Privacy Policy
KcalExpose helps you estimate the nutrition in your meals and follow your progress over time. This policy explains what we collect, why, who it is shared with, and the choices you have.
1. Who is responsible for your data
KcalExpose is operated by Serene Stars AB (company reg. no. 559536-8472, VAT no. SE559536847201), a Swedish limited company with its registered office in Ängelholm, Sweden. We are the data controller for the personal data described in this policy. Our full postal address is at the foot of this page.
For any privacy questions, or to exercise the rights described in section 9, contact us at support@kcalexpose.support.
2. The short version
- You need an account to use KcalExpose. We store your email address and the profile details you enter.
- Photos of meals are sent to an AI service to estimate nutrition, and are saved to your account so they appear on your other devices.
- Body photos stay on your phone. They are not uploaded, not backed up, and cannot be recovered by us or by you if the app or device is lost. If you used a much earlier version of the app, any body photo it had stored on our servers is fetched back to your device and deleted from them — see section 4.
- We do not sell your data, and we do not use it for advertising.
- You can delete your account and all server-side data from inside the app at any time.
3. What we collect
Account information
Your email address and a username, created when you register. Authentication and password storage are handled by Supabase; your password is only ever passed through to Supabase to be verified — we never store it, and it is never written to a log.
Profile and health information
The details you enter during setup and later change in the app: name, age, gender, height, weight, target weight, activity level, your goal, your chosen timeframe, health goal, and experience level.
Activity you record
Meals you log (description, calories, protein, carbohydrates, fat and timestamps), weigh-ins, streaks, achievements, goal history, and app settings.
Photos
Meal photos, body photos and your profile picture are treated very differently. Section 4 explains this in full.
Subscription status
If you subscribe, we receive your subscription status through RevenueCat and Apple. We never receive your card number or payment details — those stay with Apple.
Technical information
Like any internet service, ours sees the IP address your device connects from, along with the time and basic technical details of each request. Our infrastructure providers, Cloudflare and Supabase, record this in short-lived operational logs so that the service can be run and abuse detected. We do not build profiles from it and we do not use it for anything else. To prevent abuse, our AI endpoint also counts how many requests each account makes within a time window; that counter is keyed to your account identifier and expires automatically.
Health data. Your weight, height, target weight, weigh-in history and the photos you take of your meals are health-related data under Article 9 of the GDPR. We process them only to provide the features you have chosen to use. Because they are health data, we rely on the explicit consent you give with the tick-box when you create your account, alongside the contract we have with you — section 5 sets out both. That consent is stored with a timestamp on your account, so that both you and we can see when it was given.
Body photos are deliberately outside that consent: the images never reach us at all. They stay in the app's private storage on your device and are never uploaded. Section 4 explains this in full.
You can withdraw your consent at any time. Because KcalExpose cannot calculate a single target without this data, withdrawing it means the app can no longer be used — you withdraw by deleting your account under Settings → Delete account, which erases the data along with it. Withdrawal does not affect processing already carried out.
This website
The pages on kcalexpose.support store your language choice in your browser's local storage, so the site remembers it next time. If you sign in on the start page to see your own streak, your session is stored there as well and stays until you sign out. We set no cookies of our own, and the site carries no analytics and no tracking. Reading these pages loads no third-party scripts at all. If you open the sign-in box, Cloudflare Turnstile loads there — and only there — to check that the attempt comes from a person and not a bot; for that check Cloudflare receives your IP address and basic information about your browser, and may store a short-lived identifier of its own to remember that you passed. All three are strictly necessary for something you asked for — remembering your language, keeping you signed in, and stopping password-guessing attacks on the sign-in form — so we neither need nor ask for cookie consent. If you want them gone, sign out and clear your browser storage.
4. Photos — what is stored where
| Type | Where it is stored | Can it be restored? |
|---|---|---|
| Meal photos | On your device, and mirrored to a private storage area tied to your account | Yes — they reappear when you sign in on another device |
| Body photos | On your device only. The image never leaves your phone | No |
| Body photo details (date, weight, note) |
Synced to your account | Yes — but without the image |
| Profile picture (only if you choose a photo instead of an emoji) |
Stored with your account data | Yes |
Your profile picture is optional. If you pick one of the emoji options instead, no image is stored at all. A photo you choose is scaled down to a small square and saved with your account so it appears on your other devices — it is not treated as a body photo and does not stay on the device only.
Why body photos stay on your device
Progress photos are among the most personal things a person can keep. We decided that the safest place for them is the one place we cannot reach: your own phone. They are stored in the app's private storage on the device and are never uploaded to our servers.
This means body photos cannot be restored. If you delete the app, lose or reset your device, or sign in on a different phone, your body photos are gone permanently. Nobody — including us — can recover them, because no copy exists anywhere else.
When you sign in on a second device you will still see the entry with its date, weight and note, but the image itself will be missing.
If your progress photos matter to you, save copies to your own photo library or another backup of your choosing.
Earlier versions of KcalExpose did store body photos on our servers. After you update, the app downloads any such photo back to your device, verifies the local copy, and then permanently deletes the server copy. If it cannot reach our servers at that moment it tries again the next time you open the app, and it never deletes the server copy until it has confirmed the photo is safely on your device.
5. How your data is used
- To provide the service — calculating your targets, estimating nutrition from your photos and descriptions, and showing your history and progress.
- To sync across your devices — so your data is there when you sign in elsewhere.
- To manage your subscription — checking whether your account has access to paid features.
- To keep the service working and secure — preventing abuse of the AI endpoint and diagnosing faults.
We do not sell personal data, share it with advertisers, or use it to build advertising profiles.
Our legal bases
Under the GDPR we must tell you why we are allowed to process your data. These are the bases we rely on:
| What we do | Legal basis |
|---|---|
| Run your account, calculate your targets, store your history and sync it between your devices | Performance of our contract with you — Art. 6(1)(b) |
| Process your weight, height, target weight, weigh-in history and meal photos — health-related data | Your explicit consent — Art. 9(2)(a) — together with performance of our contract with you, Art. 6(1)(b) |
| Check and manage your subscription | Performance of our contract with you — Art. 6(1)(b) |
| Prevent abuse of the AI endpoint, keep the service secure, diagnose faults | Our legitimate interest in a working, affordable service — Art. 6(1)(f) |
| Respond to lawful requests from authorities | Legal obligation — Art. 6(1)(c) |
An account, and the profile details listed in section 3, are needed to use KcalExpose — without them the app cannot calculate targets or sync anything, so there is no service to provide. Everything beyond that, including photos and notes, is entirely up to you.
The nutrition estimate is not an automated decision that produces legal effects for you. It is an approximation, and you are free to accept it, edit it or ignore it.
6. AI analysis
When you photograph a meal or describe one in text, that photo or text — together with any name or note you add, your selected goal and your chosen language — is sent over an encrypted connection to our processing endpoint, and from there to Google's Gemini API, which returns the nutrition estimate.
Our endpoint does not store or log the image or the text. It passes the request through, returns the result, and keeps nothing but a request counter, keyed to your account identifier, used for rate limiting.
Google processes the request only to return the estimate. We use the paid Gemini API, under terms that prohibit Google from using the content to train or improve its models. Your photos, descriptions and notes are never used to train any AI model, ours or anyone else's, and are never used for advertising.
Nutrition estimates produced this way are approximations and can be wrong. See our Terms of Use.
7. Who we share data with
The following providers process data on our behalf, as our processors, under a written data processing agreement:
| Provider | Purpose |
|---|---|
| Supabase | Account authentication, database, and private photo storage |
| Cloudflare | Our AI processing endpoint, this website, and bot protection on the sign-in form (Turnstile) |
| Gemini API — nutrition analysis of meal photos and descriptions. Google Workspace — our support mailbox | |
| Resend | Delivery of verification and account emails |
| RevenueCat | Subscription status management |
Each of them is bound by contract to protect your data to at least the standard set out in this policy, to process it only on our instructions, and never for their own purposes.
Apple is not our processor. When you download KcalExpose or buy a subscription, Apple acts as an independent controller for App Store distribution and payment processing, under Apple's own privacy policy. All we receive back is whether your subscription is active — never your card number or payment details.
We may also disclose data where we are legally required to do so.
8. International transfers and retention
Your account data and your meal photos are stored with Supabase, on servers in the European Union (Frankfurt, Germany). Our other processors — Cloudflare, Google, RevenueCat and Resend — are established in the United States and may process data there. Those transfers are made under the European Commission's Standard Contractual Clauses and, where the provider is certified under it, additionally under the EU–US Data Privacy Framework. Write to support@kcalexpose.support and we will send you a copy of the safeguards that apply to any of them. Apple is not among them: as an independent controller (section 7), Apple makes any transfer of its own, under its own safeguards and its own privacy policy.
We keep your data for as long as your account exists. Deleting your account removes your account record, your synced data and your stored meal photos from our systems, and clears the app's local data on the device you delete it from — including the body photos stored there. You can do this at any time under Settings → Delete account in the app.
Deleted data can survive in our providers' encrypted backups for up to 30 days afterwards, until those backups are rotated and overwritten. It is never restored to your account and is never used for anything else. The rate-limit counter described in section 3 expires within a day. Records we are required by law to keep — accounting records under the Swedish Accounting Act (bokföringslagen 1999:1078), for example — are kept for as long as that law requires and for no other purpose.
9. Your rights
We are established in Sweden, so the GDPR governs everything we do with your data — wherever in the world you live. You have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent at any time, without affecting processing already carried out;
- lodge a complaint with your national data protection authority. In Sweden that is the Integritetsskyddsmyndigheten (IMY).
Your right to object. Where we rely on our legitimate interest — preventing abuse of the AI endpoint, keeping the service secure and diagnosing faults, as set out in section 5 — you may object to that processing at any time, on grounds relating to your particular situation. Tell us and we will stop, unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms.
Write to support@kcalexpose.support and we will respond within one month. If a request is unusually complex we may extend that by up to two further months, and we will tell you within the first month if that happens.
California residents
We do not and will not sell your personal information, and we do not share it for cross-context behavioural advertising — using both words as they are defined in the California Consumer Privacy Act as amended by the CPRA. We have not sold or shared personal information in the preceding twelve months, and we have no actual knowledge of selling or sharing the personal information of anyone under 16. The health data described in section 3 is sensitive personal information; we use it only to deliver the features you asked for and never to infer characteristics about you. You may exercise your rights to know, delete, correct and to be free from retaliation by writing to support@kcalexpose.support. We will not treat you differently for doing so.
10. Security
All traffic between the app and our services is encrypted in transit. Meal photos are held in a private storage area that requires your own authenticated session to access; they are not publicly reachable. Access to your synced data is restricted to your account at the database level.
No system is perfectly secure, and we cannot guarantee absolute security. Body photos are the one category we protect structurally rather than procedurally: since they are never transmitted to us, a breach of our systems cannot expose them.
11. Children
KcalExpose is not intended for anyone under 18, and we do not knowingly collect data from under-18s. The app asks for your age during setup and does not accept an age below 18.
If you believe someone under 18 is using KcalExpose, write to us and tell us why. We will look into it, and we may ask you for information supporting the claim before we act — we do not close an account on an unverified report alone, because doing so would destroy another person's data on nothing more than an assertion. Where we establish that an account belongs to someone under 18, we delete the account and the data with it.
12. Changes to this policy
If we make material changes we will update the date at the top of this page and, where the change is significant, notify you in the app. If a change means processing your health data for a new purpose, we will ask you for fresh explicit consent — we will never treat continued use of the app as consent to that. For any other change, the updated policy applies from the date shown above.