Privacy Policy
This is an English courtesy translation. In case of discrepancies, the German source version prevails to the extent permitted by law.
Last updated: 2026-09-02 · This policy applies to the CalorieMeister app and the caloriemeister.app website.
1. Controller
Controller within the meaning of the GDPR:
Oliver Demuth, sole proprietor
Am Kirchenberg 9, 2132 Hörersdorf, Austria
Email: datenschutz@caloriemeister.app · further details in the Legal Notice.
2. Data We Process
When you use CalorieMeister, the following data is processed:
- Account and profile data: email address, display name, authentication provider (Apple/Google), account ID, date of birth, sex, height, weight, activity level, goal, target weight, and selected pace for account management, age verification, and calculation of your plan.
- Health and tracking data: meals, nutritional values, meal photos, workouts, water, weight, fasting days, and progress values derived from them to provide the App features.
- Streak data: real activity days, confirmed fasting days, and automatically earned or used Streak protection - to calculate your series across devices.
- Device/usage data: app version, operating system, technical error data, and pseudonymous event identifiers for security, troubleshooting, and product improvement.
- Usage analytics: pseudonymized event logs (e.g., onboarding steps, scan results, feature views, subscription status) without plain-text content (no photo data, no meal descriptions) to improve product quality and measure conversion.
- Website and contact: When you visit the website, Firebase Hosting processes technical access data, particularly your IP address, time of access, requested URL or path, browser and operating system or user agent, referrer (if transmitted), HTTP status, and technical connection data. This is used to deliver the website securely and to detect abuse, errors, and attacks. When you use the contact form, we process your name, email address, topic, message, language, and time of receipt. This also includes any information you voluntarily provide in support, affiliate, or partner inquiries. Voluntary in-app feedback is stored for handling and product improvement.
3. AI and Voice Input
CalorieMeister uses a secure Google Cloud AI service for automatic meal and workout analyses. Only after your explicit consent and only when you request an analysis do we transmit the photo you selected or captured, your typed input or speech transcript, and optional notes and corrections. Your goal is used for relevant analysis context and your current weight is used where required for workout analysis. Your name, email address, date of birth, height, gender, activity level, and raw audio are not transmitted to the AI service.
Meal photos are also stored locally on your device and in a private storage area assigned to your account; they are not publicly accessible. For voice input, the operating system's speech-recognition service (Apple or Google) converts speech into text. CalorieMeister does not store a raw audio file; the recognized text is analyzed like regular text input.
You can continue without AI and enter meals manually. You can withdraw or grant AI consent again at any time under “Profile → App Settings → AI analyses”. After withdrawal, no new input is transmitted to Google Cloud. Do not use these features to submit information about other people.
4. Streak and Streak Protection
To calculate your Streak across devices, CalorieMeister records the local calendar days on which you actually tracked or confirmed a full fasting day. After seven real activity days, Streak protection may be earned; up to two protections are stored and used automatically for a short gap.
Backdated entries do not close a past Streak gap. Protection inventory, progress, and protected days are stored server-side so they remain consistent after reinstalling or using multiple devices.
5. Legal Bases
- Performance of a contract pursuant to Art. 6(1)(b) GDPR for account, plan, tracking, Premium, and Streak functionality.
- Legitimate interest pursuant to Art. 6(1)(f) GDPR for operating and securely delivering the website, fraud prevention, IT security, and access and error analysis.
- Consent pursuant to Art. 6(1)(a) GDPR in conjunction with explicit consent pursuant to Art. 9(2)(a) GDPR for the processing of health data (nutrition, body data, weight, activity, water, and fasting). New users provide it separately and actively after the introductory pages and immediately before the first such data entry; existing accounts provide it before the first data retrieval.
- Consent pursuant to Art. 6(1)(a) GDPR for optional features such as push notifications.
- Separate consent pursuant to Art. 6(1)(a) GDPR and, where goal or weight constitutes health data, Art. 9(2)(a) GDPR for transmitting the data listed in Section 3 to the Google Cloud AI service. No third-party AI analysis takes place without this consent.
- Performance of a contract or pre-contractual steps pursuant to Art. 6(1)(b) GDPR for support, affiliate, and partner inquiries; where necessary, our legitimate interest pursuant to Art. 6(1)(f) GDPR in efficient handling and abuse prevention also applies.
6. Retention Period
Account and tracking data is generally stored while your account is active. When an account is deleted, actively held account and tracking data is normally deleted immediately. Technical backups may continue to exist for a limited period of up to 30 days and are not restored to active operation. Data may be retained beyond that point only for as long and to the extent required by statutory retention duties or to establish, exercise, or defend legal claims. It is then erased or anonymized. Aggregated, anonymized reporting data may be retained for longer.
Technical website access and log data is stored only for as long as required for operation, security, abuse prevention, and error analysis, and is then erased or anonymized. Contact and application inquiries are generally erased within twelve months after they have been fully handled, unless statutory retention or evidentiary obligations require longer storage.
7. Recipients and Service Providers
Depending on the feature you use, the following providers receive data. Depending on the service, they act as processors or independent controllers:
- Supabase Inc. (hosting in the EU / Frankfurt; company based in the USA) - database, authentication, storage, edge functions.
- Apple Inc. / Google LLC (USA) - in-app purchases, native sign-in, and operating-system speech recognition.
- RevenueCat, Inc. (USA) - processing and management of Premium subscriptions (pseudonymous user identifier and purchase/subscription data; no email, no advertising identifier, no health or nutrition data).
- Google Cloud EMEA Limited (Google), 70 Sir John Rogerson's Quay, Dublin 2, Ireland - requested analysis of text, transcribed speech, photos, notes, and, where required, goal and weight (see Section 3).
- Google Workspace (Google LLC) - email communication for support, privacy, affiliate, and partner inquiries.
- Sentry Inc. (USA) - error/crash reports (pseudonymous account ID, no email/names, no meal content); only if enabled.
- Firebase Hosting (Google LLC) - hosting and secure delivery of this website, including the technical access and log data required for those purposes.
Insofar as personal data is transferred to the USA, this is done on the basis of the EU Standard Contractual Clauses or an adequacy decision where applicable. Only data required for the respective purpose is transferred.
Purchases and subscription management (RevenueCat)
To process and manage our Premium subscriptions we use RevenueCat, Inc., 1032 E Brandon Blvd #3003, Brandon, FL 33511, USA.
Data processed: a pseudonymous user identifier (the random UUID of your CalorieMeister account), purchase and receipt data provided by the App Store or Google Play, your subscription status (product, purchase date, expiry, cancellation, billing issues, refunds) and technical information about your device, operating system, app version and store country.
We do not send RevenueCat your email address, any advertising identifier (IDFA/AAID), or any health or nutrition data - neither your meals nor your weight or calories.
Purpose: verifying and managing your subscription, unlocking Premium features, detecting cancellations, billing issues and refunds, restoring purchases, and preventing abuse.
Legal basis: Art. 6(1)(b) GDPR (performance of the subscription contract); for abuse prevention additionally Art. 6(1)(f) GDPR (legitimate interest in a functioning, abuse-resistant purchase flow).
International transfer: RevenueCat processes data in the USA. The transfer is based on the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR) as part of a data processing agreement, supplemented by data minimisation through pseudonymisation: RevenueCat only receives a random identifier, no clear-text personal data. Access by US authorities cannot be entirely ruled out despite these measures.
Retention and deletion: we store your subscription status for as long as your account exists. If you delete your CalorieMeister account, your subscription and purchase data are deleted on our side; a technical event log remains without any personal reference (event ID, type and timestamp only) so that repeatedly delivered purchase notifications are not processed twice.
Your contractual partner for the purchase is Apple or Google - that is where the invoice and payment record are created, and their retention periods apply. We receive payout reports from Apple and Google, not individual personal receipts. Your purchase history at the App Store or Google Play is not affected by deleting your account - you need to cancel an active subscription there yourself.
More information: RevenueCat privacy policy.
8. Cookies
Our website uses no tracking or marketing cookies and no web analytics tool. No personal profiles are created for advertising purposes.
Technically necessary cookies are set exclusively in the logged-in area (e.g., admin/partner) to maintain the login session (Supabase authentication). These are required for operation (Section 165(3) Austrian TKG 2021) and do not require consent. No cookies are used within the app itself.
No non-essential cookies or comparable browser storage are used on the public pages. The contact and affiliate forms connect to Supabase only when they are intentionally submitted and do not persist an authentication session. A consent or cookie banner is therefore not currently required. If web analytics, advertising pixels, social-media plugins, or other optional storage are added in the future, they will be activated only after valid consent and this policy will be updated in advance.
9. Your Rights
Under the GDPR, you have the right to access, rectification, erasure, restriction, data portability, and objection. You may also lodge a complaint with the Austrian Data Protection Authority or another competent supervisory authority. Please send requests to datenschutz@caloriemeister.app.
You can request a data export using the privacy address above. You can withdraw consent with future effect; this does not affect the lawfulness of processing carried out before withdrawal. You can disable the separate AI consent under “Profile → App Settings → AI analyses”; this prevents any further transmission to Google Cloud. As CalorieMeister cannot function as a personal tracker without processing the health data you enter, withdrawal in the App is handled through “Delete account & data”. This also deletes your account and its associated health data.
Step-by-step instructions and an alternative request method are available on our account and data deletion page.
10. Required Data and Automated Decisions
Information marked as required for registration, age verification, and plan calculation is necessary to use the App. Without it, CalorieMeister cannot provide a personal plan. We do not make solely automated decisions that produce legal or similarly significant effects within the meaning of Art. 22 GDPR. AI output consists of estimates that you can review and correct.
11. Changes
This privacy policy may be updated to reflect changes in the legal situation or the scope of features. The current version is always available here.