KcalSnap home

Privacy Policy

KcalSnap · Last updated 18 September 2026

KcalSnap is a calorie and macro tracker. This page explains exactly what the app collects and what happens to your food photos.

What we store

Guest previews

You can try food scanning without creating an account. The app keeps a random preview token on your device. Our server stores its hash and usage counters to enforce preview limits; a guest preview does not create an account. When you choose to sign in to save a meal, the edited result is temporarily kept on your device so it can survive sign-in and setup. It is cleared after saving or leaving the restored preview. Guest photos use the same analysis process described below.

Food photos

Photos you scan are sent to an AI vision service to identify the food and estimate portions, then discarded. They are never stored by KcalSnap, never linked to your account, and never used to train anything by us.

Public agent API

The public API accepts food photos from agents and supports card-funded scan credits through Stripe or x402 payments through PayAI on Base. KcalSnap does not persist API images. Images are processed by OpenRouter and its Gemini provider; food names are sent to USDA. Provider processing is subject to their policies. We store result text for a 24-hour recovery window, then remove completed results when new API requests are recorded. Results awaiting payment reconciliation remain until resolved. Request fingerprints, wallet addresses, idempotency keys, status timestamps and settlement records are retained for accounting, abuse prevention and retry protection. On-chain payment records are public and cannot be deleted by KcalSnap. For card credits, Stripe processes payment and billing details. KcalSnap stores an API key fingerprint, balance, usage and purchase references. Our server does not store the full API key or card details. The credit purchase page saves your API key in your browser local storage so you can return to it; clear it through your browser settings when you no longer need it. A lost key cannot be reconstructed by us. Credit and payment records are retained for service delivery, accounting, refunds and abuse prevention. API activity is separate from app accounts and food logs. Contact us about retained API data at hello@kcalsnap.com.

Apple Health

Apple Health access is optional, read-only and requested only after you tap Connect. KcalSnap stores daily summaries, never raw or minute-by-minute heart-rate samples. Summaries help calculate an above-usual activity adjustment and may be combined with your food diary to generate Coach observations. Missing or denied Health data is not treated as zero.

Health and fitness data is used only to provide KcalSnap's health and nutrition features. It is never used for advertising, tracking, marketing or sale. When Health context is included in Coach, it is processed through an AI route configured to reject providers that collect prompts and to require zero data retention.

Services we rely on

First-party usage measurement

We operate Pulse, a private analytics service hosted on our servers in Germany. On this website it records page paths, referring domains, campaign tags, coarse device and country information, visible page time and App Store link clicks. We do not use analytics cookies. IP addresses are processed to create a daily, site-specific visitor hash; raw IP addresses are not stored in the analytics database. Standard web-server security logs are separate.

For the app, Pulse receives signup and meal-save events with timestamps and pseudonymous account identifiers. This helps us understand whether people start and continue using KcalSnap. It does not receive meal contents, photos, calorie totals, body measurements or Apple Health data. Website visitors are not linked to app accounts or tracked across projects. Detailed observations are retained for up to 180 days, with backups kept for up to 14 days. Analytics linked to a deleted account are removed at the next successful source sync.

Reliability diagnostics

To diagnose reliability problems, we store scan outcomes and limited app refresh diagnostics in Supabase, linked to your account. These include timestamps, app update versions, processing times, and fixed categories for failures and authentication recovery. They do not contain photos, food contents, body measurements, Apple Health data, passwords, authentication tokens, or raw error messages. These records are restricted to administrators, are deleted with your account, and records older than 90 days are removed when new diagnostics are recorded.

What we don't do

No advertising, no analytics SDKs, no selling or sharing of personal data, no tracking across apps.

Your data, your control

Delete any food entry in the app at any time. You can disconnect Apple Health and delete all stored Health summaries from Settings without deleting your account. Apple permissions can be changed in Apple's Health app. You can also delete your account and all associated data permanently from KcalSnap Settings.

Contact

MB Nexus consulting, Vilnius, Lithuania · hello@kcalsnap.com