Privacy Policy
Effective 2026-09-27
TL;DR:Your meal log lives on your device unless you opt in to cloud sync. Photos are processed by our AI provider and not stored. We don't sell your data, ever. You can export or delete everything at any time.
1. What we collect
On the free tier, Calora stores your meal log entirely in your browser's localStorage. The data never leaves your device unless you explicitly choose to create an account and enable cloud sync.
If you create a Calora Pro account, we collect your email address, account creation date, subscription status, and the meal log items you choose to sync. We do not collect your name, address, phone number, or any government ID.
2. Photos and food images
When you snap a photo for a meal scan, it first goes through an automated content-safety check, then to a free-tier AI model on OpenRouter for calorie and macro estimation. We do not store the photo itself on our servers — only a one-way hash of it (so an identical re-scan doesn't need a second AI call) and the structured result. We never turn on prompt/response logging: no human at Calora reads your meal descriptions or photos.
Which models, and what they do with your data (verified against OpenRouter's live routing behavior, 2026-09-27): we request Zero Data Retention on every call where the provider supports it. Qwen (served via ModelRun) supports it, and we use it. The two Gemma models (served via Google AI Studio) and the last-resort fallback router do not support per-call Zero Data Retention; we request the next-strongest available control instead (no non-transient storage) for those. The safety pre-filter (Nvidia, served via DeepInfra) is the one model in the chain whose free tier is flagged by OpenRouter itself as carrying a training condition we cannot opt out of per call — every uploaded photo passes through it before estimation, which is the trade-off of closing the abuse-filtering gap at zero cost. We are tracking whether that trade-off should change; this page will be updated if it does.
Photos are never used for advertising, never sold, and never shared with third parties other than the AI providers used to process them.
3. Payment information
Payment is processed by Stripe. We never see or store your credit card number, CVV, or full billing address. Stripe's privacy policy governs how they handle your payment data: stripe.com/privacy.
4. Analytics
We use privacy-respecting analytics (PostHog Cloud or Plausible) to count visits, signups, and feature usage. We do not track you across other sites, do not use third-party advertising cookies, and do not build advertising profiles. You can opt out by enabling Do Not Track in your browser; we honor the DNT header.
5. Data export and deletion
You can export all your meal data to CSV at any time from the History view. On the free tier, this is just your localStorage. On Pro, the export includes everything synced to your account.
You can delete your account and all associated data at any time from Settings → Delete Account. Deletion is permanent and processed within 7 days; backup copies are purged within 30 days.
6. Children's privacy
Calora is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact us and we will delete it.
7. International users (GDPR)
If you are in the European Economic Area, United Kingdom, or Switzerland, you have the right to access, correct, port, and delete your personal data, and to object to or restrict its processing. Contact us at the email below to exercise these rights. Our legal basis for processing is your consent (for analytics) and contract performance (for Pro subscription).
8. Changes to this policy
If we make material changes, we will email Pro subscribers at least 14 days before the changes take effect. The current effective date is shown at the top of this page.
9. Contact
Questions or requests? Email [email protected].