← Back to Caloria

Privacy Policy

Effective date: June 17, 2026 · Last updated: June 17, 2026

Plain-language summary. Caloria helps you track nutrition and get wellness coaching using AI. To do that, we process the account details you give us, the meal photos you upload, and the food/health information you enter. We use trusted third parties (OpenAI, Stripe, Resend, Cloudflare, and the USDA database) to provide these features. We do not sell your personal information. You can access, correct, or delete your data by contacting us.

This Privacy Policy explains how Paullina Ruban ("Caloria," "we," "us," or "our") collects, uses, shares, and protects personal information when you use the Caloria website, application, and related services (the "Service"). By using the Service, you agree to this Policy. If you do not agree, please do not use the Service.

1. Who we are

The operator and data controller responsible for your information is Paullina Ruban. For any privacy question or request, contact us by email at copaullin@gmail.com.

2. Information we collect

Information you provide

Information collected automatically

Payment information

Subscription payments are processed by Stripe. Your full card number and payment credentials are entered directly with Stripe and are not stored on our servers. We receive limited billing metadata (e.g., subscription status, customer/subscription identifiers, and payment success/failure events).

Sensitive information. Nutrition, body measurements, and wellness goals may be considered health-related data in some jurisdictions. Where required by law, we process this data based on your explicit consent, which you provide by entering it and using the personalization features. You may withdraw consent by deleting the data or your account.

3. How we use your information

4. Third-party service providers

We share personal information with vetted processors only as needed to operate the Service. Each acts on our instructions under contractual confidentiality and data-protection obligations.

ProviderPurposeData shared
OpenAIAI meal-photo analysis & wellness coachingMeal photos, food descriptions, coaching messages
USDA FoodData CentralNutrition reference databaseFood search terms (no personal identifiers)
StripeSubscription payments & billingEmail, billing metadata, payment details (entered with Stripe)
ResendTransactional email (verification, password reset)Email address, message content
Cloudflare (Turnstile)Bot & abuse protectionIP address, challenge token
Cloud hosting & storage providerApplication hosting & storageAll data necessary to run the Service

We may also disclose information to comply with law, respond to lawful requests, protect our rights or users' safety, or in connection with a merger, acquisition, or sale of assets (with notice where required).

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

5. AI processing

Meal photos and coaching messages are sent to OpenAI to generate analyses and responses. We instruct our AI providers not to use your content to train their general models where such controls are available. AI outputs (including calorie and macro estimates) are automated estimates and may be inaccurate; they are not medical, dietary, or health advice. See our Terms of Service for important disclaimers.

6. Data retention

We keep your information for as long as your account is active or as needed to provide the Service. Meal photos and logs are retained to power your history until you delete them or your account. Verification and reset tokens are short-lived and single-use. Billing records are retained as required by tax and accounting laws. When you delete your account, your account and personal data are removed immediately from our active systems, and any residual copies in routine backups are deleted within 30 days, except where retention is legally required.

7. Your rights & choices

Depending on where you live (including under the EU/UK GDPR and the California CCPA/CPRA), you may have the right to:

To exercise these rights, contact copaullin@gmail.com. We will verify your identity and respond within the timeframe required by applicable law. We will not discriminate against you for exercising your rights.

8. Security

We protect your information using industry-standard measures, including password hashing (PBKDF2), encrypted payment handling via Stripe, session expiration, rate limiting, and bot protection. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your password confidential.

9. International transfers

Your information may be processed in countries other than your own, including the United States. Where required, we rely on appropriate safeguards (such as Standard Contractual Clauses) for international transfers.

10. Children's privacy

The Service is intended for users aged 16 and older. Users must confirm they are at least 16 years old before using the platform. We do not knowingly collect personal information from children under 16. If you believe someone under 16 has provided us information, contact us and we will delete it. Where local law sets a higher age of digital consent, that higher age applies. (See "Eligibility" in the Terms of Service.)

11. Changes to this Policy

We may update this Policy from time to time. We will post the new effective date and, for material changes, provide additional notice (e.g., by email or in-app). Your continued use after changes take effect constitutes acceptance.

12. Contact us

Paullina Ruban
Email: copaullin@gmail.com