Version 2026-10-07. This is the version recorded against your account when you signed up.

Caloriq is a calorie and activity tracker. This policy explains what it keeps about you, why, who else ever sees it, and how to get it all back or have it deleted. It describes what the software actually does, not what it might someday do.

Caloriq is operated by CodeHaste Inc, Bengaluru, Karnataka, India. Contact: info@codehaste.com.

What Caloriq keeps

Your account

  • Your email address, used to sign you in, to send verification and password-reset codes, and to reach you about the service.
  • Your password, stored only as a bcrypt hash. Nobody at Caloriq can read it, and it is never returned by the API.
  • Your date of birth, used to check you are old enough to use Caloriq (18) and to calculate your calorie target.
  • The date you accepted these terms and which version you accepted.

What you tell it about yourself

  • Sex (female, male or unspecified), height, activity level, and whether you want to lose, maintain or gain weight. Used to calculate a starting calorie target.
  • Your daily targets for calories, macronutrients, water and steps.

What you record

  • Meals: the food, the amount in grams, the day, and when you logged it.
  • Foods you add yourself.
  • Body weight, by date.
  • Water, as a daily total.
  • Steps per day, and where each day's count came from: a health store, this phone's own sensor, or typed in by you.
  • Workouts: type, duration, energy where it is known, when they started, and the health store's own record identifier so the same workout is not stored twice.
  • Goals you set, the periods they were judged over, and the badges and messages that followed.

Technical records

  • Sessions: a SHA-256 digest of each refresh token, never the token itself. Sessions expire after 30 days, and end sooner when you log out or reset your password.
  • Verification and reset codes, stored only as a keyed hash. They expire after 15 minutes, stop working after five wrong attempts, and are replaced when a new one is sent.
  • Server logs: a request identifier, the method and path, the response status and how long it took. Request bodies and query strings are not logged.

What Caloriq does not do

  • No advertising, and no data is sold or rented to anyone.
  • No analytics or tracking software, on the phone or the server. There is no advertising identifier, no device fingerprint, no third-party tracker.
  • No location data, contacts, photos, microphone or camera access.
  • Caloriq never writes to your phone's health store. It only reads.
  • No profiling and no automated decisions with legal or similarly significant effects.

Who else sees any of it

Food catalogue providers — food search runs only against Caloriq's own database, so your search words are not sent to a food-data provider. Catalogue data is imported separately from documented sources. Source and licence details are stored with each entry. Historical meals may still contain Open Food Facts data collected by an earlier version of Caloriq.

Brevo — the service that delivers verification and password-reset emails. It receives your email address and the contents of that message.

Sentry — crash reporting, used only when Caloriq is configured with a Sentry account. It receives your account identifier and technical details of the crash. Request bodies, query strings, cookies and authorisation headers are removed before anything is sent.

Health Connect on Android, Apple Health on iOS — these stay on your phone. Caloriq reads steps and workouts from them, with your permission, and writes nothing back. You can disconnect at any time in Profile, and disconnecting revokes the permission.

DigitalOcean — rents us the server, in Bengaluru, India, on which we run the Caloriq API and its database.

Nobody else. Caloriq will disclose data if the law requires it, and would tell you unless legally prevented.

Where it is kept, and for how long

Your data is stored in a PostgreSQL database that we run on that server, in Bengaluru, India.

It is kept until you delete it. Deleting your account removes your profile, meals, custom foods, weights, water, steps, workouts, goals, badges, recognition, sessions and codes, in one operation, immediately and irreversibly. The database is backed up every night and each backup is kept for 14 days, so a deleted account can survive in a backup for up to 14 days before that backup is deleted. Backups stay on the same server and are used only to restore the service after a failure.

What you can do

  • Get a copy. Profile → Download my data returns everything Caloriq holds about you as a JSON file. It excludes your password hash and session material, which describe nobody and would only help an attacker.
  • Delete everything. Profile → Delete account. It asks for your password, and it cannot be undone.
  • Correct things. Meals, weights, water, workouts and every target can be edited or removed in the app. For anything you cannot change yourself, write to info@codehaste.com.
  • Disconnect sources. Health Connect and this phone's step counter can each be disconnected in Profile, separately, at any time.

If you are in India, the Digital Personal Data Protection Act gives you rights of access, correction, erasure and grievance redressal. Our Grievance Officer is reachable at info@codehaste.com (subject: "Grievance Officer"); we answer within 30 days. If you are in the EU or UK, the GDPR additionally gives you rights to portability, restriction and objection, and to complain to your supervisory authority.

Children

Caloriq is for adults. You must be 18 or older to create an account, and signup refuses a date of birth that makes you younger. If we learn an account belongs to someone under 18, we delete it.

Security

Passwords are hashed with bcrypt. Connections use HTTPS. Access tokens last 15 minutes; refresh tokens are opaque, stored only as digests, rotated on every use, and reusing an old one revokes every session for that account. Every request is scoped to the account that made it — asking for someone else's data returns "not found", not their data.

No system is perfectly secure. If you believe your account has been accessed by someone else, reset your password, which ends every session everywhere, and write to us.

Changes

If this policy changes in substance, the version at the top changes with it and you will be asked to accept the new version. Wording and typographical fixes do not change the version.

Contact

info@codehaste.com, or write to CodeHaste Inc, Bengaluru, Karnataka, India.