KalorIQ Privacy Policy
Effective date: [EFFECTIVE DATE] Last updated: [EFFECTIVE DATE] Provided by: [COMPANY/JURISDICTION]
1. Introduction
KalorIQ ("KalorIQ", "we", "us", or "our") is a nutrition and health-tracking application for iOS. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and the choices and rights you have. It applies to your use of the KalorIQ app and the related backend services operated by [COMPANY/JURISDICTION].
By creating an account and using KalorIQ, you agree to the collection and use of information in accordance with this Privacy Policy.
We do not use third-party advertising networks, and we do not track you across other companies' apps or websites. See Section 5 ("No Third-Party Tracking or Advertising") for details.
2. Data We Collect and Why
The following categories reflect the data types declared in the app's iOS privacy manifest. Every category below is linked to your identity (associated with your account) and is collected for the stated purpose only. None of these categories is used for cross-app or cross-site tracking.
2.1 Name
- What: The name or display name you provide when you create your account or edit your profile.
- Purpose: App functionality — to personalize your experience and to display your identity within social features (friends, followers, shared content) you choose to use.
2.2 Email Address
- What: The email address you use to register and sign in.
- Purpose: App functionality and account management — to create and secure your account, authenticate you, send account- and service-related communications, and support account recovery.
2.3 User ID
- What: A unique account identifier assigned to your KalorIQ account, used internally to associate your data with your account.
- Purpose: App functionality — to store, retrieve, and synchronize your data across sessions and devices, and to attribute requests to your authenticated account.
2.4 Health Data
- What: Health-related information you log in the app or that is read from Apple HealthKit with your permission. This includes nutrition data (calories and macronutrients), body measurements (such as weight, body fat, BMI, lean body mass, waist circumference, height), and clinical-style metrics (such as blood glucose, blood pressure, blood oxygen, heart rate, heart rate variability, respiratory rate, body temperature, and sleep).
- Purpose: App functionality — to power your nutrition and health tracking, trends, insights, and goals. See Section 3 ("Apple HealthKit") for the dedicated HealthKit disclosure.
2.5 Fitness Data
- What: Activity and fitness information such as steps, active and resting energy, exercise minutes, stand hours, walking/running/cycling/swimming distance, flights climbed, VO2 max, mindful minutes, and workout data — logged in the app or read from Apple HealthKit with your permission.
- Purpose: App functionality — to power activity tracking, fitness insights, and goal progress.
2.6 Photos or Videos
- What: Images you choose to add, such as progress photos and profile photos.
- Purpose: App functionality — to display your progress photos and profile image and, where applicable, to share content you explicitly choose to share within social features.
2.7 Purchase History
- What: Records relating to your in-app subscription and purchases (for example, your subscription status and entitlements). Payment is processed by Apple through the App Store; we do not collect or store your full payment card details.
- Purpose: App functionality — to provide and manage subscription features and entitlements.
2.8 Other Diagnostic Data
- What: Diagnostic and crash-related information, including app version and build number, device model, operating system version, and diagnostic log events containing a user identifier and contextual metadata.
- Purpose: App functionality and analytics — to diagnose errors, monitor reliability, and improve the app. See Section 4 ("Diagnostic Logging") for the dedicated disclosure of how diagnostic logs are transmitted.
3. Apple HealthKit
KalorIQ integrates with Apple HealthKit so your nutrition and health data can be viewed alongside the rest of your health and fitness ecosystem. HealthKit integration is optional and only operates after you grant the specific permissions iOS requests. You can review and change these permissions at any time in the iOS Settings → Privacy & Security → Health → KalorIQ screen, or within the Health app.
3.1 HealthKit data we read
With your authorization, KalorIQ reads the following categories of data from HealthKit:
- Body measurements: body mass (weight), height, body mass index (BMI), body fat percentage, lean body mass, waist circumference.
- Energy and activity: active energy burned, resting (basal) energy burned, step count, exercise minutes, stand hours, flights climbed, walking/running distance, cycling distance, swimming distance, running workout distance, VO2 max.
- Heart and vitals: heart rate, resting heart rate, heart rate variability (SDNN), respiratory rate, blood oxygen (oxygen saturation), body temperature, blood pressure (systolic and diastolic), blood glucose.
- Sleep and mindfulness: sleep analysis (deep, REM, core/light, and awake stages, and total sleep duration), mindful minutes.
- Nutrition and hydration: dietary water, dietary caffeine.
- Workouts: workout records (used, for example, to derive running distance).
3.2 HealthKit data we write back
With your authorization, and only when HealthKit sync is enabled, KalorIQ writes the following nutrition and hydration data you log in KalorIQ back into HealthKit so it appears in Apple Health alongside data from your other apps:
- Dietary energy consumed (calories)
- Dietary protein
- Dietary carbohydrates
- Dietary total fat
- Dietary water
- Body mass (weight)
If you delete a meal or water log in KalorIQ, the corresponding sample that KalorIQ wrote to HealthKit is also removed.
3.3 HealthKit data is uploaded to KalorIQ servers
HealthKit data that you authorize is uploaded to and stored on KalorIQ's servers operated by [COMPANY/JURISDICTION]. This is necessary to provide the core functionality of the app: synchronizing your health and fitness history across your devices, generating trends and insights, and computing goal progress. Data is transmitted over an encrypted (TLS) connection and associated with your authenticated account. KalorIQ limits each initial sync to a bounded historical window and synchronizes incrementally thereafter.
3.4 Required statement on use of HealthKit data
In accordance with Apple's App Review Guideline 5.1.3 and the HealthKit terms, we make the following commitments regarding data obtained through the HealthKit API:
- We will never use HealthKit data for advertising or any advertising-related purpose.
- We will never use HealthKit data for marketing.
- We will never use HealthKit data for data mining, or for any purpose other than providing health-management, fitness, and nutrition features to you (the user) for whom the data was collected.
- We will never sell HealthKit data, and we will never share, disclose, or otherwise provide HealthKit data to any third party (including data brokers, advertising platforms, or analytics providers) except as required to provide the service to you, or where required by law.
HealthKit data is used solely to provide and improve the health, fitness, and nutrition features of KalorIQ for you.
4. Diagnostic Logging
To keep the app reliable and to diagnose problems, KalorIQ transmits diagnostic log events to KalorIQ's servers operated by [COMPANY/JURISDICTION].
- What is transmitted: structured diagnostic log entries that may include a log level and message, a timestamp, the source file/function/line that emitted the event, your user identifier, and device and app information (device model, operating system version, app version, and build number). Limited, non-identifying contextual fields (such as request identifiers, endpoint names, HTTP methods, and status codes) may also be included.
- Why: to detect, investigate, and fix errors and crashes, monitor service reliability, and improve the app (app functionality and analytics).
- How it is protected: diagnostic logs are sent over an encrypted (TLS) connection. Before transmission, the app applies automated redaction designed to strip sensitive values — such as authentication tokens (bearer/JWT), email addresses, passwords, OAuth codes, and other secrets — from log messages. Diagnostic-context fields use a default-deny allowlist, so values for fields not explicitly permitted (for example, food names, meal names, or health values) are dropped rather than transmitted. Response bodies from sensitive endpoints (such as authentication, email, password, and session endpoints) are excluded from logging.
- Your control: diagnostic log transmission can be disabled within the app via the remote-logging control. Disabling it does not affect the core functionality of the app.
Diagnostic logs are retained only as long as needed for reliability and debugging purposes, consistent with Section 8 ("Data Retention").
5. No Third-Party Tracking or Advertising
KalorIQ does not include third-party advertising SDKs and does not integrate third-party tracking SDKs. Consistent with the app's privacy manifest:
- Tracking is disabled. The app does not track you, and it declares no tracking domains.
- We do not use your data — including your HealthKit data — to serve you advertising.
- We do not link your data with data from other companies' apps or websites for advertising or measurement.
- We do not sell your personal data.
All data described in this policy is collected for app functionality, account management, or analytics/diagnostics for KalorIQ itself, as stated per category in Section 2.
6. Account Creation, Deletion, and Data Export
6.1 Account creation
You create a KalorIQ account using your name and email address. Authentication uses secure bearer tokens (see Section 7, "Data Security").
6.2 In-app account deletion (30-day grace period)
You can delete your account directly within the app (in the privacy/account settings) using a type-to-confirm flow. When you request deletion:
- Your profile, nutrition and food logs, nutrition profiles and goals, progress photos and weight history, social content (friends, followers, and shared content), and preferences are scheduled for permanent deletion.
- A 30-day grace period applies. If you sign in again within those 30 days, your deletion request is cancelled and your account is restored.
- After the 30-day grace period elapses, your data is permanently erased and cannot be recovered.
- Any active subscription is cancelled at the end of the current billing period. Subscriptions are managed by Apple; you may also manage or cancel subscriptions through your Apple ID / App Store settings.
6.3 Data export
You can export a copy of your KalorIQ data from within the app. The export is generated on request and provided to you as a file you can save or share.
7. Data Security
We take reasonable and appropriate technical measures to protect your data:
- Encryption in transit: all communication between the app and KalorIQ's servers uses TLS (HTTPS). App Transport Security is enforced; the app does not permit plaintext connections.
- Secure credential storage: authentication tokens are stored in the iOS Keychain, protected with a device-only accessibility level (
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly), so credentials are not included in backups and remain on the device. - On-device protection of sensitive data: health-sensitive cached data stored on the device is written to encrypted files using iOS file protection (
NSFileProtectionComplete) and is excluded from iCloud/iTunes backups. - Redaction of sensitive values in logs: as described in Section 4, sensitive values are redacted before any diagnostic log is transmitted.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you have reason to believe your account is no longer secure, please contact us at [CONTACT EMAIL].
8. Data Retention
We retain your personal data for as long as your account is active or as needed to provide you the service. When you request account deletion, your data is retained only through the 30-day grace period described in Section 6.2, after which it is permanently erased, except where we are required to retain certain information to comply with legal obligations, resolve disputes, or enforce our agreements. Diagnostic logs are retained only as long as needed for reliability and debugging.
9. Children's Privacy
KalorIQ is not directed to children under the age of 13 (or the minimum age required in your jurisdiction, such as 16 in parts of the EEA/UK). We do not knowingly collect personal data from children under that age. If you believe a child has provided us with personal data, please contact us at [CONTACT EMAIL] and we will take steps to delete such information.
10. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, export, restrict, or delete your personal data, and to object to certain processing. You can exercise several of these rights directly in the app (data export and account deletion), or by contacting us at [CONTACT EMAIL]. We will respond to requests in accordance with applicable law.
If applicable to your jurisdiction, our Data Protection Officer can be reached at [DPO if applicable].
11. International Data Transfers
Your data may be processed and stored on servers located in [COMPANY/JURISDICTION] or other jurisdictions. Where required, we implement appropriate safeguards for cross-border transfers of personal data in accordance with applicable law.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, provide additional notice within the app. Your continued use of KalorIQ after the changes take effect constitutes your acceptance of the revised policy.
13. Contact Us
If you have questions or requests regarding this Privacy Policy or your data, contact us at:
- Email: [CONTACT EMAIL]
- Entity: [COMPANY/JURISDICTION]
- Data Protection Officer (if applicable): [DPO if applicable]