Calorie Arc

Privacy Policy

How Calorie Arc handles local data, optional Photo analysis, Apple Health activity energy, StoreKit, App Attest, deletion, support email, and page requests.

Effective date:

Last updated:

Scope

This policy explains how Calorie Arc handles local app information, optional Photo analysis, Apple services, Delete Local Data, voluntary support email, and these Cloudflare-hosted pages.

Information stored on your device

Calorie Arc stores your profile and energy settings, journey goals, daily food and activity records, selected photo-estimate details without photos, counted-day calculations and their receipts, weight entries you type in yourself, progress milestones, saved meals, saved activities, and a local StoreKit entitlement cache in its local app container. It also stores app-owned Apple Health synchronization values, reminder preferences, and an App Attest key identifier in iOS-managed storage.

The two captured Photo images are held only long enough to prepare and send an analysis request. Calorie Arc does not add them to your photo library or save them in its local database.

No accounts, ads, analytics, sale, or tracking

Calorie Arc has no user account, analytics SDK, crash-reporting SDK, advertising, or cloud-sync service. The developer does not sell or share app data for advertising or tracking.

Except for the narrowly scoped Photo analysis described below, Calorie Arc records and authorized Apple Health data are not transmitted to the developer.

Optional Photo analysis

When you explicitly start a Pro Photo analysis, Calorie Arc sends two reduced JPEG images of the dish, structured width, depth and optional height or volume measurements, locale, optional dish name, ingredient and preparation context, App Attest metadata, and the current StoreKit transaction proof. It does not send your Health data, body weight, profile, Journey, Food history, or saved items.

The dedicated Calorie Arc Cloudflare Worker validates the app installation and Pro purchase, enforces a burst limit and a maximum of five completed analyses per attested device per UTC day, and sends the two images and structured context to Anthropic’s Claude API. It does not accept a user-supplied AI prompt.

The Calorie Arc Worker does not store images, prompts, food names, or Claude responses in D1, KV, or R2. Its production D1 database stores one-time challenges, App Attest public keys and monotonic counters, and daily usage counters. Challenges expire after five minutes and are cleaned after ten minutes; usage rows are cleaned after 35 days; inactive attestations are cleaned after 365 days.

Under Anthropic’s standard commercial API policy, API inputs and outputs may be retained for up to 30 days and API data is not used to train models by default. Anthropic may apply its own security and legal processing. Do not include unnecessary personal information in the optional dish context.

Optional Apple Health access

With Calorie Arc Pro, you can choose to give Calorie Arc read-only access to activity energy in Apple Health. Imported activity energy is processed on your iPhone for estimated energy used.

Calorie Arc does not request or import weight from Apple Health. It does not write anything to Apple Health, does not upload Health data to a Calorie Arc server, and does not use Health data for advertising, tracking, or profiling. Weight entries in Calorie Arc are the ones you type in yourself and stay local to the app.

Apple Health access is optional and off until you turn it on. Manual food logging and manual weight entry remain available without it. Imported activity updates while the app is open or when you tap Sync Now; it does not update in the background. You can change or revoke access in iOS Settings or the Health app. Revoking access stops future reads; it does not automatically remove values already imported into Calorie Arc.

Optional local reminder

Calorie Arc can show one optional local reminder about a previous day that has food or activity but has not been counted. It is off until you turn it on, and turning it on is the only point at which Calorie Arc asks iOS for notification permission.

The reminder is scheduled entirely on the device by iOS. There is no push service, no remote notification, no server, and no delivery or engagement reporting.

Calorie Arc Pro, StoreKit, and App Attest

Calorie Arc Pro is a one-time, non-consumable purchase. Apple displays the localized price and handles purchase, payment, restoration, refund, and Apple Account information through StoreKit under Apple’s policies. Calorie Arc does not receive or store payment-card information. For Photo analysis, the Worker verifies Apple-signed transaction data, including purchase status, product and app identifiers, without receiving your Apple Account identity.

App Attest creates an app-installation key and sends attestation and assertion metadata to help distinguish a genuine Calorie Arc installation and enforce per-device abuse limits. The resulting key identifier and public-key metadata are linked to that app installation, not used for advertising or tracking.

Delete Local Data

Settings › Delete Local Data permanently removes Calorie Arc data stored by the app on that device, including your profile and energy settings, journeys, daily entries and calculations, selected photo-estimate details, progress milestones, saved meals, saved activities, weight entries, activity energy imported into Calorie Arc, the local entitlement cache, app-owned Health synchronization preferences, reminder preferences, and scheduled reminders.

Calorie Arc also makes a best-effort authenticated request to delete that installation’s App Attest registration and then removes its local identifier. If the device is offline, the remote inactive registration is retained only until normal cleanup. Daily aggregate usage may remain for up to 35 days.

Deletion does not cancel or revoke a Calorie Arc Pro purchase, remove data from Apple Health, revoke Apple Health permission, or retroactively delete a Photo request already processed under Anthropic’s retention policy. After deletion, Calorie Arc refreshes purchase status from Apple and returns to onboarding. Deletion cannot be recovered.

Voluntary support email

If you email support, the developer receives the email address, message, and any details or attachments you choose to provide. Calorie Arc does not automatically attach or upload app or Health data. Avoid sending sensitive health information or complete personal history unless it is necessary for your request. You may request deletion of support correspondence by contacting dzmitry.dziachenka@gmail.com, subject to legal and abuse-prevention obligations.

Cloudflare-hosted pages

The About, Privacy, and Support pages are delivered through Cloudflare. Visiting them can cause Cloudflare to process ordinary web request and security information—such as IP address, request headers, timing, logs, and security metadata—to deliver and protect the pages under Cloudflare’s own policies and infrastructure.

The page code does not intentionally set application cookies and contains no analytics, advertising trackers, accounts, forms, uploaded app data, or external scripts.

Retention and security

Local Calorie Arc data remains until you delete it with the in-app action or remove the app, subject to iOS device and backup behavior. Apple retains StoreKit records under Apple’s policies. Cloudflare and Anthropic may retain the limited metadata or API content described above under their policies. Calorie Arc Worker logs contain request ID, status, latency, token usage, and quota outcome, not images, food names, optional context, or request bodies. No storage or transmission system can be guaranteed absolutely secure.

Changes and contact

Material changes are published here with an updated date. Questions can be sent to dzmitry.dziachenka@gmail.com or through the Support page.