Cali
Pricing Sign in

Privacy Policy

Last updated: 25 May 2026

1. Introduction

Cali ("we", "us", "our") is operated by Nick Kuh, a sole trader based in England. We are committed to protecting your privacy and handling your personal data responsibly. This policy explains what data we collect, how we use it, and your rights.

Contact: support@heycali.app

2. Data we collect

Account information

  • Email address (for sign-in and account recovery)
  • Display name or nickname
  • Authentication data via Supabase Auth (Google sign-in or magic link)

Profile information you provide

  • Date of birth, sex and height (used to calculate your calorie targets)
  • Target weight and coaching preferences
  • Dietary preferences and allergies

Health and fitness data

  • Meal descriptions and food items logged
  • Calorie estimates
  • Weight entries and weigh-in history
  • Activity and exercise logs
  • Photos of meals (if you choose to share them)

Technical data

  • Approximate location (country/city level, derived from IP address by Cloudflare — not stored)
  • Timezone (for displaying correct dates and times)

3. How we use your data

We use your data solely to provide and improve the Cali service:

  • Calorie calculation: Your age, sex, height and weight are used to calculate your BMR and daily calorie targets using the Mifflin-St Jeor equation.
  • Meal tracking: Meal descriptions and photos are processed to estimate calories and maintain your daily food log.
  • Coaching: Your preferences, habits and history are used to personalise coaching messages.
  • Progress tracking: Weight entries are stored to show your progress over time on your dashboard.
  • Account management: Your email is used for authentication and essential service communications.

4. Data storage and security

Your data is stored securely using:

  • Supabase (hosted on AWS) — for structured data (meals, weights, preferences, profiles)
  • Cloudflare Workers — for processing requests (no data persisted at the edge)

All data is transmitted over HTTPS. We use Supabase Row Level Security (RLS) to ensure users can only access their own data. Authentication tokens are short-lived and cryptographically signed.

5. Third-party services

Cali integrates with the following third-party services:

  • Anthropic (Claude) / OpenAI (ChatGPT): When you use Cali through these platforms, your conversation passes through their systems. Please refer to their respective privacy policies for how they handle data.
  • Paddle: Our payment processor and Merchant of Record. Paddle handles all billing, payment information and tax compliance. We never see or store your credit card details. See Paddle's Privacy Policy.
  • Google: If you sign in with Google, we receive your email and display name from Google's OAuth service. We do not access any other Google data.

6. Data sharing

We do not sell your data. We do not share your personal data with third parties for marketing purposes. Your data is only shared with the service providers listed above as strictly necessary to deliver the Cali service.

7. Data retention

We retain your data for as long as your account is active. If you cancel your subscription, your data remains available should you choose to resubscribe. If you wish to delete your account and all associated data, contact us at support@heycali.app and we will process your request within 30 days.

8. Your rights (UK GDPR)

Under UK data protection law, you have the right to:

  • Access: Request a copy of the personal data we hold about you
  • Rectification: Ask us to correct inaccurate data
  • Erasure: Ask us to delete your data ("right to be forgotten")
  • Portability: Request your data in a machine-readable format
  • Object: Object to processing of your data in certain circumstances
  • Restrict processing: Ask us to limit how we use your data

To exercise any of these rights, contact us at support@heycali.app.

9. Cookies

The Cali dashboard (app.heycali.app) uses a single session cookie to keep you signed in. We do not use tracking cookies, analytics cookies or advertising cookies. We do not use any third-party cookie-based analytics.

10. Children's privacy

Cali is not intended for use by anyone under the age of 18. We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

11. Changes to this policy

We may update this privacy policy from time to time. We will notify you of material changes via email. The "Last updated" date at the top of this page indicates when this policy was last revised.

12. Contact and complaints

For any privacy-related questions or concerns, contact us at support@heycali.app.

If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

Cali — your AI calorie coach

Pricing Privacy Terms Refunds Contact