What we hold about you, why, who else sees it, and how to get it back or erased.
CalFit is the controller of the personal data described here, and is established in Israel. For anything in this policy, including a request to see or delete your data, write to omri@dicori.co.il.
This policy is written to be read, not to be survived. If a sentence in it is unclear, that is a fault worth telling us about.
Only what the app needs in order to work. There is no advertising here, no tracking pixel, and no third party analytics reading your health information.
Most of the above is health data, which the law treats as a special category and protects more strictly than an address or a name. We process it only with your explicit consent, which we ask for separately and in plain words rather than burying it in an acceptance of these documents.
You are not legally obliged to give us any of it. Providing it is voluntary.
What refusing costs you, plainly: without a date of birth, sex, height, weight and activity level, no calorie or protein target can be calculated and no plan can be produced, so the app has nothing to offer you. Without the health screening answers we cannot apply the safety limits, and we will not generate a plan blind. Refusing the optional items, which are the health platform connection, food photographs and the improvement consent below, costs you only that feature and nothing else.
You can withdraw consent at any time, and withdrawing does not make what we did beforehand unlawful. It stops the processing from that point, and you can delete everything alongside it.
Each purpose has its own basis, and a basis given for one purpose does not extend to another.
Knowing which plans actually worked is how the plans get better. To learn that we would need to keep a record of the shape of a plan and the result it produced, across many people.
We ask for this separately, it is off until you turn it on, and you can turn it off again whenever you like. Refusing changes nothing about the app you get. It is not a condition of using anything, and it never will be.
If you do turn it on, what leaves your account is stripped first: an age band rather than a birth date, a height band rather than a height, your goal, the plan version and the outcome. No name, no email, no account identifier, no free text and no photograph. If you later withdraw or delete your account, those records are removed too.
If you photograph a meal so the app can identify it, that photograph is sent to our server and from there to an artificial intelligence provider that returns a list of foods. This is how the feature works, and there is no version of it that keeps the photograph on your phone.
We require that provider to process the photograph and retain nothing, and not to use it to train its own models. We do not keep the photograph after the identification returns unless you chose to save it with the entry.
What the model returns is a suggestion. It is checked against our own validated food data before it becomes a number in your day, and it can be wrong. Do not photograph anything you would not want to send.
The connection is off until you grant it, it is granted per data type, and you can revoke it in the system settings without telling us. We read only the types you allowed, and we write back only your workouts, weights, water and dietary energy.
Data read from Apple Health is never used for advertising, never sold, never shared with a data broker and never stored in iCloud. Apple forbids all of that outright, and so do we.
We do not sell your data and we do not share it for anyone else to market to you. A small number of suppliers process it on our behalf, under contract, and only on our instructions.
Our suppliers operate internationally, so your data may be processed outside your country. Where it leaves the European Economic Area or Israel, it moves under an adequacy decision or under standard contractual clauses, and we ask suppliers to keep data in a European region where they offer one.
Your profile, plan and logged history are kept while your account exists, because the whole point of the app is the history. Delete the account and they go.
After deletion, encrypted backups still holding a copy expire within 30 days. Error reports are kept for 90 days. Records we must keep by law, such as a record of a payment, are kept for the period that law requires and for no longer.
A food photograph is not kept after the identification returns, unless you saved it with the entry yourself.
These rights are yours, they are free to use, and we answer within 30 days. You never have to explain why.
Everything travels encrypted and is stored encrypted. Access rules are enforced on the server so that an account can reach its own data and nothing else, and those rules are tested automatically on every release rather than trusted.
Anything sensitive kept on your device sits in the platform keychain rather than in an ordinary file. No security is perfect, and if a breach ever puts you at risk we will tell you and the authority, promptly.
The app is for adults and we do not knowingly hold data about anyone under 18. If you believe a minor has an account, write to us and we will delete it.
We will update this policy as the app changes. The version and date at the top tell you which one you are reading. If we ever want to use your data for something new, we will ask you again rather than quietly widen an old consent.