Privacy Policy

Effective Date: August 7, 2026

1. Purpose of Processing Personal Data

We process personal data solely for the purposes listed below. Data will not be used for any other purpose without prior separate consent. If the purpose changes, we will take necessary steps including obtaining separate consent.

  • Service delivery — Food image analysis, nutritional calculations, and personalized health management
  • AI model improvement — Enhancing recognition engine performance, algorithm training, and new feature development based on user-provided data
  • Partner integrations — Sharing data with user-selected partners (gyms, pilates studios, clinics, etc.) for expert coaching
  • Paid service operation — Subscription billing, access management, fraud prevention, and purchase history
  • Marketing & advertising — Interest-based ads via AdMob, usage analytics, and event notifications
  • Community (friend sharing) — Sending and accepting friend requests, showing records and posts you share with friends, handling comments and likes, and processing reports and enforcement actions
2. Eligibility & Data Collected

This service is available to users aged 14 and above. We do not knowingly collect personal data from children under 14. Any accounts identified as belonging to children under 14 will be deleted immediately.

CategoryItems
Registration & Auth(Social) Apple / Google / Kakao unique identifiers, email address / (Direct) Email address
Health & Body DataHeight, weight, body composition (muscle mass, body fat %, etc.), meal photos, nutrient intake, and health records
Community (friend sharing)Nickname, friend relationships and friend requests, records you share with friends (meal and daily photos, notes, nutrition data, timestamps), posts, comments and replies you write, likes, and report and block records
Payments & SubscriptionsIn-app purchase confirmation numbers, subscription status, billing history
Auto-collectedAdvertising identifiers (ADID/IDFA), IP address, usage logs, access logs, cookies, device info (OS, model)
※ Health records and body composition data constitute sensitive personal data and are collected only with separate explicit consent at sign-up. Certain features may be unavailable without this consent.
※ Who can see community content — CaloNote has no public feed. Records, posts and comments you share are visible only to friends you have mutually accepted. Sharing of new records is on by default and can be turned off at any time under Profile > Auto-share; visibility in nickname search can be turned off under Profile > Allow nickname search. Removing a friend or turning off sharing for a record stops it from being shown.
3. Retention & Use Period

We delete personal data promptly upon account termination, except as outlined below.

CategoryRetention Period & Basis
Fraud prevention records6 months post-withdrawal (internal policy)
Payment & supply records5 years (Korean E-Commerce Act)
Contract / cancellation records5 years (Korean E-Commerce Act)
Consumer complaint records3 years (Korean E-Commerce Act)
Access logs3 months (Communications Privacy Act)
Community posts & commentsDeleted when you delete them or close your account (content under an open report or dispute is kept until the case is resolved)
Report & block records3 years after the case is closed (dispute handling and repeat-violation checks — internal policy)
Anonymized AI training dataRetained in irreversibly anonymized form for service improvement (no fixed retention period)
4. Third-Party Data Sharing

We share data with third parties only when users explicitly consent via a dedicated in-app consent screen.

CategoryDetails
RecipientsPartner fitness centers, clinics, and healthcare partners
PurposePersonalized diet coaching, workout guidance, professional consultations, and product recommendations
Data sharedBody data, meal photos, and nutritional analysis records
RetentionUntil the user disconnects the integration or withdraws from the service
5. Data Processing Delegation & Cross-Border Transfers
ServiceDetails
Infrastructure (GCP)Data storage and server operations
Ad analytics (Google AdMob)Targeted ad delivery and effectiveness analysis (cross-border transfer)
Authentication (Apple, Google, Kakao)Social login and identity verification
Cross-border transfers comply with applicable data protection laws, including GDPR Standard Contractual Clauses (SCCs) where required.
6. Data Deletion

Personal data is deleted promptly once it is no longer necessary. Electronic files are destroyed using technical methods that prevent recovery or reconstruction.

You can delete your data yourself in the following ways:

  • Individual records, posts and comments — tap the more menu (⋯) on the item > Delete
  • Stop showing a record to friends — turn off sharing on the record, or turn off Profile > Auto-share
  • Your account and all data — Settings > Delete account, in the app
  • If you cannot use the app — request it on the web account deletion page
7. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access, correction, or deletion of your personal data
  • Restriction of processing
  • Data portability (GDPR users)
  • Right to object to automated decision-making / profiling
  • Withdrawal of consent at any time (without affecting prior lawful processing)
Cookies and advertising identifiers (ADID/IDFA) can be opted out via your device settings. Opting out may limit personalized ad delivery.

Certain data may be retained beyond your deletion request where required by applicable law. If you cannot install or use the app, you can submit a request on the account deletion page.

To exercise any of your rights, contact us at: support@calonote.com. We will respond within 30 days.

8. Legal Basis for Processing (GDPR)

For users in the European Economic Area (EEA) and United Kingdom, we process personal data on the following legal bases:

Processing ActivityLegal Basis
Account management & core servicePerformance of a contract (Art. 6(1)(b) GDPR)
Health & body dataExplicit consent (Art. 9(2)(a) GDPR)
Payments & fraud preventionLegal obligation / Legitimate interests (Art. 6(1)(c)(f) GDPR)
Marketing & analyticsConsent (Art. 6(1)(a) GDPR)
AI model training (anonymized)Legitimate interests (Art. 6(1)(f) GDPR)
9. Security Measures

We implement technical and organizational measures to protect your personal data, including SSL/TLS encrypted data transmission, access controls, and anti-intrusion security systems.

10. Privacy Officer & Contact
CategoryDetails
Privacy OfficerYUNHO NOH (CEO)
TeamCaloNote Operations Team
Emailsupport@calonote.com
11. Policy Updates

This policy is effective as of August 7, 2026. Material changes will be notified at least 30 days in advance; other changes 7 days in advance, via in-app notices.

Effective DateSummary of Changes
August 7, 2026Added disclosures for the community (friend sharing) feature — data collected (nickname, posts and comments, shared records, report and block records), who can see it, retention periods, and how to delete it
March 23, 2026Initial version