Privacy
Effective September 25, 2026.
The short version: ZenCal asks for an account to work, and the account holds little — your plan, with your current weight, and the address of the photos you sent for analysis. Your meals and your weight history stay on your device. What leaves it is what has to for the analysis to happen: the photo of the plate, the audio when you log by speaking, and the food name when you search.
What stays on the device only
Logged meals, weight history, progress photos, language and theme. None of it is sent to us, and none of it exists on any server. Deleting the app deletes it with the app. Your plan and your onboarding answers — your current weight among them — live here too, and they are what goes up to your account, along with the address of the photos: that is what carries them to another phone.
What leaves the device
- The meal photo. It goes to our server, which sends it to a vision model through OpenRouter (today, Google Gemini) and returns the estimate. The photo is kept in our storage under a random name, linked to your account — not inside the image, which carries nothing, but through its address in storage. That is what lets us hand it back to you on a new device, and what lets us delete it along with the account. The copy the app shows day to day is the one on your device; the server is only asked when that one is gone.
- The audio, when you log by speaking. Same path, to become text and numbers. The audio is not stored: it is gone as soon as the answer comes back.
- The exercise description, when you type or speak a workout, along with your current weight — that is what the energy estimate is worked out from. Neither is stored.
- The term you search or the barcode you scan. Our server queries Open Food Facts and the USDA database and returns the result. We query on your behalf instead of letting the app query directly — that way the external databases see our server, not your device.
- Your device language, along with the request, so the dish name and ingredients come back in your language.
Your account
An account is required to use ZenCal, and it does two things: it carries your plan to another phone, and it lets your photos come back when the phone is a different one. It holds little, and the little is listed here.
- You sign in with Apple, Google or email. From Apple and Google we receive the account identifier and the email address — which may be Apple’s relay address, if you choose to hide yours.
- On the email path you set a password, and we ask for a name to call you by. The password is never kept the way you typed it: we keep only its scrambled form, which does not turn back.
- We also keep the onboarding answers — your current weight, height, goal, pace, your daily targets and the referral code, if you typed one. Your current weight is your most recent weigh-in, including one that came from Apple Health or Health Connect. That is what comes back when you sign in on another phone.
- And the address of the photos you sent for analysis — their key in our storage, so that we can hand them back to you and delete them with the account.
- Meals and weight history stay on the device. They are not uploaded to the account — what goes up is the plan, not the diary.
- We do not send news by email. The address is for signing in and for replying when you write to support.
Deleting the account happens inside the app, under Profile › Delete account — or, before subscribing, through the link at the bottom of the plans screen: it goes at once, with no grace period and no screen asking you to stay. The photos that were in our storage go with it.
Apple Health and Health Connect
The connection is optional and you choose whether to turn it on. It exists so both sides of your day meet in one place: what you burned comes in without you logging every workout, and what you logged here shows up there alongside the rest of your health.
- We read active energy, weight and workouts, and nothing else — no steps, no heart rate.
- We write what you log here, and nothing else: the calories and nutrients of each meal, your exercises and your weigh-ins. Fixing a meal fixes the entry there; deleting it deletes it there too.
- What has been written stays yours. Turning the connection off stops the app from writing, but it does not go sweeping months out of your health history — that is your record, and you are the one who clears it, from the Health app itself.
- The exchange happens between ZenCal and Health, on your phone, and nothing that comes from there is sent to any third party. There is one exception, and it goes to your account: your most recent weigh-in — from Health or typed here — becomes the current weight in your plan, and the plan is also kept in your account. Active energy, workouts and your weigh-in history do not go up.
- You can revoke it whenever you want, without going through us: on iPhone in Settings › Health › Data Access & Devices, and on Android in the Health Connect app.
Purchases
The subscription is processed by Apple or Google and managed through RevenueCat. They receive an anonymous device identifier and the subscription state — whether it is active, when it renews, whether it is in trial. Payment details stay with the store: they never pass through the app or through us.
Advertising
We advertise ZenCal on Facebook and Instagram, and the app carries the Meta SDK to tell whether an ad led to the install. That is the only reason it is here: ZenCal shows no ads at all.
- What it sends: that the app was installed and opened, the end of onboarding and the creation of the account, along with the device model and OS, the language, the IP address and an anonymous identifier the SDK itself creates. Through RevenueCat, also the start of the free trial and the subscription, with the plan’s price.
- What it does not send: meals, photos, weight, goals, onboarding answers, e-mail or name. Nothing you log in the app reaches Meta.
- The advertising identifier (IDFA on iPhone, GAID on Android) only goes along if you allow it. On iPhone the system asks once, during onboarding, and “Ask App Not to Track” is a complete answer: the app stays the same. You can change it later in Settings › Privacy & Security › Tracking. On Android, the identifier can be deleted in Settings › Google › Ads.
- Meta handles what it receives under its own privacy policy, and may link it to your Facebook or Instagram account to measure the ad. The ad preferences of your Meta account control that side.
What we do not do
- We do not sell, rent or trade data with anyone.
- We show no advertising and build no advertising profile.
- We embed no audience-measurement or session-replay tool. The only third-party SDK that measures anything is Meta’s, for the ads, and the section above says what it sees.
- We do not follow you across other apps or websites. What Meta does with what it receives is in the section above and in its policy.
Who processes data with us
- OpenRouter and the model provider (today, Google) — analyze the photo and the audio and return the estimate.
- Railway — hosts the server and the photo storage, in the United States region.
- Open Food Facts and USDA FoodData Central — answer the food lookups.
- RevenueCat, Apple and Google — handle the subscription, and the last two also handle sign-in when you choose them.
- Meta — receives the install, open and subscription signals, from the SDK and from RevenueCat, to measure the ads.
How long we keep it
The photo stays in storage for as long as your account exists. Deleting the account deletes the photos with it, with no request and no waiting. To remove a specific photo without deleting the account, write to support with the date and time of the log.
Your rights
Brazil’s LGPD and the European GDPR grant you access, correction, deletion and portability. If you have an account, deleting everything is immediate in Profile › Delete account. For anything outside it, write to support: we answer within seven days.
Children
ZenCal is not directed to children under 13, and we do not knowingly collect data from anyone in that age range.
Changes
When this policy changes, the effective date at the top changes with it, and the previous version stops applying from that point. Any change to what leaves your device is announced inside the app.
Questions, data removal requests or anything else: matheus@tonelotto.com.