Kcal Ledger Privacy Policy

Last updated: September 12, 2026

中文/English

This Privacy Policy explains how Kcal Ledger (the “App”) handles information when you use the App. If you do not agree with this policy, please do not use the App.

1. Records stored on your device

Your meal, exercise, body-metric, goal, favorite-food, report, and saved analysis records are stored in a local SwiftData store on your device. They are not synchronized to our server, and the App does not use iCloud or CloudKit for these records. Removing the App may remove this local data unless you made a separate backup.

2. Account, purchases, and support

3. Health information

With your permission, the App reads selected Health data on your device, such as date of birth, biological sex, height, weight, and active energy, to prefill profile information, estimate daily energy needs, or synchronize activity energy. The App does not write to Health data, and raw samples are not directly uploaded to our server.

If you request exercise analysis, the request may include selected profile and body-metric values—such as weight, height, body-fat percentage, muscle mass, basal metabolic rate, and a body-metric note—after the App presents the analysis consent disclosure. These values are used only to complete that request.

4. Analysis and report requests

When you choose an analysis or report feature, the information needed for that request is encrypted in transit, sent through our server, and forwarded to a third-party processing service. Depending on the feature, this may include:

This information is used to identify food or exercise, estimate nutrition or energy expenditure, and generate the analysis or report you requested. Except for the eligible short meal-text cache described below, request text, photos, and submitted report data are not retained as a long-term server-side copy of your records. To deliver a completed request reliably and let the same request retrieve its result after a network interruption, the complete analysis or report result may be stored temporarily in a server-side delivery buffer for up to about 48 hours by default, then cleared.

For eligible short meal-text requests that pass the service’s privacy filters, our server uses a shared analysis cache to reduce repeat processing and wait time by allowing a later equivalent request to reuse an existing result. The cache key uses a non-reversible hash and version information and is not linked to your account identifier. The cache stores the complete reusable analysis result and, when a matched food reference is included in its context, may also contain the short text you submitted. Cache entries currently have no fixed automatic expiration and may remain indefinitely until they are overwritten or removed. Photos, exercise inputs and body metrics, and report inputs are not stored in this shared cache.

Results are estimates for tracking and reference and may be inaccurate. Do not submit highly sensitive identifiers or complete financial account information.

5. Operational analytics and third-party diagnostics

We retain operational product-interaction data linked to your account, such as request time, feature type, usage and cost fields, and success or failure status. This data supports the requested features, credit accounting, abuse prevention, service reliability, and aggregate analytics. The operational record itself does not contain the request text, photo, or complete response; the temporary delivery buffer described in Section 4 is handled separately.

When you click an App Store button in the navigation, hero, or footer of kcalledger.com, the website sends only the fixed button placement and page language. Our server adds the click to an anonymous daily aggregate using the server’s UTC date. This measurement sets no cookie, creates no user or device identifier, and stores no IP address, browser or device information, or full referrer in the analytics data. Repeat clicks by one person count more than once, so the total is neither an install count nor a unique-visitor count. Daily aggregates are retained for 400 days and then removed in fixed-size batches. These limits describe this website click measurement only; hosting and network providers may still process ordinary connection and diagnostic logs for operations, security, and abuse prevention.

A third-party diagnostics service may receive crash reports, performance data, device type, operating-system version, and App version. These diagnostics are not linked to your Kcal Ledger account. Advertising and cross-app tracking are not used, and the App’s behavioral analytics module is disabled.

6. Optional manual Google Drive backup

You may manually back up and restore your App records using the private app-data area of your own Google Drive account. The App requests only the drive.appdata scope. Backup and restore are user-initiated; the App does not automatically upload records in the background, and the backup does not pass through our server.

When you connect Google Drive, the App reads the email address from your Google sign-in profile and displays it on your device so you can identify the connected account. The email address is used only in the device’s Google authorization state; it is not included in the backup or sent to our server.

The backup is compressed and transferred over HTTPS but is not additionally encrypted by the App. Anyone who can access the relevant private app-data area of your Google account may be able to read its contents. You can use the App without connecting Google Drive, sign out in the App, or revoke access from your Google account.

7. Data retention and account deletion

You can delete individual local records in the App or remove the App from your device. You can delete your account from Settings → Delete Account; after confirmation, the App requests deletion of account-linked backend data, clears local App data, and signs you out. Some purchase, transaction, security, or legal records may be retained where required for accounting, fraud prevention, dispute resolution, or compliance.

Because the shared analysis cache described in Section 4 is not linked to an account identifier, deleting your account cannot identify and remove a specific cache entry. Its retention follows the cache rules described in Section 4.

Google Drive backups are controlled through your Google account. Revoking the App’s authorization does not necessarily delete an existing backup; manage or remove it using the controls available for your Google account.

8. Children

The App is not directed primarily to children below the applicable legal age. If you believe we collected a child’s information by mistake, contact us so we can review and delete it as appropriate.

9. Changes to this policy

We may update this policy. Material changes will be identified in the App or on this page, and the date above indicates the current version.

10. Contact

For privacy questions or requests, email support@kcalledger.com.