We wrote this policy to be read. Here is the short version — the full details follow below.
Calina (the “Service”, “we”, “us”) is a mobile application operated by:
Agnė Jakaitė, a sole proprietor registered under an Individual Activity Certificate in the Republic of Lithuania, registration certificate No. 1241855.
For all privacy matters, we are the data controller of your personal data under the EU General Data Protection Regulation (“GDPR”) and equivalent laws.
Contact: [email protected]
This policy applies to the Calina mobile application and the mycalina.com website. It forms part of, and should be read together with, our Terms and Conditions.
We collect only what the Service needs to work. We collect no advertising identifiers and no cross-app advertising-tracking data, and we run no advertising SDKs and no general third-party product-analytics SDKs in the app. Our subscription provider, RevenueCat, also measures how our own paywall and pricing convert so we can improve our subscription screen (see Section 2.5); this is limited to subscription and purchase signals and never uses your health data.
What: email address and password (stored by our authentication provider in hashed form — we never see your plain-text password), or, if you choose Sign in with Apple / Google, the identifier and email your provider shares with us. Why: to create and secure your account, let you sign in on your device, and send essential service emails (email confirmation, password reset). Legal basis: performance of a contract (GDPR Art. 6(1)(b)).
What: gender, age, height, weight, activity level, your nutrition goal, and the personal reason (“why”) you optionally share during onboarding; calculated calorie and protein targets. Why: to calculate your personal targets and tailor your daily and weekly insights to your goal — this is the core of what Calina does. Where: stored locally on your device; processed transiently by our AI provider when generating insights (see Section 3). Legal basis: your explicit consent (GDPR Art. 6(1)(a) and Art. 9(2)(a)) — because information about your body and diet is health data (“special category data”) under the GDPR, we ask for your explicit consent before processing it, and you may withdraw that consent at any time (see Section 6).
What: the meals you describe by text or voice, and the resulting calorie/macronutrient estimates. Why: so you can see your day, and so Calina can generate your insights. Where: stored only on your device. Meal descriptions are sent transiently to our servers and AI provider to be analysed at the moment you log them (Section 3), but we do not keep a copy of your meal history on our servers. Legal basis: your explicit consent (Art. 6(1)(a), Art. 9(2)(a)).
If you log food by voice, speech-to-text conversion is performed by your device’s operating system (e.g. Apple’s speech recognition). Depending on your device settings, Apple may process the audio on-device or on Apple’s servers under Apple’s own privacy terms. We never receive or store your audio — only the resulting text transcript, which is treated as food log data (Section 2.3).
What: your subscription status (trial/active/expired) and an anonymised app-user identifier managed by RevenueCat; purchase receipts are processed by Apple. RevenueCat also remotely configures our paywall and may run price/paywall A/B tests (“experiments”), recording which paywall variant you were shown and whether it led to a trial or subscription. Why: to know whether your subscription is active, restore purchases across reinstalls, and measure and improve how our own subscription screen and pricing convert. For this we process only non-health subscription and purchase signals — never your meals, body metrics or goals. What we never see: your card number or full payment details — payment is handled entirely by Apple. Legal basis: performance of a contract for managing your subscription (Art. 6(1)(b)); our legitimate interests in measuring and improving our paywall and pricing (Art. 6(1)(f)).
What: a per-user count of AI requests over a rolling 24-hour window (rate limiting), and security event records (e.g. rate-limit breaches, account changes) with technical metadata. Why: to protect the Service against abuse, keep AI costs sustainable, and detect suspicious account activity. Legal basis: our legitimate interests in securing the Service (Art. 6(1)(f)); we have assessed that this limited technical processing does not override your rights.
Reminders are scheduled locally on your device. We do not operate a push-notification server and do not collect push tokens. You control notifications in the app and in your device settings.
No advertising ID, no location data, no contacts, no photos, no cross-app or cross-site advertising tracking, no advertising SDKs, no general third-party product-analytics SDKs, and no data broker sources. Our subscription provider RevenueCat measures only our own paywall and subscription conversion (Section 2.5), not your activity across other companies’ apps. Because we do not track you across other apps or websites for advertising, the app does not request App Tracking Transparency permission.
Calina’s food recognition and insights are powered by large language models (currently Anthropic’s Claude models). Here is exactly what happens when you log a meal or receive an insight:
Anthropic processes this data as our processor/service provider under its commercial terms and does not use API inputs or outputs to train its models by default. We do not send Anthropic your name, email address, or account identifiers with these requests. We retain no copy of the request content on our servers — only the request count described in Section 2.6.
AI-generated content may occasionally be inaccurate. It is not medical advice (see Section 7).
We share personal data only with the providers needed to run the Service, under data processing agreements:
| Provider | Role | Data involved | Location |
|---|---|---|---|
| Supabase | Database, authentication, server functions | Account data, security data, transient AI request routing | EU (Frankfurt) |
| Anthropic | AI processing of food text and insight generation | Meal descriptions, goal context (no name/email attached) | USA |
| Apple | App distribution, payments, Sign in with Apple, on-device speech recognition | Purchase and sign-in data under Apple’s own terms | USA/global |
| Sign in with Google (optional) | Sign-in identifier and email | USA/global | |
| RevenueCat | Subscription entitlement management, paywall configuration, and price/paywall A/B testing | Anonymised app-user ID, purchase receipts, subscription status, paywall interaction events (no health data, no name/email) | USA |
| Resend | Transactional email delivery (confirmation, password reset) | Email address, email content | USA |
We do not sell personal data, we do not share it with advertisers or data brokers, and we do not use health data for advertising of any kind.
We may disclose personal data if required by law, to protect our legal rights, to prevent fraud or abuse, or as part of a business transfer (merger, acquisition) — in which case this policy will continue to apply to your data and you will be notified of any material change.
We are based in Lithuania (EU). Some of our providers process data in the United States. Where personal data is transferred outside the EU/EEA or UK, we rely on appropriate safeguards: the EU–U.S. Data Privacy Framework (where the provider is certified) and/or the European Commission’s Standard Contractual Clauses (and the UK Addendum / International Data Transfer Agreement for UK data), together with supplementary technical measures such as encryption in transit.
No system is perfectly secure. If a breach occurs that is likely to result in a high risk to your rights, we will notify you and the competent supervisory authority as required by GDPR Articles 33–34.
| Data | Kept until |
|---|---|
| Account data | You delete your account (then removed, subject to short technical backup cycles) |
| Profile, goals, meal history (on your device) | You delete the app, clear its data, or delete your account content — under your control |
| AI request counts | Automatically deleted after 30 days (nightly scheduled purge) |
| Security event records | Automatically deleted after 12 months (nightly scheduled purge) |
| Internal audit trail (account/consent change log) | Automatically deleted after 24 months; the current consent record itself is kept for the lifetime of your account |
| Subscription records (RevenueCat/Apple) | As required for accounting/tax law and by Apple’s own retention rules |
When you delete your account (Profile → Account → Delete account), your authentication record, your profile row, and your AI request counts are deleted immediately. Security event records are retained in anonymised form (with your user identifier removed) and internal audit-trail entries are kept, in both cases only until the retention periods in the table above expire, after which they are automatically purged. Data stored locally on your device is removed when you delete the app. Note: deleting your account does not cancel an active App Store subscription — cancel it in your Apple ID settings (see Terms, Section 6).
You have the right to:
To exercise any right, use the in-app controls or email [email protected]. We respond within one month (extendable by two further months for complex requests, with notice). Exercising your rights is free of charge.
Complaints: you may lodge a complaint with your local supervisory authority. Our lead authority is the Lithuanian State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, vdai.lrv.lt). UK users may contact the ICO (ico.org.uk).
We do not sell or “share” (for cross-context behavioural advertising) personal information, and we have not done so in the preceding 12 months. Depending on your state (e.g. California CCPA/CPRA, and consumer health data laws such as Washington’s My Health My Data Act), you may have rights to know, access, correct, and delete personal information, and a right to non-discrimination for exercising them. You can exercise these rights via the in-app controls or [email protected]. We honour these rights for all US users regardless of state.
We process personal information in accordance with PIPEDA and applicable provincial laws (including Québec’s Law 25). You have rights of access and correction, and may withdraw consent subject to legal and contractual restrictions. Our contact for privacy matters is [email protected].
Calina provides estimates and general informational insights only. Calorie and nutrient values are approximations generated by AI models from the information you provide. Calina does not provide medical, dietary, or psychological advice, diagnosis, or treatment, and is not a substitute for a qualified physician or registered dietitian. Always consult a healthcare professional before making significant changes to your diet — especially if you are pregnant, breastfeeding, managing a medical condition, taking medication, or have a history of disordered eating. See our Terms and Conditions, Sections 10–11 and 14, for the full disclaimer and limitation of liability. This policy and the Terms are aligned: nothing in either document expands the purposes for which your health data is used.
Calina is not directed at children. You must be at least 16 years old (or older where your local law requires a higher age for consenting to data processing) to use the Service. We do not knowingly collect personal data from anyone under this age; if we learn that we have, we will delete it and close the account.
The Calina app uses no cookies and no tracking technologies. The mycalina.com website uses only technically necessary means to serve its pages and does not set analytics or marketing cookies. Links to third-party sites (e.g. Apple’s App Store) are governed by those parties’ own policies.
We may update this policy as the Service, law, or our providers change. For material changes we will give you reasonable advance notice in the app or by email before the changes take effect, and — where the change concerns processing based on your consent — we will ask for your consent again. The “Last updated” date at the top always tells you when the policy last changed. Earlier versions are available on request.
Questions, requests, or concerns about this policy or your data:
Email: [email protected] Controller: Agnė Jakaitė, sole proprietor (Individual Activity Certificate No. 1241855, Republic of Lithuania)
This Privacy Policy is provided in English. If a translation is ever provided, the English version prevails to the extent permitted by applicable law.