Privacy Policy
Last Updated: August 16, 2026
Calimit is designed to minimize the amount of personal information we collect. Your food diary, calorie targets, manually entered foods, app preferences, and related nutrition information are generally stored locally on your device rather than in a Calimit user account.
Calimit also offers an optional Apple Health integration that allows you to write certain nutrition information from foods you log in Calimit to Apple Health. Calimit does not read information from Apple Health.
1. Information Calimit Collects and Processes
The information we process depends on how you use Calimit.
Information stored on your device
Calimit may store information locally on your device, including:
- foods you have logged
- your food diary
- calorie targets
- calories and macronutrient information
- manually entered food items
- serving and portion information
- app preferences and settings
- your Apple Health synchronization setting
- records indicating that you accepted applicable policies or disclaimers
Your food diary and locally stored nutrition information are stored on your device and are not uploaded to Neboryx servers. Certain limited information, such as barcode queries, food-search terms, anonymous identifiers, scan counts, subscription information, and technical security information, may be processed as described elsewhere in this Privacy Policy. Removing the App or clearing its locally stored data may remove some or all of the information stored locally on your device.
Barcode scans and food searches
When you scan a food barcode or search for a food or product, Calimit sends the barcode number or search term to our backend services so that we can locate nutrition information. Our backend may request product and nutrition information from third-party food databases, including Open Food Facts and USDA FoodData Central. The resulting nutrition information may be returned to the App so Calimit can calculate and display calories, macronutrients, serving information, and suggested portions.
Portion-description processing
Calimit may send limited product and nutrition information to Anthropic's Claude API to generate plain-language portion descriptions or other text used to present nutrition information to you. This information may include a product name, serving information, calorie information, and macronutrient information. Calimit does not need to send your name or email address to Anthropic for this functionality.
Anonymous app identifier
Calimit uses Firebase Anonymous Authentication. This creates an app-generated identifier that allows Calimit to provide certain functions without requiring you to create a traditional account or provide a name, email address, or password. We may associate this anonymous identifier with limited backend information, such as your free-scan count. Although this identifier does not itself contain your name or email address, it is an identifier associated with your use of the App.
Scan-count information
If your version of Calimit includes a limited number of free scans, we maintain a scan count associated with your anonymous app identifier. We use this information to administer free usage limits, determine when subscription access may be required, prevent abuse of the free tier, and operate the App.
Security and device-attestation information
Calimit uses Firebase App Check and related device-attestation technology to help determine whether requests to our backend are coming from a legitimate copy of the App. These services may process app-attestation information, security tokens, IP addresses, request information, and limited device or application information necessary to validate the App and prevent fraud or abuse.
Subscription information
Calimit may offer optional auto-renewing subscriptions through Apple's App Store. Payments are processed by Apple, and subscription access is managed with RevenueCat. Neboryx may receive subscription or entitlement status, transaction or purchase status, subscription expiration information, an app-generated identifier, and other information needed to determine whether you have access to paid features. Neboryx does not receive or store your full credit or debit card number when your purchase is processed by Apple.
Information you provide through our websites or support channels
If you join an early-access list, contact us, request support, or otherwise communicate with us, we may collect your email address, your name if provided, the contents of your message, and other information you voluntarily include in your communication.
2. Apple Health and HealthKit
Calimit offers an optional integration with Apple Health through Apple's HealthKit framework. The integration is off by default. Calimit will not write information to Apple Health unless you:
- Turn on the "Sync logged foods to Apple Health" setting in Calimit; and
- Grant the requested permission through Apple's standard Health authorization process.
You may choose not to enable Apple Health integration, and Calimit will remain fully functional without it.
Information Calimit writes to Apple Health
When Apple Health synchronization is enabled and permission has been granted, Calimit may write for each applicable food entry: dietary energy including calories, protein when available, carbohydrates when available, and total fat when available. This information reflects the nutrition figures already calculated and displayed by Calimit. Apple Health synchronization acts as a secondary copy of information from your Calimit diary, which remains stored locally on your device.
Calimit writes only available nutrition values
Calimit writes only nutrition values available for the food you logged. If a particular nutrition value is unknown or absent, Calimit does not create, infer, estimate, or fabricate a value solely for purposes of writing it to Apple Health.
Calimit does not read Apple Health information
Calimit does not use Apple Health to obtain body weight, activity or exercise information, steps, heart rate, sleep information, medications, nutrition information written by other applications, medical information, or other health or fitness information. Because Calimit does not read Apple Health information, information stored in your Apple Health account does not flow back into Calimit.
Calimit does not access clinical health records
Calimit does not access Apple's Clinical Health Records functionality. Calimit does not request or receive health records from doctors, hospitals, healthcare providers, laboratories, or other clinical sources through HealthKit.
No background Health reading or delivery
Calimit does not use HealthKit Background Delivery to continuously obtain or process Apple Health information in the background. Food information is written in connection with Calimit's food-logging functionality when you have enabled synchronization and granted the applicable permission.
No advertising, analytics, or data-mining use
Calimit does not use information written to or obtained through HealthKit for advertising, targeted advertising, marketing profiling, behavioral profiling, analytics, data mining, or unrelated secondary purposes. Calimit does not currently contain third-party advertising SDKs, Firebase Analytics, or Firebase Crashlytics. Calimit does not sell HealthKit information to advertising platforms, data brokers, information resellers, or similar parties.
Apple Health information is not transmitted to Calimit servers
Nutrition information that Calimit writes to Apple Health is transmitted from the App on your device to your Apple Health store through Apple's HealthKit framework. Calimit does not transmit information from your Apple Health store to Neboryx servers or third parties. The HealthKit write does not require information from your Apple Health store to pass through Calimit's backend.
Permission and control
You may grant or deny permission for Calimit to write supported nutrition information to Apple Health. You may also disable Calimit's Health synchronization setting or revoke Calimit's Apple Health permission using Apple's applicable privacy or Health settings. If you deny or later revoke permission, your food diary continues to work, foods continue to log normally in Calimit, your locally stored Calimit diary is not deleted, and Calimit otherwise continues to function without Apple Health synchronization. Apple Health synchronization is a secondary, best-effort feature and is not required for Calimit's core operation.
3. Information We Do Not Currently Collect Through the App
Based on the current version of Calimit:
- Calimit does not require you to create an account using your name or email address
- Calimit does not use Firebase Analytics
- Calimit does not use Firebase Crashlytics
- Calimit does not use third-party advertising SDKs
- Calimit does not use your information for cross-app behavioral advertising
- Calimit does not read information from Apple Health
- Calimit does not access Clinical Health Records through Apple Health
- Calimit does not transmit information from your Apple Health store to Neboryx servers or third parties
- Calimit does not use HealthKit information for advertising, marketing, analytics, or data-mining purposes
- Calimit does not collect your full payment-card information
If these practices change, we will update this Privacy Policy as appropriate before or when the applicable functionality is introduced.
4. How We Use Information
We use information collected or processed through Calimit to:
- provide barcode scanning and food-search functionality
- retrieve nutrition information
- calculate calories, macronutrients, servings, and portions
- generate plain-language portion descriptions
- maintain your free-scan allowance
- determine whether you have an active subscription
- process and manage subscription entitlements
- write eligible food-diary nutrition information to Apple Health when you have expressly enabled the feature and granted permission
- protect Calimit and our backend systems against fraud, abuse, and unauthorized access
- troubleshoot and maintain the Services
- respond to questions or support requests
- operate and improve the Services
- comply with applicable legal requirements
- protect the rights, safety, and security of Neboryx, our users, and others
We do not use your food diary, nutrition information, or HealthKit information for targeted advertising.
5. How We Share Information
We disclose information only as necessary to operate Calimit. Depending on how you use Calimit, service providers may include:
Google Firebase
Used for backend services, anonymous authentication, scan-count management, Cloud Functions, Firestore, and App Check. Information processed may include an anonymous app identifier, scan-count information, IP addresses, request information, and device-attestation information.
Open Food Facts
Used to locate food-product and nutrition information. A barcode or food-search term may be transmitted as part of a lookup request.
USDA FoodData Central
Used to locate food and nutrition information, including when a product or food cannot be located through another data source. A search term, food identifier, or other food-query information may be transmitted as part of the request.
Anthropic
Used through the Claude API to generate plain-language portion descriptions and related text. Limited product and nutrition information may be transmitted for this purpose.
RevenueCat
Used to manage subscriptions and paid-feature entitlements. RevenueCat may process an app-generated identifier and information concerning your subscription or purchase status.
Apple
Apple processes App Store purchases and subscription transactions under Apple's own terms and privacy practices. Apple also provides the HealthKit framework used by Calimit's optional Apple Health synchronization feature. When you enable Apple Health synchronization, eligible nutrition information is written from your device into your Apple Health store through Apple's HealthKit framework. Neboryx does not receive information back from your Apple Health store.
These providers may also automatically receive technical information normally associated with communications over the internet, such as an IP address, where applicable to the services they provide.
Legal and safety reasons
We may disclose information when we reasonably believe disclosure is necessary to comply with applicable law, regulation, subpoena, court order, or other lawful process; respond to valid governmental or regulatory requests; enforce our agreements; investigate fraud, misuse, or security incidents; or protect the rights, property, or safety of Neboryx, our users, or others.
Business transactions
Information may be transferred as part of a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar business transaction. Information stored solely within your Apple Health store and not held by Neboryx would not be part of information transferred by Neboryx in such a transaction. Where required, we will provide appropriate notice concerning material changes in the way personal information is handled.
6. Sale of Personal Information and Advertising
Neboryx does not currently sell personal information. We also do not currently share personal information with third parties for cross-context behavioral advertising or targeted advertising through the Calimit App. Calimit does not currently contain third-party advertising SDKs. Information obtained through or written to HealthKit is not used by Calimit for advertising, marketing, or use-based data mining. Calimit does not sell HealthKit information to advertising platforms, data brokers, information resellers, or similar parties.
If our broader privacy practices change in the future, we will update this Privacy Policy and provide any choices or opt-out mechanisms required by applicable law. Any changes involving HealthKit information will remain subject to Apple's applicable HealthKit requirements.
7. Aggregated and De-Identified Information
We may create or use statistical information from information lawfully available to Neboryx that does not reasonably identify an individual user to understand or improve the operation of Calimit. If information is maintained in de-identified form, we intend to maintain it in that form and not attempt to re-identify it except where permitted or required by applicable law.
Information from Apple Health is not included in Calimit's aggregated or de-identified data activities because Calimit does not read or receive information from the Apple Health store.
Calimit does not currently operate a program to sell or license user-level food diary or nutrition information. Any future program involving aggregated or de-identified information would be evaluated separately and this Privacy Policy would be updated as appropriate before such a program is implemented.
8. Data Retention
We retain information only for as long as needed for the purposes described in this Privacy Policy. Because most Calimit data remains on your device and our backend does not store information that directly identifies you, our retention practices are limited as follows.
On-device data
Your food diary, calorie targets, manually entered foods, app preferences, Apple Health synchronization setting, and other locally stored App information remain on your device. This information is not stored on Neboryx servers and is generally retained until you delete the applicable data, clear the App's locally stored data, or uninstall the App.
Anonymous identifier and scan count
Calimit uses an anonymous app-generated identifier and associated scan count to administer applicable free-scan limits. These records are not linked to your name or email address and are retained until the App is uninstalled, the anonymous identifier is no longer associated with your device, or the corresponding backend record is deleted.
Nutrition lookup cache
Calimit may temporarily cache nutrition information retrieved from Open Food Facts and USDA FoodData Central. A successfully located product may be cached for up to 45 days. A "not found" result may be retained for up to 24 hours. The cache is indexed by barcode or search term and is not designed to associate cached nutrition information with an individual user.
Server logs
Our backend may generate operational logs used to maintain security, diagnose technical problems, and operate the Services. These logs are generally retained for 30 days. Calimit's backend functions are designed not to log the details of the foods you add to your diary.
Apple Health information
Information Calimit writes to Apple Health is stored within Apple's Health ecosystem and is controlled through Apple's applicable Health and privacy controls. Calimit does not maintain a server-side copy of information obtained from your Apple Health store. Deleting Calimit does not necessarily delete nutrition information previously written to Apple Health — you can manage that through Apple's applicable controls.
Neboryx does not maintain a backend profile containing your name, email address, food diary, or Apple Health information. We may retain information longer where reasonably necessary to comply with applicable law, respond to lawful requests, investigate fraud or security incidents, resolve disputes, or establish or defend legal claims.
9. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information handled through Calimit, including:
- encrypted HTTPS connections for network communications
- server-side storage of third-party API credentials
- Firebase authentication
- Firebase App Check and device attestation
- access controls for backend services
- limiting the amount of user information stored on our servers
- using Apple's HealthKit framework for optional writes of nutrition information from the user's device to the user's Apple Health store
Calimit does not route information from your Apple Health store through Neboryx's backend. No system, network, or method of electronic transmission or storage can be guaranteed to be completely secure.
10. Your Choices and Privacy Rights
Depending on where you live, you may have rights concerning personal information we maintain about you. These may include the right to request access, correction, or deletion of personal information; obtain information about how personal information is used or disclosed; withdraw consent where processing depends on consent; obtain a portable copy of certain information; object to or restrict certain processing; and appeal certain decisions where applicable law provides that right.
Because Calimit does not require a name or email address for App use, we may have limited ability to associate an anonymous identifier with a particular individual. We may ask for information reasonably necessary to locate information associated with a request and verify that you are authorized to make the request.
Apple Health controls
Apple Health permissions and information stored in Apple Health are controlled through Apple's system settings and Health application. You may disable Calimit's Health synchronization setting or revoke Calimit's permission to write nutrition information using Apple's applicable privacy and Health controls. Revoking Apple Health permission does not prevent you from continuing to use Calimit's food diary or other core features.
To submit a privacy request concerning information maintained by Neboryx, contact us using the information in Section 14. We will not discriminate against you for exercising privacy rights provided by applicable law.
11. United States Privacy Rights
Residents of certain U.S. states may have additional rights regarding personal information under applicable state privacy laws. These rights vary by state and may include access, deletion, correction, portability, opt-out rights, consent rights, and appeal rights. Neboryx does not currently sell personal information or use Calimit App information for targeted advertising.
Nutrition and consumer health information
Certain U.S. states may provide additional protections for information that qualifies as consumer health data. Calimit may process information concerning foods, calories, macronutrients, calorie targets, and similar nutrition information in order to provide the functionality you request. Most food-diary and calorie-target information is stored locally on your device. Information sent to our backend is limited to food searches, barcode queries, product information, anonymous usage identifiers, and scan-count information. If you opt in to Apple Health synchronization, eligible nutrition information is written from your device to your Apple Health store. Calimit does not read that information back from Apple Health or transmit it from Apple Health to Neboryx servers. Where applicable law provides additional rights concerning consumer health information, you may contact us using the information in Section 14.
12. Canadian Users
If you are located in Canada, you may have rights regarding the collection, use, and disclosure of your personal information under applicable federal or provincial privacy laws. Subject to applicable exceptions, these may include rights to request access to personal information we hold about you, request correction of inaccurate personal information, withdraw consent to certain processing, and raise a question or complaint about our privacy practices. Residents of Quebec may have additional privacy rights under applicable Quebec law. Requests may be submitted to our Privacy Officer using the information in Section 14.
13. Children's Privacy
Calimit is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to us in violation of applicable requirements, please contact us. We will take appropriate steps to investigate and delete the information where required. Different minimum-age requirements may apply depending on the user's jurisdiction.
14. Nutrition Accuracy and Apple Health
Nutrition information displayed by Calimit may originate from third-party food databases and other sources. Although Calimit is designed to use available nutrition information accurately, food and nutrition information can be incomplete, incorrect, outdated, or affected by changes made by food manufacturers or database providers.
When Apple Health synchronization is enabled, Calimit writes the nutrition values associated with the corresponding logged food entry. Calimit does not independently estimate missing nutrition values solely for the purpose of completing an Apple Health entry. If a supported nutrition value is unavailable, that value is not written to Apple Health.
You should not rely on Calimit or information written by Calimit to Apple Health as a substitute for professional medical or nutritional advice. Where nutrition accuracy is particularly important, including because of a medical condition, food allergy, dietary restriction, or other health-related concern, you should verify information against the product label or another authoritative source and consult an appropriate healthcare professional when necessary.
15. Contact Us
If you have questions, concerns, complaints, or requests regarding this Privacy Policy or our privacy practices, contact:
Neboryx LLC — Privacy Officer
Email: privacy@calimit.com
Website: calimit.com
For privacy-related requests, please include enough information for us to understand and respond to your request. Do not send sensitive information that is not necessary for us to process your request.
16. Changes to This Privacy Policy
We may update this Privacy Policy as Calimit changes or as our privacy practices or legal requirements change. When we update the Policy, we will revise the "Last Updated" date at the top. If a change materially affects how we collect, use, or disclose personal information, we may provide additional notice through the App, our website, or another appropriate method. We encourage you to review this Privacy Policy periodically.