Privacy Policy
Last updated: 13 September 2026
KcalOS is a calorie- and macro-tracking app. This policy explains what data KcalOS handles. The short version: what you log is saved to your account, and only what you log. Your diary, your weight history, your daily water and your supplement checklist are stored on our server so they survive a new phone. The answers you gave during setup — beyond four shared with our other apps — stay on your device. There is no advertising and no cross-app or cross-site tracking. We use one analytics service, PostHog, described below. If you ask KcalOS to estimate a meal, the photo and the words you give it go to our server and on to an AI model for the estimate. We keep the photo on your account, and deleting the entry does not delete the photo.
What is saved to your account
These are stored on our server, under your account, and are also kept on your device so the app opens instantly and works with no signal:
- Your diary — each entry's name, portion, meal, calories and whatever macros are known, when you logged it, and any note you wrote on it.
- Your weight history — each weight in kilograms, its date, and any note.
- Your daily water total.
- Your supplement checklist — which supplements you ticked on which day.
What you log offline is held on the device and sent when there is a connection again. Nothing is lost while you have no signal.
Signing out clears this device's copy, because your account keeps one. Signing back in brings it down again. Two people using one phone therefore no longer share a diary.
What stays on your device
These are written to the app's own storage and are not uploaded:
- Your goal, activity level and training phase.
- Your ethnicity, your dietary patterns and any health conditions you entered.
- The supplements you chose to track.
- Your calorie and macro targets, and your unit preferences.
- Anything you type into food search. The food table ships inside the app, so searching it makes no network request.
Four setup answers are the exception and are covered under Your account below.
Estimating a meal
KcalOS can estimate what is on a plate from a photo, a description, or both. It only ever happens when you ask for it, on the Estimate a meal screen. Nothing is sent for an estimate at any other time, and the built-in food table needs no connection and no server.
When you ask, we send what you gave us to our own server, which passes it to an AI model and returns an estimate of the nutrition. It is a guess, it is labelled as one in the app, and you can correct every figure before you save it. Your calorie and macro targets never come from a model — those are arithmetic over a published equation and always have been.
The photo is not kept on your phone. KcalOS keeps no copy of it at all: the only copy is on your account, which is what lets the picture show up on a new phone and survive a reinstall. When you are offline, the entry shows a food icon rather than the picture, because there is nothing on the device to show.
Location and camera details are removed before the photo leaves your phone. The image is re-encoded from its pixels, so GPS coordinates, the capture time and your device's make and model do not travel with it. What we receive is the picture, not a record of where you were.
Deleting an entry does not delete its photo. The record of the estimate we ran points at the same picture, so the picture stays on your account.
There is a daily limit on how many estimates one account can ask for. It resets at midnight UTC.
Your account
KcalOS requires an account, created with Sign in with Apple or Sign in with Google. Either way the provider gives us two things: an identifier that stands for you within our apps, and an email address — your real one or, with Apple's Hide My Email, a private relay address Apple manages. We never see your Apple or Google password. Accounts made with different providers are joined only when their verified email addresses match; otherwise they are separate accounts.
On our server we store that identifier, that email address, and session records — which app you signed in to, an identifier for the device, and timestamps — so you stay signed in and can see and revoke your sessions.
We also store a small shared profile that our apps have in common: your date of birth, your sex, your height and your weight. It is shared so that another of our apps can offer those four back instead of asking you again. No other setup answer is on it.
And we store what you log — see What is saved to your account above.
What we do not do
- We do not use what you log for anything except giving it back to you in this app. It is not analysed for advertising, not sold, and not shared.
- We do not use your photo or your description for anything except producing the estimate you asked for and keeping the picture with your entry. They are not used to train a model of ours, not sold, and not shared beyond the model provider that answers the request.
- We do not send what you log to our analytics service. See “Product analytics” below — that list is exhaustive and no food, weight or target value is on it.
- We do not sell, rent or share your data with anyone.
- We do not track you across other companies' apps or websites, build an advertising profile of you, or serve advertising.
- We use two third-party SDKs that receive data: PostHog, limited to the events listed under “Product analytics” above, and Firebase Crashlytics, which receives the crash reports described there. We do not use an advertising SDK.
Product analytics
KcalOS uses PostHog for product analytics. It records how the app is used so we can find what is broken and what is confusing. It is deliberately narrow, and this list is exhaustive:
- Screen views — the name of the screen you opened, e.g. "today" or "settings".
- Sign-in outcomes — that a sign-in succeeded or failed, and which provider (Apple or Google) was used. Cancelling a sign-in sheet records nothing.
- Error reports — the type of an error and where in the app it happened.
- Crash reports — if the app crashes, the technical report of where it stopped: the stack, your device model and its iOS version. No part of your data is in it.
- Every event carries the app's name, so events from KcalOS can be told from those of our other apps.
What analytics never receives: the foods you log, your calorie or macro numbers, your body measurements, your goal, your targets, or any answer you gave during setup. Those values are not sent to PostHog by any code path in the app.
These events are not linked to you. The app never sends your user id, your email address or your name to PostHog, and never asks it to build a profile of you. PostHog does receive the technical information any network request carries, including your IP address, and it acts as our processor under our instructions. It does not sell your data or use it for advertising, and we do not combine these events with data from other companies' apps or websites.
Deleting your data
Signing out is not deletion: it clears this device's copy and leaves your account's copy in place, so signing back in restores it.
Deleting the app removes what is on the device. Your account keeps its copy.
A photo you sent for an estimate stays with your account. Deleting a single entry does not remove its photo.
If your device backs up to iCloud, your KcalOS data may be included in that backup. That backup is between you and Apple under Apple's terms; we have no access to it.
Children
KcalOS is not directed at children under 13, and we do not knowingly collect data from them.
Changes
If this policy changes, the date at the top of this page changes with it.
An earlier version of this page promised that if KcalOS ever gained a feature that sent your log anywhere, this policy would say so plainly before that feature shipped. That feature is diary sync, and this update is that notice.
Contact
Questions about this policy? Write to resources@thetinyapp.com.