Privacy policy
Last updated 15 August 2026
CheckCal is made by Dobreon sp. z o.o., a company registered in Poland, which is the controller of the small amount of personal data described here. Write to support@dobreon.com about anything on this page.
The short version: one thing leaves your phone, and it is the meal photograph. It has to, because that is how the estimate is produced. Everything else stays on the device.
There is no account
CheckCal has no sign-up, no login and no user profile on any server. We do not know who you are, we cannot look up your data, and we have no way to send you anything. That also means your log lives on your phone: it moves to a new device only through your own iCloud or iTunes backup, and deleting the app deletes it.
Meal photographs
When you photograph a meal, the app resizes the picture and sends it to our server, which forwards it to the vision model that produces the estimate. We currently use OpenAI as that model provider. If we change provider we will update this page before the change ships.
- We do not store the photograph. Our server holds it in memory for the length of the request and writes it nowhere. Our logs record the size of the image, how long the request took and which model answered — never the image and never the estimate.
- The model provider processes it under their API terms, which exclude data sent through the API from being used to train their models. They may retain it briefly for abuse monitoring under their own policy.
- A copy stays on your phone, in the app's own storage, attached to the meal. It is deleted when you delete the meal, and it is never uploaded anywhere else.
- The legal basis is performance of the contract: you asked the app to read a photograph and it cannot do that locally.
Photographs are the only images involved. The app never reads your photo library.
Barcodes
Scanning a barcode sends the number — and nothing else — to Open Food Facts, a free public food database, to look the product up. No photograph is sent and nothing identifies you or your device beyond what any web request carries. If the product is not there, the app takes you to the manual form instead.
What never leaves the device
- Everything you log: foods, weights, portions, meals, the day's totals.
- Your profile from the opening questions — the formula, activity, height, weight, date of birth, goal — and the targets calculated from it.
- Your weigh-ins and the trend drawn from them.
- How many free photos you have used today.
None of this is sent anywhere. There is no analytics SDK, no crash reporter, no advertising identifier and no third-party tracker of any kind in the app.
Apple Health
Health is off until you switch it on in Settings, and switching it on asks your permission separately. With it on, the app writes what you log — energy, protein, carbohydrate, fat — into Health as food entries, and reads your body mass so a connected scale saves you typing the number twice.
Health data stays on your device. It is never sent to our server, never sent to the model, never used for advertising or shared with anyone, and it is not used for any purpose other than showing you your own figures. You can withdraw the permission at any time in the Health app.
Subscriptions
Subscriptions are sold and processed by Apple. We never see your card, your Apple Account or your name — the app only learns from Apple whether a subscription is currently active. Apple's own privacy policy covers the transaction.
Children
CheckCal is not intended for children. The opening questions do not accept a date of birth under 13 years ago.
Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction, portability and objection. In practice these are unusually simple here, because we hold almost nothing: the data is on your phone, so you already have all of it, and deleting the app erases it. We keep no copy to send you or to delete.
For the meal photographs, which do pass through our server: they are not retained, so there is nothing to access or erase after the request finishes. You can stop sending them by not using the photo feature — barcodes and manual entry do not involve our server at all.
You may also complain to a supervisory authority. In Poland that is the Urząd Ochrony Danych Osobowych.
Changes
If this policy changes in a way that affects what is sent or kept, we will update the date at the top and describe the change here before the new version of the app ships.