Privacy Policy
Effective 31 July 2026
Kally ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose and safeguard your information when you use our mobile application (the "App"). Please read it carefully. If you do not agree with it, please do not use the App.
The short version
We never sell your data, never share it for advertising, and run no advertising, analytics or tracking SDKs of any kind.
Meal photos are sent to be read for what is on the plate. Nothing identifying you goes with them, and they are not used to train anybody's models.
Everything is locked to your account at the database level — no other user can read your rows, and neither can an unauthenticated request.
You can export or delete all of it yourself from Privacy & Data, at any time, without asking us.
1. Information We Collect
Everything in this section is either given to us by you or generated by your use of the App. We do not buy data about you, we do not obtain it from data brokers, and we do not combine what you give us with data from other sources.
1.1 Account Information
Your email address, and your name if you give one. If you sign in with Apple or Google we receive the name and email that service releases to us — including Apple's private relay address if you choose to hide your real one — plus a profile photo where one exists. We never receive your password for those accounts.
1.2 Health and Body Information
Your year of birth, biological sex, height, current weight and target weight, together with the onboarding answers you gave about symptoms, bloating, sleep, meal timing, activity and goals. This is used to calculate your daily calorie, sodium and potassium targets and your bloat readings. It is not used for anything else, and it is never used for advertising or shared with an advertiser.
1.3 Meal Photos and Food Logs
Photographs of the meals and nutrition labels you scan, the foods identified in them, the portions you set, and the nutrition figures attached to each entry.
1.4 Routines
The daily routines you track and the days you marked each one kept. No photographs and no free text beyond the name you give a routine.
1.5 Subscription Information
Which plan you hold and when it renews, so the App knows what to unlock. Payment is taken by Apple or Google — we never see your card number, billing address or any part of your payment method.
1.6 Service and Security Records
The timestamps of your scans, which we count in order to enforce per-account rate limits, and server error logs that may contain your account id. These exist to stop abuse and to let us fix faults. They are not used to profile you.
1.7 Information We Do NOT Collect
We do not collect:
Your contacts or address book
Your location, or any GPS coordinates
Your advertising identifier (IDFA)
Your browsing activity, or your activity in other apps
Device identifiers such as UDID or IMEI
We ship no analytics, attribution, advertising or crash-reporting SDK, so there is no third-party code in the App watching what you tap. Apple and Google may give us anonymised crash and usage summaries for the App itself, but only where you have allowed your device to share them, and those summaries are aggregated and not tied to your account.
2. How We Use Your Information
To produce your readings. Your logs and body details are what the daily Bloat Score, your targets and your suggestions are calculated from.
To analyse a scan. A photo you submit is read for what is on the plate — see section 4 for exactly how.
To show you your history. Your entries are kept so that trends across days and weeks are available to you.
To manage your subscription. To know which plan you hold and what to unlock.
To keep the service working and safe. Rate limits, abuse prevention and diagnosing faults.
To answer you when you contact support.
3. Our Legal Bases
Where UK or EU data protection law applies, our legal bases are:
Contract — running your account and delivering the features you signed up for.
Explicit consent — for your health and body information and for your photographs, which are special category data. You give that consent by choosing to answer and to scan, and you withdraw it by deleting the data or your account. Withdrawing does not affect anything done before you withdrew.
Legitimate interests — keeping the service secure, enforcing rate limits, preventing abuse and diagnosing faults, balanced against your rights.
Legal obligation — where we must keep or produce something by law.
4. What Happens to a Photo You Scan
This is the only point at which your photographs leave our systems, so it is worth being plain about.
A photo you scan is sent to our servers, and from there to a third-party provider that reads what is on the plate and returns a result. Nothing identifying you travels with it — no name, no email, no account id — and it is not used to train anybody's models.
For packaged food we look the product up by name or barcode in public food databases. Those lookups never include your photo, and never include anything about you.
The result is saved to your account, and the photo itself goes to private storage that only your signed-in session can open. There is no public link to any image you have ever uploaded.
5. Third-Party Services
These are the only third parties involved in running the App. Each acts on our instructions under a contract, or as an independent service the App depends on:
An AI analysis provider
Reads the meal photos you submit and returns what is on the plate
Called from our servers, never from your device
A hosting and database provider
Stores your account, your entries and your images
Hosted infrastructure
Public food databases
Nutrition figures for packaged products, looked up by name or barcode
Neither your photo nor anything about you is sent to them
Apple and Google
Account sign-in, app distribution and subscription billing
Platform services
6. Data Storage and Security
6.1 Stored on Your Own Device
Some things never leave your phone. Your onboarding answers stay on the device while you go through the flow, and are written to your account in a single step at the end of it — nothing you answered is sent before that. Your sign-in session is stored encrypted, with the key held in your device's own secure storage. Your notification preferences and any reminders you schedule stay on the device and are delivered by iOS itself — we operate no push server, and we cannot send you a message you did not schedule.
Deleting the App removes everything stored locally. It does not delete your account — use Privacy & Data for that, and see section 8.
6.2 Stored on Our Servers
Your entries are locked to your account by the database itself, so another user cannot read them and neither can a request that is not signed in. Your images are held in private storage and reached only through short-lived links issued to your own session.
6.3 Security Measures
Traffic is encrypted in transit, and your sign-in session is encrypted at rest on your device. Our own credentials for the services we depend on are held on our servers and are never shipped inside the App, and every request is checked against your verified identity before anything is read or written.
No system is perfectly secure. If a breach ever affects your personal data we will notify the relevant supervisory authority within 72 hours where the law requires it, and tell you directly and without undue delay where there is a high risk to you.
7. Data Sharing and Disclosure
We do not sell, trade or rent your information. Stated plainly, because these are commitments and not aspirations:
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are defined by California law. We have never done either.
We do not track you across other companies' apps or websites, and we do not ask for App Tracking Transparency permission because we have nothing to track you with.
We do not use your photographs, health data or logs to train artificial intelligence models.
We do not use health data for advertising or marketing, ever, and we do not disclose it to data brokers.
We share information only with the service providers listed in section 5, and we may disclose it where the law genuinely requires it, or to establish, exercise or defend a legal claim. Where we are permitted to tell you about such a request, we will. If the App is ever sold or transferred, your data would move to the buyer under this same policy and we would tell you before it happened, so that you can delete your account first if you would rather.
8. Data Retention
Your logs and scans stay in your account until you delete them or close the account — the history is the product, and a bloat trend with holes in it is not much use to you.
Deleting a single entry removes that entry and its image immediately.
Deleting your account removes your profile, preferences, meals, routines, recommendations, entitlements and every stored image, and then removes the sign-in itself. It is immediate and it is not recoverable — we keep no copy you could ask for afterwards.
Encrypted backups roll off within 30 days, after which deleted data is gone from those too.
Security and rate-limit records are kept for up to 90 days, then deleted.
Anonymous, aggregated statistics that cannot be traced back to you or to any individual may be kept indefinitely.
Records we are required by law to retain — a tax record of a subscription, for instance, held by the app stores — are kept for as long as the law requires and no longer.
9. Your Rights and Choices
9.1 In the App
You can exercise most of these yourself, without contacting anyone — Settings → Privacy & Data.
Access and portability. Export everything we hold as a machine-readable JSON file.
Correction. Edit your name, email and body measurements in Personal Information.
Erasure. Delete individual entries, or your account and everything in it.
Withdrawing consent. Stop scanning at any time, and delete what you have already scanned.
Objection and restriction. Email privacy@kally.app and we will action it within 30 days.
We do not charge for any of this, and we will never treat you differently — worse pricing, degraded features — for exercising a privacy right.
9.2 UK and EU
You have the rights above under the UK GDPR and GDPR, and the right to complain to your supervisory authority — in the UK, the Information Commissioner's Office. We would rather you came to us first, but it is your right either way.
9.3 California and Other US States
Under the CCPA/CPRA and the equivalent laws of Virginia, Colorado, Connecticut, Utah, Texas and other states, you have the right to know, delete, correct, and obtain a portable copy of your personal information, and to opt out of sale, sharing, and profiling. We do not sell or share personal information and we do not profile you for decisions producing legal or similarly significant effects, so there is nothing to opt out of. We collect sensitive personal information — health data and photographs — but only to provide the service you asked for, which is the one purpose the law permits without a further right to limit; we do not use or disclose it for any other purpose. Use the in-app controls, or email privacy@kally.app. You may use an authorised agent, and we will verify the request against your account.
9.4 Managing Your Subscription
You can manage or cancel your subscription at any time through your device's App Store or Play Store settings. Subscription management is handled entirely by Apple or Google, not by us. See our Terms of Service for the billing detail.
10. Apple Health
If you connect Apple Health, Kally reads only the sleep and active energy figures used to refine your bloat score, and only with your permission, which you can revoke in the Health app at any time. Health data is processed for that purpose alone. We do not use it for advertising or marketing, we do not disclose it to third parties for their own purposes, we do not send it to the analysis service with your photos, and we do not use it for any purpose other than your own health and fitness within the App. If the section is not visible in Settings, the integration is not active in your build and no Health data is being read at all.
11. Automated Analysis, and Its Limits
Your scores, nutrition estimates and suggestions are produced automatically by a model rather than reviewed by a person. They are estimates rather than measurements, and they are not a diagnosis. No decision producing a legal or similarly significant effect on you is made automatically. Do not use Kally to make a medical decision — talk to a qualified professional. If you have or suspect an eating disorder, or a kidney, heart or blood-pressure condition, or you are pregnant, speak to a clinician before using calorie or sodium targets from this or any other app.
12. Children's Privacy
Kally is not intended for children. You must be at least 16 to use it — or at least 13, where your country's data protection law sets the lower age and your parent or guardian consents. We do not knowingly collect data from anyone below that age. If you are a parent or guardian and believe a child has given us information, email privacy@kally.app and we will delete the account and its contents promptly.
13. International Transfers
Our providers process data outside the UK and EU, including in the United States. Where those transfers need a safeguard we rely on the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, together with the technical measures described in section 6. You can ask us for details of the safeguard applying to any particular transfer.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we change it materially we will tell you in the App before the change takes effect, and where the change requires your consent we will ask for it rather than assume it. The effective date at the foot of this page always tells you which version you are reading.
15. Contact Us
If you have any questions about this Privacy Policy or our privacy practices, please contact us at:
Email: privacy@kally.app
Website: kally.app
We answer privacy requests within 30 days.
Kally · Effective 31 July 2026 We'll tell you in the app before any material change takes effect.