Calories Protein — Privacy Policy

Effective September 23, 2026

Calories Protein is a personal calorie and protein tracker, available as a web app and native iOS and Android apps. This policy describes what data the app handles and how.

What we collect

What we don't do

AI food estimation

If you use "Add with AI," the description and optional photo you submit are sent to our server and forwarded to OpenAI's API to estimate calories and protein. Our server verifies that you are signed in, but does not send your email address, Calories Protein account identifier, or authentication token to OpenAI. OpenAI receives only the content you submit and the instructions needed to generate the estimate.

We request that OpenAI not store the generated response. Calories Protein does not save the raw meal description, original prompt text, or photo after the estimation request. Normally, only entries you choose to log are saved. If you voluntarily report an AI result, we also save the selected report reason, optional report comments, and the structured estimate submitted with the report after basic validation, including estimated items and portions, calorie and protein amounts, and any note. A saved report is associated with your account and includes its submission time and limited technical context (whether a photo was used and the app platform and version), but it excludes the meal photo and raw image bytes as well as the original description or other prompt text. Under OpenAI's standard API data controls, request and response content may be retained for up to 30 days in abuse-monitoring logs. OpenAI states that API data is not used to train its models by default. Images flagged for suspected child sexual abuse material may be retained for manual review as described in OpenAI's API data controls.

We normally delete submitted AI safety reports after 180 days. We may retain a report longer when it is needed for an open safety investigation, security incident, or legal obligation. When you delete your account, reports associated with it are deleted automatically along with the account record.

To enforce fair-use limits, we also keep a small usage record for each AI request: the time, whether it was an estimate or a revision, whether a photo was attached, and the app platform. This record contains no food text, no photos, and no results. It is deleted after 30 days and removed with your account.

Crash and error reporting

The web, server, iOS, and Android apps send crash and error reports to Sentry so we can find and fix problems. A report can include the error and its stack trace, the device model, operating system, app version, and basic breadcrumbs (for example, that a screen was opened or a request failed); on iOS, breadcrumbs are limited to a short list of known keys. Performance tracing and session replay are turned off, and we do not send request bodies, cookies, or the query part of page URLs.

Personal information collection is turned off, and signed-in users are identified only by a one-way hash of their account id — never by email. The contents of your food log, including food names, notes, amounts, and photos, are not included.

Where data lives

Your data is stored in a Supabase (PostgreSQL) database with row-level security, so each account can read only its own food-log rows. AI safety reports are kept in a separate private moderation queue that app users cannot read, update, or delete directly. Passwords are handled by Supabase Auth and are never visible to the app. Cloudflare provides the sign-in abuse protection described above.

Your choices

You can export your complete history at any time: as CSV from iOS or Android Settings, or as a formatted Excel workbook from web Settings.

You may also use the iOS and Android apps without creating an account. Guest-mode logs stay on that device and are not synced to the web app.

Your web appearance choice is saved only in your browser and is not uploaded to Calories Protein.

Deleting data without deleting your account

You can delete individual food-log entries from Today or Log while keeping your account. This removes the selected entry from your synchronized food log. For help requesting deletion of specific data without closing your account, use the contact address below.

Account deletion

Signed-in users can permanently delete their Calories Protein account and all associated food-log data and AI safety reports from Settings → Account → Delete account in the iOS, Android, or web app. You can also sign in to web Settings to complete the same deletion flow. For help with a deletion request, use the contact address below.

Contact

Questions or deletion requests: joshua.w.lyons@outlook.com