Last Updated: February 28, 2026
👋 Introduction
NoCalories is developed by Dmitrii Pinchuk ("we", "us", "our"). We are committed to protecting your privacy.
This Privacy Policy explains what data the App collects, how it is used, and your rights regarding that data.
In short: All your personal and nutrition data stays on your device. We don't create user accounts,
we don't track you, and we don't sell data. The only server communication is for AI-powered food analysis.
❤️ Health & Fitness Data (HealthKit)
With your explicit permission, the App reads and writes the following data from Apple HealthKit:
- Active energy burned (calories)
- Steps count
- Exercise minutes
- Walking/running distance
- Workout sessions
- Weight entries
This data is used solely to display your daily activity summary, track weight progress,
and calculate net calorie balance within the App.
We do not store HealthKit data on any server. All HealthKit data remains on your device and in Apple's Health app.
👤 Profile Information
You may optionally provide personal details to receive personalized calorie and hydration recommendations:
- Age, gender, height, weight
- Activity level
- Diet plan preference
- Unit system preference (metric / imperial)
This information is stored locally on your device only and is never transmitted to any server.
📷 Food Photos
When you use the photo analysis feature, the App captures or selects a photo of your food. The photo is:
- Compressed on your device before any processing
- Sent to our server solely for forwarding to API for food recognition and calorie estimation
- Not stored on our server — processed in real-time and discarded immediately
- Cached locally on your device (as a hash) to avoid redundant API calls for identical images
⌨️ Food Names (Text Input)
When you manually enter a food name, it is:
- Sent to our server solely for forwarding to API for nutritional analysis
- Not stored on our server — processed in real-time and discarded
- Cached locally on your device to provide instant results for repeated queries
📱 On-Device Data
The following data is stored exclusively on your device using Apple's SwiftData framework and is never transmitted to any external server:
- Meal entries, calorie counts, junk ratings, and ingredients
- Daily nutrition history and archived summaries
- Weight tracking entries
- Hydration / water intake logs
- Notification preferences
- Food analysis cache (text and image hashes)
🔐 Device Attestation
The App uses Apple's App Attest framework to verify that requests originate from a legitimate copy of the App on a genuine Apple device. This process:
- Generates a cryptographic key pair on your device
- Sends attestation and assertion data to our server for verification
- Does not collect any personal information — purely a device integrity check
Attestation key identifiers are stored on our server solely for ongoing verification.
💳 Subscriptions & Purchases
The App uses Apple's StoreKit for in-app subscriptions. All purchase transactions are handled entirely by Apple.
We do not collect, process, or store any payment information.
We only receive a confirmation of your subscription status from Apple's servers.
🛡️ IP Address & Rate Limiting
Our server temporarily logs your IP address in hashed form solely for rate-limiting purposes (to prevent abuse). These records are:
- Stored as anonymized hashes — not raw IP addresses
- Automatically purged after 60 seconds
- Never used for tracking, analytics, or identification
🔗 Third-Party Services
Apple
- HealthKit — governed by Apple's privacy policies; data is never sent to our servers
- StoreKit — subscription management handled by Apple
- App Attest — device integrity verification handled by Apple's DeviceCheck framework
🚫 Data We Do NOT Collect
✕ Names or email addresses
✕ Phone numbers
✕ Analytics or tracking SDKs
✕ Advertising frameworks
✕ User accounts or registration
✕ Cookies
✕ Location data
✕ Data sold to third parties
🔒 Data Storage & Security
- All personal and nutritional data is stored on your device only
- Server communication uses HTTPS/TLS encryption
- API requests are authenticated using an app secret and Apple App Attest
- No user data is persisted on our servers
🗂️ Data Retention
- On-device data — retained until you delete the App or clear its data. Past meal entries are archived into daily summaries automatically.
- Server-side — no user data is retained. Rate-limiting records are purged within 60 seconds. Attestation keys are retained for device verification only.
🧒 Children's Privacy
The App is not directed at children under the age of 13. We do not knowingly collect any personal information from children.
If you believe a child has provided us with personal data, please contact us so we can delete it.
✅ Your Rights
You have the right to:
- Delete all local data by uninstalling the App
- Revoke HealthKit access — Settings → Privacy & Security → Health
- Revoke camera access — Settings → Privacy & Security → Camera
- Revoke photo library access — Settings → Privacy & Security → Photos
- Revoke notification permissions — Settings → Notifications
- Cancel your subscription — Settings → Subscriptions
📝 Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be reflected by updating the "Last Updated" date
at the top of this document. Continued use of the App after changes constitutes acceptance of the updated policy.
📧 Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Email: uspinchuk@gmail.com