Calories Protein — Privacy Policy
Effective September 23, 2026
Calories Protein is a personal calorie and protein tracker, available as a web app and native iOS and Android apps. This policy describes what data the app handles and how.
What we collect
- Account information — your email address and a hashed password, used solely to sign you in.
- Food log data — the days, food entries, calories, protein amounts, and goals you record. This is the app's purpose and is stored so you can access your history across devices.
- Optional AI submissions — a meal description and/or photo you choose to submit through Add with AI. These are sent off-device only to generate the estimate described below.
- Optional AI safety reports — if you report an AI result while signed in, we store the reason you select, any optional comments you provide, the structured estimate submitted with the report (food names, portions, calorie and protein estimates, and note), the report submission time, whether a photo was used, your app platform and version, and the association with your Calories Protein account. We use this information only to moderate reported results, improve safety, enforce report limits, and meet security or legal obligations.
- Sign-in security signals — when you sign in or create an account, Cloudflare Turnstile may process your IP address and limited device, browser, and interaction signals to distinguish people from automated abuse.
What we don't do
- No advertising, no analytics trackers, no data sale or sharing with data brokers.
- No use of your data for advertising or tracking.
AI food estimation
If you use "Add with AI," the description and optional photo you submit are sent to our server and forwarded to OpenAI's API to estimate calories and protein. Our server verifies that you are signed in, but does not send your email address, Calories Protein account identifier, or authentication token to OpenAI. OpenAI receives only the content you submit and the instructions needed to generate the estimate.
We request that OpenAI not store the generated response. Calories Protein does not save the raw meal description, original prompt text, or photo after the estimation request. Normally, only entries you choose to log are saved. If you voluntarily report an AI result, we also save the selected report reason, optional report comments, and the structured estimate submitted with the report after basic validation, including estimated items and portions, calorie and protein amounts, and any note. A saved report is associated with your account and includes its submission time and limited technical context (whether a photo was used and the app platform and version), but it excludes the meal photo and raw image bytes as well as the original description or other prompt text. Under OpenAI's standard API data controls, request and response content may be retained for up to 30 days in abuse-monitoring logs. OpenAI states that API data is not used to train its models by default. Images flagged for suspected child sexual abuse material may be retained for manual review as described in OpenAI's API data controls.
We normally delete submitted AI safety reports after 180 days. We may retain a report longer when it is needed for an open safety investigation, security incident, or legal obligation. When you delete your account, reports associated with it are deleted automatically along with the account record.
To enforce fair-use limits, we also keep a small usage record for each AI request: the time, whether it was an estimate or a revision, whether a photo was attached, and the app platform. This record contains no food text, no photos, and no results. It is deleted after 30 days and removed with your account.
Crash and error reporting
The web, server, iOS, and Android apps send crash and error reports to Sentry so we can find and fix problems. A report can include the error and its stack trace, the device model, operating system, app version, and basic breadcrumbs (for example, that a screen was opened or a request failed); on iOS, breadcrumbs are limited to a short list of known keys. Performance tracing and session replay are turned off, and we do not send request bodies, cookies, or the query part of page URLs.
Personal information collection is turned off, and signed-in users are identified only by a one-way hash of their account id — never by email. The contents of your food log, including food names, notes, amounts, and photos, are not included.
Where data lives
Your data is stored in a Supabase (PostgreSQL) database with row-level security, so each account can read only its own food-log rows. AI safety reports are kept in a separate private moderation queue that app users cannot read, update, or delete directly. Passwords are handled by Supabase Auth and are never visible to the app. Cloudflare provides the sign-in abuse protection described above.
Your choices
You can export your complete history at any time: as CSV from iOS or Android Settings, or as a formatted Excel workbook from web Settings.
You may also use the iOS and Android apps without creating an account. Guest-mode logs stay on that device and are not synced to the web app.
Your web appearance choice is saved only in your browser and is not uploaded to Calories Protein.
Deleting data without deleting your account
You can delete individual food-log entries from Today or Log while keeping your account. This removes the selected entry from your synchronized food log. For help requesting deletion of specific data without closing your account, use the contact address below.
Account deletion
Signed-in users can permanently delete their Calories Protein account and all associated food-log data and AI safety reports from Settings → Account → Delete account in the iOS, Android, or web app. You can also sign in to web Settings to complete the same deletion flow. For help with a deletion request, use the contact address below.
Contact
Questions or deletion requests: joshua.w.lyons@outlook.com