← Back to Caltra

Privacy Policy

Effective date: 15 August 2026 · Version: 2026-08-15

Caltra is operated by Nodal Apps, a business based in Finland (“Caltra,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal data when you use the Caltra mobile application, website, support channels, and related services (the ”Services”).

Contact: privacy@getcaltra.com

1. Data we collect

Account and contact data. Your email address, account identifier, authentication provider, and profile information made available by Apple, Google, or another sign-in provider, such as your name.

Health, fitness, and nutrition data. Information you enter or choose to import, including age or birth date, sex, height, weight, body-fat percentage, steps, activity information, nutrition and food logs, meal timing, dietary preferences, goals, body measurements, progress information, and calculated nutrition or expenditure estimates.

Apple Health data. If you enable Apple Health, Caltra may read and write the HealthKit data types shown in Apple’s permission sheet, including steps, body mass, body-fat percentage, and dietary nutrition samples. You control these permissions in Apple Health or device Settings and may revoke them at any time.

Photos and other content. Meal photos, nutrition-label or packaging photos, meal descriptions, custom foods, food contributions, and other content you choose to submit. Meal and label images may be sent to an AI service to generate a result. Caltra does not intentionally retain the input image after ordinary meal or label analysis, but derived results may be saved when you add them to your account. If you explicitly submit a food contribution, its label or packaging photos are retained for review with that contribution.

Food search service data. Search terms and barcodes go to Caltra’s search service. This is required to provide search results. We process the search term or barcode, request timing, result and error information, and related technical data needed to return and secure those results.

Optional food-search analytics. Food-search analytics are separate from the required search service and are off by default. If you enable “Help Improve Food Search,” Caltra collects account-linked normalized food-search queries, result counts, selected catalog item and position, barcode misses, request timing, and error metadata. We use this information to improve search quality and reliability. You can turn this setting off at any time.

Optional product analytics. Product analytics are enabled by default during onboarding, and you can disable them before continuing or later under Privacy & Diagnostics. When enabled, PostHog receives a pseudonymous installation identifier, app lifecycle events, screen names, app version and build, operating-system name and version, device type, SDK version, and session identifier. Caltra does not send PostHog touch events, screen recordings, route parameters, account identity, health or nutrition data, food-search terms, photos, or other user content through this integration. PostHog geolocation enrichment, feature flags, push-token collection, error capture, logs, and session replay are disabled in Caltra.

Optional crash diagnostics. Crash diagnostics are enabled by default during onboarding, and you can disable them before continuing or later under Privacy & Diagnostics. When enabled, Sentry receives error and crash stack traces, error type, app version and build, operating-system and runtime information, device type, SDK-generated crash context, and related technical diagnostics. Caltra does not deliberately attach account identity, request bodies, custom app state, screenshots, view hierarchies, session replays, or performance traces. JavaScript error events are additionally scrubbed before transmission. Please do not put personal information into error messages when reporting a problem.

Subscription data. Subscription status, product identifier, purchase history, entitlement status, renewal state, and store transaction identifiers. Caltra does not receive your full payment-card details from Apple or Google.

Security and technical data. IP-derived security signals, device, installation, or request identifiers, request timestamps, rate-limit and abuse-prevention records, and technical diagnostics needed to secure and operate the Services. Network providers necessarily receive an IP address when a device connects to them; Caltra disables PostHog GeoIP enrichment and does not intentionally include an IP address in Sentry event payloads.

Support communications. Messages and information you send when asking for help, reporting a problem, or exercising a privacy right.

2. How we use data

We use personal data to:

  • create and authenticate your account;
  • provide food logging, nutrition analysis, goals, trends, check-ins, subscriptions, Apple Health synchronization, exports, and account deletion;
  • provide food-search results for the search terms and barcodes you submit;
  • personalize nutrition targets, recommendations, and app settings;
  • analyze submitted meal or nutrition-label content with AI at your request;
  • operate, secure, troubleshoot, and prevent abuse of the Services;
  • improve food search, reliability, and product features;
  • analyze pseudonymous app lifecycle and screen usage while product analytics is enabled;
  • diagnose crashes and technical failures while crash diagnostics is enabled;
  • respond to support and privacy requests; and
  • comply with law and enforce our Terms of Service.

We do not sell personal data. We do not use HealthKit data, health data, nutrition data, or photos for third-party advertising, and we do not use advertising networks to track you across other companies’ apps or websites.

3. Legal bases for processing

Where the GDPR, UK GDPR, or similar law applies, we rely on:

  • Contract: processing necessary to provide the Services you request.
  • Consent: processing health or other sensitive data, accessing Apple Health, optional account-linked food-search analytics, optional product analytics, optional crash diagnostics, and other processing where consent is legally required. You may withdraw consent, but features that require the data may stop working.
  • Legitimate interests: securing, maintaining, and improving the Services where those interests are not overridden by your rights.
  • Legal obligation: processing necessary to comply with law, valid legal process, tax, accounting, or consumer-protection requirements.

Health information may be “special category” data. Where required, we process it based on your explicit consent. Apple Health permission is optional and is separate from acceptance of this Privacy Policy.

4. When we disclose data

We disclose data only as needed to provide and protect the Services, including to:

  • Supabase for authentication, databases, storage, and server functions;
  • OpenAI for AI meal and nutrition-label analysis requested by you;
  • Cloudflare for operating Caltra’s food-search service, including processing search terms and barcodes to return results, and for performance and security;
  • RevenueCat for subscription and entitlement management;
  • PostHog for optional pseudonymous product analytics while it is enabled;
  • Sentry for optional scrubbed crash diagnostics while it is enabled;
  • Apple and Google for authentication, app distribution, purchases, and platform services;
  • email delivery providers when needed for operational or review messages;
  • professional advisers, auditors, insurers, or authorities where legally necessary; and
  • a successor in a merger, financing, reorganization, or sale, subject to appropriate safeguards.

Service providers may process data only for the services they provide to us and under their applicable contractual and legal obligations. We do not authorize them to use Caltra health data for advertising.

5. International transfers

Our providers may process data outside your country, including in the United States. Where required, we use recognized transfer mechanisms such as adequacy decisions, Standard Contractual Clauses, and supplementary safeguards.

6. Retention

Account, profile, nutrition, health, search-event, contribution, and subscription-related data is generally retained while your account remains active so the Services and history remain available. Search-service request records, including search terms and barcode lookups, are retained only as needed to provide, secure, troubleshoot, and improve the search service, subject to our applicable retention practices. Optional PostHog analytics and Sentry diagnostic events are retained according to the retention period configured in those services and are then deleted or aggregated. Turning a setting off stops future collection but does not instantly remove events already transmitted. You may contact privacy@getcaltra.com to request deletion of identifiable or linkable analytics or diagnostic data where applicable.

When you delete your account, Caltra deletes user-owned database records, retained contribution uploads, the Caltra authentication account, and the linked RevenueCat customer record. PostHog and Sentry are not given your Caltra account identifier through these integrations, so their pseudonymous installation-level events may not be automatically located by account deletion alone. Contact privacy@getcaltra.com before deleting the app if you want help requesting deletion of those events. Limited copies may remain temporarily in provider backups or logs until they expire under provider backup and security schedules. We may retain narrowly limited records longer where required by law, necessary to resolve disputes, or needed to prevent fraud or abuse.

Ordinary AI meal or label input images are processed for the requested analysis and are not intentionally saved in Caltra’s account database or storage. Images you explicitly submit as a food contribution are retained with the contribution until the contribution or account is deleted.

7. Your choices and rights

Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to processing, withdraw consent, and lodge a complaint with a data-protection authority. You can update many settings in Caltra, keep optional food-search analytics off or disable them again under Food Log settings, disable optional product analytics or crash diagnostics during onboarding or later under Privacy & Diagnostics, disconnect Apple Health in Caltra or device Settings, export your data in the app, and delete your account in the app. Turning off optional analytics or diagnostics does not affect core app functionality. You may also contact privacy@getcaltra.com.

Withdrawing Apple Health permission stops future access but does not automatically delete data already imported to your Caltra account. Use Caltra’s account deletion or contact us if you also want that account data deleted.

If you are in the EEA, you may complain to your local supervisory authority. In Finland, the authority is the Office of the Data Protection Ombudsman.

8. Security and local device storage

We use administrative, technical, and organizational safeguards designed to protect personal data. Authentication credentials and the bounded local account bootstrap cache are stored using operating-system protected storage on supported mobile platforms. Privacy choices and bounded SDK delivery queues may be stored in Caltra’s app storage on the device. Long-term health and nutrition history remains server-backed rather than being kept as an ever-growing local device cache. No method of storage or transmission is completely secure.

9. Children

The Services are not directed to children under 18. Contact privacy@getcaltra.com if you believe a child has provided data unlawfully.

10. Changes to this policy

We may update this policy. We will change the effective date and version and provide any notice or renewed consent required by law. Caltra records the Terms and Privacy Policy versions accepted by an account and the server timestamp of acceptance.

11. Contact

Nodal Apps
Finland
privacy@getcaltra.com