Privacy Policy
CalPad
Last updated: February 2026
1. Information We Collect
- Account information (email, name) via Apple or Google Sign-In
- Health data you voluntarily provide (weight, height, age, activity level)
- Meal data and descriptions you submit for analysis
- App usage analytics (screens viewed, features used)
- Device identifiers (IDFA) if you grant tracking permission
2. How We Use Your Information
- To provide personalized nutrition tracking and calorie calculations
- To improve app performance and user experience through analytics
- To send meal reminder notifications (if enabled)
- To sync your data across devices (optional)
- To measure the effectiveness of advertising campaigns
3. Advertising & Tracking
We use TikTok's App Events SDK to measure advertising campaign performance. If you grant permission via Apple's App Tracking Transparency prompt, we may collect your device identifier (IDFA) and share app events (such as registration and purchases) with TikTok for ad attribution and optimization. You can withdraw this permission at any time in your device Settings under Privacy & Security > Tracking.
4. Analytics
We use first-party analytics (PostHog) to understand how the app is used. This helps us improve CalPad's features and performance.
5. Data Storage & Security
Your health data is stored locally on your device and optionally synced to our secure servers. All data transmission uses industry-standard encryption.
6. Your Rights (CCPA/GDPR)
You have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account and all associated data
- Export your data
- Opt out of tracking via your device settings
- Opt out of data collection by deleting your account
To exercise these rights, use the "Delete Account" option in Settings or contact gary-jensen@outlook.com.
7. Children's Privacy
CalPad is not intended for children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us data, contact us immediately.
8. Data Retention
We retain your data while your account is active. Upon account deletion, all personal data is permanently removed within 30 days.
9. Third-Party Services
- Authentication: Apple Sign-In, Google Sign-In
- Backend: Supabase (database, authentication)
- AI Analysis: Google Gemini API (meal descriptions only, no personal data)
- Payments: Apple App Store (subscription management)
- Advertising: TikTok App Events SDK (ad attribution and campaign measurement)
10. Changes to Privacy Policy
We may update this policy periodically. We will notify you of significant changes.
11. Contact
For privacy concerns: gary-jensen@outlook.com
For support: gary-jensen@outlook.com