Privacy Policy

Effective date: 11 September 2026  ·  Last updated: 11 September 2026

1. Who we are

Calso is a mobile app that estimates the calories and macronutrients in a meal from a photograph, and tracks them against daily targets.

Calso is operated by YATECH, a sole proprietorship registered in Quebec, Canada, with its business address at 1187C rue Jogues, Drummondville, Quebec J2B 4X8, Canada. For applicable privacy laws, YATECH is the controller of — and the enterprise responsible for — the personal information described in this policy. You can reach us at contact@calso.app.

This policy covers the Calso mobile app and these pages. It sits alongside our Terms of Service.

2. The short version

3. What we collect

3.1 Account and identity

You sign in with Apple or with Google. Authentication is handled by Clerk, which creates and holds your identity record. Through it we receive and store your email address and a user identifier. Your name and profile picture are shown in the app from your Clerk profile. We never see or store your Apple or Google password.

3.2 Body and health-related data

The onboarding questionnaire collects nine answers: gender, date of birth, height, current weight, goal (lose, maintain or gain), target weight, activity level, desired weekly pace, and diet preference. We also store your device's timezone, so that "today" means your day and not ours.

From these we generate and store your daily calorie target, your protein, carbohydrate and fat targets, and a one-line explanation of how they were derived.

Special category data

Body statistics, diet preference and meal photographs are health-related data. Under the GDPR they are "special category" data (Article 9), and under Quebec law they are sensitive personal information. We handle them only with your explicit consent, and you can withdraw that consent at any time by deleting your account.

3.3 Meal photographs and nutrition records

When you log a meal we store the photograph you took or chose, and the record produced from it: the meal name, the estimated calories, protein, carbohydrate and fat, the time you logged it, and whether the analysis succeeded or failed.

Photographs are taken from your camera or picked from your photo library. Nothing leaves your device until you tap to analyse a meal. If the model decides a photo is not food, the record is discarded — though the uploaded image file itself remains in storage until you delete your account.

3.4 Diagnostic and technical data

We use Sentry to detect crashes and diagnose bugs. Sentry receives:

We also record a small number of events describing how far you got in the app — that onboarding completed, that a meal scan finished, how long it took, and whether it succeeded. These carry your goal, your generated calorie target, your timezone and a meal's calorie count. They exist to tell us the product is working, not to profile you.

4. What we do not collect

This list is as much a part of the policy as the one above, and it is verifiable in our source code:

One thing to be aware of

The app declares an iOS microphone usage string. It comes from the camera library we use and is not used by Calso — we never record or transmit audio. We intend to remove them.

5. Why we process your data, and on what legal basis

Calso is operated from Quebec, Canada. In Canada, and in Quebec in particular, we collect and use personal information with your consent and under the exceptions permitted by the Act respecting the protection of personal information in the private sector and by PIPEDA: what is necessary to provide the service you asked for, to support and secure it, and to meet our legal obligations. Where the law of another jurisdiction applies to you and requires a stated legal basis, the table below gives it.

Data Purpose Legal basis
Email address, user identifier Create your account, sign you in, keep your data available across devices Performance of our contract with you (GDPR Art. 6(1)(b)) · in Canada, information necessary to provide the service you asked for
Body statistics, diet preference, timezone Generate and store your daily calorie and macronutrient targets Explicit consent (GDPR Art. 9(2)(a)) · in Canada, your express consent to handle sensitive personal information
Meal photographs and nutrition records Estimate what you ate and show you your day Explicit consent (GDPR Art. 9(2)(a)) · in Canada, your express consent to handle sensitive personal information
Crash reports, performance traces, masked recordings, IP address Keep the app working, find and fix defects, prevent abuse Legitimate interests (GDPR Art. 6(1)(f)) · in Canada, operating and securing the service under the exceptions the Act and PIPEDA permit
Feedback you submit Answer you and improve the app Legitimate interests (GDPR Art. 6(1)(f)) · in Canada, operating and securing the service under the exceptions the Act and PIPEDA permit

Where we rely on explicit consent, you may withdraw it at any time by deleting your account (section 12). Withdrawal does not affect processing carried out beforehand.

Before you have an account. You can complete the questionnaire and see your targets before signing in. In that flow your answers are sent to our servers and on to OpenAI to generate the plan, but nothing is written to our database and no account exists. Your answers are saved only once you sign in and the plan is attached to an account.

6. Who else receives your data

We do not sell your data and we do not share it for anyone else's marketing. We use the following processors to run the Service. Each receives only what it needs.

Provider What it receives Why
Clerk Email address, sign-in identity, session and device metadata Account creation and authentication
Apple, Google Sign-in request; app distribution You chose them as your sign-in provider
OpenAI Your meal photographs (resized) and your onboarding answers, including age derived from your date of birth Estimating meal nutrition and generating your targets
ImageKit Your meal photographs Image storage and delivery
Neon Your profile, targets and meal records Our database
Trigger.dev Onboarding answers, meal identifiers and image links, email address for account-sync events Runs the background jobs that generate plans and analyse meals
Sentry Diagnostics as described in section 3.4, including user identifier and IP address Crash reporting and debugging
Expo App framework and API hosting Runs the app and its server endpoints

We may also disclose data where we are legally required to, or to establish or defend legal claims. If the Service is ever transferred to another operator, we will tell you before your data moves.

7. Where your data goes

Our providers operate outside Quebec and outside Canada. In particular, our database is hosted in the United States (AWS us-east-2), and OpenAI processes your photographs and answers in the United States. Our diagnostics are processed in the European Union (Sentry's Germany region).

Your personal information is therefore stored and may be accessed outside Quebec and outside Canada, primarily in the United States, where laws differ from those of your province, state or country and where public authorities may in some circumstances obtain access under local law.

Before entrusting personal information to a provider we assess the privacy risk of the transfer, as Quebec law requires, and we rely on written agreements: each provider's data-processing terms, which bind it to act on our instructions, to apply security measures, to restrict its own sub-processors, and to delete the information at our request — incorporating the European Commission's Standard Contractual Clauses where that provider's terms include them, or an adequacy decision where one applies. You can ask us which provider holds a given category of information by writing to contact@calso.app.

8. How long we keep it

Data Retention
Profile, targets, meal records and photographs Until you delete your account. If you do not sign in for 24 months, we delete it.
Sign-in identity Deleted with your account
Diagnostic data held by Sentry 90 days, then deleted by Sentry under its own schedule
Background job history held by Trigger.dev 1 day of run history on our current Trigger.dev plan, then deleted by Trigger.dev
Encrypted backups Our database provider keeps a short point-in-time restore history — 6 hours on our current plan. Deleted rows age out of it on that schedule.

9. How we protect your data

These are the measures actually implemented in the app and its API:

Encryption at rest, physical security and network isolation are provided by our infrastructure providers under their own certifications. No system is perfectly secure, and we cannot guarantee absolute security. If a confidentiality incident affects your rights, we will notify you and the competent authority as the law requires — in Quebec, the Commission d'accès à l'information and the people concerned, with diligence, where the incident presents a risk of serious injury; under PIPEDA, the Office of the Privacy Commissioner of Canada as soon as feasible where there is a real risk of significant harm; and within 72 hours where the GDPR applies to you.

10. Automated processing

Your daily targets and every meal estimate are produced automatically by AI models, with no human review. If the model fails or returns an implausible target, the app falls back to a standard published formula and shows you that result instead, without indicating which method was used.

We do not consider this to produce legal or similarly significant effects on you: the output is a nutrition estimate, not a decision about you, and nothing follows from it automatically. We do not profile you for advertising, scoring or any other purpose. If you disagree with a result or want a human to look at it, write to us at contact@calso.app.

11. Your rights

Under Quebec's Act respecting the protection of personal information in the private sector, under PIPEDA, and — where they apply to you — under the GDPR or a U.S. state privacy law, you have the right to:

If you live in Quebec, you may also ask for your information in a structured, commonly used technological format, and ask us to stop disseminating information or to de-index a link where the law allows. We will not charge you for a request, and we will not treat you differently for making one. We may need to verify that the request comes from the account holder before we act.

How these work in practice

Erasure is self-service — Profile tab, immediate, no request needed. Access, portability and correction are handled manually: the app has no data-export screen, and there is currently no screen for editing your body statistics after onboarding. Email contact@calso.app and we will action your request. We respond within 30 days, as Quebec law and PIPEDA require, within one month under the GDPR, and within 45 days under U.S. state privacy laws.

12. What deletion really removes — and what it does not

Deleting your account from the Profile tab is immediate and permanent. There is no recovery period and we cannot restore it. It removes:

Being straight with you about what it does not reach:

If you want these cleared sooner, email contact@calso.app and we will make the requests on your behalf.

13. Children

Calso is not intended for anyone under 16, and our Terms of Service require you to be at least that age. We do not knowingly collect data from children. The app asks for your date of birth to calculate calorie needs, not to verify your age. If you believe a child has given us their data, contact us at contact@calso.app and we will delete it.

14. Changes to this policy

We will update this policy when what we do changes. The current version always lives at this address with its effective date at the top. Where a change materially affects how we use your data, we will make reasonable efforts to tell you in the app or by email before it takes effect, and where the law requires it we will ask for your consent again.

15. Contact and complaints

For any privacy question, or to exercise any right above, write to contact@calso.app, or to 1187C rue Jogues, Drummondville, Quebec J2B 4X8, Canada.

If you are not satisfied with our response and you live in Quebec, you may complain to the Commission d'accès à l'information du Québec at cai.gouv.qc.ca. Elsewhere in Canada, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca. If you are in the EEA, you may instead complain to the supervisory authority where you live or work.