Privacy Policy
Last Updated: August 4, 2026
This Privacy Policy describes how CalEasy (“Application”), developed by Tomas Dorda (“we”, “us”), collects and uses your information. By using the Application, you agree to this Privacy Policy.
1. Data Controller
Tomas Dorda
Hrncirska 8, Vyskov 682 01, Czech Republic
Email: info@caleasy.app
2. International Data Transfers
Your data is processed primarily on servers in the United States by our service providers. For EU/EEA/UK users, these transfers are protected by the EU-US Data Privacy Framework, Standard Contractual Clauses, or another safeguard permitted under Chapter V of the GDPR.
3. Data We Collect
Data You Provide:
- Account: Your email address and name (via Google Sign-In, Sign in with Apple, or email)
- Health & Nutrition: Age (year of birth), weight, height, sex, activity level
- Goals: Target weight, daily calorie/macro targets
- Meal Data: Food photos and text descriptions of what you eat
- Weight & Hydration History: Measurements you record over time
Voice input: When you describe a meal by voice, your device’s built-in dictation converts your speech to text. Depending on your device and language, that speech may be processed by Apple or Google under their own privacy policies. We only ever receive the transcribed text — never an audio recording.
Automatically Collected:
- Device type, OS, app version, language, and IP address
- Device and installation identifiers (for example, a unique installation ID linked to the meals you upload)
- Where advertising measurement is active (see Section 7): an advertising-measurement identifier, and on iOS the device advertising identifier if you allow tracking
- Usage analytics, session analytics, and crash reports
- Performance data
Note: Payment details are handled by Apple, Google, and our subscription provider, and are never stored by us. We do not collect your precise device location.
4. How AI Analyzes Your Meals
To estimate calories and nutrition, your meal photos and text descriptions are sent to a third-party AI provider for analysis. The provider processes this content only to return a result to you and is contractually restricted from using it to train its own AI models. Because meal photos and descriptions can reveal information about your diet and health, we treat them as sensitive and limit their use to operating and improving the Application. AI results are estimates and can be inaccurate — please verify them (see our Terms & Conditions).
5. How We Use Your Data
- Provide calorie estimation, AI meal analysis, and nutrition tracking
- Personalize recommendations based on your profile
- Schedule reminders and notifications on your device
- Understand how the Application is used and improve it
- Fix bugs and maintain security
- Develop, train, and improve our AI models and the Application using de-identified and aggregated data
- Send you service-related messages (for example, subscription and trial reminders)
- Marketing communications (only with your consent)
Data that has been de-identified or aggregated so that it no longer identifies you is not personal data, and we may use and retain it for any lawful purpose.
6. Analytics & Session Analytics
We use analytics and diagnostics tools to understand usage and improve the Application:
- Product, crash, and performance analytics — usage events, crash reports, and performance metrics.
- Session analytics — records in-app interactions (such as taps and the screens you view) so we can improve usability. This runs only in the public release of the Application, recordings are pseudonymized, and text is masked by default.
You can limit analytics through your device’s privacy settings.
7. Third-Party Service Providers
We share data with the following categories of providers strictly to operate the Application:
| Category | Purpose | Data shared |
|---|---|---|
| Cloud hosting & infrastructure | Hosting, database, storage, authentication | Account, health, and meal data |
| AI processing provider | AI meal analysis | Meal photos and descriptions |
| Sign-in providers (Apple, Google) | Authentication | Email, name |
| Subscription & payment management | Managing your subscription | User ID, email, purchase and subscription status |
| Analytics providers | Product, crash, and session analytics | Usage and in-app interaction data |
| Email delivery | Sending service emails | Email address |
| Food database | Barcode product lookup | The scanned barcode only (no personal data) |
| Attribution / measurement | Measuring which ad campaign led to an install | Store-provided campaign token |
| Advertising partners | Measuring which of our ads lead to installs and subscriptions | That you installed the Application and subscribed, your email address, and device or advertising identifiers |
Our current advertising partner is Meta Platforms (Facebook, Instagram). We will update this list before adding another.
We never share your meals, your weight, your body measurements or your goals with advertising partners, and we never use or share health data for advertising or marketing purposes — not the data itself, and not through event names, labels or parameters that would reveal it. This restriction overrides every other data-sharing, advertising, or marketing provision in this Privacy Policy, including the table above, and will override any future amendment unless that amendment revises this paragraph expressly.
Advertising measurement starts when you first open the Application and runs unless you turn it off. The switch is Settings → Privacy → Ad measurement; turning it off takes effect immediately, stops all future sharing, and removes the identifiers from the records we use to send events, so nothing further can be linked to you. It does not undo sharing that already took place. You lose no functionality by turning it off. On iOS, sharing the device advertising identifier additionally requires your permission through Apple’s App Tracking Transparency prompt, which we show when you first open the Application; if you decline it, measurement continues without that identifier. You can withdraw that permission at any time in your device settings (Settings → Privacy & Security → Tracking).
We may also disclose information when required by law, to protect rights and safety, or to service providers bound by confidentiality. We do not sell your personal data.
If we are ever involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. This Privacy Policy will continue to apply to it, and we will notify you of any change of controller.
The Application and our website may contain links to third-party websites and services. Their privacy policies, not this one, govern what happens there.
8. Legal Bases (GDPR)
For EU/EEA/UK users:
- Contract: Account data, health data, meal tracking, and AI analysis
- Legitimate Interests: Analytics, session analytics, security, developing, training, and improving our models and the Application (including with de-identified data), and advertising measurement — sharing installation and subscription events with advertising partners, including any device or advertising identifier, so we can tell which of our ads work. Our interest is in reaching new users and keeping the Application affordable; we balance it by excluding all health data, by not using it to build advertising profiles about you, and by giving you the objection route below.
- Consent: Marketing communications, and — on iOS — access to the device advertising identifier through Apple’s App Tracking Transparency prompt.
- Legal Obligation: Tax and accounting records
Your right to object (Article 21 GDPR). You can object to advertising measurement at any time, with no reason given and no loss of functionality, using Settings → Privacy → Ad measurement. We treat that switch as an absolute objection: we stop immediately and do not weigh our interest against it. Objecting does not affect sharing that already took place.
Automated decision-making (Article 22 GDPR). We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing. The Application’s calorie targets and recommendations are automated personalization that you can review and change at any time.
9. Data Retention
- Account, meal, and health data: Until you delete your account
- Analytics & crash data: For a limited period as needed for service improvement
- Billing and tax records: For as long as the law requires
When you delete your account, we automatically and recursively delete your profile, meals, photos, and related data within 30 days. Some records may be retained where legally required (for example, accounting records), and we may retain specific data for longer where necessary to establish, exercise, or defend legal claims.
10. Your Privacy Rights
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data (in the app under Settings → Delete Account, or contact us)
- Export your data in a structured, commonly used, machine-readable format (contact us)
- Restrict processing of your data
- Object to processing
- Withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal
Contact us at info@caleasy.app. Because your account contains health data, we may first ask you to verify your identity — for example by writing from the email address on your account — so that your data is never released to someone impersonating you. We respond within one month; for complex or numerous requests we may extend this by up to two further months and will tell you why. We may decline requests that are manifestly unfounded or excessive, as the GDPR permits.
11. Data Deletion
You can delete your account at any time in the Application’s settings, or by emailing us. Deleting your account automatically removes your profile, meals, and photos from our systems. Some data may persist where legally required.
12. Children’s Privacy
The Application is intended for users aged 16 and over and is not directed to children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with data, contact us and we will delete it.
13. Security
We use technical and organizational safeguards to protect your data, including encryption in transit and at rest, access controls that limit each user to their own data, and separate testing and production environments. However, no method of transmission or storage is entirely secure, and we cannot guarantee absolute security. If a personal data breach occurs, we will notify the supervisory authority and affected users where the law requires it.
14. Supervisory Authority (EU)
For complaints, contact the Czech Office for Personal Data Protection (ÚOOÚ): https://www.uoou.cz — or the supervisory authority of the EU/EEA country where you live or work.
15. Changes to This Policy
We may update this Policy from time to time. The “Last Updated” date above shows the current version. We will notify you of material changes through the Application before they take effect. If you continue to use the Application after a change takes effect, the updated Policy applies to you; where a change requires your consent under applicable law, we will ask for it.
16. Contact Us
Tomas Dorda
Hrncirska 8, Vyskov 682 01, Czech Republic
Email: info@caleasy.app