Kalorika is a food and calorie diary: an iOS app with an Apple Watch companion, a Telegram bot (@kalorika_gobot) and a Mini App. This policy covers all of them — they are one account and one database. The service is operated by the Kalorika team (dev-industry.tech) at kalorika.net.
In short
We store the diary you create — meals, photos, weight, workouts, your questions to the assistant — and nothing we do not need to show it back to you.
Apple Health data is read only with your permission, leaves the device only as day totals and workout sessions, and is never used for advertising. It goes to nobody — unless you yourself open sections of your diary to a trainer or nutritionist you connect (below).
There are no advertising or analytics SDKs in the app, no tracking across other apps and websites, and we sell data to nobody.
You can delete your account from the app. Deletion starts a 30-day countdown and then erases everything.
Apple Health
Health access is off until you turn it on in Settings → Apple Health, one purpose group at a time. Each group is a separate iOS permission sheet, each can be refused, and you can revoke any of it later in iOS Settings → Privacy & Security → Health → Kalorika. Refusing a group costs you that group’s numbers and nothing else.
What we read
Body
so weight and composition appear in the diary without being retyped
Weight HKQuantityTypeIdentifierBodyMass
Body fat percentage HKQuantityTypeIdentifierBodyFatPercentage
Lean body mass HKQuantityTypeIdentifierLeanBodyMass
Menstrual flow is read only if you switch it on yourself. It is off by default, it is never part of a group’s permission request, and switching it off stops the reading.
The app sends two things to our server through POST /api/health/sync: one row of totals per calendar day, and one record per workout session. Nothing else — no raw samples, no series, no minute-by-minute data, no location.
A day row: weight, body fat, lean mass, waist, active and resting energy, steps, distance, flights, exercise and stand minutes, water, resting pulse, HRV, sleep (total, deep, REM), VO₂ max — and, if you enabled it, the cycle flow. Days are cut in the timezone saved in your profile.
A workout: start time, duration, type, calories, distance, average and maximum heart rate during that workout, the name of the app that recorded it, and its HealthKit identifier — which we store only so the same workout is not imported twice.
Health values are never written to our server logs. The log lines about a sync hold counts and identifiers, never numbers.
What we write back
With your separate permission the app writes your own entries back into Health, so other apps can see them. Nothing is written without that permission, and we never delete or modify data another app wrote:
Dietary energy HKQuantityTypeIdentifierDietaryEnergyConsumed
It is never used for advertising or marketing — ours or anyone else’s.
It is never sold or disclosed to third parties, data brokers, insurers or employers. The only parties that ever see it are you, our server, and a specialist you connect yourself — and they see only the sections you open, only while you keep them connected.
It is used for one purpose: showing you your own numbers, computing your targets and trends, and answering the questions you ask the assistant.
What we store
Account: e-mail (if you registered with one) or Apple’s anonymous identifier for Sign in with Apple, your Telegram id if you use the bot, a password hash if you set a password, and your active device sessions.
Profile and goal: sex, age, height, weight, target weight, pace, activity answers, timezone, language, reminder time, notification switches.
The diary: meals with their calories and macros, the photos you send, barcodes you scan, corrections, workouts, water, daily metrics and the trends computed from them.
Your conversation with the assistant: the messages you write and the answers it gives, because the diary is built out of them.
Payments: Telegram Stars payments and Apple subscription transactions (Apple’s transaction identifiers and dates — never card details, which we never see).
Technical counters: feature usage counts, request counts per day, error events. Used to keep the service running and to see which features are used at all.
Kalorika Coach, if you use it: who you connected, which sections you opened and when, and when the specialist looked.
Sharing with your specialist
A trainer or nutritionist who uses Kalorika Coach can invite you. Nothing is shared until you accept on a consent screen that names them, lists every section with its own switch (all off at first) and asks you to tick a box yourself. We record what you agreed to, under which wording, and when.
The specialist sees only the sections you open: food, food photos, weight and measurements, workouts, activity and sleep from Health, how you feel. Menstrual cycle data is never shown to a specialist, whatever you choose.
You can change the sections or disconnect at any moment, without asking the specialist; access ends at once, past days included. You see when the specialist last looked at your data.
The specialist is not our employee. Before seeing any client they accept terms: the data is used only to work with you, never exported, copied, sold or passed on. Their title is stated by them; we do not check diplomas.
Who else processes it
We use a small number of providers, each for one job:
OpenAI and Google (Gemini) — recognising food from a photo, voice or text, and generating the assistant’s answers. They receive the photo or text you sent and the context the answer needs (your targets, the relevant part of the diary and, when you ask about activity or sleep, the aggregated numbers derived from Health). They do not receive your e-mail, your name or any advertising identifier.
Telegram — the bot and the Mini App, for accounts that use them.
Apple — Sign in with Apple, push notifications and App Store subscriptions.
Resend — sending the verification and password-reset e-mails.
DigitalOcean — the server and the database the service runs on.
Advertising and tracking
The app contains no advertising SDK and no third-party analytics SDK. We do not track you across other apps or websites, we do not build advertising profiles, and we do not sell or rent your data. Marketing links (for example /l/) count opens and clicks per campaign, not per person.
How long we keep it, and how to delete it
Your data is kept while your account exists — a food diary is only useful with its history.
Deleting the account: Settings → Delete account in the app, or DELETE /api/account. We do not erase on the spot, because one accidental tap would cost months of diary. Instead the account is marked, every device session is logged out, and 30 days later a scheduled job erases everything: profile, meals, items, chats, workouts, metrics, usage, payments, sessions, the photo files on disk and the audit rows that reference the account.
Changing your mind is enough to cancel it: any login, or any message to the bot, clears the mark during those 30 days.
Health specifically: revoking permission in iOS Settings stops new data immediately. Workouts and diary entries already imported can be deleted one by one in the app, and all of them go when the account is erased.
Your rights
You can see everything we hold about you in the app, correct it there, export your diary, and delete the account. If you want a copy of your data or have a question about this policy, ask — the contacts are below.
Not medical advice
Kalorika estimates calories, macros and expenditure. These are estimates for your own planning, not a diagnosis, not a treatment and not a medical device.
Contact
Write to us by e-mail or to the bot, or use Feedback in the app’s settings: