01 WHO IS RESPONSIBLE
The data controller
calorie.one is run from Denmark by Benyamin Mannan, who is the data controller for everything described below. For any privacy question or request, write to hello@calorie.one — we answer in plain English (or Danish), normally within days and always within the one month the law allows.
02 WHAT WE STORE
The complete inventory
Your account — your email and name, synced from Clerk (our login provider, who holds your credentials), plus your timezone, unit preference and daily calorie goal.
Your meals — descriptions, ingredient breakdowns and nutrition numbers, so your history and stats work. Meal photos are analyzed and immediately discarded — we never store your photos.
Your body details and weight — only if you choose to add them: sex, age, height, activity level and your weight entries. They are used for exactly one thing: computing your own targets. They are served only to you, appear in no admin screen and no statistic, and can be erased on their own (Profile → Privacy) without touching the rest of your account.
Your coach conversations — the chat history, so the coach has context, and a “what the coach remembers” note (things like allergies) which the AI may write to. You can read, edit or empty that note in your profile at any time.
Foods you add to the shared database — if you add a food, we store the name, brand, servings and nutrition figures you typed, and a link to your account so you can edit it and so it appears in your data export. It is also the one thing here that does not disappear when you delete your account: once other people have logged it, their meal history was priced from it, and deleting it would silently rewrite their records. Instead the link to you is erased, permanently and irreversibly — the food stays, you become unidentifiable. That is the anonymised outcome Art. 17 asks for, and it is why the food picker says so before you add anything. We also store which catalogue foods you have logged, which is dietary data about you and is deleted with your account, and any reports you file about a wrong entry (the report survives, without your name, because a moderator still has to act on it).
Your recipes — the name, the ingredients and the weights of anything you save as a recipe. Unlike a food you add to the shared database, a recipe is private: no other account can find it, read it or log it, and it is deleted outright when you delete your account. Nobody else depends on it, so there is nothing to weigh against erasing it.
Visit statistics — for public pages only. We store a one-way daily hash instead of your IP address, so we can count “how many readers today” without being able to tell who you are, follow you across days, or see what a logged-in user does. Pages behind login are never logged at all.
Backups — encrypted nightly database backups, kept 30 days. Deleted data disappears from them on the same schedule.
We never ask for or store national identification numbers (CPR), payment details, or your precise location.
03 WHY WE MAY
Purpose and legal basis, per piece
Running your account (email, settings, goal) — necessary for the service you signed up for. Legal basis: contract, GDPR Art. 6(1)(b).
Your food logs, coach chat and body details — what you eat and weigh is health data, which the GDPR protects extra strictly (Art. 9). We process it only with your explicit consent (Art. 9(2)(a)), which the app asks for before your first meal is logged, and separately before body details are saved. You can withdraw either at any time — body-detail consent under Profile → Privacy (which erases those fields and every weight entry on the spot), and the core consent by deleting your account, since the app cannot count calories without your food data.
Visit counting on public pages — our legitimate interest (Art. 6(1)(f)) in knowing whether anyone reads what we publish, done with hashed, day-scoped identifiers precisely so it cannot identify you.
Your right to object: because visit counting rests on legitimate interest, you have the right to object to it (Art. 21). Write to hello@calorie.one — though note the hashes make it impossible for us to find “your” rows, which is the point.
We do not use your data for advertising, sell or share it with anyone for their purposes, or use it to train AI models. What you eat is nobody’s business model.
04 WHERE IT GOES
The only two processors that see anything
Clerk (login provider, USA) holds your email and credentials and handles sign-in. OpenAI (USA) receives the text or photo of a meal when you analyze one, and — for the coach — your conversation and today’s numbers, so it can answer in context. Neither ever receives your name, email or any account identifier from us, and OpenAI’s API terms bar it from training models on your data.
Both companies are in the US, so EU law requires a valid transfer safeguard: Clerk is certified under the EU–US Data Privacy Framework (the EU Commission’s adequacy decision), and the transfer to OpenAI rests on the EU Standard Contractual Clauses built into OpenAI’s data processing agreement — alongside the fact that what we send them carries no identity to begin with.
Everything else runs on our own servers in the EU: the USDA nutrition database lookups that produce your numbers never leave the building, and our fonts are self-hosted, so opening a page sends nothing to Google or anyone else. No analytics scripts, no ad trackers, no pixels.
05 HOW LONG
Retention, in one table
| Data | Kept |
|---|---|
| Meals, weight, chat, settings | Until you delete them or your account |
| Meal photos | Not stored — analyzed and discarded |
| Photo-analysis previews | 48 hours |
| Hashed visit rows (public pages) | 90 days, then only daily totals |
| Backups | 30 days, rolling |
| Foods you added to the shared database | Indefinitely, with your name removed on account deletion |
| Which catalogue foods you have logged | Until you delete your account |
| Your recipes (private) | Until you delete them or your account |
| Consent records | Until account deletion (we must be able to prove consent) |
06 YOUR RIGHTS
Built into the product, not hidden behind an inbox
See and take everything — Profile → Privacy → “Download my data” gives you a single machine-readable JSON file with every meal, weight entry, conversation and setting (your rights of access and portability, Art. 15 and 20).
Fix anything — meals, weights, goals and the coach’s notes are all editable in place (Art. 16).
Delete everything — Profile → Danger zone. It removes your data here and your login identity at Clerk. Not a deactivation, a deletion; backups roll off within 30 days (Art. 17).
Withdraw consent as easily as you gave it (Art. 7(3)), restrict or object to processing (Art. 18, 21) — in-app where a button exists, by email where it doesn’t.
Complain — if you think we handle your data wrongly, you can complain to the Danish Data Protection Agency: Datatilsynet, Carl Jacobsens Vej 35, 2500 Valby, datatilsynet.dk. We’d appreciate the chance to fix it first.
07 COOKIES & STORAGE
Why there is no cookie banner
A banner exists to ask permission for storage that isn’t needed to run the site. We don’t have any. The complete list of what calorie.one puts in your browser:
Clerk’s session cookies — set when you log in, strictly necessary for staying logged in. Your theme choice (light/dark) and a one-time flag that remembers you dismissed the setup screen — both plain functional settings stored locally at your request, readable by no one else. That’s all. No analytics storage, no fingerprinting, nothing from third parties — so there is nothing to consent to, and no banner to click away.
08 AGE & CHANGES
The small print that isn't small
Age — calorie.one is for people aged 13 or over (the Danish threshold for consenting to online services). If you’re under 18, please involve a parent — and remember the app counts calories; it doesn’t give medical advice. See also the terms.
Security — everything travels encrypted (TLS), access to personal data is limited to what each function needs, and the design principle throughout is to hold less: hashed visitor ids, discarded photos, no identifiers to OpenAI. Should a breach ever put your data at risk, we notify Datatilsynet within 72 hours and affected users without undue delay, as Articles 33–34 require.
Changes — if this policy changes in a way that matters, the date at the top changes and logged-in users are told in the app. We will never quietly widen what we do with your data; anything new that needs consent will ask for it.