Privacy Policy
CalPod is a food-logging app. Our privacy stance in one line: your diary stays private outside spaces you deliberately join or content you publish; joining a pod is explicit, adult nutrition is then shared inside it by default with an anytime opt-out, and we never sell your data.
What we collect
| Data | Examples | Why |
|---|---|---|
| Food & health data | Meals you log, macros, weight entries, goals, streaks | The product itself: your diary, rings and plan |
| Meal photos & text | Photos you snap, meal descriptions you type or dictate | To identify foods and estimate portions |
| Profile | Age, sex, height, weight, goal; optional display name and handle | To compute your plan; name/handle only if you use social features |
| Account | Anonymous ID; email only if you Sign in with Apple | You can use CalPod without creating an account |
| Purchases | Subscription status (via RevenueCat) | To unlock CalPod Pro; Apple processes payment |
| Usage analytics | Feature usage events, device model, app version (via PostHog); aggregate visits and CTA clicks on public recap links | To improve the product; app events use your pseudonymous ID, while public-recap events are personless |
| Advertising attribution | Install and conversion events; your device advertising identifier only if you grant Apple's tracking permission (via Meta) | To measure which CalPod ads lead to installs and subscriptions |
We do not collect your location, contacts, or browsing history. If you grant Apple's App Tracking Transparency permission, Meta may use your device advertising identifier and conversion events to attribute a CalPod install or subscription to an ad across apps. Denying that permission does not limit any CalPod feature, and you can change it at any time in iOS Settings.
How AI recognition works
When you snap a meal, the photo (or your text description) is sent to our servers and processed by an AI vision model operated by our providers (Google, Anthropic) to identify foods and estimate portions, then checked against public nutrition databases (USDA FoodData Central, Open Food Facts). Per our agreements with these providers, your photos and descriptions are not used to train their models. Barcode scans skip AI entirely.
Apple Health
If you enable Health sync, CalPod writes nutrition, water and weight; reads weight and water for two-way sync; and reads steps for your private activity card. HealthKit data is never used for advertising or marketing, never shared with third parties, and never used for any purpose other than the sync or activity view you asked for. You can revoke access anytime in the Health app.
What your pod can see
CalPod is built around pods: two to eight friends who track together. Joining a private pod is an explicit action. For adult members, nutrition detail is shared with that pod by default and can be switched off at any time; minors always use a consistency-only view.
- Inside your private pod. Other members see that you logged and your streak. For adults, they also see real calories and macros against your own goals from the last 7 days, plus today's meals, unless you turn nutrition sharing off.
- You stay in control. You can switch nutrition detail off at any time. CalPod first blocks future sharing, then removes calories, macros, goals and meals from all of your pod history; the app confirms “Hidden” only when that removal succeeds. Your consistency facts remain.
- Seven-day nutrition window. While sharing is on, amount details are automatically removed after the day falls outside the pod's 7-day view. Consistency history can remain so the pod's chain still works.
- Never your weight. Your weight and body measurements stay on your device and are never shared with a pod. Minors are excluded from number-sharing automatically.
- Pod intake stays inside the pod. CalPod has no public leaderboards and no cross-user intake rankings outside your own pod.
- If you explicitly share or publish a single meal, its foods, photo and macros become visible per the visibility you chose. Your full daily intake is never published.
- Anonymous benchmarks are computed only over groups of 50+ people and can never be traced back to you.
Who processes data for us
Google (Firebase: authentication, database, storage, cloud functions; Gemini: AI food recognition), Anthropic (AI food recognition), RevenueCat (subscriptions), PostHog (product analytics), Meta (advertising attribution), and Apple (payments, push notifications). Each processes data for the purposes described above. We never sell personal data, and CalPod does not display third-party ads.
Your controls
- Export: Profile → Your data → Export my data creates a portable JSON copy of the diary, profile and settings stored locally on your device. It is not a complete export of provider billing, analytics, or moderation records; email us to make a broader data-access request.
- Delete: Profile → Your data → Delete all my data removes your local diary, plan, photos and the Health data CalPod wrote; erases the active account and owned app data from Firebase (including your handle, shared meals and pod membership); and requests deletion of the customer/person keyed to your CalPod ID from RevenueCat and PostHog.
- EU/UK (GDPR) and California (CCPA) rights: access, rectification, erasure, portability, objection. Exercise any of these in-app or by emailing us.
Retention & security
Active account and product data is kept while your account is active and is erased through the deletion flow above. We may retain the minimum subscription, transaction, referral-payout, fraud, or abuse/moderation records required for legal, accounting, dispute, fraud-prevention, or user-safety duties. Retained records are separated from the active account, access-restricted, and de-identified where possible; they are not used to restore your profile or for product analytics. Everything is encrypted in transit (TLS) and at rest on our providers' infrastructure. Public share pages contain only the content you chose to share and expire after 90 days. Personless recap-page-visit and CTA-click events may remain for PostHog's analytics retention period; they contain a one-way share identifier and fresh event identifier, not the raw share token, recap URL, account ID, persistent viewer ID, or viewer IP at PostHog, and cannot restore or identify the expired share.
Age
CalPod is for people 13 and older. If you are below the age at which you may consent to digital services in your jurisdiction, you may use CalPod only with verified permission from a parent or guardian. We don't knowingly collect data from children under 13; if you believe we have, contact us and we'll delete it.
Changes & contact
We'll notify you in-app of material changes. Questions or requests: support@stolenorbit.com.