your account. Once you request deletion, your account, profile and logs are removed within 30 days. See Delete your account.
Your rights
Under the GDPR you may request access to your data, correction of it, erasure, restriction of processing, portability, or object to processing. Email krmghazzi@gmail.com and we will respond within 30 days.
If you are unhappy with how we handle your request, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens.
Children
Caloroot is intended for adults. It is not designed for anyone under 18 and we do not knowingly collect data from children.
Not medical advice
Caloroot produces general nutrition estimates using standard formulas. It is not medical advice and is not a substitute for a doctor or a registered dietitian. Speak to a healthcare professional before making significant changes to your diet, particularly if you have a medical condition.
Changes to this policy
If we change how Caloroot handles data, we will update this page and change the date at the top.