Calorie Tracker
Privacy Policy
Last updated:
This policy describes how Calorie Tracker, also known in earlier versions as ShapeUpMe: Calorie Tracker, handles information. “I,” “we” and “us” refer to the app’s developer, Anmol Kulshreshtha. Contact: anmolsoftwaredeveloper@gmail.com.
The native iOS practices below apply to the updated native app. Android and older app versions may have different measurement controls, as explained below. Using the app does not, by itself, grant permission for optional analytics.
Optional Firebase event measurement
With your permission, we use Google Analytics for Firebase (GA4) to understand where onboarding is difficult, which subscription steps succeed or fail, and whether food logging works reliably.
What the events contain
- Onboarding: screen identifiers, screen order, forward and back navigation, time spent actively viewing a screen, and bounded validation or save-failure categories.
- Subscriptions: offer loading, paywall views, selected product or package identifiers, checkout, cancellation, failure, confirmed purchase or trial outcomes, and restore results. A trial preview or purchase-button tap is not recorded as a confirmed trial.
- Food-logging reliability: the selected logging method, capture and analysis starts, completion, retries, cancellation, failure categories, processing time, review/edit actions, and whether a meal was successfully saved. Saving your first new food entry can produce a first-use milestone.
- Technical context: app and operating-system information, device information, language, timestamps, and a Firebase app-instance identifier. Google Analytics may also derive approximate location, such as country or city, from the network IP address; the app does not request GPS location for analytics. Event, onboarding-journey, screen-visit and operation identifiers help associate related actions and avoid counting duplicates.
This is identifier-based, pseudonymous information, not fully anonymous data. It can distinguish an app installation or a sequence of interactions without including your name.
What our native analytics events do not contain
We do not include your onboarding answers, body measurements, birth year, gender, dietary choices, Health records, meal contents, photographs, barcodes, voice transcripts, food descriptions, AI prompts or raw error messages in these event payloads. We use limited error categories rather than the content that caused an error. These events are not used to create advertising audiences based on nutrition, body goals or Health information.
Your measurement choice
New native iOS users enter Welcome without an analytics prompt. During “Building your starting plan,” an English-language native dialog asks “Allow usage measurement?” with Allow and Not now. Calculation, saving and the progress animation continue independently of the dialog.
Firebase Analytics collection remains disabled until Allow is successfully saved. Choosing Not now leaves it disabled and does not limit app features. For a new choice, if saving fails, collection stays off and you can retry. Previously saved choices are respected; we do not ask again simply because you relaunch the app.
For existing users who have completed onboarding but have no saved choice, the same optional dialog appears on Today. Users who resume an older draft beyond plan generation can finish normally and receive that Today prompt. Onboarding replay and ordinary previews do not request consent or generate usage events.
When you allow measurement partway through onboarding, measurement begins with the screen currently visible. We do not queue earlier interactions and upload them afterward. Consequently, our reports cannot measure your earlier onboarding activity from before that consent.
You can change your choice in Settings → Privacy → Usage measurement. Successfully saving an off choice stops optional Firebase Analytics collection, resets the local analytics identity and removes the Firebase app-instance association supplied to RevenueCat. It does not erase your diary or cancel your subscription. If a settings change cannot be saved, the app displays an error and the previously saved choice remains in effect; retry until the off choice is saved.
Withdrawal does not automatically delete information already received by service providers or purchase records needed to manage a subscription. You can contact us with an access or deletion request using the address below.
Advertising identifiers and version differences
The updated native iOS app does not request App Tracking Transparency (ATT) permission, collect the Identifier for Advertisers (IDFA), or enable Apple Ads attribution-token collection. Firebase’s collection of the Identifier for Vendors (IDFV) is also disabled. Advertising storage, advertising user data and ad personalization remain denied even if you previously authorized ATT in an older version. A Firebase app-instance identifier is still used when you allow usage measurement.
Android and older versions: earlier versions described by this policy may use the Android Advertising ID (AAID), or IDFA on iOS with ATT permission, for campaign measurement. Their own measurement settings and platform permissions apply. Updating this policy does not change the behavior of an older installed binary. The native iOS dialog and advertising-removal changes above should not be read as a claim that every older or Android version has the same implementation.
Purchases and RevenueCat
Apple handles payment for purchases in the native iOS app; Google Play handles purchases in the Android app. RevenueCat helps the app retrieve products, validate purchase status, restore purchases and determine subscription access. This involves app-user identifiers, store transaction information, product identifiers, subscription status and technical device/app information processed by the purchase SDK. The app does not receive your full payment-card details.
When native usage measurement is allowed, we associate the Firebase app-instance identifier with RevenueCat so subscription lifecycle events, such as renewals, cancellation, expiry or billing issues, may be reported through a RevenueCat-to-Firebase integration where it is enabled. This association does not mean every lifecycle event is necessarily delivered. Withdrawal requests removal of the association for future reporting; processing by RevenueCat can depend on network availability and does not recall events already sent. It does not delete essential RevenueCat or store purchase records. Subscription access and restore functionality continue to operate without optional usage measurement.
Your diary, photos and local storage
The native iOS app stores your onboarding answers, body measurements, goals, nutrition targets, diary, saved foods, exercise, preferences and subscription-access cache on your device. These are used to calculate and display your plan and tracking history. The current native app does not provide an app-account cloud diary sync service.
Food photographs and unfinished text or voice-transcript drafts can also be saved locally so you can return to a logging task. Cancelling analysis does not necessarily discard its draft. A saved meal may retain its photograph and analysis-derived ingredients and nutrition. The app does not save a standalone voice recording for the diary.
When upgrading from the earlier Flutter app, the native app can retain the original diary, preferences, photographs and recovery copies on your device to protect against migration failure. Local app data may also be included in device or computer backups, depending on your Apple settings. Local storage does not mean that a photo or description you submit for online analysis stays only on your device.
Food analysis, search and voice input
AI food and label analysis
When you request analysis, the app sends the selected food or label image and/or food description, portion information and requested output language to Google’s Gemini Developer API through Firebase AI Logic. Google processes this input to return estimated ingredients and nutrition. The app does not send your complete diary, body profile or Apple Health history with that request. An image or description may itself reveal personal information, so include only what you want analyzed.
Our Firebase project currently uses an active billing account. Under Google’s paid-service terms, submitted prompts and responses are not used to improve Google’s products. This is not a zero-retention promise: Google’s published abuse-monitoring policy describes retention of prompts, context and responses for 55 days and possible authorized human review of flagged content. Other operational records are subject to Google’s terms. See Firebase AI data governance, Gemini API terms and abuse-monitoring information.
These feature inputs are separate from Firebase Analytics events. Declining usage measurement does not prevent processing needed for analysis you request. Manual food entry remains available without submitting a photo or description to AI.
Food search and barcodes
Food search sends your search text to USDA FoodData Central. Barcode lookup sends the product’s barcode to Open Food Facts; barcode recognition from a selected image is performed on the device before the lookup. These providers receive normal network request information, including the connecting IP address. Search terms and barcodes are excluded from our analytics event payloads, but are required by the lookup provider. See USDA’s Privacy Policy and Open Food Facts’ Privacy Policy.
Voice descriptions and photos
Voice input requests microphone and Apple speech-recognition access. Depending on device, language and service availability, audio may be processed by Apple’s servers; the app does not require transcription to stay on-device. You can review the resulting text before submitting it to Google for food analysis. Apple’s handling is described in Siri, Dictation & Privacy.
The camera is used when you choose to capture a meal or label. The system photo picker gives the app the images you select, rather than blanket access to your photo library. You can manage camera, microphone and speech permissions in iOS Settings. Analytics consent does not grant any of these permissions.
Apple Health
With the access you choose to grant, the app reads workouts and active energy to display activity and calculate eligible exercise credit. Imported activity and Health record identifiers are stored locally for history, synchronization and duplicate prevention.
Separate sharing controls let the app write workouts, active energy and nutrition to Apple Health. Nutrition can include calories, protein, carbohydrates, fat, fiber and sugar. Existing food history is not automatically exported merely because you enable sharing. Updates and deletions target records owned by this app; disabling sharing does not automatically erase records already written to Health.
We do not send Health records to Firebase Analytics or Gemini food analysis, or use Health information for advertising. You can change the app’s sharing preferences in Settings → Apple Health and manage permission or previously shared records in Apple’s Health app. Health data and any Apple-managed synchronization remain subject to your Apple settings.
Widgets and notifications
To show widgets, the app writes a summary to a shared on-device container accessible to its widget extension. This can include calories, macro totals and goals, exercise and rollover credit, meal counts, weekly logging progress, time zone, widget preferences and subscription-access status. Widgets may make these summaries visible on your Home Screen or Lock Screen. Widget settings include an option to hide exact values; this changes display, not deletion of the underlying summary. You can remove widgets through iOS.
With notification permission, the native app can schedule a local reminder before a confirmed future subscription renewal or trial expiry. iOS holds and displays the reminder; the app does not need to upload your diary to send it. Reminder text may appear on your Lock Screen according to your notification settings. Permission or a reminder is not a purchase and does not start a trial.
Operational services and support
Firebase App Check uses app/device attestation and security tokens to protect backend requests. Firebase Remote Config uses installation identifiers and technical app information to supply configuration, such as feature availability and analysis settings. These services operate independently of optional Analytics and can contact Google before you make an analytics choice. Native diagnostic logs can record technical outcomes and bounded error categories.
Turning off usage measurement does not disable requested food analysis, database lookups, subscription verification or these operational services. Providers necessarily process network information to handle requests. See Firebase privacy and security and Google’s Privacy Policy.
If you contact us, we receive the email address and information you choose to include. Please avoid sending sensitive diary or Health information unless necessary for your request.
Retention and privacy requests
On your device: diary records and preferences remain until changed or removed. You can edit or delete entries using the app. Deleting a diary entry does not currently guarantee deletion of associated image files, saved-food copies, old migration data or recovery copies. The native app does not currently have a single in-app control that erases every retained local copy. Contact us for help with a complete local-data removal request. Offloading the app keeps its data; removal of device backups and Health records is managed separately through Apple’s controls.
At service providers: Analytics retention depends on the configured Google Analytics settings and any retained reporting exports; withdrawing consent or resetting an identifier does not automatically erase previously received data. Subscription records follow RevenueCat’s and the store’s retention requirements, including transaction, fraud-prevention and legal needs. AI retention is described above. We do not promise a single fixed deletion period across these different systems.
To request access, correction or deletion, or ask about retention for a specific record, email anmolsoftwaredeveloper@gmail.com. We may need information to locate records and verify your request. We cannot remotely retrieve a diary that exists only on your device. Where applicable, you may also request portability or restriction, object to processing, withdraw consent, or complain to your local data-protection authority. Some records may need to be retained for legal obligations; we will explain applicable limits when responding.
Service providers, websites and security
We use service providers to operate app features, manage subscriptions, secure requests, provide support and, with the choice described above, measure usage. Providers may process information outside your country under their applicable terms and privacy arrangements.
This privacy-policy page does not include our own analytics scripts or advertising cookies. Its host, Vercel, may process ordinary request information to serve and secure the page. Linked websites have their own privacy and cookie policies. See Vercel’s Privacy Policy.
We use reasonable measures to protect information, but no method of transmission or electronic storage is completely secure.
Children’s privacy
The current native iOS app and its AI features are intended for adults aged 18 or over; native onboarding applies an adult age check. They are not directed to children. If you believe a child has provided personal information, please contact us so we can investigate and address the request.