Privacy Policy
Last updated 22 September 2026
kcalready holds what you tell it about your body and what you eat. That is personal, and some of it counts as health data, so this page sets out plainly what is collected, where it goes, how long it stays and how to get it back or get rid of it. You can export everything or delete your account outright from Settings, at any time, without asking anyone.
1. Who is responsible for your data
kcalready is run by Vitor Margis, an individual based in the Netherlands, acting as the data controller. There is no company behind it.
For anything in this policy — a question, a request, or a complaint — write to vitor.margis@gmail.com. A reply should come within 30 days, which is the limit both the GDPR and the LGPD set.
This policy is written to satisfy both the EU/UK General Data Protection Regulation and the Brazilian Lei Geral de Proteção de Dados. Where the two differ, whichever gives you more is what applies.
2. What is collected
Only what the app needs to do its job. There is no tracking pixel, no advertising network and no data broker involved.
- Account: your email address, the name you sign up with, and — if you set one — a password, which is stored only as a bcrypt hash and can never be read back. Signing in with Google supplies your email and name from your Google profile; no password is created.
- Body stats: sex, age, height and weight, your training load, your goal and the rate you are aiming for. These drive the calorie and macro maths and nothing else.
- Meals: what you logged, the day and meal slot, the per-food grams and macros, any note you typed, and a small photo thumbnail of roughly 192 pixels when you logged from a photo.
- Preferences: theme, units, language and your time zone, so that "today" means your today rather than the server’s.
- Technical: your browser sends an IP address and a user-agent with every request, as browsers do. These are used to serve the page and are not stored in the database alongside your account.
3. Health data, and why consent matters here
Your weight, height, sex, age and dietary intake are health data. The GDPR calls this a special category (Article 9) and the LGPD calls it sensitive (Article 11), and both require a stronger basis than ordinary data.
That basis is your explicit consent, given when you enter these details. You are never required to enter them: the app works as a plain food log without them, and the only thing you lose is the calculated targets.
You can withdraw that consent at any time by clearing the fields or deleting your account. Withdrawing does not undo processing that already happened, which is the standard position under both laws.
4. Why each thing is processed, and on what legal basis
- To run your account and show you your own data — because it is necessary to perform the contract between us (GDPR Art. 6(1)(b); LGPD Art. 7(V)).
- To calculate your targets and estimate your meals — on your explicit consent, because health data is involved (GDPR Art. 6(1)(a) and 9(2)(a); LGPD Art. 11(I)).
- To send you a sign-in link or a password reset — necessary to perform the contract, and to keep the account secure.
- To keep the service working, secure and free of abuse — our legitimate interest in a service that stays up and is not attacked (GDPR Art. 6(1)(f); LGPD Art. 7(IX)).
- To take payment, if you are on a paid plan — necessary to perform the contract, and to meet the tax and accounting law that obliges us to keep invoices.
5. Your photos, and what the AI sees
When you ask for an estimate, the photo is reduced to at most 1024 pixels in your own browser and sent, together with any note you typed and your local time, to more than one AI provider — currently OpenAI, Anthropic and Google. Each reads the same photo in turn and returns the foods it can identify with estimated weights and macros, and those readings are averaged. Which providers are used can change; this section is updated when it does. Nothing is saved at that point — you see the estimate first, and it reaches the database only when you press to log it.
The full-size photo is never stored. What is kept with a logged meal is a separate thumbnail of roughly 192 pixels, made in your browser. There is no photo storage bucket and no original to recover.
Under each provider’s API terms, content sent through the API is not used to train their models, and each states that it retains content for a limited period for abuse monitoring before deleting it. We do not control that retention; if it concerns you, log your meals by hand instead, which sends nothing to any of them at all.
The optional plan review is separate and goes to OpenAI alone: your stats and targets are sent as numbers, with no name or email attached.
6. Who else handles it
The service runs on other companies’ infrastructure. Each is bound by a data processing agreement and may only act on instructions.
- Supabase — the database holding your account, profile and meals.
- Vercel — hosting, and Vercel Analytics and Speed Insights for page-view counts, counts of a few in-app actions, and page-load timings. Both are cookieless and do not profile individuals.
- OpenAI — one of the readings behind a meal estimate, and the plan review, as described above.
- Anthropic — one of the readings behind a meal estimate, as described above. Nothing else is sent to them.
- Resend — delivery of sign-in and password-reset emails.
- Google — one of the readings behind a meal estimate, as described above; and, separately, confirming who you are if you choose to sign in with Google.
- Gumroad — payment for a membership, if you take one. Gumroad is the merchant of record: it sells the membership, takes the payment and issues the receipt. Card numbers are handled entirely by them and never reach our servers; all we ever hold is a licence key and whether it is currently valid.
Some of these are in the United States. Transfers out of the EEA rely on the European Commission’s Standard Contractual Clauses, and transfers out of Brazil rely on the equivalent mechanism under LGPD Article 33.
Your data is never sold, rented or traded. It would be handed to a court or a regulator only where the law actually compels it.
7. How long it is kept
Your account and everything in it is kept for as long as the account exists. There is no automatic expiry, because a food log is only useful as a history.
Deleting your account removes your profile and every meal immediately and permanently, then removes the account itself. This is not a soft delete and there is no recovery window — export first if you want a copy.
Two things outlive the account, and only because the law requires it: invoices for any payment, kept for the period your tax authority sets, and server logs, which roll over on their own within a short period.
8. Your rights
Under both the GDPR and the LGPD you can:
- See what is held about you, and get a copy of it.
- Correct anything wrong — every field in the app is editable by you directly.
- Delete it all.
- Take it elsewhere, in a machine-readable format.
- Object to processing based on legitimate interests, or restrict it while a dispute is resolved.
- Withdraw consent for the health data, at any time.
- Ask to be told who the data has been shared with — which is the list in section 6.
- Be free of decisions made purely by automatic means with a legal or similarly significant effect. A calorie estimate is not such a decision, and no such decision is made here.
The first, second, third and fourth of those need no request: Settings → Account has an export button that hands you everything as one JSON file, and a delete button that removes the account for good. For anything else, write to vitor.margis@gmail.com.
No fee is charged, and you will not be asked why.
9. Cookies and browser storage
kcalready sets one cookie: the session cookie that keeps you signed in. It is strictly necessary — without it there is no way to know it is you — so your consent is not asked for it, and under the EU ePrivacy rules none is required.
Your browser also holds two small things of its own: the theme you picked, so the page does not flash the wrong colours before it loads, and a record of the cookie choice you made, so you are not asked again on every visit. Neither leaves your device.
Everything beyond that is behind your choice. You are asked when you first arrive, nothing in the optional categories runs until you actively turn it on, and refusing is a single click in the same row as accepting — never a level down.
- Strictly necessary — the two items above. No switch, because the app cannot work without them.
- Analytics — page-view counts, counts of a few in-app actions so we can see where people get stuck (an estimate requested, a meal logged, the membership screen shown, a checkout started), and how quickly pages load for you. These carry a count and a label, never the name of a food, the title of a meal or anything you typed. Off unless you turn it on.
- Marketing — measuring whether an advert brought you here, and showing kcalready to similar people elsewhere. This is the category that can follow you between sites. Off unless you turn it on.
Change your mind whenever you like: "Cookie preferences" sits in the footer and in Settings → Account, and turning something off takes effect immediately. As things stand today no advertising tag is running at all, Vercel Analytics and Speed Insights measure without a cookie and without identifying anyone, and the fonts are served from our own domain rather than fetched from Google — so visiting a page tells Google nothing.
10. How it is kept safe
Traffic runs over HTTPS. Passwords are stored as bcrypt hashes, never in plain text. Database access uses a key that lives only on the server and is never exposed to your browser, and every query is scoped to the signed-in account.
The installable app deliberately caches almost nothing — page content and API responses always go to the network — so a shared device does not show one person’s meals to the next.
No system is perfectly secure, and anyone who claims otherwise is selling something. If a breach occurs that is likely to put your rights at risk, you will be told, and so will the supervisory authority, within 72 hours of it being discovered.
11. Age
kcalready is for adults. You must be 18 or over to hold an account, and data is not knowingly collected from anyone younger.
If you believe someone under 18 has an account, write to vitor.margis@gmail.com and it will be removed.
12. Changes to this policy
This policy may change as the app changes. The date at the top always reflects the current version.
Anything that materially reduces your rights or widens what is collected will be notified by email, or in the app, before it takes effect.
13. Complaints
If something here is wrong, tell us first — it is usually quicker. But you do not have to go through us.
In the EU or UK you may complain to your national data protection authority. In Brazil you may complain to the Autoridade Nacional de Proteção de Dados (ANPD). Either way, the right to complain is yours and using it costs nothing.