PikCal · Legal
Privacy Policy
This Privacy Policy describes how PikCal (“we”, “us”) collects, uses, stores, and shares information when you use the PikCal applications on iOS and Android (the “Service”). By using the Service you agree to this Policy. Our Terms of Use govern use of the Service. Questions: support@pikcal.app.
1. Summary
We collect the information needed to operate a nutrition tracker: your account, the meals you log, and the body and preference data you enter. We do not sell personal information.
A meal photograph or typed description is sent to OpenRouter, which routes it to Google and/or OpenAI models, only after you tap Allow in the app. Height, weight, age, calories and dates are not sent to those models when we write your plan. You may export or delete your account from Settings.
2. Information we collect
2.1 Account
Email address obtained through Sign in with Apple or Google Sign-In, used to identify your account and synchronise data.
2.2 Body metrics
Height, weight, age and sex, used on the device to calculate calorie and macro targets. These figures are stored on your signed-in account. They are not sent to the models that write plan copy.
2.3 Fitness profile
Activity level, weight goal, pace, diet style, and the qualitative answers you provide during onboarding.
2.4 Meals
Photographs you scan, typed descriptions, barcode lookups, identified foods, portions, calories and macros, and later corrections.
2.5 Preferences
Language, units of measurement, appearance, and portion display.
2.6 Device
Device model, operating system version and application version, for crash reports and support. We do not include meal content in those reports.
3. Artificial intelligence
Scanning a plate, a nutrition label, or a typed description uses cloud-hosted models. Nothing is sent until you allow it in the application (Allow / Not now). You may change this later in Settings.
When you allow analysis:
- Only the cropped photograph, or the text you typed, is uploaded.
- OpenRouter routes the request to Google and/or OpenAI models.
- Estimates of foods, portions, calories and macros are saved to your account.
- The photograph is stored so you can review and edit the meal later.
We do not sell this data. We share it with the processors listed in section 8 so the feature can operate, and only after in-app Allow. Model providers process inputs under their own privacy policies. Some providers may use inputs to improve their models. We do not train our own models on your meals. We do not send weight, height, age, calories or dates to those models.
Barcode lookups for packaged foods use Open Food Facts and similar public catalogues. That path does not send a meal photograph to the AI models.
4. Your nutrition plan
Calorie and macro targets are calculated on your device from the body figures you entered. If you allow plan copy, qualitative onboarding answers (diet style, obstacles, what already works) may be sent through OpenRouter to Google and OpenAI so the application can write the wording of the plan. The model is not shown a number and is instructed not to write one. The device substitutes the real figures locally.
Qualitative plan sentences may be stored in a shared, de-identified cache so the same wording can be reused. That cache is not keyed to your account. Deleting your account does not wipe every cached sentence.
5. Health data
Health integrations are optional and off until you connect them.
5.1 Apple Health (iOS)
If you connect Apple Health, we may read weight and active calories, and write logged nutrition to HealthKit. You choose the data types. You may revoke access in Apple Health.
5.2 Health Connect (Android)
Health Connect is the Android analogue of Apple Health. We do not use Google Fit. Reads of today’s steps, active calories and latest weight stay on the device and are not uploaded to PikCal servers or sent to analytics. If “Sync meals” is on, we write a nutrition record for each saved meal. Disconnecting stops further writes.
Health numbers used to compute your plan stay on the device. They are not sent to OpenRouter, Google or OpenAI.
6. Analytics and crash reporting
6.1 PostHog
We record product events (for example meal logged, edited or deleted, screens viewed, application opened). We use an anonymous identifier, then your PikCal user identifier after sign-in. We do not send email, meal photographs or ingredient lists. Session replay is off. You may opt out in Settings under usage statistics.
6.2 Firebase Crashlytics
When the application crashes we collect a stack trace, application state, device model, operating system and locale. We do not put meal photographs or email in crash reports. On Android we never attach your user identifier to Crashlytics.
7. Notifications
Meal reminders are scheduled on your device and do not require our servers.
On iOS, optional remote notifications (tips and product updates) may use Firebase Cloud Messaging. We then store a device token — not your email — and delete it when you turn notifications off or delete the account. Android does not currently send remote push notifications.
8. Service providers
We use the following processors. Each name links to that provider’s privacy policy.
| Provider | Purpose |
|---|---|
| Supabase | Database, authentication and storage |
| OpenRouter | Routing of AI requests |
| Sign-In, Gemini models, Google Play | |
| OpenAI | Plan-copy models |
| Apple | Sign-In, Health, App Store billing |
| RevenueCat | Subscriptions |
| Firebase | Crash reports; iOS push |
| PostHog | Product analytics |
| Open Food Facts | Barcode catalogue |
9. Your rights
You may access meals, goals and profile data in the application. You may correct any meal, portion or goal at any time. You may export a JSON file of what the application holds locally via Settings → Export my data. You may delete your account via Settings → Delete account.
10. Additional information for European users (GDPR)
10.1 Legal bases
We process personal data on the following bases: performance of a contract, for the core tracker; consent, for AI analysis, plan copy, analytics and optional notifications; and legitimate interests, for security and fraud prevention.
10.2 International transfers
Some processors (including OpenRouter, Google, OpenAI, PostHog and Firebase) may process data in the United States. Transfers rely on the EU–US Data Privacy Framework where applicable, and on Standard Contractual Clauses.
10.3 Retention
Account data is kept while the account is open. Crash logs are kept for about 90 days. Analytics data is kept for about 12 months. After deletion, personal data is removed from active systems promptly and from backups within 30 days.
10.4 Requests
You may request access, rectification, erasure, portability, restriction, or object to processing, and you may withdraw consent, by writing to support@pikcal.app. You may also lodge a complaint with your local supervisory authority.
11. Account deletion
Settings → Delete account permanently removes: your profile and email; meal scans, food entries and stored photographs; goals, preferences and onboarding answers tied to you; push tokens and analytics associations; and the authentication account. Apple Sign-In tokens are revoked.
Store purchases remain with Apple or Google; we cannot erase a store receipt. The de-identified plan-copy cache is not wiped per user. Deletion is irreversible.
12. Children
The Service is intended for persons 13 years of age and older. We do not knowingly collect personal information from children under 13. If you believe we have, write to support@pikcal.app and we will delete it.
13. Changes
We may revise this Policy as the Service changes. Material changes will be flagged in the application. The date at the top is the date of the latest revision.
14. Contact
PikCal. Email: support@pikcal.app.