Privacy Policy
Last updated: August 18, 2026 • Effective date: August 18, 2026
1. Data Controller & Contact Information
Calabi is operated by Youssef El Fajlaoui as an individual software developer based in Valencia, Spain("Calabi", "we", "us", or "our").
For questions concerning this Privacy Policy, your personal data, or to exercise your GDPR rights:
- Data Protection & Privacy Contact: privacy@calabi.fit
- General User Support: support@calabi.fit
- Supervisory Authority: Agencia Española de Protección de Datos (AEPD) — www.aepd.es
2. Core Privacy Principles
- Zero Advertising & No Data Selling: We do not sell, rent, or trade your personal or health data. Calabi contains zero commercial advertising SDKs, cross-site tracking pixels, or data broker integrations.
- Ephemeral Photo Analysis: Meal and label photos uploaded for AI analysis are processed in volatile memory during the request and are never stored permanently in cloud databases or storage buckets.
- Privacy by Architecture: User database records are protected by PostgreSQL Row-Level Security (RLS) policies ensuring users can only query their own authenticated data.
- AI Processing Safeguards: AI prompts route through our secure server proxy. Microsoft Azure OpenAI's standard commercial terms provide that customer prompt inputs and completions are not used to train base foundation models.
3. Special Category Data (Health & Biometric Data — GDPR Art. 9)
Because Calabi is a personal fitness and nutrition companion, the service handles special category health data under Article 9 of the EU General Data Protection Regulation (GDPR) and Spanish Organic Law 3/2018 (LOPDGDD).
This includes your weight history, body measurements, dietary preferences, food logs, active/past injuries, allergies, daily readiness scores, and meal plate photographs.
Explicit Consent Requirement (GDPR Art. 9(2)(a)): We process health data based on your explicit, opt-in consent provided during onboarding and before camera photo scanning. You may withdraw consent at any time in app settings.
4. Categories of Data Collected & Purpose of Processing
4.1 User Profile & Fitness Baseline
Age, biological sex, height, current/target weight, fitness goals, equipment, dietary preferences, and declared injuries/allergies. Used to calculate metabolic targets (Mifflin-St Jeor TDEE) and tailor training plans safely.
4.2 Nutrition & Meal Logging
Logged food items, estimated calories, protein, carbs, and fats. Used to track daily macro goals, energy balance, and weekly nutritional adherence.
4.3 Workout Tracking & Progressive Overload
Exercises, sets, repetitions, weight lifted (kg), and session duration. Used to log exercise history, calculate volume progression, and provide progressive overload suggestions.
4.4 Photographs for AI Vision Processing
User-captured photos of food plates and nutrition facts panels. Processed ephemerally in RAM during the API request and discarded immediately after structured data is returned.
4.5 AI Conversations & Epistemic Memory
Chat messages with Cal and inferred graph facts (e.g. declared injury constraints, PR milestones). Memory adapts when you report an injury resolved (AGM belief contraction).
4.6 Account & Authentication Data
Email address and Supabase Auth UID for registered accounts (guest mode requires no email). Used for cross-device cloud sync and password reset.
4.7 Device Telemetry & Usage Metering
App version, platform, device model, and internal AI token usage counters to manage quota limits and ensure system reliability.
5. Third-Party Subprocessors
We work with trusted technical infrastructure providers under Data Processing Agreements (DPAs):
- Supabase, Inc. (Configured in EU Region) — Cloud database, authentication, and encrypted state synchronization.
- Microsoft Corporation (Azure OpenAI) (Configured in EU Region) — AI streaming coach and computer vision meal analysis under zero-training enterprise terms.
- Open Food Facts (France, EU) — Public barcode and ingredient database queries (zero personal data shared).
- Google LLC (Ireland / EU) — Google Play Store distribution, in-app billing verification, and OS notification delivery.
6. Data Retention & Erasure
User profile data, workout logs, nutrition logs, and memory nodes are retained while your account remains active. Meal photographs have a retention period of 0 days (ephemeral processing).
When you request account deletion, all database records associated with your account are immediately soft-deleted and scheduled for permanent purge following a 30-day grace period.
7. Your Data Subject Rights (GDPR & Spanish LOPDGDD)
Under EU and Spanish data protection law, you have the right to:
- Access (Art. 15): Request confirmation and a copy of your personal data.
- Rectification (Art. 16): Update or correct your profile and records at any time.
- Erasure (Art. 17): Delete your account and wipe all data in-app or via our Web Deletion Page.
- Portability (Art. 20): Export a machine-readable JSON archive (Schema v1) of your data in-app.
- Withdraw Consent (Art. 7(3)): Revoke consent for photo analysis or AI features in Settings.
To exercise your rights, email us at privacy@calabi.fit. We respond within 30 days without charge.
8. Cookies & Website Local Storage
The website https://calabi.fit uses minimal, privacy-friendly storage:
- Technical Cookies: CDN routing and security cookies (e.g. Cloudflare / Vercel
_cfuvid) for DDoS protection. - Consent Cookie:
calabi_cookie_consent_v1(stores your cookie preferences). - Local Storage:
calabi_calc_units(remembers your metric/imperial unit choices in calculators). - No Advertising Cookies: We do not use third-party advertising cookies, retargeting pixels, or behavioral tracking scripts.
9. Minors & Age Restriction
Calabi is designed and intended strictly for users aged 16 years and older. We do not knowingly collect personal data from individuals under 16.
10. Contact
Calabi Privacy & Data Protection • Email: privacy@calabi.fit • Location: Valencia, Spain