Your information
App Privacy Policy
Calorimeter is operated by Bogdan Dovgopol, based in Australia, and is available globally. This policy describes the Calorimeter mobile app and the services it uses. For the previous app privacy policy, see the policy archive.
For questions, concerns or privacy requests, email info@calorimeter.app.
Apple Health and saved records
With your permission, Calorimeter reads Apple Health records to show energy, nutrition, recorded workouts, weight and progress, and to support goal calculations and personal burn estimates. Requested categories include active and resting energy; nutrition; workouts, physical effort, heart rate and cycling power; weight, height and body fat; date of birth and biological sex. The categories used depend on the feature, available records and permissions you grant. Requesting permission does not mean every category is continually read.
Calorimeter also requests permission to write nutrition and active energy records. Food logs and quick entries can write records to Apple Health when you allow this. You can review or revoke permissions through Apple’s Health and system settings. Revoking access can limit features; it does not delete existing Health records or disable analytics and diagnostics.
Food logs, favorites, custom foods, recipes, goals and goal-achievement records are stored locally using Apple’s SwiftData system, with automatic iCloud synchronization through CloudKit. Synchronization depends on your Apple account, settings and connectivity. The Watch companion receives selected settings and summary snapshots from your iPhone and also reads permitted Health data locally.
The app’s normal food-search and community-submission requests do not upload your meal diary or Apple Health records to our food backend. Some information leaves your device through the separate services below. Diagnostic error content can include information arising from Health or saved-record workflows.
Apple controls its Health and iCloud services. Read Apple’s Health privacy information and Apple’s Privacy Policy.
Online food search, barcodes and community submissions
Online food search sends your search terms and pagination to Calorimeter’s backend. Remote barcode lookup sends the barcode; food-detail requests identify the selected catalogue item. Requests also include app version and language information. Barcode lookup can request product data from Open Food Facts through our backend. See Open Food Facts’ privacy information.
If you choose to submit a custom food to the community catalogue, its name, optional brand and barcode, nutrients, serving information and language are sent to our backend for review. Correction and submission-status requests identify the relevant submission. These payloads do not include a name, email address or app account identity for the person submitting them. Approved food information can become available to other users.
Technical request information, including IP addresses, is processed to deliver and protect these services. The backend uses IP addresses for rate limiting; community-submission limits use a daily keyed hash of the IP address. Service logs can include requested paths, search queries, barcodes and error details. This technical processing is separate from the submitted food information.
Analytics, purchases and diagnostics
TelemetryDeck analytics
TelemetryDeck starts when the app launches. It receives usage events and session information to help us understand and improve the app. Current app events concern subscription screens, purchases and restoration, purchase results, subscription status and usage-limit interactions. Parameters can include the entry source, product identifier, trial eligibility, restriction reason and result. The SDK also supplies technical context such as app and operating-system version, device model, language, region and accessibility settings.
TelemetryDeck uses a hashed identifier derived from a device vendor identifier. Calorimeter passes the TelemetryDeck app identifier and hashed user identifier to RevenueCat as integration attributes, allowing usage and purchase information to be associated. Current explicit analytics calls do not send Health measurements, food-search text or barcodes. See TelemetryDeck’s Privacy Policy and its SDK parameter documentation.
Apple and RevenueCat purchases
Apple processes App Store purchases. RevenueCat helps verify purchases, restore access and manage subscriptions. It receives a generated app user identifier, purchase and subscription records, receipt or transaction information and app/device context. We do not supply a custom account name or email to RevenueCat from the app. SDK diagnostics are enabled to collect performance and debugging information. Calorimeter also enables Apple Search Ads attribution-token collection through Apple’s AdServices framework.
Read RevenueCat’s Privacy Policy, its Apple Search Ads documentation and Apple’s Privacy Policy. The app does not include the AdMob advertising integration.
Bugsnag app diagnostics
Bugsnag runs in production to help identify crashes and errors. Reports can include error messages, stack traces, app and device information, session information, a generated device identifier and diagnostic breadcrumbs. Explicit app reports also include the source file and line number. Error descriptions from libraries or app workflows may contain user-provided content or data related to those workflows. We therefore cannot promise that reports never contain such information.
See Bugsnag’s captured-data documentation and SmartBear’s Privacy Policy.
Feature requests, issue feedback and support
Feature requests and the hosted feedback board use FeaturesVote. Requests can include text, optional image attachments and contact details you choose to provide. The native request flow sends a persistent SDK identifier and a purchase amount associated with an eligible active subscription, or zero when no eligible amount is available. This is not a promise of anonymous feedback.
The issue-feedback page opens the FeaturesVote board and supplies the app’s light or dark appearance. Hosted feedback pages may use cookies and collect technical information under FeaturesVote’s Privacy Policy. Treat a feature-board post as content intended for the board and avoid including private Health records or other sensitive information.
If you email support, we receive your email address, message and any attachments you send so we can respond and handle your request. Use info@calorimeter.app for private support or privacy matters.
App backend infrastructure
Cloudflare handles requests and security protection for Calorimeter’s app backend services. It processes technical traffic information such as IP address, requested URL, app or device information, timestamps and security signals to deliver and protect these services. Our app backend is hosted on Fly.io and uses database storage for catalogue and community-submission records. Sentry receives warnings and errors from the backend, including diagnostic messages and technical context. Bugsnag handles diagnostics in the mobile app, as described above.
See the policies for Cloudflare, Fly.io and Sentry. Providers may process information in countries other than your own, including Australia and the United States, depending on the service. We do not promise that all processing occurs in one country.
Retention, deletion and your choices
Your local and Apple-synced records remain under the app’s and Apple’s storage controls. You can edit or delete supported food logs, custom foods and recipes in the app. Apple Health records and iCloud data have separate controls; removing the app alone should not be treated as deleting every Health record or synchronized copy.
Community food submissions have no automatic expiry. They are kept indefinitely unless an administrator deletes them; approved catalogue entries may continue to be available to other users. Removing a local custom food does not retract an already submitted community record. Short-lived abuse-prevention counters are managed separately and do not determine how long submissions or infrastructure logs are retained.
Purchase, diagnostic and feedback records are handled under the relevant provider arrangements and policies. There is no single fixed retention period that applies to all these services, infrastructure logs or support correspondence. Contact us about a particular record or deletion request rather than assuming that uninstalling Calorimeter deletes data held by providers.
There is currently no in-app switch to disable analytics or crash reporting. Health access, notifications, iCloud settings and subscriptions are controlled separately through the relevant Apple settings. Optional food submissions, feedback and support messages are initiated by you.
Depending on the law that applies to you, you may have rights to request access, correction or deletion, object to or restrict processing, or raise a privacy complaint. Email info@calorimeter.app, describe your request and include enough information to identify the relevant record or service. We may need to verify the request. We cannot retrieve or delete your device’s entire Apple Health or iCloud history through our food backend. Provider-controlled data may require a request to that provider.
We use the information described here to provide requested app functions, manage purchases, review community contributions, respond to support, diagnose problems, improve the product and protect our services. We may also disclose information where required by applicable law. This page will be updated when the services or data handling change; the date above identifies the latest revision.