CalBiss Privacy Policy
Last updated August 2, 2026
This document is being finalised. Text shown in square brackets is awaiting confirmation.
1. Who we are
This Privacy Policy explains how [CalBiss Ltd. — exact registered Israeli legal name] ("CalBiss", "we", "us") collects, uses, and protects your personal information when you use the CalBiss mobile application and website (together, the "Service").
Data controller:
[CalBiss Ltd. — exact registered Israeli legal name]
[Registered address, City, Israel]
Privacy contact:
[privacy@calbiss.app]
EU representative (Art. 27 GDPR):
[Name + contact details of appointed EU (Art. 27 GDPR) representative]
UK representative:
[Name + contact details of appointed UK GDPR representative]
Data Protection Officer:
[DPO name + contact, or remove if counsel confirms none is required]
CalBiss is a nutrition and wellness app. It is not a medical device and does not provide medical advice.
2. Information we collect
Account data: name, email address, and password (stored hashed) — or, if you sign in with Google or Apple, the name and email those services provide — plus your app language, profile photo, and settings.
Health and nutrition data you provide: meals and foods you log, calorie and macronutrient history, body metrics (such as weight, height, age, sex), activity level, weight or nutrition goals, and any allergies, dietary restrictions, or food dislikes you enter. This information is treated as health data — "special category data" under the GDPR, "sensitive personal information" under California law, and "consumer health data" under Washington's My Health My Data Act.
Apple Health and Health Connect data: with your permission, we read your step count, active energy burned, and workout sessions from Apple Health (iOS) or Health Connect (Android) to show your daily activity and calorie balance. This data is uploaded to our servers to provide these features. We never use Apple Health or Health Connect data for marketing or advertising, never disclose it to advertisers or data brokers, and never store it in iCloud. You can revoke this access at any time in your device's health settings.
Food photos: photos you choose to take or upload. Photos are captured only when you actively use the camera or photo picker — never in the background. Photos submitted for AI analysis are processed transiently and are not kept on our servers after analysis; photos you choose to save with a meal are stored with that meal until you delete it.
AI-derived data: nutrition estimates (food identification, calories, macronutrients) inferred from your photos and logs, and any corrections you type.
Social features: friend connections, group memberships, messages, comments, reactions, and the updates you share with other users.
Barcode scans: when you scan a product barcode, we process the barcode number to look up nutrition information. Scan lookups are logged for reliability without being linked to your identity.
Support data: if you contact support, the name, email, optional phone number, and message content you provide.
Purchase data: if you buy a paid subscription (where offered), subscription status and transaction identifiers from Apple App Store or Google Play. We never receive your full payment card details.
Technical data: platform (iOS/Android), app version, language, timezone, push-notification token, and standard server logs (such as IP address and request timestamps) kept for security. We do not currently use any third-party analytics, crash-reporting, or advertising SDKs, and we do not use advertising identifiers or track you across other companies' apps or websites; if this ever changes, we will update this Policy first.
3. How we use your information and legal bases
We use your information to:
• Provide the Service: log meals, calculate nutrition targets, show your history and progress (performance of our contract with you — GDPR Art. 6(1)(b)).
• Analyze food photos and generate nutrition estimates (your explicit consent, given on the AI consent screen shown before you first use an AI feature — GDPR Art. 9(2)(a); you may withdraw it at any time in Settings).
• Process health and body-metric data to personalize daily targets (your explicit consent, given when you accept these documents at sign-up — GDPR Art. 9(2)(a)).
• Operate social features you opt into (contract and consent).
• Maintain, secure, and improve the Service, fix crashes, and prevent abuse (legitimate interests — GDPR Art. 6(1)(f)).
• Send service communications, and — only with your consent — marketing messages (consent — GDPR Art. 6(1)(a)).
• Comply with legal obligations (GDPR Art. 6(1)(c)).
We do NOT use your health data, food photos, or data derived from them for advertising, marketing profiling, or use-based data mining, and we do not sell your personal information.
4. AI processing of your food photos
When you photograph food for analysis, the photo is transmitted securely to our servers (with location metadata stripped) and forwarded to our third-party AI provider, OpenAI, which processes it solely to identify the food and estimate its nutritional content and returns the result to us. Photos submitted for analysis are processed in memory and are not retained on our servers afterwards. If you then choose to save the meal, the photo is stored with that meal and appears in your history until you delete it.
We use OpenAI's business API, not its consumer products. Under OpenAI's API terms, data sent through the API is not used to train OpenAI's models. OpenAI may retain API inputs and outputs for a limited period (currently up to 30 days) for abuse monitoring, after which they are deleted, unless a longer period is legally required.
When you use AI advice features, we also send OpenAI relevant parts of your nutrition profile — such as age, weight, height, sex, goals, activity level, allergies and dietary restrictions, and recent meal history — so the advice can be personalized.
You are interacting with an artificial-intelligence system. AI-generated nutrition and calorie estimates are approximations and may be inaccurate. They are not medical, dietary, or nutritional advice.
AI analysis happens only when you actively use an AI feature, and only with your explicit consent. We ask for that consent on a dedicated screen the first time you use an AI feature, before your camera or photo library is opened. You can withdraw it at any time in Settings, or by contacting [privacy@calbiss.app] — manual logging keeps working without AI.
5. Who we share information with
We share personal information only with service providers ("sub-processors") who process it on our behalf under data-processing agreements:
• Cloud hosting and database providers (application hosting and data storage)
• Cloud object storage (saved meal photos and profile photos)
• OpenAI (AI food-photo analysis and AI advice, as described above)
• Expo (delivery of push notifications)
• Apple and Google (sign-in verification, and subscription billing where offered)
When you scan a barcode, the barcode number (never your identity) is sent to public food databases — Open Food Facts and USDA FoodData Central — to retrieve nutrition information.
We may also disclose information when required by law, to protect our rights or users' safety, or as part of a merger or acquisition (in which case this Policy continues to apply to your data and you will be notified).
Social sharing: friends you connect with can see your display name and profile photo and — according to your sharing settings — your calories eaten versus goal, macronutrients, steps and active calories burned, streaks and badges, meal details, and meal photos, along with any group messages, comments, and reactions you post. You can control each of these categories in your privacy settings and block or report other users at any time. We share your consumer health data with other users only with your consent.
6. International data transfers
We are based in Israel, which the European Commission recognizes as providing an adequate level of data protection, so data may flow between the EEA/UK and Israel without additional safeguards.
Where we transfer personal data to countries without an adequacy decision (for example, sub-processors in the United States), we use the European Commission's Standard Contractual Clauses, supplemented by the UK International Data Transfer Addendum for UK data, together with additional technical and organizational safeguards.
7. How long we keep your data
• Account, nutrition, health, and social data: kept while your account is active; deleted within [30] days after account deletion.
• Photos submitted for AI analysis: processed transiently and not stored on our servers after analysis. Our AI provider may hold them for up to 30 days for abuse monitoring before deleting them.
• Photos you save with meals, and your profile photo: stored and shown in your history until you delete the meal, the photo, or your account.
• Server and security logs: retained for [90] days.
• Support messages: retained for [24] months after your case is closed.
• Purchase records (where subscriptions are offered): retained as required by tax and accounting law (typically 7 years).
When retention ends, data is deleted or irreversibly anonymized, subject to a short additional window for backups to roll off.
8. Your rights
Depending on where you live, you have the right to: access your data; receive a portable copy; correct inaccurate data; delete your data; restrict or object to processing; withdraw consent at any time (without affecting prior processing); and not be subject to solely automated decisions with legal or similarly significant effects — CalBiss makes no such decisions.
To exercise any right, use the in-app tools (Settings → Account) or contact [privacy@calbiss.app]. We respond within the time required by your local law (e.g. one month under GDPR, 15 days under Brazil's LGPD). We will never discriminate against you for exercising your rights.
You may also lodge a complaint with your data protection authority: in the EU, your national supervisory authority; in the UK, the ICO; in Israel, the Privacy Protection Authority; in Brazil, the ANPD.
9. United States state privacy rights
California (Notice at Collection): We collect the categories described in Section 2, including sensitive personal information (health and nutrition data), for the purposes in Section 3, and retain them as described in Section 7. We do not sell or share personal information as defined by the CCPA/CPRA, and we do not use sensitive personal information beyond the purposes permitted by law. We honor Global Privacy Control signals on our website. California residents may exercise access, deletion, correction, and portability rights via [privacy@calbiss.app].
Washington residents: our separate Consumer Health Data Privacy Policy, required by the My Health My Data Act, is available at [https://calbiss.app/consumer-health-data-policy]. We collect and share consumer health data only with your opt-in consent.
Residents of other states with comprehensive privacy laws (Colorado, Connecticut, Virginia, Texas, and others) have similar rights of access, correction, deletion, and portability, and the right to appeal a refusal, via [privacy@calbiss.app].
10. Children
CalBiss is not intended for children under 16, and we do not knowingly collect personal information from them. If you believe a child under 16 has created an account, contact [privacy@calbiss.app] and we will delete the account and its data. The app is not directed at children and is not part of any "kids" store category.
11. Security
We protect your data with encryption in transit (TLS) and at rest, access controls limiting data access to personnel who need it, audit logging, and vendor security review. No system is completely secure; if a breach affects your personal data we will notify you and the relevant authorities as required by law (including within 72 hours to EU supervisory authorities where the GDPR applies).
12. Deleting your account
You can permanently delete your account and associated data at any time in the app (Settings → Account → Delete Account) or via [https://calbiss.app/delete-account], which requires no login.
Deletion removes your account, profile, meal and nutrition history, body metrics, photos, and social connections. We retain only what the law requires us to keep (e.g. purchase records for tax law) and minimal fraud-prevention records, each deleted when its retention period ends. Deletion is processed within [30] days.
13. Changes and contact
We may update this Policy from time to time. For material changes we will notify you in the app and, where the change affects how we process health data, ask for your consent again before it applies to you. The "Last updated" date always reflects the current version.
Questions or requests: [privacy@calbiss.app]
[CalBiss Ltd. — exact registered Israeli legal name]
[Registered address, City, Israel]
General support: [support@calbiss.app]
Website: [https://calbiss.app]