Privacy Policy

Last updated: July 7, 2026

1. What We Collect

When you sign in with Google, we receive your name and email address. We store: food and workout entries you log (including any photos you upload); your profile data (height, weight, age, gender, activity level, goal, dietary preferences, and intermittent fasting protocol if set); weight logs and body fat measurements you enter; AI-powered weekly insights summaries generated from your logged data. If you enable push notifications, we store your browser push subscription endpoint to deliver reminders. We use your email address to send you a weekly digest summary (if you are subscribed). We also collect product usage data via PostHog — including which screens and features you use and session recordings of your on-screen activity in the app — to help us understand and improve calog.cc. For signed-in users, this usage data is linked to your account; it is not anonymous.

2. Trying calog.cc Before You Sign In

"Try it first" lets you log up to 3 food or workout entries without creating an account. We temporarily store your IP address to enforce a fair-use limit (max 5 guest sessions per IP per 24 hours); this is not linked to any other data unless you later create an account. Food and workout entries you submit as a guest are sent to Google Gemini for analysis and the result is returned to your browser — we do not store guest entries on our servers, and they exist only in your device's local storage until you close the tab or sign in. If you sign in afterward, your guest entries are transferred into your new account.

3. How We Use Your Data

Your data is used solely to provide the calog.cc service — to show you your calorie and protein logs, calculate daily totals, and track your streak. We do not sell, share, or trade your personal data with any third party.

4. Food Photos

When you upload a food or workout photo, it is sent to Google Gemini's API for AI analysis and stored in our secure cloud storage (Supabase). Photos are private and linked only to your account. You can delete any entry (and its photo) at any time from within the app.

5. Third-Party Services

We use the following third-party services: Google (authentication via OAuth), Supabase (database and file storage), Google Gemini (AI food analysis, workout analysis, and weekly insights generation — including for guest sessions before you create an account), PostHog (product usage analytics and session recordings), Sentry (error tracking — may capture technical error context such as user ID), Resend (transactional email delivery for weekly digests), and Netlify (hosting). Each of these services has its own privacy policy.

6. Data Retention

Your data is stored for as long as your account is active. You can permanently delete your account and all associated data at any time from within the app — tap your profile picture and select "Delete account". This removes all logs, photos, and your account instantly. You can also email zair@grocode.cc if you need further assistance.

7. Security

All data is transmitted over HTTPS. Access to your data is protected by Google OAuth — only you can access your account. We use Supabase Row Level Security (RLS) to ensure your data is never accessible to other users.

8. Children's Privacy

calog.cc is not intended for children under 13. We do not knowingly collect data from children.

9. Changes to This Policy

If we make significant changes to this policy, we will update the date at the top of this page. Continued use of the app after changes constitutes acceptance of the updated policy.

Questions? Email us at zair@grocode.cc