Consumer Health Data Privacy Policy for Cal Counter
This Consumer Health Data Privacy Policy supplements our Privacy Policy and describes how Metabola LLC ("we," "us," or "our") collects, uses, and protects "consumer health data" as defined by the Washington My Health My Data Act and the Nevada Consumer Health Data Privacy Law. It applies to consumers whose consumer health data is collected in Washington or Nevada, though we apply the same practices to all Cal Counter users regardless of where they live. It covers the Cal Counter app only; other Metabola apps have their own policies.
1. Consumer Health Data We Collect
We collect consumer health data from one source only: you, directly, when you enter it or take a photo within the app. The categories are limited to what the app needs to do its job:
- Body and demographic characteristics, which you provide during onboarding and can edit later: your date of birth, biological sex, height, your weight along with a dated history of your weight entries over time, and your self-described activity level.
- Health-related goals: your fitness goal (such as losing, maintaining, or gaining weight) and your daily calorie and macronutrient targets, whether the app calculated them for you or you set them yourself.
- Dietary and nutrition information: photographs of your meals, taken in the app or chosen from your photo library; the food names, portion descriptions, item counts, and calorie and macronutrient estimates associated with each meal, whether our AI produced them, you entered them, or you adjusted them; the date and time each meal was logged; your saved and favorite meals, including their photos and how often you reuse each one; and the calorie goal that was in effect at the moment each meal was logged.
- Usage information tied to the above: product analytics events recording that something happened in the app (for example, that a meal scan completed or that a subscription screen was shown), counts of how many scans you have used, and your push notification token and notification preferences.
Alongside this, and not itself health data, your account holds your email address, the name you ask us to call you, and your subscription tier.
We want to be equally clear about what we do not collect. We never collect your precise location — the app does not request location permission at all — and we do not perform geofencing of any kind. We do not connect to Apple Health, Google Fit, or any external health record, and we do not collect consumer health data from data brokers, public sources, partners, or any other third party. We do not use your data to infer health information about you beyond the nutritional estimates the app displays to you.
2. Why We Collect It and How We Use It
We collect and use consumer health data to provide the services you request from the app:
- To analyze your food photos and produce estimated calorie and macronutrient information.
- To calculate your calorie and macronutrient targets from the body characteristics and goals you provide, and to track your intake against them.
- To maintain your meal history and show your trends over time.
- To send you the notifications you have enabled.
- To keep the app working — diagnosing crashes and errors, and measuring in aggregate how features are used so we can improve them.
- To provide customer support when you ask for it.
We do not use consumer health data for advertising, and we do not sell it. We will not collect, use, or share your consumer health data for any purpose not disclosed in this policy without first obtaining your consent.
3. Sharing of Consumer Health Data
We do not share or sell your consumer health data. The categories of third parties and affiliates with whom we share consumer health data: none.
To operate the app we rely on service providers (processors) who handle data only on our behalf, under contract, and only according to our instructions:
- Supabase — our database, private file storage, and user authentication. Supabase holds all of the data described in this policy.
- Railway — hosting for our backend application. Your consumer health data passes through Railway in transit, and may appear briefly in short-lived operational logs.
- Google (Gemini), Anthropic (Claude), and OpenAI — analysis of the meal photographs you submit, solely to return nutritional estimates to you. Which of these services analyzes any given photograph depends on your subscription tier and on operational factors such as availability and fallback, and we may change that routing at any time — so you should assume that any one of them may process a meal photograph you submit.
- Sentry — crash and error reporting. Sentry does not receive consumer health data: fields describing your body, your goals, or what you ate are redacted on your device before a report is transmitted.
- RevenueCat — subscription and purchase management. RevenueCat receives an account identifier only, and no consumer health data.
- Expo push service — delivery of push notifications. It receives a device token only, and no consumer health data.
None of these processors is permitted to use your consumer health data for their own purposes. We use all three AI analysis services on terms that do not permit them to train models on the data we submit or otherwise use it independently; our Google account is on the paid Gemini API tier, where Google does not use submitted data to improve its products. These services may retain a submitted photograph briefly for security and abuse monitoring under their own contractual retention periods, after which they delete it on their own schedule. They do not build a profile of you and they do not receive your name, email address, or account history.
Your meal photographs are stored in private storage, never in a public bucket. They are transmitted to the AI services directly from our backend as image data, so those services never reach into our storage themselves, and your photographs are never exposed at a public or permanent web address. Any link the app itself uses to display one of your photos expires within one hour.
4. Consent
We ask for your consent during onboarding, before we request any health data from you, as two separate opt-ins:
- Your consent to our collecting health data in order to operate the app.
- A separate, distinct consent to our sharing your meal photographs with the third-party AI services described above for nutritional analysis.
Neither is pre-checked, and neither is bundled into your acceptance of our general Terms of Service — you can accept the Terms and decline either consent. We record each consent with a timestamp and the version of this policy that was in effect when you gave it. We will never obtain consent through misleading design or "dark patterns." Apart from these consents, we collect and use consumer health data only to the extent necessary to provide a product or service you have requested from us. If we ever wish to share your consumer health data beyond what is described here, we will first ask for your separate consent; if we ever wished to sell it (we do not and will not), the law would require your signed authorization.
5. Your Rights
You have the right to:
- Confirm and access: confirm whether we are collecting, sharing, or selling your consumer health data, and access that data, including a list of any third parties with whom it has been shared (currently: none).
- Withdraw consent: withdraw either of the consents described above at any time, from the profile screen in the app.
- Delete: have your consumer health data deleted, using the account deletion option in the app's settings or by asking us.
When you delete your account, we immediately delete your authentication record, which cascades through our database and removes every row holding your profile, your meals, your saved meals, your weight history, your goals, your notification preferences, and your push tokens. We delete your meal photographs from storage at the same time. A follow-up cleanup process sweeps for anything the first pass did not remove — for example, a photograph left behind by a storage error — so that nothing is retained indefinitely by accident. Your product analytics events are unlinked from your identity: the events remain as anonymous rows that can no longer be associated with you, which lets us keep accurate historical usage totals without keeping a record about you. We do not need to instruct the AI analysis services to delete anything, because they do not retain your photographs on our behalf; as described above, they delete submitted images on their own schedule and we hold nothing there to recall. Residual copies of your data in our encrypted backups are purged as described in the next section.
To exercise any of these rights, use the in-app options where available or contact us at support@metabola.io. We will need to verify that the request is coming from you (typically by confirming control of the email address on the account). We will respond within 45 days; if we need more time, we may extend once by an additional 45 days and will tell you why. Exercising your rights is free, and we will not discriminate against you for doing so.
6. How Long We Keep Your Data
- While your account is active: we retain your consumer health data for the life of your account. Your meal history and your long-term trends are the service itself, so we do not expire them.
- Dormant accounts: we do not delete dormant accounts. If you stop using Cal Counter, your data stays until you delete it or ask us to.
- After you delete: your data is removed from our active systems immediately, as described above. Our database backups are encrypted and taken daily on a rolling seven-day retention window, so residual copies in backups are purged within seven days of your deletion — well inside the timeframe the law allows.
- De-identified data: aggregate statistics that can no longer be linked to you or to any individual — such as the anonymous analytics events described above — may be retained indefinitely.
7. Appeals
If we decline to act on a request, you may appeal by replying to our response or emailing support@metabola.io with the subject line "Health Data Appeal." We will respond to your appeal in writing within 45 days, including an explanation of our decision. If your appeal is unsuccessful, you may contact the Washington State Attorney General at atg.wa.gov/file-complaint or the Nevada Attorney General at ag.nv.gov.
8. Changes to This Policy
We may update this policy from time to time. Each version carries an effective date and a version identifier, shown at the top of this page, and every superseded version stays permanently available at its own dated address so you can see what it said when you consented to it. If we make material changes to how we handle consumer health data, we will notify you through the app or by email, and where the law requires it, we will ask for your consent before applying new practices to data we already collected.
9. Contact Us
For any questions about this policy or your consumer health data, contact: support@metabola.io