Privacy Policy

Last updated: August 15, 2026

This Privacy Policy describes how Victor Chung (“I”, “me”, or “the publisher”) collects, uses, and shares information when you use the SimpleCalories Android application (the “App”).

Contact: victorchung2013@gmail.com

1. Who this applies to

This policy applies to people who install and use SimpleCalories on Android. The App is published by Victor Chung as an individual, not as a registered company named “SimpleCalories.”

2. Information we collect

Depending on how you use the App, we may process:

Account and identity

  • Google account identifiers and basic profile details provided through Google Sign-In (such as Google user ID, display name, and email), used to create and authenticate your cloud account.

Profile and health / fitness data you enter or sync

  • Profile settings (for example goals, units, onboarding choices)
  • Food and meal logs
  • Weight logs
  • Step / activity data when you connect Health Connect or otherwise record steps in the App
  • Custom foods you create

Health Connect data is used only for the tracking and goal features that you request. We do not sell it, use it for advertising or ad targeting, or transfer it to an unrelated advertising service.

When you are signed in, this data is synced to our cloud backend (hosted database) so it is available across devices and recoverable after reinstall.

Photos

  • Meal photos you take or pick in the App are stored on your device.
  • If you use AI meal scan, a photo may be sent to our backend and forwarded to Google Gemini to estimate food and nutrition. Production uses the paid Gemini path when no trusted server-side region signal is available. When enabled by the deployment, GEMINI_TRUSTED_REGION is an operator-supplied server-side ISO-3166-1 alpha-2 region/egress signal; it is never copied from client playCountry. Only a recognized, non-restricted value can select an unpaid/free primary. EEA countries (including IS/LI/NO), Switzerland, and GB/UK are restricted; empty, malformed, unrecognized, or unknown values route paid, with paid fallback on provider quota exhaustion. Meal photos are not included in the regular cloud sync push of your food log history.

App activity and diagnostics

  • Crash reports and related diagnostic breadcrumbs via Firebase Crashlytics. The current build does not ship Firebase Analytics collection or use analytics event calls; Crashlytics diagnostics remain a separate operational service.
  • Technical request data needed to operate the API (for example authentication tokens, timestamps, and error responses)
  • If you leave the first-party measurement notice enabled, the App periodically uploads a small, authenticated batch of content-free product events to our backend (POST /api/v1/telemetry/batch). Events use a pseudonymous installation identifier plus an allowlisted event name and coarse properties such as app version, method, outcome, or elapsed-time value. They do not include food names, search text, photos, nutrition, goals, weight, Health Connect values, email, or account identifiers. Server telemetry is retained for about 90 days, and account deletion removes live rows; opting out clears the local queue.

Purchases and subscriptions

  • If you subscribe through Google Play, the App sends the purchase token to our backend so the subscription can be verified with Google Play and linked to your SimpleCalories account.
  • The backend does not store the purchase token in clear text. It stores a one-way hash and the provider metadata needed to enforce access and reconcile renewals, such as product/base-plan/offer identifiers, subscription state, expiry time, acknowledgement state, test-purchase state, the latest order identifier, and auto-renewal state.
  • Google Play real-time developer notifications may contain the purchase token so the backend can refresh that provider metadata. Account deletion removes the associated billing records through the account’s database cascade. Google processes payments under its own terms and privacy policy; SimpleCalories does not receive your full payment-card details.

Search and catalog lookups

When you search for foods or scan barcodes, queries may be sent through our backend to third-party nutrition databases (when configured), such as USDA, Open Food Facts, FatSecret, and Nutritionix.

If you save a result from the online catalog while signed in, the selected catalog result and normalized search query may be included with your synced food log. We use this information in aggregate, based on distinct users, to improve search ordering. It is not displayed as an individual activity report.

For FatSecret-backed food entries, the cloud log stores the diary transaction and the FatSecret food/serving identifiers needed to request current details. FatSecret names, serving descriptions, and nutrition responses are not stored in the cloud. Current details are requested when a relevant entry is visible and cached only on the device for up to 23 hours; expired details are removed even if the device is offline. Product-independent daily calorie aggregates may be synced to support history and expenditure trends.

Community food catalog

If you submit a product to the community catalog, we store the product details you submit and associate the submission with your account while your account exists. After account deletion, the catalog entry may remain for other users, but the submitter link is anonymized (cleared).

Administrators can view, correct, approve, reject, hide, or remove catalog entries in order to moderate the shared database. A submission may include the food name, brand, barcode, serving information, nutrition values, review status, review notes, and audit history. We do not need to collect a photo or a brand’s private data to publish a basic catalog entry.

If you use in-app Report on a community catalog entry, we store the report with your account: the entry identifier, a reason you select, an optional free-text note, and timestamps. Reports do not include photos. We use them to hide or remove entries that reach a report threshold and to resolve reports in the administrator tools. We may keep a moderation record of the action taken (for example that an entry was hidden) after a report is resolved.

AI estimate flags

If you use in-app Flag on an AI nutrition estimate, we store the flag with your account: the scan identifier, a reason you select, an optional free-text note, and timestamps. Flags do not include the meal photo and do not include health or nutrition values in the flag itself. We use flags to review estimate quality and to investigate abuse of the scan feature. Flagged scan events and their flags may be retained for up to two years (730 days) for quality and safety review; ordinary unflagged scan telemetry is retained for about 90 days. The original AI scan, when you used it, is still processed as described under Photos above.

3. How we use information

We use the information above to:

  • Authenticate you and operate your account
  • Sync and back up your profile and logs
  • Provide food search, barcode lookup, and (when enabled) AI meal scanning
  • Moderate and share community food submissions, including handling in-app reports and hiding or removing entries
  • Review in-app flags on AI nutrition estimates
  • Diagnose crashes and improve reliability
  • Comply with legal obligations where applicable

We do not sell your personal information. The App does not use advertising SDKs or the advertising ID for ads in the current implementation.

4. How we share information

We share data only as needed to run the App:

Recipient Purpose
Google (Sign-In) Account authentication
Google Gemini AI meal photo analysis when you use AI scan. The backend uses a paid production path by default; any unpaid/free primary is conditional on GEMINI_TRUSTED_REGION being a trusted, recognized non-restricted server-side region, while EEA/CH/GB/UK and unknown values use paid processing.
Firebase Crashlytics (Google) Crash reporting / diagnostics
Google Play Billing Subscription verification and renewal metadata; payment processing remains with Google
Our backend & database hosting (e.g. Neon Postgres) Account, sync, community catalog, API
Object storage used for encrypted database backups (e.g. Oracle Cloud Infrastructure) Operational backups of the server database
USDA / Open Food Facts / FatSecret / Nutritionix Food search and barcode nutrition lookup when those integrations are configured
Device Health Connect Reading or writing activity data you authorize

Service providers process data under their own terms and privacy policies.

5. Storage, security, and retention

  • Data in transit to our backend is protected with HTTPS / TLS.
  • Meal photos remain on-device unless you use AI scan (then they are transmitted for analysis as described above).
  • Signed-in profile and log data are stored in our cloud database.
  • Community reports and AI-estimate flags are stored in our cloud database for moderation and quality review. Ordinary scan events are retained for about 90 days; flagged scan events and their flags may be retained for up to two years (730 days) for quality and safety review. Live user-owned rows are removed with your account except where we need a limited moderation record (for example that a catalog entry was hidden) to operate the shared catalog.
  • If you request a cloud portability snapshot, the authenticated backend export (GET /api/v1/export, also available as /api/v1/account/export) is limited to your account’s approved rows. It excludes provider credentials, refresh or purchase tokens, provider identity IDs, and token hashes, and is rate limited. The in-app Settings export remains a local JSON snapshot; treat either file as sensitive personal data.
  • We maintain encrypted operational backups of the server database. Backup copies are retained for roughly 30 days, then age out under the backup retention schedule.
  • Local App data remains on your device until you clear it, uninstall, or delete your account (see below).
  • FatSecret detail responses are a bounded device cache (23-hour lifetime, with size limits and periodic cleanup); clearing App data or the FatSecret cache removes them.

6. Account deletion

You can delete your account from Settings → Delete account in the App. If you cannot access the App, use the web account-deletion request page.

When you delete your account:

  • Your cloud account and synced personal data are deleted from the live database (including cascade of related user-owned rows).
  • AI-estimate flags, product telemetry, and other user-owned rows tied to your account are deleted from the live database with that cascade, including any two-year flagged-scan retention. A community report may remain as an anonymized moderation record (its reporter link is cleared) when the shared catalog still needs the report or resulting hide state.
  • You are signed out on the device.
  • Local App database data and on-device meal photos are removed from the device.
  • Community food contributions may remain in the shared catalog with the submitter identity anonymized.
  • Encrypted operational backups may still contain residual copies of server data for up to about 30 days until those backups expire.
  • Deleting the SimpleCalories account does not cancel a Google Play subscription. Cancel it in the Google Play subscription center before deletion; uninstalling the App also does not cancel billing.

7. Children’s privacy

For the Closed-test and Production launch listing, the owner has decided on an adult target audience (18+). This launch decision does not rewrite or re-age existing profiles whose stored date of birth is under 18: their entered DOB, history, and targets remain as stored, and AI scan remains subject to the shipped age gate. The App is not directed to children under 13 (or the equivalent minimum age in your region). Do not use the App if you are under that minimum age.

8. Changes

We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Continued use of the App after an update means you accept the revised policy.

9. Contact

Questions about privacy or this policy:

Victor Chung
Email: victorchung2013@gmail.com