KcalOSby thetinyapp

Privacy Policy

Last updated: 13 September 2026

KcalOS is a calorie- and macro-tracking app. This policy explains what data KcalOS handles. The short version: what you log is saved to your account, and only what you log. Your diary, your weight history, your daily water and your supplement checklist are stored on our server so they survive a new phone. The answers you gave during setup — beyond four shared with our other apps — stay on your device. There is no advertising and no cross-app or cross-site tracking. We use one analytics service, PostHog, described below. If you ask KcalOS to estimate a meal, the photo and the words you give it go to our server and on to an AI model for the estimate. We keep the photo on your account, and deleting the entry does not delete the photo.

What is saved to your account

These are stored on our server, under your account, and are also kept on your device so the app opens instantly and works with no signal:

What you log offline is held on the device and sent when there is a connection again. Nothing is lost while you have no signal.

Signing out clears this device's copy, because your account keeps one. Signing back in brings it down again. Two people using one phone therefore no longer share a diary.

What stays on your device

These are written to the app's own storage and are not uploaded:

Four setup answers are the exception and are covered under Your account below.

Estimating a meal

KcalOS can estimate what is on a plate from a photo, a description, or both. It only ever happens when you ask for it, on the Estimate a meal screen. Nothing is sent for an estimate at any other time, and the built-in food table needs no connection and no server.

When you ask, we send what you gave us to our own server, which passes it to an AI model and returns an estimate of the nutrition. It is a guess, it is labelled as one in the app, and you can correct every figure before you save it. Your calorie and macro targets never come from a model — those are arithmetic over a published equation and always have been.

The photo is not kept on your phone. KcalOS keeps no copy of it at all: the only copy is on your account, which is what lets the picture show up on a new phone and survive a reinstall. When you are offline, the entry shows a food icon rather than the picture, because there is nothing on the device to show.

Location and camera details are removed before the photo leaves your phone. The image is re-encoded from its pixels, so GPS coordinates, the capture time and your device's make and model do not travel with it. What we receive is the picture, not a record of where you were.

Deleting an entry does not delete its photo. The record of the estimate we ran points at the same picture, so the picture stays on your account.

There is a daily limit on how many estimates one account can ask for. It resets at midnight UTC.

Your account

KcalOS requires an account, created with Sign in with Apple or Sign in with Google. Either way the provider gives us two things: an identifier that stands for you within our apps, and an email address — your real one or, with Apple's Hide My Email, a private relay address Apple manages. We never see your Apple or Google password. Accounts made with different providers are joined only when their verified email addresses match; otherwise they are separate accounts.

On our server we store that identifier, that email address, and session records — which app you signed in to, an identifier for the device, and timestamps — so you stay signed in and can see and revoke your sessions.

We also store a small shared profile that our apps have in common: your date of birth, your sex, your height and your weight. It is shared so that another of our apps can offer those four back instead of asking you again. No other setup answer is on it.

And we store what you log — see What is saved to your account above.

What we do not do

Product analytics

KcalOS uses PostHog for product analytics. It records how the app is used so we can find what is broken and what is confusing. It is deliberately narrow, and this list is exhaustive:

What analytics never receives: the foods you log, your calorie or macro numbers, your body measurements, your goal, your targets, or any answer you gave during setup. Those values are not sent to PostHog by any code path in the app.

These events are not linked to you. The app never sends your user id, your email address or your name to PostHog, and never asks it to build a profile of you. PostHog does receive the technical information any network request carries, including your IP address, and it acts as our processor under our instructions. It does not sell your data or use it for advertising, and we do not combine these events with data from other companies' apps or websites.

Deleting your data

Signing out is not deletion: it clears this device's copy and leaves your account's copy in place, so signing back in restores it.

Deleting the app removes what is on the device. Your account keeps its copy.

A photo you sent for an estimate stays with your account. Deleting a single entry does not remove its photo.

If your device backs up to iCloud, your KcalOS data may be included in that backup. That backup is between you and Apple under Apple's terms; we have no access to it.

Children

KcalOS is not directed at children under 13, and we do not knowingly collect data from them.

Changes

If this policy changes, the date at the top of this page changes with it.

An earlier version of this page promised that if KcalOS ever gained a feature that sent your log anywhere, this policy would say so plainly before that feature shipped. That feature is diary sync, and this update is that notice.

Contact

Questions about this policy? Write to resources@thetinyapp.com.