Cal OtterCal Otter

Privacy Policy

Last Updated: August 16, 2026

This Privacy Policy describes how Lumina Impact Pte Ltd (“Cal Otter,” “Company,” “we,” “our,” or “us”) collects, uses, discloses, and otherwise processes personal information when you use Calorie Tracker – Cal Otter (the “Service”), and the choices available to you.

1. Overview

This Policy forms part of our Terms of Service. Terms not defined here are defined in the Terms of Service.

Cal Otter stores your profile, meal history, weight logs, goals, and related app data in our cloud database so the Service can work across sessions and devices. Photo-based food analysis also sends images and related inputs to our cloud storage and third-party AI processors. An internet connection is required for core features.

If you reside in the European Economic Area, Switzerland, the United Kingdom, California, or other jurisdictions with specific privacy laws, please also see Additional Information for Certain Jurisdictions.

2. Personal Information We Collect

We may collect personal information directly from you, automatically through your use of the Service, and from third parties you choose to connect.

2.1 Information You Provide

  • Profile and body metrics. Name (optional), date of birth or age, height, weight, desired weight, weekly weight change preference, unit system preferences, fitness or diet goals, and related onboarding answers (for example accomplishments, obstacles, or diet preferences).
  • Food and activity data. Meal photos, barcode lookups, food names, calorie and macronutrient estimates, ingredients, dietary habits, nutrition goals, weight logs, and optional progress or before/after photos. Food and activity data may include sensitive personal information when it indicates or allows someone to infer a health condition.
  • Communications. Information you include when you contact support (for example by emailing help@luminaimpact.co), such as your email address and the content of your message.
  • Preferences. Notification preferences (including meal reminder times), app settings, and similar choices.
  • Payment information. If you purchase a subscription or in-app product, purchases are processed by third-party platforms such as the Apple App Store or Google Play Store. We do not receive your full payment card details; those platforms’ terms govern payment processing, renewals, and refunds.

2.2 Information Collected Automatically

  • Device and usage data. When the Application contacts our servers (for example syncing profile or meal data, uploading a meal photo, or requesting analysis), we may receive technical information such as IP address, device type, operating system, app version, request timestamps, and basic diagnostics needed to operate and secure the Service.
  • User identifiers. The Application may generate a user identifier so your data can be stored and retrieved in our cloud database and associated with that Device. This identifier is not an email login.
  • Product analytics. We use PostHog, a product analytics provider, to understand how the Application is used (for example screens viewed, onboarding progress, scan and subscription events). This may include a device-generated user identifier, device type, operating system, app version, and event names. We do not use PostHog to show ads, and we do not send Apple HealthKit data or meal photos to PostHog.
  • Website cookies. If you visit our Website, we or our hosting providers may use cookies or similar technologies that are necessary for the site to function, for security, or for basic analytics. You can control cookies through your browser settings.

2.3 Information From Third Parties

  • Apple Health (HealthKit). With your permission on iOS, we may read and write weight data from Apple Health. See Apple Health and Connected Health Data.
  • Open Food Facts and similar food databases. When you scan a barcode, we may retrieve publicly available product and nutrition information from third-party food databases.
  • App stores. Purchase status, subscription state, and related receipts may be provided by Apple or Google when you buy or restore a subscription.
  • Service providers. Providers that host our database and object storage, run AI analysis, or help us operate support and infrastructure may return technical or processed results necessary to provide the Service.

2.4 Aggregated, De-identified, or Anonymized Information

We may aggregate, de-identify, or anonymize information so that it is no longer personal information under applicable law. We may use and disclose such information for purposes consistent with this Policy or as otherwise permitted by law.

3. How We Use Personal Information

  • Provide the Service. Create and maintain your profile in our cloud database, log meals and weight, estimate nutrition from photos or barcodes, sync optional Health data, and deliver local meal reminders you enable.
  • Operate AI food analysis. Process meal images and related inputs to identify foods and estimate calories and macronutrients. See AI Processing of Meal Images.
  • Personalize your experience. Calculate plans, goals, BMI estimates, progress views, and recommendations based on information you provide.
  • Communicate with you. Respond to support requests and send administrative notices about the Service, Terms, or this Policy when appropriate.
  • Improve and develop the Service. Debug issues, improve accuracy of food recognition and nutrition estimates, develop new features, and maintain quality, including through machine learning and artificial intelligence systems as described in our Terms.
  • Security and integrity. Prevent fraud, abuse, unauthorized access, and other misuse; protect users, the Company, and the Service.
  • Legal compliance. Comply with applicable laws, respond to lawful requests, enforce our Terms, and establish, exercise, or defend legal claims.
  • Business transactions. Evaluate or complete a merger, acquisition, financing, reorganization, or sale of assets where personal information may be among the assets transferred.

We do not use Apple HealthKit data for marketing or advertising, and we do not sell personal information for money. See Apple Health and Connected Health Data and Your Privacy Rights.

4. How We Disclose Personal Information

We disclose personal information to the categories of recipients below, only as needed for the purposes in this Policy:

  • Service providers. Vendors that provide hosting, managed cloud databases (including Neon, currently hosted in Frankfurt, Germany), cloud object storage (including Cloudflare R2), AI model inference (including Anthropic Claude, OpenAI GPT, Google Gemini or similar providers), product analytics (PostHog), customer support tooling, infrastructure, security, and professional advisors.
  • Food data providers. When you look up a barcode, your request may be sent to Open Food Facts or a similar database to retrieve product nutrition information.
  • App platforms. Apple, Google, and related store services for distribution, permissions, Health integrations, and in-app purchases where applicable.
  • Legal and safety recipients. Law enforcement, regulators, courts, or other parties when required by law or to protect rights, safety, and the Service.
  • Business transferees. Counterparties and advisors in connection with a corporate transaction as described above.
  • With your direction. Other parties when you ask us to share information or otherwise provide consent.

Cal Otter does not currently offer public community forums, groups, or social feeds. If we introduce public-facing features later, any information you choose to post there may be visible to others as described at that time.

5. Apple Health and Connected Health Data

Information you choose to share from Apple HealthKit is governed by Apple’s terms and privacy policy in addition to this Policy. HealthKit data is used only to provide health, fitness, and nutrition features you request—primarily reading and writing weight.
  • We do not use HealthKit information for marketing or advertising.
  • We do not transfer HealthKit information to third parties for marketing, advertising, or product analytics (including PostHog).
  • You can revoke Health access at any time in iOS Settings → Privacy & Security → Health.

If we later support Android health platforms (such as Health Connect), similar limitations will apply to data obtained from those platforms.

6. AI Processing of Meal Images

When you use photo-based food logging, your image (and related request metadata such as IP address for security and routing) may be uploaded to our cloud object storage and processed by AI providers to estimate foods, calories, and macronutrients. Structured results (such as food names and nutrition estimates) are stored with your other meal data in our cloud database.

  • Do not upload images of other people without lawful consent, or images containing sensitive content unrelated to food logging.
  • AI outputs are automated approximations and may be inaccurate. See the health disclaimers in our Terms.
  • As described in the Terms, User Content may be used to operate and improve the Service, including training or improving AI models, subject to applicable law and this Policy.

7. International Transfers

Lumina Impact Pte Ltd is based in Singapore. Your profile, meal history, weight logs, goals, and related structured app data are stored in our primary database hosted in the European Union (Frankfurt, Germany) by Neon. Other service providers may process data in Singapore, the United States, the European Economic Area, and other countries—for example when you upload meal images to cloud object storage or when AI providers analyze those images. As a result, your personal information may be transferred to jurisdictions with privacy laws that differ from those in your country of residence.

When we transfer personal information internationally, we do so in accordance with applicable law and take steps designed to protect your information. While outside your home jurisdiction, your information may be subject to local laws, including lawful access by courts, law enforcement, or regulators in those countries.

8. How We Protect Your Information

We maintain reasonable technical, organizational, and administrative safeguards designed to protect personal information under our control from loss, misuse, and unauthorized access, disclosure, alteration, and destruction. Personal information is transmitted to and stored with cloud service providers we engage to operate the Service. No method of transmission or storage is completely secure. Please use device passcodes, keep your OS updated, and contact us if you believe your account or data has been compromised.

9. How We Retain Your Information

We retain personal information only as long as needed for the purposes in this Policy, including to operate the Service, comply with legal obligations, resolve disputes, and enforce agreements, unless a longer period is required or permitted by law.

Profile, meal, weight, settings, and related data stored in our cloud database remain until we fulfill a verified deletion request, or until we no longer need them for the purposes above. Uninstalling the Application from your Device does not by itself delete data stored on our servers. The Application may also keep a temporary local cache on your Device; that cache is cleared when you clear app data or uninstall (subject to OS backup behavior). Images and analysis requests processed in cloud object storage or by AI providers are retained only as needed to provide, secure, and improve the Service, then deleted or de-identified according to our retention practices.

If we de-identify information, we will maintain and use it in de-identified form and will not attempt to re-identify it except as required or permitted by law.

10. Children's Privacy

The Service is not directed to children under 13. Consistent with our Terms, you must be at least 13 years old to use the Service. If you are between 13 and 17, you may use the Service only with the consent and supervision of a parent or legal guardian.

If we become aware that we have collected personal information from a child under 13 without appropriate consent, we will take steps to delete that information. Parents or guardians may contact us at help@luminaimpact.co.

If you reside in the EEA, Switzerland, or UK and applicable law imposes a higher digital age of consent, you should not use the Service below that age without required parental authorization.

11. Your Privacy Rights

Depending on where you live, you may have rights regarding your personal information, including rights to:

  • Access and portability — confirm whether we process your information and obtain a copy in a portable format where technically feasible.
  • Deletion — request deletion of personal information, subject to legal exceptions.
  • Correction — request correction of inaccurate personal information.
  • Limit or object to certain processing — including, where applicable, opting out of “sale,” “sharing,” targeted advertising, or certain profiling as those terms are defined by law.
  • Withdraw consent — where processing is based on consent, withdraw it without affecting prior lawful processing.
  • Non-discrimination — we will not discriminate against you for exercising privacy rights available to you.
  • Appeal — where required by law, appeal our decision on a privacy request by emailing us with “APPEAL” in the subject line.

How to exercise your rights

Email help@luminaimpact.co and describe the request you wish to make. We may need to verify your identity before fulfilling a request. Where permitted, you may submit a request through an authorized agent; we will need to verify the agent’s authority.

You can delete your account and associated app data from Settings → Delete account in the Application. You may also email help@luminaimpact.co to request deletion of personal information we hold on our servers. Uninstalling the Application alone may not delete server-stored data.

12. Additional Information for Certain Jurisdictions

12.1 California (CCPA/CPRA)

California residents have rights to know/access, delete, correct, and opt out of certain “sales” or “sharing” of personal information, and to limit use of sensitive personal information, subject to exceptions.

Categories of personal information we may collect include: identifiers (such as user/device IDs and IP address); protected classification characteristics (such as age range or gender if provided); commercial information related to purchases or subscriptions; internet or electronic activity related to Service use; approximate geolocation inferred from IP; audio/visual information such as meal or progress photos; inferences drawn from profile and usage data; and sensitive personal information such as health and nutrition data you input.

We collect these categories from you, your Device, service providers, food databases, and (with permission) Apple Health. We use them for the business purposes described in Sections 3 and 4. We do not sell personal information for money. Certain disclosures to advertising or analytics partners—if enabled in the future—could be considered a “sale” or “sharing” under California law; you may opt out by contacting us.

To exercise California rights, contact help@luminaimpact.co. “Shine the Light” requests for information about disclosures for direct marketing purposes may be sent to the same address.

12.2 EEA, Switzerland, and United Kingdom

For applicable data protection laws, Lumina Impact Pte Ltd is the controller of personal information processed in connection with the Service. Our primary application database is hosted in the EU (Frankfurt, Germany); other processing by service providers may occur outside the EEA as described in Section 7.

Lawful bases we rely on may include:

Processing activityLawful basis
Provide and manage the ServicePerformance of a contract; consent for sensitive health or nutrition data where required
AI meal image analysis and product improvementPerformance of a contract; legitimate interests in improving accuracy and features; consent where required for sensitive data
Support and service communicationsPerformance of a contract; legitimate interests
Security, fraud prevention, and abuse detectionLegitimate interests; legal obligation where applicable
Legal compliance and dispute handlingLegal obligation; legitimate interests
Marketing communications (if any)Consent where required; otherwise legitimate interests

You may have rights of access, rectification, erasure, restriction, objection, portability, and withdrawal of consent, and the right to lodge a complaint with your local supervisory authority. Contact us at help@luminaimpact.co to exercise these rights.

12.3 Singapore

We process personal data in accordance with Singapore’s Personal Data Protection Act 2012 (PDPA) and related regulations. You may contact us to access or correct your personal data, or to withdraw consent where processing is based on consent, subject to legal and contractual limits. Withdrawal of consent may mean we cannot continue providing certain features.

12.4 Canada

Where Canadian law applies, we generally collect, use, and disclose personal information with your consent (express or implied) or as otherwise permitted by law. You may request access to or correction of your information, and you may contact the relevant privacy commissioner if you have unresolved concerns.

13. Changes to This Policy

We may update this Privacy Policy from time to time. The “Last Updated” date at the top will change when we do. Material changes will be communicated through reasonable notice, such as an in-app notice or an update on this page. Continued use of the Service after an update becomes effective constitutes acceptance of the revised Policy, except where applicable law requires additional consent.

14. Contact Us

If you have questions or concerns about this Policy or our privacy practices, contact us at: