Privacy Policy
Only the data the diary requires is collected, health data is processed on the basis of your explicit consent, photographs and conversations are not kept on our servers, and no personal data is sold or used for advertising.
Updated: 30 September 2026
Controller and contact details
This Privacy Policy describes how personal data is processed in connection with the Calvi application and the services provided through it. The controller of that data is Mykhailo Nahreba, who may be contacted at [email protected].
Categories of data processed
- Account data. An identifier generated at first launch and, where you choose to sign in, the email address supplied by Google or Apple together with the identifier that provider uses for you. Your time zone and interface language are stored so that days and reminders fall where you are. Each signed-in session is recorded as a hashed credential with the times at which it was created and last used.
- Profile data. Sex, year of birth, height, starting and target weight, the direction and pace of your goal, activity level, daily energy and macronutrient targets, water target, preferred form of address, interface theme, and the body measurements you have chosen to track.
- Diary data. Meals with their descriptions, weights and nutritional values, the time and category of each entry, water intake, weigh-ins, body measurements and recorded physical activity. Where an entry is waiting for a weight you have not yet stated, the words you used to describe the dish are held until the entry is completed or discarded.
- Health data. Allergies you select and whether you have marked them as severe; medications with their form, dose, schedule and course dates, and the doses you record as taken.
- Apple Health data. Only where you connect Apple Health on an iPhone, and only the kinds you allow: the workouts recorded there with their type, time, duration and active energy, the number of steps you take, and your body weight. In the other direction, the energy, protein, fat and carbohydrates of the meals you record, your water intake and your weight are written to Apple Health.
- Assistant data. The notes the assistant retains about you, which you can read and delete within the application, and the weekly reviews it has produced at your request.
- Recipes. Recipes saved to your account, whether composed by the assistant or entered by you.
- Nutritional corrections. Where you correct the energy or macronutrients of a dish, or state the weight of a portion you use often, that correction is stored against your account so that it applies the next time the same dish is recorded.
- Allowance data. Your token balance and a record of grants and expenditure, and, where you hold a subscription, the period for which paid access applies.
- Technical data. Server request logs containing the time of the request, the endpoint addressed, the response status and the originating IP address. Request bodies are not written to the logs, and authorisation credentials are excluded from them.
The application contains no advertising and uses no advertising identifiers, and no third-party analytics or crash-reporting component is embedded in it. Reminders are raised by your own device, so no push notification identifier is created or held.
What is not retained
- Photographs. A photograph submitted for analysis is transmitted for processing and discarded once a reply has been produced. It is not written to the database and not saved to disk.
- Conversations. The text of your conversations with the assistant is held on your device. Each request carries the recent part of the conversation with it so that a reply can be produced in context, and that content is not retained on the server afterwards. What persists is only the notes described above, which you can read and delete.
- Audio. Dictation is performed by the speech recognition built into your device, which returns text. Audio is never transmitted to us. That recognition is governed by the terms of your device operating system.
Purposes and legal bases of processing
- Provision of the Service, Article 6(1)(b) GDPR. Storing your entries, displaying them to you, synchronising them between your devices, and producing the calculations shown in the application. This processing is necessary to perform the contract constituted by the Terms of Use.
- Operation of the assistant, Article 6(1)(b) GDPR. Transmitting the content you address to the assistant, together with the profile context required to answer it, so that a reply can be generated.
- Administration of paid access, Article 6(1)(b) GDPR. Recording that a subscription is active and for what period, so that the allowance limits do not apply to you.
- Security and reliability, Article 6(1)(f) GDPR. Retaining short-lived server logs and counting requests in aggregate in order to detect faults and abuse. The legitimate interest pursued is the secure and continuous operation of the Service.
- Health data, Article 9(2)(a) GDPR. Allergies and medication records are processed solely on the basis of your explicit consent, given by entering them. Consent may be withdrawn at any time by deleting those entries or your account.
- Apple Health data, Article 9(2)(a) GDPR. Workouts, steps and weight are read from Apple Health, and meals, water intake and weight are written to it, solely on the basis of your explicit consent, given by connecting Apple Health and allowing each kind on the permission screen of your iPhone. Consent may be withdrawn at any time by turning those kinds off within Calvi or in the Health app.
Processing by the assistant
When you write to the assistant or submit a photograph, that content is transmitted to DeepSeek for processing by its models, together with the context required to produce a reply. That context comprises your daily targets, the entries of the day concerned, including workouts and steps brought in from Apple Health, the allergies you have recorded, the notes the assistant retains, and the recent part of the conversation sent by your device.
The provider processes that content in order to return a reply, under the terms of the service tier through which the request is made, and those terms determine whether it may also be used to improve the services of that provider. No models are operated or trained by us. You should not submit information relating to other people to the assistant.
Apple Health
Connecting Apple Health is optional. Which kinds of data Calvi may read and write is chosen by you on the permission screen of your iPhone, and can be changed at any time in the Health app and within Calvi. Data read from Apple Health is used only to keep your diary and to calculate your daily balance: workouts and steps appear as entries of the day and count towards the energy you have spent, and a weight from a connected scale appears as a weigh-in. It then forms part of your diary and is processed as such: stored on your device and, where you have signed in, synchronised with our servers and available to the assistant.
Data from Apple Health is never used for advertising, marketing or data mining, is never sold, and is not disclosed to anyone other than the processors listed below that are needed to provide the Service. It is not stored in iCloud by Calvi. An entry you delete in Calvi is also removed from Apple Health where Calvi wrote it. What is already in Apple Health otherwise remains there under your control, including after your account is deleted, and can be removed in the Health app.
Recipients and processors
- DeepSeek. Processes assistant messages and submitted photographs through its models.
- Google and Apple. Only where you choose to sign in, and only for the purpose of verifying your identity and supplying the email address associated with that account.
- Apple and Google as store operators. Where you purchase a subscription, the transaction is concluded with the store from which the application was obtained.
- Hosting provider. Operates the infrastructure on which the server and database run.
- Public food reference databases. Open Food Facts and USDA FoodData Central are queried for product information. A barcode or a search term is transmitted; your identity is not.
Personal data is not sold and is not disclosed for advertising purposes.
Subscriptions and payment
Subscriptions are purchased through the store from which the application was obtained, and payment is handled entirely by that store. No card number, billing address or other payment detail is received or stored by us. What is recorded against your account is the period for which paid access applies.
Aggregate data
Counts of requests are kept in aggregate by hour, endpoint and response status, together with product barcodes that no reference database was able to name. These records carry no account identifier and cannot be attributed to a person. They are used to keep the Service running and to decide which products to describe next.
International transfers
Processing may take place outside your country of residence. Where personal data is transferred outside the European Economic Area, that transfer is made subject to the safeguards permitted by applicable data protection law, including standard contractual clauses concluded with the relevant processor.
Retention
- For the duration of the account. Profile, diary, health, assistant and recipe data are retained until you delete them individually or delete your account.
- Upon a deletion request. When you ask to delete your account from the settings, all data held on your device is removed immediately and your sessions are ended. On the server the account is marked for deletion and placed in a queue; its records are neither used nor shown while it waits. Signing in with the same account before the deletion is carried out cancels the request and restores the account together with its data; a new request is then needed to delete it.
- Upon deletion. Deletion is carried out by us after the request is reviewed, within 30 business days of the request. All records associated with the account are then removed from the operational database: the account itself, sign-in identifiers, sessions, the diary, body measurements, workouts, medications, the assistant conversation and its notes, recipes and the assistant allowance. Residual copies held in system backups are overwritten in the ordinary course of their rotation.
- Server logs. Retained for a short operational period and then discarded.
- Aggregate records. Kept without limitation of time, as they contain no personal data and deletion of an account does not make them attributable.
Your rights
Where the General Data Protection Regulation applies to you, you have the right to obtain confirmation as to whether your personal data is processed and to receive a copy of it; to have inaccurate data rectified; to have your data erased; to restrict or object to processing; to receive your data in a structured, commonly used and machine-readable format; to withdraw consent at any time without affecting the lawfulness of processing carried out beforehand; and to lodge a complaint with your national supervisory authority.
Most of these rights may be exercised directly within the application: entries can be edited or deleted individually, the notes the assistant retains can be read and removed, the connection to Apple Health can be turned off, and the deletion of the account together with all associated data can be requested from the settings, as described under Retention. For any other request, write to [email protected].
Security
Data is transmitted over encrypted connections and stored on access-controlled infrastructure. Session credentials are stored as hashes rather than in their original form, and authorisation headers are excluded from server logs. No system is entirely secure, and absolute security cannot be guaranteed.
Children
The Service is not directed to persons under 13 years of age, and their personal data is not knowingly processed. Any account identified as belonging to such a person will be deleted.
Where the law of your country sets a higher age at which a person may consent to the processing of their personal data, processing below that age is carried out only with the consent of a parent or guardian, who may exercise the rights set out below on behalf of the person concerned by writing to [email protected].
Amendments to this Policy
This Policy may be updated. The date of the current revision appears at the head of this document, and material amendments will be notified within the application before they take effect.
Contact
Enquiries and requests concerning personal data may be addressed to [email protected].