Privacy Policy
← Back to DashboardHow personal information is collected, used, stored and protected.
1. Who this policy applies to
This policy explains how Calorie Repay processes personal data when you create an account and use the service. This Privacy Policy explains how Calorie Repay collects, uses, stores and protects your personal information when you create an account and use the service.
Privacy contact: support@calorierepay.com.
2. Data we process
- Account information, including email address, display name, authentication status and security settings.
- Plan information, such as current weight, target weight, maintenance estimate and forecast settings.
- Food, exercise, check-in, weight-history and journal information you choose to enter.
- Progress photographs you choose to upload.
- Technical and security information needed to operate, protect and troubleshoot the service, such as timestamps, session information and limited logs.
- Your acceptance of the current Terms, Privacy Policy and Disclaimer.
3. Why we process it
We use this information to provide your account, calculate your calorie balance and forecasts, save your entries, secure the service, respond to support requests and comply with legal obligations. The main lawful bases are performance of the service requested by you, legitimate interests in operating and securing the service, and legal obligation where applicable.
4. Service providers and data sharing
Calorie Repay does not sell your personal data. Data may be processed by authorised service providers needed to operate the app, including Supabase for database, authentication and storage, and Netlify for website hosting and serverless functions. Food searches may be sent to food-data providers such as Open Food Facts or FatSecret; the search phrase should not include information that identifies you.
Information may also be disclosed where required by law, to protect users or the service, or in connection with a legitimate business transfer subject to appropriate safeguards.
5. Security and retention
Connections use HTTPS and access is restricted through authentication and database access controls. No online service can guarantee absolute security. Data is kept only for as long as reasonably needed for the purposes described, to provide your account, resolve disputes and meet legal obligations. A documented retention schedule should be adopted before public launch.
6. Your UK data-protection rights
Depending on the circumstances, you may have rights to access, correct, erase, restrict or object to processing, and to receive certain data in portable form. You can also complain to the UK Information Commissioner’s Office. Requests can be sent to the privacy contact above; identity verification may be required.
7. Security incidents
If a personal-data incident occurs, Calorie Repay will investigate, contain and assess it, keep appropriate records, notify the ICO where legally required and notify affected people where the law requires that step.
8. Changes
Material changes will be communicated in the app or by email where appropriate. The current version date is 27 July 2026.