Privacy Policy
1. Who we are
Calgo Fit is a mobile app that estimates the calories and macronutrients in a meal from a photograph, and tracks them against daily targets.
The data controller — data fiduciary under India's Digital Personal Data Protection Act, 2023 (the DPDP Act) — is Amit Waman Somkuwar, a sole proprietor established in India, of House No. 910, Lashkaribagh 17/23, Bajirao Sakhre Line, Near Kose Hospital, Nagpur, Maharashtra 440017. You can reach us at support@calgo.in.
This policy covers the Calgo Fit mobile app and these pages. It sits alongside our Terms of Service. Calgo Fit is offered in India only, and this policy is written to India's data protection law.
2. The short version
- We collect your sign-in identity, the body statistics you enter during onboarding, and the meal photographs you upload.
- Your meal photographs and your body statistics are sent to Google so that the app can estimate nutrition and build your targets.
- We use one diagnostics provider (Sentry) to find crashes and bugs. There is no analytics SDK, no advertising SDK, and no cross-app tracking of any kind.
- We never sell your data, and we never use it to train our own AI models.
- You can erase your account and its data yourself, from the Profile tab, at any time.
3. What we collect
3.1 Account and identity
You sign in with Apple or with Google. Authentication is handled by Clerk, which creates and holds your identity record. Through it we receive and store your email address and a user identifier. Your name and profile picture are shown in the app from your Clerk profile. We never see or store your Apple or Google password.
3.2 Body and health-related data
The onboarding questionnaire collects nine answers: gender, date of birth, height, current weight, goal (lose, maintain or gain), target weight, activity level, desired weekly pace, and diet preference. We also store your device's timezone, so that "today" means your day and not ours.
From these we generate and store your daily calorie target, your protein, carbohydrate and fat targets, and a one-line explanation of how they were derived.
Body statistics, diet preference and meal photographs are health-related data. Under India’s Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 they are "sensitive personal data or information". We handle them only with your explicit consent, and you can withdraw that consent at any time by deleting your account. Treating this data as sensitive is not the same as it being clinical: Calgo Fit is a general wellness and self-tracking tool, it is not a medical device and does not diagnose, treat, cure, or prevent any medical condition, and nothing we store about you is a clinical record or is used as one.
3.3 Meal photographs and nutrition records
When you log a meal we store the photograph you took or chose, and the record produced from it: the meal name, the estimated calories, protein, carbohydrate and fat, the time you logged it, and whether the analysis succeeded or failed.
Photographs are taken from your camera or picked from your photo library. Nothing leaves your device until you tap to analyse a meal. If the model decides a photo is not food, the record is discarded — though the uploaded image file itself remains in storage until you delete your account.
3.4 Diagnostic and technical data
We use Sentry to detect crashes and diagnose bugs. Sentry receives:
- crash reports and error messages, with your user identifier attached;
- performance traces and screen-to-screen navigation timings (currently sampled at 100%);
- device and app information — model, operating system version, app version. The app is configured not to send default personal identifiers, so your IP address is not attached to these reports;
- anything you write into the in-app "Send feedback" form, which is Sentry's own widget.
Sentry does not record your screen. Session replay is switched off in the app — no session is recorded, sampled or uploaded, masked or otherwise, and that applies to error sessions too. Nothing that appears on your screen, including your meal photographs, is captured as a recording.
We also record a small number of events describing how far you got in the app — that onboarding completed, that a meal scan finished, how long it took, and whether it succeeded. These carry your goal, your generated calorie target, your timezone and a meal's calorie count. They exist to tell us the product is working, not to profile you.
4. What we do not collect
This list is as much a part of the policy as the one above, and it is verifiable in our source code:
- No location data. The app never requests or accesses your location.
- No advertising identifiers and no tracking. There is no ad SDK, no IDFA or Android advertising ID, no App Tracking Transparency prompt, and no sharing of data with advertisers or data brokers. We do not track you across other apps or websites. Your health and fitness data — your body statistics, your targets, your meal photographs and your nutrition records — is never used for advertising, marketing or data mining, by us or by anyone we send it to, and it is never sold.
- No third-party analytics SDK. Sentry is our only telemetry provider, and it is used for diagnostics.
- No contacts, calendar, health-app data or microphone recordings. The app never reads your device's Health/Google Fit data, and never records audio.
- No payment data. The app is free and has no billing of any kind.
- No social features. Your data is never shown to other users.
On Android the app declares the RECORD_AUDIO permission, and on iOS a
microphone usage string. These come from the camera library we use and are
not used by Calgo Fit — we never record or transmit audio. We intend
to remove them.
5. Why we process your data, and the consent it rests on
Under the DPDP Act we may process your personal data only for a lawful purpose for which you have given us free, specific, informed, unconditional and unambiguous consent, and only the data needed for that purpose. Every use below rests on that consent, given when you accept this policy and continue through the app.
| Data | Purpose | Basis under the DPDP Act |
|---|---|---|
| Email address, user identifier | Create your account, sign you in, keep your data available across devices | Your consent, given when you create an account |
| Body statistics, diet preference, timezone | Generate and store your daily calorie and macronutrient targets | Your explicit consent, given before the questionnaire |
| Meal photographs and nutrition records | Estimate what you ate and show you your day | Your explicit consent, given before a photo is analysed |
| Crash reports, performance traces, user identifier | Keep the app working, find and fix defects, prevent abuse | Your consent to diagnostics, given when you accept this policy |
| Feedback you submit | Answer you and improve the app | Your consent, given when you send the feedback |
You may withdraw your consent at any time, and with the same ease with which you gave it, by deleting your account (section 12). Withdrawal does not affect processing carried out beforehand. If you withdraw consent we stop processing and erase your data, except where a law requires us to keep it.
Before you have an account. You can complete the questionnaire and see your targets before signing in. In that flow your answers are sent to our servers and on to Google to generate the plan, but nothing is written to our database and no account exists. Your answers are saved only once you sign in and the plan is attached to an account.
6. Who else receives your data
We do not sell your data and we do not share it for anyone else's marketing. We use the following processors to run the Service. Each receives only what it needs, and each is bound by a written contract to process it solely on our instructions and to protect it to a standard at least equal to the one this policy sets out. We do not pass your data to any third party that offers weaker protection than we do.
| Provider | What it receives | Why |
|---|---|---|
| Clerk | Email address, sign-in identity, session and device metadata | Account creation and authentication |
| Apple, Google | Sign-in request; app distribution | You chose them as your sign-in provider |
| Google (Gemini API) — the AI provider we use today. Should it be unavailable we may send the same request to another provider instead; we will name any such provider in this table before it receives anything, and the app tells you who reads your photograph before you agree to send it. | Your meal photographs (resized) and your onboarding answers, including age derived from your date of birth | Estimating meal nutrition and generating your targets |
| ImageKit | Your meal photographs | Image storage and delivery |
| Neon | Your profile, targets and meal records | Our database |
| Trigger.dev | Onboarding answers, meal identifiers and image links, email address for account-sync events | Runs the background jobs that generate plans and analyse meals |
| Sentry | Diagnostics as described in section 3.4, including user identifier and IP address | Crash reporting and debugging |
| Expo | App framework and API hosting | Runs the app and its server endpoints |
We may also disclose data where we are legally required to, or to establish or defend legal claims. If the Service is ever transferred to another operator, we will tell you before your data moves.
7. Where your data goes
Calgo Fit is offered in India, but your data is stored and processed outside
India. Our database is hosted in the United States (Neon, on
AWS us-east-2), our meal photographs are stored in the
United States (ImageKit, North Virginia), and Google processes your
photographs and answers in the United States. Our diagnostics are
processed in Germany (Sentry's EU region).
Under section 16 of the DPDP Act a transfer out of India is permitted unless the Central Government restricts the destination country by notification; none of the countries named above is currently restricted. We remain answerable to you for your data wherever it sits, and we place each provider under a written contract that binds it to process your data only on our instructions and to protect it to the standard this policy describes. [CONFIRM the data-processing agreement with each provider]
8. How long we keep it
| Data | Retention |
|---|---|
| Profile, targets, meal records and photographs | Until you delete your account. We run no automatic expiry or inactivity purge, so an account left untouched keeps its data indefinitely until you delete it yourself from the Profile tab. |
| Sign-in identity | Deleted with your account |
| Diagnostic data held by Sentry | [SENTRY RETENTION — typically 30–90 days by plan] |
| Background job history held by Trigger.dev | [TRIGGER.DEV RETENTION — confirm on your plan] |
| Encrypted backups | [BACKUP RETENTION — confirm with Neon] |
9. How we protect your data
These are the measures actually implemented in the app and its API:
- All traffic between the app, our API and our providers runs over encrypted connections (HTTPS/TLS).
- Your session token is held in the device's secure storage — the iOS Keychain or the Android Keystore — not in ordinary app storage.
- Every endpoint that touches your data verifies a signed session token before doing anything, and resolves your records from that token rather than from anything the app sends.
- Our API returns an explicit allow-list of fields, so internal identifiers and columns never leave the server.
- Incoming account webhooks are rejected unless their cryptographic signature verifies, and each event is processed exactly once.
- Credentials for the database, image storage and AI providers exist only on the server; the app never holds them.
- Live progress updates for your meal analysis use a short-lived token scoped to that single job.
- Uploads are size-limited and validated before being accepted.
Encryption at rest, physical security and network isolation are provided by our infrastructure providers under their own certifications. No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your rights, we will notify you and the competent authority as the law requires — under the DPDP Act, notice to each affected Data Principal and to the Data Protection Board of India without delay.
10. Automated processing
Your daily targets and every meal estimate are produced automatically by AI models, with no human review. If the model fails or returns an implausible target, the app falls back to a standard published formula and shows you that result instead, without indicating which method was used.
We do not consider this to produce legal or similarly significant effects on you: the output is a nutrition estimate, not a decision about you, and nothing follows from it automatically. We do not profile you for advertising, scoring or any other purpose. If you disagree with a result or want a human to look at it, write to us at support@calgo.in.
11. Your rights
As a Data Principal under the DPDP Act, you have the right to:
- obtain a summary of the personal data we process and of the processing itself (DPDP Act, s.11);
- know the third parties with whom we have shared it, and what was shared;
- have inaccurate or misleading data corrected, and incomplete data completed or updated (DPDP Act, s.12);
- have your data erased (DPDP Act, s.12);
- withdraw your consent at any time, as easily as you gave it (DPDP Act, s.6);
- nominate someone to exercise these rights on your behalf if you die or become incapacitated (DPDP Act, s.14);
- have your grievance heard by us, and escalate it to the Data Protection Board of India if we do not resolve it (DPDP Act, s.13; see section 15 of this policy).
The DPDP Act does not grant a right to data portability or a right to object to processing. We say so plainly rather than promise rights the law does not give you — but if you want a copy of your data in a usable form, ask, and we will send one.
Erasure is self-service — Profile tab, immediate, no request needed. Access and correction are handled manually: the app has no data-export screen, and there is currently no screen for editing your body statistics after onboarding. Email support@calgo.in and we will action your request. We respond within 30 days. Rule 14(3) of the DPDP Rules allows a Data Fiduciary up to ninety days to respond to a grievance; the 30 days we promise here is our own, stricter commitment, and it is the one we hold ourselves to.
12. What deletion really removes — and what it does not
Deleting your account from the Profile tab is immediate and permanent. There is no recovery period and we cannot restore it. It removes:
- every meal photograph you have uploaded, from our image storage;
- your profile record — body statistics, goal, preferences, timezone and targets;
- every meal you have logged, with all its nutrition data;
- your sign-in identity with our authentication provider.
Being straight with you about what it does not reach:
- Diagnostic records held by Sentry — crash reports, traces, and the user identifier attached to them — are not deleted by the in-app action. They expire on Sentry's own schedule. Ask us and we will have them removed.
- Background job history held by Trigger.dev retains the inputs those jobs ran on — including your onboarding answers and meal image links — until it expires under that provider's retention schedule.
- Encrypted backups may hold copies for a limited period before they age out.
If you want these cleared sooner, email support@calgo.in and we will make the requests on your behalf.
13. Children
Calgo Fit is not intended for anyone under 18, and our Terms of Service require you to be at least that age. We do not knowingly collect data from children. The app asks for your date of birth to calculate calorie needs, not to verify your age. If you believe a child has given us their data, contact us at support@calgo.in and we will delete it.
14. Changes to this policy
We will update this policy when what we do changes. The current version always lives at this address with its effective date at the top. Where a change materially affects how we use your data, we will make reasonable efforts to tell you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.
15. Contact and complaints
For any privacy question, or to exercise any right above, write to support@calgo.in, or to House No. 910, Lashkaribagh 17/23, Bajirao Sakhre Line, Near Kose Hospital, Nagpur, Maharashtra 440017, India. Complaints are handled by our Grievance Officer, Amit Waman Somkuwar, who can be reached at that same email address. He will acknowledge your complaint within 24 hours of receiving it and resolve it within 15 days, and in no case later than one month, which is the outer limit the SPDI Rules, 2011 allow.
If you are not satisfied with our response, you may complain to the Data Protection Board of India, after first raising the matter with us — the DPDP Act requires you to exhaust our grievance redressal before approaching the Board.
To complain to the Board: first email us at support@calgo.in with the word "Grievance" in the subject line, and keep our reply, or a note of the date you wrote if we do not reply. Then take the complaint to the Board, which the DPDP Act requires to function as a digital office — complaints are filed and heard online, with no need to appear in person. The Board publishes its filing channel and its current contact details through the Ministry of Electronics and Information Technology at www.meity.gov.in; if you cannot find them, write to us and we will send you the current route. Complaining to the Board costs you nothing and does not require a lawyer.
This draft is not legal advice and must be reviewed by a qualified attorney or data-protection adviser before publication. It was written from the codebase as it stands on 31 July 2026 and describes actual behaviour, not intentions.
Blocking — the policy is untrue until these ship:
-
Sentry replay masking — FIXED in the policy, 27 August 2026. The
masking question is moot:
src/app/_layout.tsxsetsreplaysSessionSampleRate: 0andreplaysOnErrorSampleRate: 0, with onlynavigationIntegrationin the integrations array — mobile replay and native profiling were both disabled after they crashed the app with SIGABRT (CAL-GO-1). No session recording happens at all, so every recording claim was removed from sections 3.4, 6 and 11 rather than softened. Still outstanding:sendDefaultPiiistrue, which is why Sentry receives IP addresses and the user identifier — now stated plainly in section 3.4. Set it tofalseif you would rather it did not. -
Explicit consent. Section 5 relies on explicit consent for health
data. Today the only notice is passive text on the sign-in screen
(
src/app/sign-in.tsx:150), which appears after the questionnaire has already collected body statistics. Explicit consent needs an unticked, affirmative opt-in shown before the questionnaire starts. -
The 24-month inactivity purge — FIXED in the policy, 27 August 2026.
Re-verified:
src/db/schema.tshas nolastSeenAtor last-active column, andsrc/trigger/holds only event-driven tasks (analyze-meal,clerk-users,generate-plan) — no scheduled task, nothing that expires anything. Section 8 now says the data is kept until you delete your account, and says there is no automatic expiry. If the purge is ever built, section 8 has to change back. -
The iOS privacy manifest is declared in
app.json.ios.privacyManifestsdeclares email address, user ID, health, fitness, photos and crash/performance data, withNSPrivacyTrackingfalse. Prebuild merges it intoPrivacyInfo.xcprivacy. Keep it in step with this policy, and make the App Store Connect questionnaire say the same thing.
Assumptions taken (confirm or correct):
- Controller is a sole proprietor in India; audience is India only, so the DPDP Act is the sole framework — no GDPR and no CCPA section. Retention is deletion-only, since no inactivity purge exists, and explicit consent is the basis for health data. All four were chosen by you.
- The DPDP Act treats everyone under 18 as a child (section 9), requiring verifiable parental consent and barring tracking. Section 13 has been set to 18 for that reason. Serving 16- and 17-year-olds would mean building a parental-consent flow.
- Section 7 asserts that every provider is under a written contract binding it to process data only on our instructions. Verify you have actually executed a data-processing agreement with Clerk, Google, ImageKit, Neon, Trigger.dev and Sentry — the policy makes a promise that only exists if those are signed.
- Retention periods for Sentry, Trigger.dev and Neon backups are left bracketed because they depend on your plan tier, not the code.
Evidence for the less obvious claims:
-
No analytics or ad SDK: verified by dependency and source scan — Sentry is the only
telemetry package, and
NSPrivacyTrackingisfalse. -
US transfer:
DATABASE_URLresolves to Neon in AWSus-east-2. EU diagnostics: the Sentry DSN targetsingest.de.sentry.io. -
Pre-account processing (section 5):
POST /api/planis deliberately unauthenticated and writes nothing to the database, but does forward the answers to Google. -
Deletion coverage (section 12):
DELETE /api/profileremoves ImageKit files by filename prefix, then the user row (meals cascade off the foreign key), then the Clerk user. It makes no call to Sentry or Trigger.dev. -
Microphone permission (section 4):
RECORD_AUDIOinapp.jsonandNSMicrophoneUsageDescriptioninInfo.plistboth come from expo-camera. No code path records audio. Removing them is cleaner than disclosing them.
Deliberately not claimed: encryption at rest by us (it is our providers'), penetration testing, security certifications, staff training, a DPO (Calgo Fit is not a Significant Data Fiduciary), cookie or web-tracking practices (there are none — this is a mobile app), and any data-sale or targeted-advertising disclosure, since neither occurs.