Privacy Policy
1. Who we are
The operator of the CalAura mobile application and website (hereinafter “we”, “us”, “operator”): [legal name or individual entrepreneur / company name].
For privacy-related inquiries: [privacy contact email].
The app is distributed via Google Play, RuStore, and the App Store under the name
CalAura (Android package identifier: dad.dev.calaura).
2. Summary
CalAura helps you track nutrition and activity. Most data is stored on your device. Our servers receive only what is needed for food recognition and related AI features (images and/or text you send), including the demo on calaura.info. If analytics is enabled, Yandex AppMetrica may process in-app usage statistics; the website may use Yandex Metrica. Access to steps is only possible if you explicitly allow it through Health Connect (Android) or HealthKit (iOS).
3. Data we process
3.1. Information you provide in the app
- Food entries (name, calories, macros, portion weight where applicable, date and time).
- Workouts (name, duration, calories burned, date and time).
- Daily goals (calories, macros, steps), including a weight-loss, maintain, or muscle-gain target.
- Profile and settings you save in the app (if applicable).
- Photos of meals when you use camera-based recognition — they are sent to the server for processing (see Section 4).
- Text descriptions of food or AI-assisted edits — sent to the server as part of the API request.
3.2. Device and integration data
- Step counts for the selected day are read via Health Connect or HealthKit only with your permission; they are not uploaded to our servers and are used locally in the app.
- Technical data: device type, OS version, interface language (including the
Accept-Languageheader when calling the API), network requests to our backend.
3.3. Local storage
Food logs, workouts, goals, and related data are stored locally by default (app database, DataStore, or equivalent). Backup and restore depend on your device and account settings (for example Android / Google or iOS).
4. Data sent to our servers (backend)
When you use photo food recognition, text parsing, or AI-assisted edits — in the app or in the website demo — the client sends data to our backend (the same pipeline as calaura.info):
- an image file (JPEG/PNG) and/or a JSON body with a food description or edit instruction;
- HTTP headers required for the API to function.
On the server, images and text may be passed to an AI provider (e.g. a multimodal language model) to estimate dish name and nutrition values. We do not use this for public display of your photos; retention on our infrastructure and at the AI provider depends on server configuration — contact us for current practices.
Other data (full diet history, workouts, goals) is generally not synchronized with the server unless a future version explicitly adds such a feature. The website demo does not save a food diary.
5. Analytics (AppMetrica and Yandex Metrica)
If the app build includes a non-empty AppMetrica API key (Yandex), we may collect de-identified or pseudonymous analytics: in-app events, device and session parameters as defined by the AppMetrica SDK.
The website may use Yandex Metrica (cookies, anonymized visit statistics, click maps, Webvisor) when a counter ID is configured.
Processing is governed by Yandex policies: https://yandex.com/legal/confidential/
You can adjust ad personalization and related settings via your device and Google or Apple account controls.
If analytics is disabled (empty API key or empty website counter in production), the corresponding part of this section does not apply.
6. App permissions
- Internet — communication with the backend and, when configured, analytics endpoints.
- Camera — capturing meals for recognition (only when you choose to).
- Health Connect or HealthKit (read steps) — only after you grant permission in the system dialog.
7. Legal bases (EEA, UK, and similar regimes)
- Performance of the service and your request to process food recognition and AI features.
- Consent — for camera, Health Connect / HealthKit, and analytics where consent is required.
- Legitimate interests — minimal technical logging for security and reliability (e.g. server logs).
8. Third parties
- Hosting or cloud provider for the backend (if used).
- AI provider connected by the backend for image and text analysis.
- Yandex (AppMetrica, Metrica) — when analytics is enabled.
- Google Play, RuStore, and the App Store — distribution under their terms.
We do not sell your personal data.
9. Retention
- On device — until you delete data in the app or uninstall the app.
- On our servers — operational logs and temporary files as needed; details available on request (see Section 1).
- AppMetrica / Metrica — per Yandex policy.
10. Security
We apply reasonable organizational and technical measures (e.g. HTTPS when the server is configured correctly, restricted access to API keys). No method of transmission over the Internet is 100% secure.
11. Your rights
Depending on your location, you may have the right to access, rectify, erase, restrict processing, object, data portability, and to withdraw consent where processing is consent-based. Contact [privacy contact email]. You may lodge a complaint with a supervisory authority in your country.
12. Children
The app is not directed at children under [13 / 16 — set per your market]. If you believe a child has provided us with data, contact us and we will take appropriate steps to delete it.
13. International transfers
Processing on our servers, at AppMetrica / Metrica, or at AI providers may occur outside your country. Where required by law, we rely on appropriate safeguards (e.g. standard contractual clauses).
14. Changes
We may update this policy. The current version is available at https://calaura.info/privacy. For material changes, we will notify you by reasonable means (e.g. in-app notice or store update notes).
15. Contact
[Operator name]
[Privacy email]
Website: https://calaura.info