PRIVACY POLICY
Your meals are yours.
This policy explains what Kalorimy collects, why, where it goes, and how to delete it. We collect the minimum needed to run the service and comply with Malaysia’s Personal Data Protection Act 2010.
Last updated 29 August 2026
What we collect
- Account details — your name, email address and profile picture from Google sign-in, or the email and password you register with.
- Profile details — sex assigned at birth, age, height, weight, activity level and goal. These are used only to calculate your calorie and protein guide.
- Meal data — the photos you scan and the meals you log, including AI-estimated calories, protein and items.
- Billing — your subscription status and Stripe customer ID. Card details are handled entirely by Stripe; we never see or store them.
- Technical — standard server logs (IP address, browser, timestamps) kept briefly for security and debugging.
How we use it
To sign you in, personalise your daily guide, store your meal diary, estimate meals from photos, bill your subscription, answer support requests, and keep the service secure. We don’t sell personal data, we don’t run advertising, and we don’t use your photos to train models.
Who we share it with
- OpenAI — meal photos are sent to OpenAI’s API to produce calorie estimates. Photos are processed under OpenAI’s API data policy and are not used to train their models.
- Stripe — payment processing and subscription management.
- Cloudflare — hosting, database and photo storage.
- Google — sign-in, if you choose “Continue with Google”.
We share data only when required by law or to protect Kalorimy and its users.
Where it lives and for how long
Your data is stored on Cloudflare infrastructure and kept for as long as your account exists. Meal photos are private to your account and are never made public. Server logs are kept for up to 30 days.
Your rights
You can view and edit your profile in Settings, delete individual meals from your diary, and permanently delete your whole account — including all photos, meals and profile data — from Settings → Delete account. Deleting your account also cancels any active subscription and removes your Stripe customer record. Under the PDPA you may also request access to or correction of your data by emailing support@kalorimy.com.
Cookies
Kalorimy uses a single session cookie to keep you signed in and browser storage to remember your onboarding progress. There are no tracking or advertising cookies.
Changes
If this policy changes materially we’ll tell you in the app or by email. The “last updated” date above shows the current version.
Questions? Email support@kalorimy.com.