Last updated: 25 September 2026
This policy explains what personal data the Caloora app and website (“Caloora”, “we”, “us”) process, why, and what rights you have as a user.
1. Controller
MKV Group s.r.o.
Abrahám 271, 925 45 Abrahám, Slovak Republic
Company ID (IČO): 52358046
Tax ID (DIČ): 2121011530
VAT ID: SK2121011530 (VAT payer under §4 since 1 September 2020)
Contact email: support@caloora.app
2. What data we process
2.1 Account and sign-in
Email address and password (or sign-in with a Google / Apple account), registration date, app language.
2.2 Health and nutrition data (special category)
Age, sex, height, weight, activity level, goal (lose / maintain / gain weight), pace of weight change, diet obstacles, the calculated daily calorie and macro target, history of logged meals (name, calories, macros, time), water intake, weight over time.
Under the GDPR this is a “special category of personal data” (data concerning health). We process it only on the basis of your explicit consent, which you give during onboarding in the app.
2.3 Food photos
If you use the “Photo” or “Describe” feature to recognise a meal, the photo or text description is sent to our AI provider (Google Gemini) to analyse it and estimate calories and macros. We do not store photos on our servers for longer than needed to produce the analysis result.
2.4 Technical and device data
IP address, device and operating system type, app version, a device identifier used for security, debugging and delivering push notifications.
2.5 Push notifications
To deliver reminders (e.g. “don’t forget to log a meal today”) we use OneSignal, to which we assign your internal user identifier and the device notification token.
2.6 Payments and subscription
Payments for Caloora Pro are processed directly by Google Play (Android) or the App Store (iOS) — we never see or store payment card numbers. To manage subscription status (active/cancelled, renewal date) we use RevenueCat, with which we share your internal user identifier and subscription status.
2.7 Marketing analytics
To measure app and marketing campaign performance we use Firebase Analytics (Google) and Meta App Events (Facebook/Instagram). On iOS we ask for your consent through Apple’s “App Tracking Transparency” system dialog before this tracking is enabled. You can decline it at any time in your device or app settings.
3. Why we process data (legal basis)
| Purpose | Legal basis |
|---|---|
| Providing app features (calorie tracking, AI food recognition) | Performance of a contract |
| Health/nutrition data | Explicit consent (GDPR Art. 9(2)(a)) |
| Subscription and billing | Performance of a contract |
| Push notifications | Consent |
| Marketing analytics and advertising | Consent |
| Security, fraud prevention, troubleshooting | Legitimate interest |
| Accounting and tax obligations | Legal obligation |
| Record of account deletion (proof the request was handled) | Legitimate interest |
4. Who we share data with (processors)
Your data is processed on our behalf by the following third parties, each under a data processing agreement:
- Hostzone (hostzone.sk) — server and database hosting (profile, meals, history); the servers are located in the European Union
- Google Firebase — sign-in, app configuration, analytics
- Google Gemini (Google Cloud) — AI recognition of meals from photos/text
- OneSignal — delivery of push notifications
- RevenueCat — subscription status management
- Meta Platforms (Facebook/Instagram) — marketing attribution
- Google Play / Apple App Store — payment processing
Some of these providers may process data outside the European Economic Area (e.g. the USA). In that case we rely on Standard Contractual Clauses or another valid mechanism under the GDPR.
5. How long we keep data
We keep your account data and meal history while your account is active. After you delete your account we erase or anonymise the data within 30 days, except where the law requires longer retention (e.g. accounting records).
After you delete your account we keep only a record of the deletion itself: your email address, name, internal account identifier, the date of deletion and whether the account was deleted in the app or at your request. It serves as proof that we handled the erasure request and protects us against unfounded claims (legitimate interest). It does not include your meals, photos, health data or activity history. We keep it only as long as needed for this purpose; if you want this record erased too, write to support@caloora.app.
6. Your rights
You have the right to access your data, rectify it, erase it, restrict processing, data portability and the right to object. You can withdraw consent to the processing of health data or marketing analytics at any time in the app settings or by writing to support@caloora.app. You can delete your account and all related data at any time directly in the app (Settings → Delete account).
You also have the right to lodge a complaint with the Office for Personal Data Protection of the Slovak Republic (dataprotection.gov.sk).
7. Children
Caloora is not intended for children under 16. We do not knowingly collect data from children under 16.
8. Changes to this policy
We may update this policy from time to time. We will inform you of material changes in the app.
9. Contact
Questions about the processing of personal data can be sent to: support@caloora.app