Перейти до вмісту
Calvi

Privacy Policy

In short: we keep what you enter yourself, we do not store photographs, there is no analytics and no advertising, and everything can be deleted.

Updated: 24 August 2026

Who is responsible

Calvi is run by Mykhailo Nahreba, an individual, Ukraine. That is the person who decides what data is collected and why, the controller in the sense of the law. You can write to [email protected].

What we store

Exactly what you enter yourself, and what signing in cannot work without.

  • Profile. Sex, year of birth, height, goal and pace, daily target, how to address you
  • Diary. Dishes with weights and figures, water, weight, body measurements, workouts
  • Health. Medicines with doses and times, marks that a dose was taken, allergies
  • Assistant memory. Short notes about you that you asked it to remember
  • Sign-in. If you signed in with Google, we store your email address and a stable Google identifier. We take neither your name nor your profile picture
  • Sessions. A fingerprint of the access token and a line about the device, such as "Pixel 8, Android 15", so you can see where you signed in from
  • Assistant tokens. How many are left and what they were spent on

What we do not collect

A shorter list, and a more important one than the first.

  • There is no analytics. None at all: neither ours nor anyone else’s
  • There is no advertising, and no advertising identifiers
  • There is no crash reporting. The app sends us no crash reports
  • There is no location. We neither ask for it nor receive it
  • No contacts, no calendar, no files
  • The app creates no device identifier of its own

Photographs

A photo of a meal is not stored anywhere. It lives in memory for exactly as long as one request takes: it arrives at the server, goes to the model that reads it, and is gone. It is not in the database, not on disk, not in backups.

The same on the phone: the frame does not reach your gallery and does not stay in your files.

Talking to the assistant

The text of the conversation is not stored on the server. It passes through to get an answer and stays only on your phone. What is stored is the dish itself, once you add it to the diary.

Voice

Dictation is done by your phone’s own speech recognition, not by us. What reaches us is finished text. We neither receive nor store audio.

Who it is passed to

Three parties, each getting exactly as much as its job needs.

  • Google Gemini, to work your description or photo into a dish and figures. It receives the text you wrote, the photo, a few previous messages, and a short block about you: how to address you, sex, age, height, weight, goal, daily target, allergies and pinned notes. Your email, your account identifiers and anything that would reveal your name beyond what you asked to be called do not go there
  • Open Food Facts and USDA, when you scan a barcode. Only the barcode itself goes there, nothing else
  • Hosting. The server and the database sit on a rented machine, with Cloudflare in front of it passing traffic through and seeing your IP address

It goes to no one else. We do not sell it, trade it or hand it to advertising networks.

What stays in the server logs

The request method, the address, the response code and the IP the request came from. Request bodies are not written to the logs: not the text, not the photo, not the figures in your diary. Access keys are stripped out of the logs.

On what legal basis

Your profile, syncing and sign-in are processed to do what we agreed on: give you a diary that works. Health data, that is weight, measurements, medicines and allergies, is processed on your explicit consent, which you give by entering it.

You can take that consent back: delete those entries, or delete the whole account.

How long it is kept

As long as your account lives. Delete the account and the data is gone.

  • Diary and profile stay until you delete them
  • A session lasts a year from the last sign-in, then expires by itself
  • Server logs are kept for no longer than 30 days
  • Database backups are overwritten within 30 days

Your rights

All of this is done by letter, and we answer within 30 days.

  • Get a copy of everything we store about you
  • Correct anything recorded wrongly
  • Delete the account along with everything on the server
  • Wipe the diary and keep the account: start from a clean slate without losing the sign-in
  • Object to the processing, or ask us to restrict it
  • Complain to the supervisory authority in your country

Write to [email protected] from the address you signed in with, or from the phone the app is on. You can also use the diary without the assistant, in which case no message goes out at all.

Automated reading

The dish and the figures are determined by a model, automatically. That is an estimate, not a decision about you: it has no consequence beyond a number in your diary, and any number can be corrected by hand.

Security

Traffic to the server goes over a secure connection only. Access tokens are stored as fingerprints rather than as the values themselves. One person, the one who runs the service, has access to the database.

If a breach happens that puts you at risk, we will tell you and the supervisory authority as soon as we know.

Children

Calvi is for adults. We do not knowingly collect data from anyone under 18. If you are a parent or guardian and believe a child has an account here, write to [email protected] and we will delete it.

If this page changes

The revision date is at the top. We will tell you about material changes in the app before they take effect, not after.