Privacy policy

Last updated · 17 September 2026

What Kalv stores, where it stores it, and how to get rid of it.

This policy covers the Kalv iPhone app and the website at kalv.app. It is written to be read, not to be survived — if something here is unclear, write to support@kalv.app and it will be fixed.

The short version. Your account lives on servers in Paris and never leaves the European Union. A photograph you scan is sent to our server for analysis and is stored nowhere but on your own phone. Nothing is sold, there is no advertising network, no analytics SDK and no third-party tracker inside the app — the one thing we measure is our own onboarding, and you can switch that off. One tap in Profile › Data deletes the account, and it is a real deletion, not a flag on a row.

Who is responsible

The data controller is Aleksandar Dzavric, a French micro-entreprise, SIRET 94471075500017, 63 chemin des Moellerons, 73100 Aix-les-Bains, France. Contact: support@kalv.app. The supervisory authority is the CNIL (cnil.fr). Kalv is small enough that the law does not require a data protection officer, and it does not have one — the address above reaches the person who decides.

What Kalv stores about you

An account is required to use Kalv: there is no anonymous mode, because the plan has to follow you across a preparation and a device. Everything below is either something you typed or something the app computed from it.

DataWhyLegal basis
Sign-in identity — your email address, or the private relay address Apple gives us if you sign in with Apple, plus which method you used To have an account at all, to let you back into it, and to reach you about it Performance of the contract
Athlete profile — display name, handle, sex, date of birth, height, starting, current and target weight, discipline, weight class, weigh-in date, phase, training load, water goal, and any daily target you override by hand These are the inputs the plan is computed from. Without them there is no plan Contract, and your explicit consent for the health part below
Your log — weigh-ins, meals and their nutrition values, water, streak and trophies To show your history, your averages and where you sit in the corridor Contract, and your explicit consent for the health part below
Profile photo, if you set one Displayed in the app, and the only image you can put on our servers Consent — you choose to upload it
App settings, subscription status and a referral code generated for your account To keep the app configured the way you left it across devices, and to know what you have access to Performance of the contract
The six-digit code, if you sign in by email — sent to you, checked, then spent To prove the address is yours Performance of the contract
The onboarding, screen by screen — which question you were on, what you answered, when you moved on, and where you stopped. Recorded under a temporary identifier the app creates the first time it opens, before you have an account, and attached to your account the moment you create one To see where the onboarding loses people and to fix it. This is the only thing Kalv measures about how the app is used, it is done by us and not by an analytics company, and it is off the moment you turn off Profile › Preferences › Share anonymous analytics Our legitimate interest in improving our own product; the health answers among them rest on the same explicit consent as the profile
The scan ledger — for each scan: when, which kind, what it cost us to run, and the figures it returned. Never the image To apply the daily scan allowance and to know what the scanner costs Performance of the contract
What you send to support@kalv.app or through the form on this site — your name, your address and the message To answer you Our legitimate interest in answering our own users

Health data — the part that needs your explicit consent

Your weight, your body measurements, what you eat and what you drink are data concerning health under Article 9 of the GDPR. That is a special category: it may only be processed with your explicit consent, and that consent is separate from the contract.

You give it by entering those numbers into the app, having been told here what they are used for. They are used for one thing — computing and displaying your own plan — and for nothing else. They are not analysed across users, not shared, not sold, and no human at Kalv reads them in the ordinary course of running the service.

You can withdraw that consent at any moment by deleting your account from Profile › Data, which erases the data with it. Withdrawing does not make the earlier processing unlawful, and it does not undo a payment.

Apple Health

If you connect Apple Health, Kalv reads two things and only two: your step count and your active energy. Not sleep, not heart rate, not heart-rate variability, not workouts, not anything else that is sitting there available.

  • It is read only after you grant it in the iOS system sheet, and you can take it back at any time in iOS Settings › Privacy & Security › Health › Kalv.
  • It stays on the phone. It is read into the app to draw your day and is never sent to our servers and never written to iCloud.
  • It is never used for advertising or marketing, never disclosed to a third party, and never sold. Apple forbids all three, and so do we.

Reading Health is also how Kalv reads a Whoop, a Garmin, an Oura, a Fitbit or an Apple Watch: those devices write into Health, and Kalv reads Health. It does not connect to any of them directly and holds no account with any of them.

Meal photographs, and the scanner

The scanner is the one part of Kalv that sends an image of yours anywhere. It is written out here in full because you should be able to decide about that before you use it rather than after.

When you scan a plate or a nutrition label, that one photograph goes from your phone to our server, which passes it to Anthropic — the company whose model reads it — and returns the figures to the app. We do not store the image. What our server keeps is the ledger row above: when, which kind, what it cost, what came back. Anthropic processes the image under its API terms, which exclude using it to train their models, and holds it no longer than the analysis needs. Every figure that comes back lands in a sheet you confirm, and every one of them can be replaced by your own.

Scanning a barcode sends the number, and nothing else, to Open Food Facts, an open food database. They see the barcode and your IP address. They do not see your account, because the app does not send it.

A copy of each meal photograph stays on your phone, as the thumbnail beside the meal in your log. It is written to the app's own container on the device, it is not attached to your account and it is not in any bucket of ours. Deleting the meal deletes it; deleting the app deletes them all. The consequence is worth saying plainly rather than discovering: sign in on a second phone and you get every meal you ever logged, and none of their photographs.

Where it is stored

In the European Union. The database, the authentication and the file storage are provided by Supabase on infrastructure located in Paris, France (AWS eu-west-3). Every table is protected by row-level security keyed to your own account: there is no query a client can make that returns another athlete's data, and the avatar bucket is private, each athlete confined to their own folder.

Who else touches it

ProcessorWhat forWhere
SupabaseDatabase, authentication, avatar storage, and the server function that relays a scan to the model and writes the ledgerParis, France (EU)
HostingerThe support@kalv.app mailbox, and the mail that carries your six-digit sign-in codeEU
AppleApp Store distribution and payment; Sign in with Apple, if you use it Apple's own terms apply
GoogleGoogle Sign-In, if you use itGoogle's own terms apply
VercelHosting for this website only — no app data touches it See the legal notice
AnthropicReading the plate or the label you scan — the one image, for the time of the analysis, not storedUnited States
Open Food FactsBarcode lookups — the barcode number onlyFrance (EU)

Nothing is sold. Nothing is shared with advertisers. There is no advertising network, no analytics SDK, no crash-reporting SDK, no advertising identifier and no third-party tracker inside the app. If that ever changes, this page changes first and the app tells you.

Leaving the European Union

Everything Kalv stores stays in Paris. Two things can cross the Atlantic and both are your choice: signing in with Google, and scanning a plate or a label, whose photograph is read by Anthropic in the United States. Those transfers rest on the European Commission's standard contractual clauses and, where the provider is certified, the EU–US Data Privacy Framework. Sign in with Apple keeps your real address behind Apple's private relay.

What stays on your phone

  • The copy of each meal photograph, as above.
  • A local copy of your log, so the app works on a mat with no signal. It lives in the app container and goes when the app goes.
  • Everything Apple Health hands over.

Notifications

Reminders are scheduled by the app on the device. There is no push server, we hold no device token, and nothing about a reminder reaches us. Turn them off in the app or in iOS Settings and nothing else changes.

How long it is kept

  • While your account exists — your profile and your log are kept, because they are the product.
  • When you delete your account — the account is destroyed, every row attached to it is deleted by cascade, your onboarding records are deleted with it, and your storage folder is purged. Scan ledger rows lose their link to you and keep only the counts and the costs. There is no grace period during which it sits waiting to be restored, and there is no copy in an archive of ours.
  • If you never create an account — the temporary identity the app opened on first launch is deleted after thirty days. The onboarding records it wrote stay, with no identifier left on them.
  • Backups — our host keeps short-lived encrypted backups of the database for disaster recovery. A deleted row can survive inside one until it rolls off, usually within a week. Nothing reads a backup except a restore.
  • Support email — kept for up to three years from the last exchange, so a returning question has its history.
  • Website server logs — kept by the host for a short technical period and never joined to an account.

How it is protected

  • Everything travels over TLS, and every table sits behind row-level security keyed to your session — not to a filter the app remembers to apply.
  • The key compiled into the app is the publishable one, which can do nothing your own session cannot. The key that could read everything exists only on the server side and is not in the app, in this website, or in any repository.
  • Sign-in codes expire, and a code is spent the moment it is used.

No system is perfect and this one is run by one person. If a breach ever puts your data at risk, we notify the CNIL within 72 hours as the GDPR requires, and we tell you directly and without delay whenever the risk to you is high. You will hear it from us, not from a forum.

Nothing here decides anything about you

Your targets and your corridor are arithmetic, run on the numbers you typed in. There is no profiling, no scoring, no ranking against other athletes, and no automated decision that produces legal effects or anything similar within the meaning of Article 22 GDPR. The app computes; you decide.

Your rights

Under the GDPR you may request access to your data, its correction, its erasure, its portability, restriction of processing, and you may object to processing. You may withdraw any consent at any time. Two of those need no request at all:

  • Rectification — every number in the app is editable by you.
  • Erasure — Profile › Data deletes the account and everything attached to it.

For anything else — a copy of your data included — write to support@kalv.app. We answer within one month, and tell you if a request is complex enough to need two more. If the answer does not satisfy you, you may lodge a complaint with the CNIL at any time. French law also lets you leave directives about what happens to your data after your death; send them to the same address.

Children

Kalv is for adults. You must be 18 or over, and an account may not be created by anyone younger. The reason belongs to this page: what Kalv holds is health data, and a minor cannot give the explicit consent Article 9 requires — in France that consent sits with the holders of parental authority, which is not something an app can collect honestly. There is a second reason, and it is about bodies rather than data: see the safety page.

We do not verify age beyond the date of birth you enter — we say so rather than pretend otherwise. If you believe a minor has an account, write to us and it will be removed.

The website

kalv.app sets no cookies and runs no analytics — the cookie policy covers it in full. The contact form sends what you typed to our own mailbox and stores nothing in your browser. The host keeps standard technical logs. Nothing on this site is loaded from a third party — the typeface is the one already installed on your device — so reading these pages tells no one but our host that you were here.

Changes

If this policy changes materially, the app tells you before the change applies, and asks again for any consent that has genuinely changed shape. The date at the top of this page always reflects the current version.