Privacy Policy

Effective date: July 17, 2026

Summary

CalFitness helps you track nutrition, meals and fitness. This Privacy Policy explains what information we collect, why we collect it, how we use it, and your choices. It applies to the CalFitness mobile app, the CalFitness website, and the CalFitness integration that lets AI assistants such as ChatGPT and Claude create workout routines and meal plans in your account.

Data we collect

We collect the minimum data needed to provide and improve the service. This may include:

How we use your data

We use data to operate and improve the service and respond to support requests. Where required, we aggregate or de-identify data for analytics and product development.

Connected AI assistants

CalFitness can be connected to third-party AI assistants. This is entirely optional and off unless you set it up. There are two ways to connect:

A connected assistant acts on your behalf, and is limited to the following:

It canIt cannot
Search the CalFitness exercise and food catalogues (this is reference data, not your personal data).

Read your own workout routines and meal plans — their names, the exercises or foods in them, and the sets or portions you planned.

Create workout routines, workout programs and meal plans in your account.
Read your food diary, weight history, body measurements, profile or account settings.

Delete or modify anything that already exists in your account.

Read or send messages, or access data belonging to any other user.

What the AI provider sees. When you use a connected assistant, the content of that conversation — including any routine or meal-plan data returned to it by CalFitness — is processed by that assistant's provider (for example OpenAI or Anthropic) under their own privacy policy, not ours. We do not control their retention or model-training practices. Please review their policy before connecting.

Credentials. API keys and OAuth tokens are stored only as a SHA-256 hash. We cannot recover or display a credential after it is created, which is why a new key is shown to you exactly once.

Disconnecting. API keys can be revoked at any time in Settings → Integrations; revocation takes effect immediately. To end an OAuth connection, disconnect or remove the CalFitness app from within the assistant that you connected, which revokes the token. If you cannot do that, or want to be certain a connection is gone, contact us at the address below and we will revoke it for you.

Third parties and integrations

We use third-party services to host and process data when you use account features or cloud sync. These include Supabase as our backend and database provider, Oracle Cloud Infrastructure which hosts the integration server, and third-party analytics and crash-reporting providers. Where you connect an AI assistant, that assistant's provider also processes data, as described above.

Sharing and disclosures

We do not sell your personal information. We may share data with service providers who perform services on our behalf (hosting, analytics, crash reporting). We may disclose information in response to legal requests or to protect rights and safety.

Security

We take reasonable administrative, technical, and physical safeguards to protect data. Account data is isolated per user at the database level, and integration credentials are stored only as hashes. However, no system is completely secure — please take steps to protect access to your accounts and devices, and only connect AI assistants you trust.

Children

Our apps are not intended for children under 13. We do not knowingly collect information from children under 13. If you believe we have collected such information, please contact us and we will take steps to delete it.

Your choices

You can:

Data retention & international transfers

We retain data as needed to provide the service and comply with legal obligations. Revoked integration credentials are retained as hashes so that a revoked credential is never silently reissued or reused. Data stored with our backend provider may be processed and stored in locations outside your country.

Changes to this policy

We may update this policy occasionally. We'll post the updated policy at this URL and update the effective date.

Contact

For privacy questions or requests, contact support@calfitness.app.