Privacy policy
Last updated: 9 October 2026
This policy explains what personal data the CalorieCounter+ app (“the app”) processes, why, and what rights you have. We keep it short on purpose: we collect only what the app needs to work, and we do not use advertising or analytics.
1. Who is responsible for your data
The data controller is Andrii Semeniuk, an individual based in the Czech Republic. Contact: [email protected].
2. What data we process
- Account: your email address, a password (stored only as a one-way hash, never in readable form), your language, unit and time-zone settings, and an optional nickname.
- Profile (optional): height, weight, age, sex, activity level and goal type, used to suggest calorie and macro goals, plus the goals you set. This can be health-related data. You choose whether to enter it.
- Food diary: the foods you log (what, how many grams, which meal, when), your activities (type, duration, estimated calories burned) and the meal photos you choose to attach.
- Foods you create: a name and nutrition values you type in. They are visible only to you.
- Friends: friend requests and friendships between accounts.
- Sign-in sessions: a hash of your session token and its expiry, one per signed-in device.
- Email verification: a one-time 6-digit code (stored only as a hash) that we email you to confirm your address.
We do not collect your precise location, contacts, advertising identifiers or browsing activity. The camera is used only when you scan a barcode or take a meal photo; barcodes are read on your device. Your photo library is accessed only when you pick a photo or save a progress image.
On your device, the app also stores your sign-in token in secure storage, your recently used foods, your language choice and whether you have seen the introduction. This stays on your device.
3. Why we use it and on what legal basis
- To create your account, run the diary, calculate your totals and goals, and provide the friends features: performance of a contract (Article 6(1)(b) GDPR).
- To process health-related data you enter, such as weight and height: your explicit consent (Article 9(2)(a) GDPR), given by entering it. You can withdraw it at any time by removing the data or deleting your account.
- To keep the service secure and prevent abuse, for example limiting repeated requests: our legitimate interest (Article 6(1)(f) GDPR).
- To send you the email verification code: performance of a contract. We do not send marketing emails.
4. What your friends can see
Only people you are friends with (a request that both sides accepted) can see your today: your progress, the foods you logged, your activity and your meal photos. They never see older days. Your height, weight and age are shown to friends only if you turn that on in your profile. Your email address is not shown to other users; your nickname is how people find you.
5. How long we keep it
- Every night, the previous day’s food entries, activities and meal photos are summed into daily totals (calories, macros, whether your goal was met) and then deleted. The photo files are deleted from storage as well.
- Daily totals, your goals, your streak and your profile are kept until you delete your account.
- Foods you create yourself are deleted automatically after 7 days without use.
- Sign-in sessions expire and are removed automatically. Email codes expire shortly after they are sent.
- When you delete your account, your data is deleted immediately (see the account deletion page).
6. Who receives your data
We do not sell your data and we do not share it for advertising. We use these service providers (processors), who handle data only on our instructions:
- Railway hosts the app’s server, database and photo storage in a data center in the EU (Western Europe). Railway is a US company, so transfers outside the EU may rely on the EU Standard Contractual Clauses.
- Brevo (France) sends the verification emails. It receives your email address and the message.
- Open Food Facts is queried by our server when you use online food search or scan a barcode that is not in our catalog. Only the search text or barcode is sent, never anything that identifies you.
- Google Play (or the Apple App Store) distributes the app and has its own privacy practices for the download itself.
7. Your rights
You have the right to access your data, correct it, have it erased, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time. You can edit your profile and delete your account in the app. For anything else, such as a copy of your data, email [email protected]; we answer within one month.
You also have the right to complain to the supervisory authority: the Czech Office for Personal Data Protection (Úřad pro ochranu osobních údajů, uoou.gov.cz) or the authority in your own country.
8. Security
Passwords are stored only as hashes, connections to the server are encrypted, and access to the database is restricted. No system is perfectly secure, but we limit what we collect and keep so there is less to lose.
9. Children
The app is not intended for people under 16, and we do not knowingly collect their data. If you believe a child has created an account, email us and we will delete it.
10. Changes
If we change this policy in a meaningful way, we will update the date above and, for significant changes, tell you in the app.
11. Contact
Andrii Semeniuk, Czech Republic – [email protected]
This policy is also available in Czech, Ukrainian and Russian. If the translations differ, the English version prevails.