Effective date: 6 July 2026 · Last updated: 6 July 2026
This Privacy Policy explains how kaél (“we”, “us”, or “our”) collects, uses, shares, and protects information when you use the kaél mobile application and related services (the “Service”). kaél is a nutrition, fitness, and wellness app that lets you log meals, track activity and body metrics, sync device health data, and connect with other people. Because the Service handles health and fitness information, we treat your data with particular care, as described below.
By using kaél you agree to this Policy. If you do not agree, please do not use the Service.
| Category | Examples |
|---|---|
| Account | Email address, password (stored only as a salted hash), name, username. If you sign in with Google or Apple, we receive your email and a stable account identifier from them. |
| Profile | Bio, profile and “ring” photos, city and country, and whether your account is private. |
| Body & goal data | Age, gender, height, weight, target weight, body-fat and waist measurements, activity level, goal and intensity, dietary type, allergies, dislikes, and cuisine preferences. |
| Food & activity logs | Meals (names, macros, calories, and photos), workouts, water intake, weight entries, and progress photos. |
| Social content | Posts, captions, comments, likes, follows, and 1:1 chat messages and any images you send in chat. |
| Support & reports | Messages you send to support, and any content or accounts you report or block. |
| Category | Examples |
|---|---|
| Device & technical | Device type and operating system, app version, your time zone, and IP address (used transiently for security and rate limiting). |
| Push notification token | A push token (via Expo) so we can deliver notifications, where you have enabled them. |
| Usage & diagnostics | Product-analytics events (for example, opening the app, logging a meal, or viewing the paywall) and crash/error diagnostics, used to operate and improve the Service. |
If you connect Apple Health (HealthKit) or Google Health Connect, we read the specific metrics you authorize — such as steps and active energy burned — to display and use them in the app. We only access what you grant, you can revoke access at any time in your device settings, and we do not receive data from these sources unless you connect them.
Legal bases (EEA/UK users): we process data to perform our contract with you (running the app), for our legitimate interests (security, improving the Service, preventing abuse), with your consent (health-device sync, optional notifications), and to comply with legal obligations.
To power meal recognition and to keep the community safe, images and text you submit may be sent to our AI provider (OpenAI) for processing:
These automated results (such as calorie estimates) are approximations and may be inaccurate; they are not a substitute for professional advice. We do not permit our AI provider to use your content to train their models for their own purposes under our arrangement, and we send the minimum necessary to perform the feature.
We consider your meals, body metrics, workouts, progress photos, and any device health metrics to be sensitive. For this data we commit that we:
Health data obtained from Apple Health is handled in accordance with Apple’s HealthKit requirements, and data from Health Connect in accordance with Google’s Health Connect policies.
We do not sell your personal information. We share it only as follows:
| Provider | Purpose |
|---|---|
| OpenAI | AI meal recognition and content moderation |
| MongoDB | Database and storage of your account and content |
| Cloudflare | DNS, security, and email routing |
| Resend | Sending transactional email (verification, password reset) |
| Expo | Push notification delivery |
| Apple & Google | Sign-in, in-app purchases, and (if connected) health-data sync |
| USDA FoodData Central & Open Food Facts | Nutrition and barcode lookups |
These providers are permitted to use your information only to perform services for us. Their own handling of any data is governed by their respective privacy policies.
We keep your information for as long as your account is active or as needed to provide the Service. You can delete your account at any time in Settings → Delete Account. Deletion is a soft-delete with a 30-day grace period during which your account is hidden and you can restore it by signing back in; after the grace period your personal data is permanently erased, except where we must retain limited records to comply with law, resolve disputes, or enforce our agreements.
You can download a copy of your data at any time via Settings → Export My Data.
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. You can exercise many of these directly in the app (edit profile, export data, delete account) or by contacting us.
EEA/UK (GDPR): you have the rights above and may lodge a complaint with your local data protection authority.
California (CCPA/CPRA): you have the right to know, delete, correct, and opt out of the “sale” or “sharing” of personal information. We do not sell or share your personal information as those terms are defined, and we do not use sensitive personal information for purposes other than providing the Service. We will not discriminate against you for exercising your rights.
To make a request, email support@kaelapp.com. We may need to verify your identity before acting.
We protect your information with technical and organizational measures, including encrypted transport (HTTPS), hashed passwords (bcrypt), secure token storage on your device, session-revocation controls, and automated content screening. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we work continually to protect your data.
kaél is not directed to children under 13, and we do not knowingly collect personal information from them. If you are in the EEA/UK, you must be at least 16 (or the minimum age of digital consent in your country). If you believe a child has provided us personal information, contact us and we will delete it.
We may process and store information in countries other than where you live, including where our service providers operate. Where required, we use appropriate safeguards (such as standard contractual clauses) for cross-border transfers.
We may update this Policy from time to time. If we make material changes, we will update the “Last updated” date and, where appropriate, notify you in the app or by email. Your continued use of the Service after changes take effect constitutes acceptance.
Questions or requests about this Policy or your data: