Privacy Policy


1. Preamble

This privacy policy (the “Policy”) describes how the KCalories application (the “App”) collects, uses, retains, shares and protects your personal data, in accordance with the General Data Protection Regulation (Regulation EU 2016/679, the “GDPR”) and applicable French data-protection law (Loi Informatique et Libertés n° 78-17, as amended).

The App is designed to help you track your nutrition, hydration, physical activity and weight goals. To deliver these services, the App processes health data within the meaning of Article 9 GDPR. Such data benefits from heightened protection and is processed solely on the basis of your explicit consent.

We are committed to processing your data lawfully, fairly, transparently, proportionately and securely, and to ensuring that you can exercise all the rights conferred upon you by the regulation.


2. Data controller

The data controller within the meaning of Article 4(7) GDPR is the publisher of the Application, acting in an individual capacity. The full legal identity and, where applicable, the registration number (e.g. SIREN) of the controller, together with the postal address, are available on request at the contact address below.

For any question regarding this Policy, the exercise of your rights, or to report a personal data breach:

At this stage, the Application is not operated by an organisation required to appoint a Data Protection Officer (DPO) within the meaning of Article 37 GDPR ; the data controller can be reached directly at the addresses above. Any change to this obligation will be reflected in an updated version of this Policy.


3. Scope and purposes of processing

The App processes your personal data only for the purposes described below. No data is used for advertising profiling, resale to third parties, or automated decision-making producing legal effects within the meaning of Article 22 GDPR.

The only advertising-related measurement we carry out concerns the effectiveness of our own acquisition campaigns: it is Apple-mediated and aggregated (SKAdNetwork, Apple Search Ads), or — for in-app and web audience measurement — subject to your consent (Google, Meta, and the cookieless Vercel Web Analytics, which we hold to the same opt-in even though it would qualify for the audience-measurement exemption). It uses no advertising identifier (IDFA), no individual profiling, no fingerprinting.

#PurposeData involvedGDPR legal basis
F1Anonymous authentication and stable cross-device identificationFirebase Anonymous user ID, AppCheck tokenArt. 6(1)(b) — performance of the contract
F2Profile personalisation and computation of your nutritional goals (energy needs, macros)Sex, age, height, weight, activity level, weight goal, dietary modeArt. 6(1)(b) and Art. 9(2)(a) — explicit consent (health data)
F3Daily food tracking: meals, foods, calories, macronutrients, micronutrients, hydration, activityMeal history, scanned foods, food photos (if you provide them), water entries, step countArt. 6(1)(b) and Art. 9(2)(a) — explicit consent (health data)
F4Optional Apple HealthKit synchronisationSteps, active calories, weight, activity (read/write per your authorisations)Art. 6(1)(a) and Art. 9(2)(a) — explicit consent via the iOS authorisation system
F5Reminders, streak alerts, weekly summaries, contextual notificationsNotification preferences, FCM token, time zone, languageArt. 6(1)(a) — consent (iOS system authorisation)
F6Optional social features: friends, leaderboards, challenges, activity feed, shared grocery listsDisplay name, friend code, friend identifiers, activity events, visibility settingsArt. 6(1)(a) — consent (each action is voluntary)
F7Optional contact-based friend discovery — phone numbers are never transmitted in plaintext: only a SHA-256 hash computed locally is sent for matchingSHA-256 hash of phone numbers, your own hash stored server-sideArt. 6(1)(a) — explicit consent
F8App security: fraud prevention, authenticity verification (AppCheck), rate limitingAppCheck token, technical request headers, server logsArt. 6(1)(f) — legitimate interest (security)
F9Crash reporting, server-error monitoring and stability improvementAnonymised crash reports, technical breadcrumbs, technical error context (route/endpoint, HTTP method and status code, app version and environment), opaque user identifier (Firebase UID), device model, iOS version — never health dataArt. 6(1)(f) — legitimate interest (reliability and product quality)
F10In-app analytics and feature-usage understandingAnonymised or pseudonymised events (action, timestamp, screen), sent to Firebase / Google Analytics 4Art. 6(1)(a) — consent (measurement not strictly necessary, art. 82 French DPA / ePrivacy Directive); granular opt-in, off by default, withdrawable anytime in Settings
F11User support: handling your requests through the in-app formFree-text message, app version, hashed user identifier (never the raw UID)Art. 6(1)(b) — performance of the contract
F12Food lookup by barcode (Open Food Facts; USDA FoodData Central as a fallback when the food is absent from Open Food Facts)Scanned barcode, User-Agent headerArt. 6(1)(f) — legitimate interest (open-database lookup)
F13Understanding the acquisition channel: learning how you discovered the App, to steer our outreach effortsSelf-declared acquisition channel (social media, advertising, word of mouth, App Store, web search, other) and a boolean flag indicating whether a referral code was entered, both supplied voluntarily during onboardingArt. 6(1)(f) — legitimate interest (growth steering); declarative, non-sensitive data
F14Identifier-free attribution of our paid acquisition campaigns (measuring their effectiveness, without IDFA)Apple AdServices token (single-use, Apple Search Ads); SKAdNetwork conversion value (funnel stage, aggregated by Apple); conversion signals shared with Google Ads / Meta only subject to your marketing consent — no IDFA, no ATT prompt, no fingerprintingArt. 6(1)(f) — legitimate interest (efficacy measurement, Apple-mediated and aggregated); for Google/Meta signals: Art. 6(1)(a) — consent
F15Personal allergen radar: letting you declare your allergens so the App flags, when you scan or add a food, those that contain an allergen you declared. The matching happens locally on your device; it never alters a food’s quality scoreThe list of allergens you declare (among the 14 regulatory categories of Annex II to EU Regulation No. 1169/2011) and your preference to also be alerted on traces (“may contain”)Art. 9(2)(a) — explicit consent (health data): the declaration is voluntary, never pre-checked, never inferred

4. Categories of data processed in detail

4.1 Identification and profile data

4.2 Health data (Article 9 GDPR)

The App processes the following special categories of data, which benefit from heightened protection:

Processing of this data is always based on your explicit consent (Article 9(2)(a) GDPR), evidenced by your acceptance of this Policy and by the granular choices you make in the App (whether to enable HealthKit, whether to submit a photo, etc.).

4.3 Technical data and persistent identifiers

4.4 Behavioural and technical data

4.5 Social data (when you enable these features)

4.6 Photos

No biometric processing within the meaning of Article 9 GDPR is applied to these photos. No facial recognition or biometric identification is performed.

4.7 Data we do not collect

For transparency, please note that the App does not collect:


In accordance with Articles 6 and 9 GDPR, every processing operation carried out by the App is based on one of the following legal bases:

You may withdraw your consent at any time without affecting the lawfulness of prior processing (Article 7(3) GDPR). Withdrawal can be made through the App settings (notifications, HealthKit, social features) or by deleting your account.


6. Recipients and processors

Your data may be shared with the following recipients, strictly limited to the purposes described:

RecipientRolePurposesStorage countryEngagement link
Google LLC / FirebaseProcessorAuthentication, database (Firestore), file storage (Storage), notifications (FCM), crash reporting (Crashlytics), authenticity verification (AppCheck); audience measurement (Google Analytics 4) and, subject to your marketing consent, conversion signals for optimisation toward Google Ads — aggregated, no IDFAUnited States (Google Cloud)https://firebase.google.com/terms/data-processing-terms
Functional Software, Inc. (dba Sentry)ProcessorError and reliability monitoring (application, server and back-office) — no health dataEuropean Union (Germany) — EU data regionhttps://sentry.io/legal/dpa/
Vercel Inc.ProcessorHosting of the public website (kcaloriesapp.com); cookieless, aggregated web audience measurement (Vercel Web Analytics) — no cookie, no cross-site identifier, no individual profiling, loaded only after your analytics consentUnited Stateshttps://vercel.com/legal/dpa
Apple Inc.Joint controller / processor depending on serviceHealthKit (health data stays on device), Apple Push (APNs as relay for FCM); Apple Search Ads (campaign attribution, no IDFA); relay of aggregated SKAdNetwork postbacksUnited Stateshttps://www.apple.com/legal/privacy/
Meta Platforms, Inc.Processor / recipientRecipient of aggregated SKAdNetwork postbacks (Apple-mediated, no IDFA); on the website, a measurement pixel loaded only after your consentUnited Stateshttps://www.facebook.com/legal/terms/dataprocessing
Open Food FactsPublic data sourceProduct lookup by barcode (open-database query)France / European Unionhttps://world.openfoodfacts.org/
USDA FoodData CentralPublic data sourceProduct lookup by barcode — fallback queried only when the food is absent from Open Food Facts (public-database query)United Stateshttps://fdc.nal.usda.gov/

Key commitment: we do not sell or rent your data to any third party. The only signals shared for advertising-measurement purposes are aggregated and Apple-mediated (SKAdNetwork, Apple Search Ads), or subject to your consent for web measurement (Google, Meta) — with no IDFA, no individual profiling, no data brokerage.

Note: should any new processor become involved, this section will be updated before any such activation.


7. Transfers outside the European Union

Several processors are located in the United States (notably Google/Firebase, Apple and Vercel, the website host), so your data may be transferred outside the European Economic Area.

In addition, some processors host your data within the European Union while belonging to a non-EU group (for example Sentry, whose data is hosted in Germany but whose operating company is established in the United States). Any residual access from a third country is governed by the Standard Contractual Clauses set out in their data-processing agreement (DPA).

These transfers are governed by:

The advertising-measurement signals shared with Google (Google Ads) and Meta (United States) are governed by the Standard Contractual Clauses and, for web measurement, conditional on your consent; they remain aggregated and IDFA-free.

You may contact us at privacy@kcaloriesapp.com to obtain a copy of the safeguards applicable to a specific transfer of your data.


8. Retention periods

Data categoryRetention period
Profile data, food tracking, weight, hydration, activity, declared allergensAs long as your account is active. Full deletion upon account deletion request (see section 10).
Avatar photos, meal photos, grocery photosSame — until you explicitly remove them or delete your account.
Food data cache (per barcode)Thirty (30) days server-side, refreshed on a new request.
Local scan historyStored locally on your device. You can clear it at any time from settings.
Data pending synchronisation (changes made offline : meals, water intake, weight, body measurements, activity, profile)Stored locally on your device, encrypted by iOS. Automatically deleted once synchronisation succeeds, and wiped when you delete your account or sign out.
Deleted entries (meals, weight log, body measurements)When you delete an entry, it is first marked as deleted server-side (not immediately purged) to keep your data consistent, retained for at most thirty (30) days, then permanently deleted.
Social data (friends, challenges, activity feed)As long as the relationship is active; deleted on request or upon feature withdrawal.
Contact SHA-256 hashesNot retained: used in flow for matching, then erased. Your own hash is retained as long as you keep the feature enabled.
Crash reports (Crashlytics)Ninety (90) days by default.
Technical error logs (Sentry)Ninety (90) days (Sentry default retention).
Pseudonymised analytics eventsNinety (90) days for unit events; statistical aggregates retained without personal data.
Attribution data (Apple Search Ads campaign source, SKAdNetwork conversion value)At most twenty-four (24) months; a field attached to your account, deleted with the account.
Activation flag (“first time active 3/7” timestamp)A field attached to your account, deleted with the account.
Support requestsFor the duration necessary to handle your request, plus the legal retention period for evidence (typically three years).

At the end of these periods, data is either permanently deleted or irreversibly anonymised.


9. Security

We implement appropriate technical and organisational measures to protect your data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access:

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we undertake to notify the CNIL within seventy-two (72) hours pursuant to Article 33 GDPR, and to inform you where Article 34 so requires.


10. Your rights

In accordance with Articles 15 to 22 GDPR, you have the following rights over your personal data:

The attribution data and the activation flag described in sections 3 and 4 are included in the export of your data (right of access / portability) and in the erasure of your account (right to erasure).

Exercising your rights:

Complaint to the CNIL: if you believe that the processing of your data does not comply with the regulation, you may lodge a complaint with the Commission Nationale de l’Informatique et des Libertés (CNIL):

3 Place de Fontenoy — TSA 80715 — 75334 Paris Cedex 07 https://www.cnil.fr


11. Minors

The App is not intended for persons under the age of sixteen (16). No registration is accepted for users below this age without the explicit consent of the holders of parental responsibility, in accordance with Article 8 GDPR.

If you are a parent or guardian and notice that a minor under your responsibility uses the App without your consent, please contact us at privacy@kcaloriesapp.com so we can delete the account.


12. Cookies and persistent identifiers

The App is a native mobile application and does not use cookies within the meaning of Directive 2002/58/EC (“ePrivacy”) — this paragraph concerns the native app itself; our public website (kcaloriesapp.com) is addressed at the end of this section. The app uses the following native iOS storage mechanisms:

None of these mechanisms is used for advertising tracking.

SKAdNetwork (Apple) is an aggregated, Apple-mediated advertising-measurement mechanism: no cookie, no IDFA, no cross-app identifier — it does not require your consent (no personal data is processed by us). The in-app audience measurement (Firebase / Google Analytics 4) and the web measurement (Google, Meta, and the cookieless Vercel Web Analytics) are off by default and loaded only after your consent (the site’s dedicated banner / the in-app setting), withdrawable at any time.


13. Automated decision-making and profiling

The App does not make any solely automated decisions producing legal effects or significantly affecting your situation within the meaning of Article 22 GDPR.

Nutritional calculations (energy needs, macronutrient goals) are provided for guidance and support only and do not substitute for medical advice in any way. The App does not provide medical advice and shall not replace consultation with a qualified healthcare professional.


14. Changes to this Policy

We may amend this Policy to reflect a regulatory development, the addition of a feature or processor, or the implementation of a CNIL recommendation.

In the event of a substantial change, you will be notified upon opening the App, and a fresh consent will be requested where the nature of the changes so requires. Previous versions remain available on request to privacy@kcaloriesapp.com.

The last updated date appears at the top of this Policy.


15. Download and local retention

At any time, you may download this Policy as a PDF from the screen displaying it in the App, in order to keep a copy. The generated PDF mirrors exactly the version displayed, with its update date and version number.


16. Contact

For any question, request to exercise your rights or prior complaint:


End of document.