Calvin needs no account, and does not sell, share, or advertise against your data. Your food log lives on your phone. Some features send specific data to Calvin's server, and this policy sets out exactly which.
What stays on your phone
Everything you log is stored on your device: food entries, calories, macros, weight, goals, recipes, your history, and the name you give at setup. Calvin requires no account — the optional Apple or Google sign-in is described below — and keeps no cloud copy of your log. Deleting the app deletes this data. You can export it as CSV at any time from Settings.
Calvin's server
Calvin uses a server (a Google Cloud Run service) for a few things: AI photo scanning, Smart Log, food and barcode lookups, verifying a Calvin Plus subscription, the optional sign-in, and the optional Google Health connection. Everything below describes what is sent and what is kept.
AI photo scanning (Calvin Plus)
When you scan a meal photo with Calvin Plus, the photo is sent to Calvin's server and passed to Google's Gemini API, which returns the foods it recognizes. Google processes the image under its API terms.
The photo itself and the note are not stored. Calvin keeps a one-way hash made from the photo, note, and other request context, alongside the resulting food list for 24 hours, so retrying the same request does not cost another scan. The hash cannot be turned back into your picture or note.
A few other things travel with the photo, so the estimate matches what you actually eat rather than a generic plate:
| Sent with the photo | Reaches Google? |
|---|---|
| Any note you type about the photo | Yes |
| The names of up to 30 of your most recently used saved foods, so a recognized item can be matched to your own product | Yes |
| The nutrition figures for those saved foods | No — they stop at Calvin's server, which substitutes your own numbers into the result. Google never sees them, and never gets to change them |
| Your dietary pattern and your avoided-foods list, if you have set them under How you eat | Yes |
The dietary pattern is used only to break a tie between two foods the photo could equally be. The avoided-foods list is explicitly prevented from changing what the scan reports; it is read afterwards, to flag avoided foods in what was already identified. Calvin is not an allergen test, and the app says so at the point it shows a flag.
The photo, note, saved-food names and nutrition figures, dietary pattern, and avoided-foods list are used for the request and are not stored in their original form. Only the 24-hour request hash and resulting food list described above outlive the scan. Nothing else from your log is sent for this feature.
Smart Log (Calvin Plus)
When you type a meal into Smart Log, the description is sent to Calvin's server and to Google's Gemini API so it can be turned into a structured food estimate.
The request can also include the names of up to 30 recently used saved foods, the names of foods on your kitchen shelf, and — if you set them — your dietary pattern and avoided-foods list. Those names and preferences reach Google. Nutrition figures for your saved foods stop at Calvin's server, which substitutes your own figures into the result after Google responds.
Calvin does not store the original description or that context. For 24 hours it keeps a one-way hash made from the description and context, alongside the structured food estimate, so retrying the same request does not consume another estimate. The estimate itself can contain food names derived from what you typed.
Daily Insights (Calvin Plus)
Daily Insights are off by default. If you turn them on in Settings, Calvin writes a short summary of the previous completed day's movement, sleep, and heart readings, comparing them against your own recent range. This is computed entirely on your device; nothing is sent to Calvin's server or to Google for this feature. An earlier version of this policy described Daily Insights as calling Google Gemini; that was true until 2026-08-19, when the feature was rebuilt to run locally and the underlying server call was removed.
Food and barcode lookups
Searching for a food or scanning a barcode sends the search text or the barcode number to Calvin's server, which looks it up in a public USDA product database, and to Open Food Facts if nothing is found. These requests carry only the search text or barcode.
Subscription and abuse limits
To confirm a Calvin Plus subscription and stop the AI endpoints being abused, Calvin sends Apple's App Attest device identifier and your App Store transaction identifier with each AI estimate. Calvin stores separate daily photo and Smart Log counts against these identifiers. They identify a device and a subscription, not you by name.
Apple Health
If you connect Apple Health, Calvin reads activity, energy, weight, sleep, and heart data to show trends and import weigh-ins. It stays on your device; Daily Insights, described above, reads the same data but also stays on your device rather than sending it anywhere.
Google Health
These connections are optional and off unless you turn them on. They work differently from Apple Health, because the data comes from the provider's servers rather than from your phone.
If you connect one, Calvin's server stores:
| Data | Kept |
|---|---|
| Access and refresh tokens for the provider you connected | Until you disconnect |
| Daily steps, active calories, distance, and weight (Google Health) | Until you disconnect |
This data is stored against your device identifier, not your name or email.
Disconnecting in Settings erases all of it. The stored tokens are deleted, every synced activity, weight, and workout row for your device is deleted, and where the provider supports it Calvin asks them to revoke the connection so the grant cannot be reused. Rows left behind by a connection that can no longer be reached are deleted on a schedule. Nothing is retained for later.
Optional sign-in
You can sign in with Apple or Google during onboarding, or later from Settings. This is optional and skippable, and Calvin works fully without it. If you do, Calvin's server stores only the provider's opaque per-user identifier linked to your device identifier — not your name or email. Signing in does not upload your stored food log; Smart Log sends only the information described in its section when you choose to use it.
To be precise about what it is for: the link exists so that a future restore has something to recognise you by. It is not itself a backup, and there is no cloud copy of your log to restore from today. Your log lives on your phone.
You can delete your Calvin account at any time from Settings → Delete Account, without contacting us. Deleting it erases the sign-in link and any connected Google Health tokens from Calvin's server. Your food log, weight history and goals stay on your phone, because they were never uploaded. Deleting your account does not cancel a Calvin Plus subscription — that is billed by Apple through your Apple ID and is managed in the App Store.
Purchases
Calvin Plus subscriptions are processed entirely by Apple through the App Store. Calvin never sees your payment details.
Analytics and advertising
Calvin shows no advertising and does not use third-party advertising SDKs, third-party trackers, or data brokers. Calvin sends Apple's AdServices attribution token to Calvin's server to measure acquisition. Calvin uses it to record whether an install came from an Apple Ads campaign, including campaign, ad group, keyword and country dimensions, and to associate later Calvin Plus transactions with that install. This data is pseudonymous, retained for up to 13 months, and removed when you delete the associated Calvin data. Apple handles the ad auction and its own advertising records. Calvin also records aggregate daily AI usage and cost totals that are not tied to individual users.
Optional app-usage sharing
You can choose “Share app usage to improve Calvin” in Settings. Sharing is off by default. If you opt in, Calvin can send limited app-usage events to its own server: active days, setup completion, the first saved meal, subscription-screen views, and whether photo or Smart Log estimates succeed. Events include a random installation identifier, the app version and build, an event time stored only as a calendar date, and fixed categories. Apple’s App Attest authenticates the device that sends them.
These events do not include your food entries, photos, search text, calories, weight, health readings, goals, name, or email. The pseudonymous records are kept for up to 13 months. Product-usage events are not joined to advertising, purchase, or account records. No third-party analytics SDK receives them.
Turning sharing off stops new collection, clears queued events on your device, and requests deletion of earlier shared usage. If you are offline, Calvin retries deletion when it can connect again, even if you later turn sharing back on. A new opt-in uses a new usage-sharing identifier. Deleting your Calvin account also requests deletion of the associated usage records. Turning sharing off does not change the separate Apple Ads acquisition measurement described above.
Diagnostics
Calvin uses Apple's on-device MetricKit for crash and performance diagnostics. These reports are handled by Apple's standard, opt-in mechanisms. Calvin operates no collection service of its own.
Age
Calvin is for people aged 13 and over. It is not directed at children under 13, and Calvin does not knowingly collect anything from them. If you believe a child under 13 has used Calvin, email the address below and anything held for that device will be deleted.
If you are between 13 and 18, some places require a parent or guardian to agree on your behalf before you use a service like this — please check with them first.
Calorie tracking can be harder on teenagers than on adults, so Calvin treats them differently on purpose: under 18, the daily calorie floor is raised to the estimated needs of someone still growing rather than the adult minimum, and the only weight-change pace offered is the gentlest one. These are limits on what the app will suggest, not settings you can turn off.
Calvin is not medical advice
Calvin is a food and activity log. It is not a medical device, and it does not diagnose, treat, cure, or prevent anything. Calorie targets, maintenance figures, weight projections, AI photo estimates, and anything Calvin says about a trend are estimates, produced by general-purpose formulas and models that know nothing about you beyond what you entered.
Do not use Calvin to make a medical decision. Talk to a doctor or a registered dietitian before starting a diet, especially if you are pregnant or breastfeeding, are managing a condition such as diabetes or an eating disorder, or take medication affected by what you eat.
Calvin is not an allergen test. The avoided-foods flag reads a list you wrote against foods the app thinks it recognized; it can miss an ingredient entirely, and it should never be the thing standing between you and an allergic reaction.
If tracking has stopped feeling healthy, NEDA's free screening tool is a good place to start. The same link is in the app, under Settings.
Who is responsible for this data
Calvin is made by Kevin Estrada, who is the data controller for the small amount of data described above. The way to reach him about any of it is [email protected].
Where your data goes
Calvin's server is the Google Cloud Run service described above, so Google Cloud and Google Gemini process requests on Calvin's behalf. Both may handle the request in the United States, including for people in the UK and the EU. Apple handles subscriptions, and Open Food Facts answers a lookup when the USDA database has no match.
Nothing is sold, and Calvin does not share your data with advertisers or data brokers. The limited service data described above may be processed by Calvin's hosting and service providers, including the Apple Ads attribution response and Apple App Store subscription records.
Your rights
Deleting the app removes everything stored on your device. Calvin's server holds only the limited data described above: connected-service data, device and subscription counters, optional sign-in links, short-lived AI request hashes and results, Apple Ads acquisition measurement, and app-usage events if you opted in. Disconnecting erases connected-service data, and AI caches expire after 24 hours. If you want anything else removed, or want confirmation that it is gone, email the address below.
Depending on where you live — including anywhere in the UK or the EU, and in several US states — you also have the right to ask what is held about you, to have it corrected or deleted, to receive a copy of it, and to object to how it is used. Ask at the address below and you will get an answer. There is no charge, and asking will not change how the app works for you.
If you are in the UK or the EU and think this has been handled badly, you can complain to your national data protection authority. You are not required to raise it here first, though it is usually faster.
Contact
Questions? Email [email protected].
Effective 9 September 2026. Updated to describe Apple Ads attribution and optional app-usage sharing, including retention and deletion. If this policy changes, the updated version will be posted at this address.