What we collect
Account
- Email address or social provider ID (Apple/Google) when you sign in
- A Firebase user identifier we use to scope your data
Health and fitness data you choose to log
- Profile: gender, age, height, weight, target weight, activity level, goals
- Daily logs: meals (with optional photos), water, fasting sessions, workouts, weigh-ins
- Mascot, palette, units, and reminder preferences
Device and usage
- App version, OS version, device type
- Anonymous events for product quality (e.g. "meal_logged", "workout_completed", "purchase_started"). These contain no health values and no message content.
How your data is stored
- On your device for offline access (encrypted at rest by the OS)
- In Firebase Cloud Firestore under your account, secured by per-user rules so only you can read or write your data
How we use it
- To operate the app: render your dashboard, charts, streaks, and personalized targets
- To improve product quality through aggregated, de-identified analytics
- To process subscriptions through Apple, Google, and RevenueCat
- We do not sell your data and do not share it with advertisers
Photos and camera
- When you scan a meal, the photo is sent to our food analysis service to estimate calories and macros
- Photos are processed transiently for that request and not retained by Calfit
- You can revoke camera or photo access at any time in your device Settings
Subprocessors
- Google Firebase (auth, database, remote config) — provides backend infrastructure
- RevenueCat — handles subscription state on iOS and Android
- Apple App Store / Google Play — handle purchases and refunds per their own policies
Children
Calfit is not intended for children under 13. If you believe a child has provided us data, contact us and we will remove it.
Your controls
- Settings → Account → Delete account permanently deletes your Firebase user and all associated data within 30 days
- Settings → Sign out keeps your local data on the device and stops syncing
- Settings → Subscription → Restore purchases reconnects an existing entitlement
- Email us to request a copy or correction of your data
Security
We use Firebase's standard transport (TLS) and at-rest encryption. No system is perfectly secure; please contact us promptly if you suspect unauthorized access to your account.
Changes
If we change this policy in a material way, we will notify you in-app before the change takes effect.