In one paragraph: Calivora AI is an AI calorie and macro tracker for Android. Your food photos are processed, not stored — they are sent to an AI provider to generate the result and are then discarded, and they are never used to train AI models. Camera, microphone and notification permissions are each used only for the feature you tap. We do not sell any data, and your health, food, body and AI-chat data are never shared with advertisers. You must be 18 or over to use the app. You can delete your account and all data from inside the app, with a 7-day grace period to change your mind.
1. Introduction
This Privacy Policy explains how the Calivora AI Team
("Calivora AI", "we",
"us") collects, uses, shares, stores and protects personal
data when you use the Calivora AI Android application
(package com.calivora.ai, the "App") and this
website.
It is written to meet the Google Play User Data policy, the Google Play Data Safety requirements, the EU and UK General Data Protection Regulation ("GDPR"), the California Consumer Privacy Act as amended ("CCPA/CPRA") and comparable privacy laws.
By installing or using the App you confirm you have read and understood this policy. If you do not agree with it, please do not use the App.
2. Who we are
Calivora AI is built and operated by an independent development team. There is no registered company entity. The team is the data controller for the personal data described here.
| Data controller | Calivora AI Team |
|---|---|
| Team members | Muhammad Umer · Muhammad Shahkar · Muhammad Huzaifa |
| Contact email | aicalivora@gmail.com |
| App package | com.calivora.ai |
| Platform | Android, distributed via Google Play |
3. Age requirement (18+)
Calivora AI is for adults aged 18 and over. The App is not directed to children, and we do not knowingly collect personal data from anyone under 18.
If you believe someone under 18 has created an account, email aicalivora@gmail.com and we will delete the account and its data promptly.
4. Data we collect
We collect only what the App needs to function. Every category below maps to a feature you can see in the App.
4.1 Account data
- Email address.
- Password, stored only as a salted hash by Supabase Auth. We can never read or recover it.
- If you use Continue with Google: your email address, basic profile information and a stable Google account identifier.
- Profile name and, if you upload one, an avatar image.
4.2 Body & goal data
- Sex, age, height and current weight.
- Activity level.
- Your selected goal: Lose Weight, Maintain Weight or Build Muscle.
- The daily calorie and macro targets calculated from the above.
- Weight entries you log over time, used for trends and pace projections.
4.3 Food & nutrition logs
- Meal names, portions, calories, protein, carbohydrates and fat.
- The meal type each entry is assigned to (breakfast, lunch, dinner, snack).
- Corrections you make to any AI-detected item before saving it.
- Water intake logged against your daily cup target.
- Streak and achievement progress.
4.4 Exercise data
- Workout descriptions you type and the duration in minutes.
- The MET-based calorie burn the AI returns, used in the Maintain Weight energy balance.
4.5 Calivora Coach conversations
- The messages you send to the in-app AI coach and its replies.
- Chat history, stored on your device and associated with your account.
- Your name, weight, goal and targets, sent as context so replies are relevant.
4.6 Subscription data
- Your entitlement tier and whether a subscription or free trial is currently active.
- The Google Play
purchaseTokenand the subscription state returned by Google's Play Developer API.
We never receive or store your payment card details. Google Play handles all payment.
4.7 Preferences
- Your chosen app language, bound to your account and followed across devices.
- Dark mode preference.
- Per-category notification toggles.
- Your notification push token, if you enable reminders.
4.8 Diagnostics
- Crash reports and error diagnostics collected by Sentry — see Section 16.
4.9 Advertising data (free plan only)
- Google AdMob collects your Android Advertising ID and ad interaction data directly, as an independent controller — see Section 15.
5. What we never collect
- We do not store your food photos. See Section 7.
- We do not collect GPS or any location data.
- We do not access your contacts, SMS, call logs or calendar.
- We do not record audio outside an active Voice Log recording, and never in the background.
- We do not read your photo library — only images you explicitly capture or select.
- We do not collect payment card numbers, CVV codes or bank details.
- We do not use behavioural analytics. There is no product-analytics SDK in the App.
- We do not sell personal data, and we never share health, food, body or AI-chat data with advertisers.
6. Permissions explained
Every Android permission the App requests, and exactly why:
| Permission | Why it is needed | Optional? |
|---|---|---|
| Camera | Live camera for AI Photo Scan and for the barcode scanner. | Yes — barcodes can be entered manually and meals added by voice or Quick Add. |
| Photos / media | Selecting an existing meal photo from your gallery, and setting a profile avatar. | Yes |
| Microphone | Recording a Voice Log entry so speech-to-text can transcribe what you ate. | Yes — the rest of the App is unaffected if denied. |
| Notifications | Meal, water, calorie-check, streak and weigh-in reminders, achievement alerts and the midnight daily summary. | Yes — every category has its own toggle. |
| Internet / network state | Syncing with our backend, running AI features, and powering the offline gate that tells you when you have lost connection. | No — required for the App to function. |
You can revoke any optional permission at any time in Android Settings. Only the feature that depends on it stops working.
7. Food photos: processed, not stored
This is one of the most important things to understand about Calivora AI.
- When you scan a meal, the photo is transmitted over an encrypted (TLS) connection to our Supabase Edge Function.
- The Edge Function forwards it to an AI vision provider, which returns the detected foods with calories and macros.
- The photo is then discarded. We do not retain it, and it is not saved into your meal history.
- What is saved is the resulting nutrition data — meal name, calories, protein, carbs and fat — after you review and confirm it.
- Your photos are never used to train AI models, ours or anyone else's.
- Your photos are never sold, published, or shared with advertisers.
AI providers may hold API content briefly for their own abuse monitoring under their published terms. That is outside our control and is not retention by us.
8. Voice Log & the microphone
Voice Log lets you say what you ate instead of photographing
or typing it. This requires the Android RECORD_AUDIO permission.
8.1 How Voice Log works
- You tap the microphone control to start recording.
- You describe your meal out loud, in any language.
- You tap stop. The microphone switches off immediately.
- The recording is sent over an encrypted connection to our
voice-logEdge Function. - OpenAI Whisper transcribes the audio into text.
- The AI parses that text into individual foods with calories and macros.
- Every detected item is shown to you and is editable before you save it.
8.2 Microphone guarantees
- The microphone is active only between your tap to start and your tap to stop.
- It is never used in the background, never while the App is closed, and never to listen passively.
- Audio is used for one purpose: transcribing your meal description.
- The recording is not retained after transcription. Only the resulting text and the nutrition entry you save are kept.
- Your voice is never used for identification, biometrics, profiling or advertising.
- Deny or revoke the permission and only Voice Log stops working. Photo scan, barcode and Quick Add are unaffected.
9. AI features & providers
Calivora AI uses several AI features. All of them run through our own Supabase Edge Functions. The App never calls an AI provider directly, and API keys are held server-side only.
9.1 The AI features
- AI Photo Scan — vision analysis of a meal photo.
- Voice Log — speech-to-text plus food parsing.
- AI Workout Analysis — turns a typed workout description and duration into a MET-based calorie burn.
- Calivora Coach — the in-app AI nutrition chatbot.
- Translation — translating the interface into your chosen language.
9.2 Providers and failover
We use a multi-provider backend with automatic failover, so a single provider outage does not break the App:
- Anthropic — Claude Haiku 4.5. Primary provider, including vision.
- OpenRouter — used as a fallback route to Anthropic models only.
- OpenAI — gpt-4o / gpt-4o-mini as a final fallback, and Whisper for all speech-to-text.
Which provider handles a given request depends on availability at that moment. All three are bound by their own terms; we use API tiers on which submitted content is not used to train the provider's models.
9.3 What is sent to AI providers
We send the minimum needed to produce a result:
- The meal photo, voice recording, workout description or coach message itself.
- For Calivora Coach only: your first name, weight, goal and daily targets, so the answer is relevant to you.
We do not send your email address, password, account identifier, subscription status or advertising ID to any AI provider.
9.4 Rate limiting
Every AI Edge Function requires a signed-in user and enforces a per-account daily rate limit. This protects the service from abuse and keeps it sustainable.
9.5 Accuracy
AI output is an estimate, not a measurement. See Section 26 and our Terms of Service.
10. Calivora Coach
Calivora Coach is an in-app AI chatbot, scoped strictly to nutrition, training, your goal and using the App. Off-topic or abusive messages are politely refused.
- Conversations are saved so you can reopen and continue them. Chat history is stored on your device and tied to your account.
- The coach is given your name, weight, goal and targets as context.
- It remembers recent messages within the open conversation.
- It replies in the exact language and script you write in.
- You can start a new chat or delete any past conversation at any time.
- Messages are processed by the
ai-chatEdge Function using the providers in Section 9. - Your chat content is never shared with advertisers and is never sold.
11. Barcode lookups
When you scan or type a product barcode, the App looks it up through the free,
public Open Food Facts database via our
barcode-lookup Edge Function.
- Only the barcode number is sent. No account data, no personal identifiers, nothing that identifies you.
- The nutrition values returned are shown for you to confirm and edit.
- Open Food Facts is an independent, open-data project and is not owned by us.
12. Multi-language translation
Calivora AI can run its entire interface in any language, including right-to-left scripts.
- Interface strings are translated by AI through the
translateEdge Function. - Translations are cached in Supabase and on your device, so the same string is not translated twice.
- Only interface text is translated. Your personal meal entries and body data are not sent for translation.
- Your language choice is bound to your account and follows you across devices.
13. Accounts & sign-in
Authentication is handled by Supabase Auth, acting as our processor.
13.1 Email & password
- Your password is stored only as a salted hash. Neither we nor Supabase can read it.
- Email confirmation is off, so sign-up goes straight into onboarding.
- Sessions persist on your device until you sign out manually.
13.2 Continue with Google
You may sign in with Google instead. Google shares your email address, basic profile information and a stable account identifier with us.
- We never receive your Google password.
- We gain no access to Gmail, Drive, Contacts or any other Google service.
- You can revoke access at any time from your Google Account permissions page.
14. Subscriptions & billing
Premium is an auto-renewing subscription (calivora_premium) sold
exclusively through Google Play Billing, with monthly and
yearly base plans and a 7-day free trial.
- We use no third-party billing service. There is no external subscription-management vendor.
- The App opens Google Play's purchase sheet and forwards only the
purchaseTokento our ownverify-purchaseEdge Function. - That function verifies the token against Google's Play Developer API and is the only thing that can grant a paid tier. The client never decides entitlement.
- Google sends us subscription lifecycle events (renewal, cancellation, grace period, on-hold, pause, refund) through Real-Time Developer Notifications.
- Our
subscriptionstable is the source of truth and is read-only to the client. - We never receive your payment instrument. Google Play is the merchant of record and processes payment as an independent controller under its own privacy policy.
15. Advertising (Google AdMob)
The free plan is supported by ads served by Google AdMob. Premium subscribers, including during the free trial, never see ads.
15.1 Ad formats used
- Banner ads on the Log and Progress tabs.
- Interstitial ads, shown once after a capture completes and frequency-capped.
- App Open, Rewarded and Native ad formats are not implemented.
15.2 What AdMob collects
Google AdMob collects the following directly, as an independent controller:
- Your Android Advertising ID, a resettable identifier you control.
- Device type, operating system version and IP-derived country or region.
- Ad impressions and clicks.
15.3 Consent in the EEA and UK
In the European Economic Area and the United Kingdom, a Google-certified UMP consent form is shown before any personalised advertising. Unless you consent, non-personalised ads are requested instead.
15.4 What advertisers never receive
Your health, food, body and AI-chat data are never shared with AdMob, advertisers or any ad network, and are never used to target ads. Nothing is sold.
15.5 Your choices
- Reset or delete your Advertising ID in Android Settings → Privacy → Ads.
- Enable Opt out of Ads Personalisation for non-personalised ads only.
- Subscribe to Premium to remove advertising entirely.
Google's handling of ad data is described in Google Privacy & Terms. Our authorised sellers file is at app-ads.txt.
16. Crash reporting (Sentry)
We use Sentry to capture crashes and errors so we can fix them. This is the only third-party SDK that receives diagnostic data.
- A crash report may include the stack trace, device model, OS version, app version and the screen that was open.
- Crash data is used only for stability and debugging.
- It is never used for advertising, profiling or behavioural analytics.
- We do not attach your meal data, photos, coach messages or body measurements to crash reports.
Separately, users never see raw backend errors: the App routes every user-facing error through a generic message layer while full detail is logged server-side.
17. How we use your data
| Purpose | Data used |
|---|---|
| Detect foods and estimate nutrition from a photo | Meal photo (discarded after processing) |
| Transcribe and parse a Voice Log entry | Voice recording (discarded after transcription) |
| Return product nutrition from a barcode | Barcode number only |
| Estimate calories burned in a workout | Workout description and duration |
| Answer questions in Calivora Coach | Your message, name, weight, goal and targets |
| Calculate your daily calorie and macro targets | Sex, age, height, weight, activity level, goal |
| Roll over unmet calories and protein at midnight | Yesterday's totals against your targets |
| Show progress, trends, streaks and achievements | Nutrition logs, water, weight entries |
| Run the interface in your language | Interface strings and your language choice |
| Create your account and keep you signed in | Email, password hash or Google identifier |
| Unlock Premium features you paid for | Google Play purchase token, subscription state |
| Send the reminders you enabled | Notification toggles, push token |
| Show ads on the free plan | Advertising data collected by AdMob |
| Diagnose and fix crashes | Sentry crash reports |
| Answer your support or privacy request | Your email and the content of your message |
18. Legal bases for processing (GDPR)
- Performance of a contract (Art. 6(1)(b)) — your account, meal logging, targets, Premium entitlement.
- Explicit consent (Art. 9(2)(a)) — body measurements, nutrition logs and weight history, which concern health.
- Consent (Art. 6(1)(a)) — camera, microphone and notification permissions, and personalised advertising via the UMP form.
- Legitimate interests (Art. 6(1)(f)) — security, abuse prevention, rate limiting and crash diagnostics, balanced against your rights.
- Legal obligation (Art. 6(1)(c)) — records we must keep and lawful requests we must answer.
You may withdraw consent at any time. Withdrawal does not affect processing carried out beforehand.
19. Third-party processors
These are the only third parties involved, and exactly what each receives.
| Service | Purpose | Data received |
|---|---|---|
| Supabase | Database, authentication, storage, Edge Functions | Account, body, nutrition, water, weight, coach history |
| Anthropic | Primary AI, including vision | Meal photos, parsed text, coach messages |
| OpenRouter | Fallback route to Anthropic models | Same as above, only on failover |
| OpenAI | Fallback AI, and Whisper speech-to-text | Voice recordings, meal photos, coach messages |
| Google Sign-In | Optional federated sign-in | Email, basic profile, account identifier |
| Google Play Billing | Payment and subscription lifecycle | Purchase transactions (handled by Google) |
| Google AdMob | Ads on the free plan | Advertising ID, device data, ad interactions |
| Open Food Facts | Barcode product lookup | Barcode number only |
| Sentry | Crash and error reporting | Stack traces, device and app state |
There is no product-analytics provider and no third-party billing vendor in this list, because the App uses neither.
21. International transfers
We are based in Pakistan and our processors operate in other countries, including the United States and the European Union. Using the App therefore involves international data transfers.
For transfers out of the EEA or UK, our processors rely on appropriate safeguards including the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, supported by encryption in transit and at rest. Email aicalivora@gmail.com for details.
22. Data retention
| Data | Retention |
|---|---|
| Food photos | Not retained. Discarded immediately after the AI returns a result |
| Voice recordings | Not retained. Discarded immediately after transcription |
| Account, body and goal data | While your account is active |
| Nutrition logs, water, weight, streaks | While your account is active, or until you delete the entry |
| Calivora Coach history | Until you delete the conversation or your account |
| Subscription records | While active, plus the period Google Play requires |
| Push notification token | Until you disable notifications or sign out |
| Translation cache | Indefinitely — interface strings only, no personal data |
| Deletion request | Executed after the 7-day grace period |
| Optional exit survey answers | Retained to help improve the App, if you choose to complete it |
| Encrypted backups | Deleted as those backups expire on their normal cycle |
| Crash logs (Sentry) | Retained for a limited period, then deleted automatically |
| Support correspondence | Up to 24 months after resolution |
23. Security
- Encrypted in transit (TLS) and at rest.
- Row-level security in Postgres, so an account can only ever read and write its own rows.
- Hardened, access-controlled storage buckets that are not publicly browsable.
- Passwords stored only as salted hashes.
- All AI provider keys live server-side in Edge Functions and are never shipped in the app binary.
- Every AI function requires a signed-in user and enforces a per-account daily rate limit.
- Subscription entitlement is server-verified; the client cannot grant itself a paid tier.
- Purchase tokens already bound to another account are rejected.
No system is perfectly secure. If we become aware of a personal data breach likely to risk your rights, we will notify the relevant authority and affected users without undue delay, as required by law.
24. Your rights
24.1 Available to everyone
- Access — a copy of the data we hold about you. The App also has an Export option.
- Rectification — correct anything inaccurate.
- Erasure — delete your account and data. See Section 25.
- Portability — your data in a machine-readable format.
- Withdraw consent — at any time.
24.2 Additional GDPR rights
- Restriction of processing.
- Objection to processing based on legitimate interests.
- Not to be subject to solely automated decisions with legal or similarly significant effects. Calivora AI makes none — all AI output is advisory and editable.
- Complaint to your local supervisory authority.
24.3 Additional CCPA/CPRA rights
- To know what is collected and why.
- To delete and to correct.
- To limit the use of sensitive personal information.
- To opt out of sale or sharing — we do neither, so there is nothing to opt out of.
- Not to be treated differently for exercising any right.
24.4 How to exercise them
In the App, use Profile → Data Consent and the export and deletion controls. Or email aicalivora@gmail.com from your account address. We respond within 30 days, free of charge unless a request is manifestly unfounded or excessive.
25. Account deletion
You can permanently delete your account and data from inside the App: Profile → Data Consent → Delete account.
- Deletion is scheduled and your account enters a 7-day grace period.
- Sign in again within those 7 days and the deletion is cancelled — your account and all data are fully restored.
- After 7 days, deletion is permanent and processed by our daily purge.
Can't open the App? Email aicalivora@gmail.com from your account address with the subject "Delete my account".
Full instructions, exactly what is deleted, and what may be briefly retained are on our dedicated page:
Deleting your account does not cancel a Google Play subscription. Cancel it separately in Google Play to stop billing.
26. Health disclaimer
Calivora AI provides general wellness information only. It is not a medical device and does not provide medical advice, diagnosis or treatment. AI nutrition and calorie-burn values are estimates and may be inaccurate.
Consult a qualified healthcare professional before changing your diet or calorie intake, particularly if you have a medical condition, are pregnant or nursing, or have a history of disordered eating.
27. This website
- It sets no advertising or tracking cookies.
- It runs no analytics scripts.
- There are no external fonts, scripts or trackers — every asset is served from this site.
- Your light or dark theme preference is kept in your browser's local storage. It never leaves your device.
Our hosting provider may process server logs including IP addresses for security and abuse prevention.
28. Changes to this policy
We may update this policy as the App evolves. The "Last updated" date at the top always shows the current version. For material changes — a new data category, a new purpose, or a new processor with access to your health data — we will give prominent notice in the App and, where legally required, ask for renewed consent first.
29. Contact us
| aicalivora@gmail.com | |
| Controller | Calivora AI Team |
| Response time | Within 30 days of a verified request |
If you are in the EEA or UK and we have not resolved your concern, you may complain to your national data protection authority.
See also our Terms of Service, Account Deletion page and Contact page.