Privacy Policy
Last updated: 2026-07-23
1. Introduction and Controller
This Privacy Policy explains how the Calpaca app processes your personal data. We take the protection of your data seriously and process it in accordance with the EU General Data Protection Regulation (GDPR) and German data protection law.
The controller responsible for data processing is Michael Veltkamp, [ADDRESS], Germany. You can contact us at [CONTACT EMAIL] for any privacy-related questions or requests.
2. Data We Collect
Account data: your email address and authentication identity. Depending on your chosen sign-in method this includes an email and password, or an identifier provided by Sign in with Apple or Google Sign-In.
Profile data: birth date, sex, height, weight and weight history, goals, activity level, dietary preferences and allergies, and optionally your country and how you heard about the App.
Usage content: your food and drink logs including alcohol entries, water intake, recipes you save or generate, and optionally messages you send to the AI coach and food photos you submit for analysis.
Subscription data: your subscription status and entitlement, provided through our subscription management provider. We do not receive or store your payment card details.
3. Health Data and Explicit Consent
Several categories listed above, in particular your weight history, dietary logs, allergies, goals and related profile details, are health-related data and constitute special categories of personal data under Article 9 GDPR.
We process this health-related data exclusively on the basis of your explicit consent under Article 9(2)(a) GDPR, which you give during onboarding before entering this data. Without this consent the core functionality of the App cannot be provided.
You may withdraw your consent at any time with effect for the future by deleting your account in the App settings. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
4. Purposes and Legal Bases
We process your data to provide the App and its features, including calorie and nutrient calculations, goal tracking, recipes, reminders and insights. The legal bases are the performance of our contract with you (Article 6(1)(b) GDPR) and, for health-related data, your explicit consent (Article 9(2)(a) GDPR).
We process account and subscription data to manage your account and entitlements (Article 6(1)(b) GDPR) and to comply with legal obligations such as tax and commercial record-keeping (Article 6(1)(c) GDPR).
We process the self-reported acquisition source in aggregate to understand how users find the App, based on our legitimate interest in improving the service (Article 6(1)(f) GDPR). We do not use your data for third-party advertising or profiling for advertising purposes.
5. AI Features
When you use the AI coach chat, meal photo scanning or AI recipe generation, the content you submit (chat messages, food photos, relevant profile context such as goals or dietary preferences) is transmitted to our AI provider Anthropic for processing and generation of a response.
This processing takes place only when you actively use an AI feature and is based on the performance of the contract (Article 6(1)(b) GDPR) and, insofar as health-related data is involved, on your explicit consent (Article 9(2)(a) GDPR).
We do not use your content to train our own models. Please do not include personal data of other people in chat messages or photos.
6. Processors and Recipients
We use the following service providers as processors or independent recipients: Supabase (database hosting and authentication), RevenueCat (subscription management), Apple App Store and Google Play (payment processing and app distribution), Apple and Google (sign-in services), and Anthropic (AI features).
Processors act on our instructions under data processing agreements pursuant to Article 28 GDPR. Apple and Google act as independent controllers for payments and their sign-in services under their own privacy policies.
We do not share your data with any other third parties unless we are legally obliged to do so.
7. International Data Transfers
Some of our providers process data in the United States or other countries outside the European Economic Area, including Supabase (depending on hosting region), RevenueCat, Apple, Google and Anthropic.
Where data is transferred to third countries, we rely on adequacy decisions of the European Commission, including the EU-US Data Privacy Framework where the provider is certified, or on the EU Standard Contractual Clauses with supplementary measures where required.
8. Subscriptions and Payment Data
Purchases are processed entirely by the Apple App Store or Google Play. We never receive your payment card or bank details.
RevenueCat processes pseudonymous purchase and entitlement information (such as a user identifier, product identifier, purchase and renewal events) on our behalf so that we can activate premium features on your account.
9. Notifications and Local Data
Reminder notifications are generated locally on your device and require your permission at the operating system level. We do not process notification content on our servers.
The App stores certain settings and cached data locally on your device to work smoothly. This local data is removed when you uninstall the App.
10. Data Retention
We store your personal data for as long as your account exists, because your historical logs are the core of the service you use.
When you delete your account, all data associated with it is permanently erased from our database. Statutory retention obligations, for example for billing records held by the stores, remain unaffected and are handled by the respective provider.
Backups that may temporarily contain deleted data are overwritten within the regular backup rotation of our hosting provider.
11. Deleting Your Account
You can delete your account at any time directly in the App settings. This function erases every record associated with your account, including your profile, health-related data, food and drink logs, photos, chat history and generated recipes.
Account deletion also constitutes withdrawal of your consent to the processing of health-related data. Remember to separately cancel any active subscription in your App Store or Google Play account.
12. Your Rights
Under the GDPR you have the right of access (Article 15), the right to rectification (Article 16), the right to erasure (Article 17), the right to restriction of processing (Article 18), the right to data portability (Article 20) and the right to object to processing based on legitimate interests (Article 21).
Where processing is based on consent, you have the right to withdraw that consent at any time with effect for the future.
To exercise your rights, contact us at [CONTACT EMAIL]. You also have the right to lodge a complaint with a data protection supervisory authority, in particular the authority of the German federal state in which the Operator is established or of your habitual residence.
13. No Sale of Data
We do not sell your personal data and we do not share it with advertisers, data brokers or analytics networks for advertising purposes. Your health-related data is used solely to provide the App to you.
14. Children
The App is not directed at children under 16. We do not knowingly collect personal data from children under 16 without the consent or authorisation of a holder of parental responsibility.
If you believe a child has provided us with personal data without such consent, contact us at [CONTACT EMAIL] and we will delete the data.
15. Data Security
We use appropriate technical and organisational measures to protect your data, including encrypted transmission (TLS), encryption at rest at our hosting provider, and access controls that restrict database access to your own account.
No system is completely secure. Protect your account by using a strong, unique password or a platform sign-in method such as Sign in with Apple or Google Sign-In.
16. Our Website
This Privacy Policy also covers our website at [WEBSITE DOMAIN], which presents the App and hosts our legal documents. The website does not use cookies, analytics or tracking technologies, and fonts are served from our own hosting rather than from third-party servers.
When you visit the website, our hosting provider processes the technical data your browser transmits (IP address, date and time of access, requested page, browser type and version) in server logs in order to deliver the site and to ensure its security and stability. The legal basis is our legitimate interest in providing a functional and secure website (Article 6(1)(f) GDPR). Log data is not merged with other data and is deleted after a short retention period.
The website is built and hosted with Lovable. Hosting infrastructure may involve sub-processors outside the European Economic Area; in that case the safeguards described in Section 7 apply.
17. Changes and Contact
We may update this Privacy Policy when our processing activities or legal requirements change. The date of the latest revision is shown in the App, and we will inform you of material changes in the App or by email.
Questions about this Privacy Policy and requests concerning your data can be sent to Michael Veltkamp, [ADDRESS], [CONTACT EMAIL].