Privacy Policy
Last updated: June 17, 2026
This Privacy Policy explains how Calobuddy (“Calobuddy”, “we”, “us”) collects, uses, and shares information when you use our website and service at calobuddy.com (the “Service”). Calobuddy is operated by Moheb Boules, an individual based in Egypt. If you do not agree with this policy, do not use the Service.
1. Who is responsible for your data
Calobuddy is operated as a sole proprietorship by Moheb Boules in Egypt. For any questions about this policy or to exercise your rights, contact us at support@calobuddy.com.
2. What data we collect
We collect only what we need to provide the Service:
- Account data: email address (used as your login) and name.
- Profile data you provide during onboarding: age, gender, height (cm), weight (kg), daily calorie goal, and your chosen eating-window start and end times.
- Food and calorie logs: meal descriptions you type or send to the assistant, calorie and macronutrient estimates, timestamps, and any edits you make.
- Fasting data: start and end times of fasting windows you track.
- Buddy data: the email or identifier of the user you invite as a buddy, and any data shared between you (see Section 6).
- Authentication data: one-time codes sent to your email and short-lived session tokens stored as cookies.
- Technical data: IP address, browser type, device type, and basic request logs collected automatically by our hosting provider for security and abuse prevention.
We do not knowingly collect government IDs, payment card data (the Service is currently free), precise GPS location, or biometric data.
3. How we use your data
- To create and maintain your account.
- To send authentication codes so you can sign in (no marketing emails are sent without separate consent).
- To compute calorie targets, fasting windows, and progress views shown in your dashboard.
- To process meal descriptions through our AI provider (see Section 5) to estimate calories and macros.
- To share your logs with the buddy you have connected with (see Section 6).
- To monitor for abuse, debug errors, and improve the Service. We do not sell your data or use it for advertising.
4. Service providers we share data with
We use the following processors. Each receives only the data needed to perform its function and is contractually bound by a Data Processing Agreement.
- Vercel Inc. — hosting and request logs. Data may be processed in the United States and the European Union.
- Supabase Inc. — database and authentication backend. Stores your account, profile, logs, and buddy relationships. Region: eu-west-1 (Ireland, European Union).
- Resend — delivery of one-time authentication codes by email. Resend receives only your email address and the code.
- Google LLC (Gemini API) — generates calorie estimates from the meal text you submit. See Section 5.
5. How we use AI (Google Gemini)
When you describe a meal in the logging interface, the text you enter is sent to Google's Gemini API to estimate the foods, portions, calories, and macronutrients. Only the text you submit and minimal context (such as a system prompt) is sent; we do not send your name, email, weight, or other profile data unless you have included it in your message yourself.
We use the paid Gemini API tier, under which Google states that customer prompts and responses are not used to train its models and are retained only for a short period for abuse monitoring. You can review Google's terms at ai.google.dev/gemini-api/terms.
All AI-generated calorie and nutrition estimates are approximate and may be wrong. They are not guaranteed to be correct, and they are not medical or nutritional advice. See our Terms of Service for the full disclaimer.
6. The Buddy feature
The Buddy feature is the core of Calobuddy. When you connect with a buddy, that buddy can see everything you log, including the raw text of your meal entries, the estimated calories and macros, the timestamps of your logs, your fasting windows, and your progress against your calorie goal. They can also see your name and profile metrics relevant to the goal (such as your calorie target).
By connecting with a buddy, you consent to this sharing. You can disconnect from a buddy at any time in your settings, after which they will no longer see new entries. Entries shared while connected may remain visible in their historical view.
7. Data retention and deletion
We keep your data for as long as your account exists. When you delete your account from settings, we perform a hard delete of your profile, logs, fasting data, and buddy connections from our primary database. Daily backups held by our database provider are retained on a rolling basis and are fully purged within seven (7) days of account deletion.
Email delivery logs at Resend and request logs at Vercel may retain metadata (such as your email and IP address) for a short period according to those providers' own retention policies.
8. Your rights
Depending on where you live, you may have rights under the EU General Data Protection Regulation (GDPR), the UK GDPR, the California Consumer Privacy Act (CCPA), and Egypt's Personal Data Protection Law (Law No. 151 of 2020). These include:
- The right to access the data we hold about you.
- The right to correct inaccurate data.
- The right to delete your data (you can trigger this yourself by deleting your account, or by emailing us).
- The right to export your data in a portable format.
- The right to object to or restrict certain processing, and to withdraw consent.
- The right to lodge a complaint with your local data protection authority.
To exercise any of these rights, email support@calobuddy.com. We aim to respond within 30 days.
9. International transfers
Calobuddy is operated from Egypt, and our processors (Vercel, Supabase, Resend, Google) process data in the United States, the European Union, and other regions. Where required, transfers from the European Economic Area, the UK, or Switzerland rely on the European Commission's Standard Contractual Clauses or equivalent safeguards offered by those providers.
10. Security
We use authentication, encryption in transit (HTTPS/TLS), and access controls provided by our hosting and database providers. No system is perfectly secure; if we become aware of a breach affecting your data, we will notify you and the relevant authorities as required by applicable law.
11. Children
Calobuddy is not intended for users under the age of 16. We do not knowingly collect data from anyone under 16. If you believe a child has provided us data, contact support@calobuddy.com and we will delete it.
12. Changes to this policy
We may update this policy as the Service evolves. When we make material changes, we will update the “Last updated” date at the top and, where appropriate, notify you by email or in the app. Continued use of the Service after changes means you accept the updated policy.
13. Contact
Questions, requests, or complaints: support@calobuddy.com.