KcalNow Privacy Policy (Draft)
Last updated: October 10, 2026
Operator: KcalNow (brand name; interim until a registered legal entity is set)
Contact email: support@mealnow.top
Website: https://mealnow.top
This document is a product template draft and does not constitute legal advice. Replace every placeholder before public release, and have qualified counsel review it.
1. Introduction
Welcome to KcalNow (“the App,” “we,” or “us”). This policy explains how we collect, use, store, share, and protect information related to you. It applies to the KcalNow iOS app and our official website (including the privacy and terms pages at https://mealnow.top).
Please read and understand this policy before using the App or related services. Checking “I agree” in the App means you acknowledge this policy. If you disagree, stop using the service.
Calorie and nutrition recognition results are estimates only and are not medical, diagnostic, or dietary prescriptions.
2. Information we collect
Depending on which features you use, we may process:
2.1 Account and sign-in
- When you use Sign in with Apple, we may receive an Apple identifier, email address (real or Apple private relay), and any name you provide.
- Session credentials used to keep you signed in (access tokens, refresh tokens and their hashes).
- Note: email/password registration and sign-in have been removed. Legacy password accounts, if any, may only be linked when the email matches Sign in with Apple; password login is not offered.
2.2 Meal recognition and food log
- Meal photos you capture or pick from the library (JPEG, server limit about 5MB): used to recognize foods and estimate calories. Recognition requests are processed in server memory; we do not keep the original full-size image as a long-term food-log archive.
- For cost control and ops, the server may retain recognition-related thumbnails and cost logs (with user id, model usage, and similar fields) for about 30 days, then prune them.
- Cloud food log: entry time, meal slot, food names / portions / calories and related structured data. Server food-log rows do not include the on-device thumbnail files.
- On device: food-log thumbnails, favorite meals, and similar content may be stored locally and are not synced to our servers by default.
2.3 Goals, habits, and client-side features
- Daily calorie goals, streak check-ins, meal-quest progress, weekly report display and share cards, and similar stickiness features are computed and shown mostly on device. Some interactions are reported via analytics (below).
- Weekly share images are created when you choose to share. Non-subscribers may be blocked from sharing. Content you share to third-party apps is governed by those apps’ policies.
2.4 Push and reminders
- Scan reminder settings: local time, timezone, repeat rules, and enabled state.
- APNs device tokens and app version, used to send reminders at the times you configure.
- You can turn off notifications in system settings or manage reminders in the App.
2.5 Subscriptions and entitlements
- Auto-renewable subscription transaction data from Apple App Store / StoreKit (for example product id, transaction identifiers, expiry time, environment).
- After purchase, restore, or entitlement refresh, the App may sync Apple’s transaction JWS to our servers so we can verify premium entitlements (for example recognition quota, ad removal, certain share features).
- Apple may also send App Store Server Notifications V2 (renewal, expiry, refund, revoke, and similar). We update entitlement status from those notifications.
- Payment card details are handled by Apple; we do not collect full card numbers.
2.6 Advertising (free tier)
- Free users may see Google AdMob ads (banner, interstitial, app open, and similar). The ads SDK may collect device and advertising identifiers, coarse location, and interaction data under Google / Apple rules.
- We keep server-side counters for free “skip ad” style quotas used in ad policy.
- Subscribers may be exempt from some or all ads per product design.
2.7 Analytics and diagnostics
- Product analytics events such as app launch, screen views, button clicks, recognize start / success / fail, auth-related events, reminders, paywall, share, and streak.
- Events may include an install-scoped
device_id, session id, app version and build, OS and OS version, optional user id, and event properties. - Raw analytics events are retained for about 90 days, then purged.
- Separate ops logs (performance / errors) and recognition cost logs (cost logs about 30 days) support reliability and spend monitoring.
2.8 Feedback and support
- In-app feedback text, optional contact info, and app version; plus messages you send to
support@mealnow.top.
2.9 Device permissions
With your permission, the App may access camera, photo library (meal photos), and notifications (scan reminders). You can revoke these in system settings at any time.
2.10 What we do not require
We do not require sensitive personal information unrelated to the service. Please do not submit other people’s personal data in feedback.
3. Purposes of collection and use
We process information to:
- Create and maintain accounts, and provide sign-in and food-log sync;
- Provide core features such as meal recognition, calorie estimates, diet tips (text generation from today’s summary), and reminder pushes;
- Verify subscription entitlements and enforce free-tier quotas and ad policy;
- Protect security, prevent abuse, troubleshoot issues, and control recognition cost;
- Improve the product using aggregated or de-identified data;
- Respond to your rights requests and comply with law.
Diet tips and recognition results are for personal reference only and are not a substitute for licensed medical or nutrition professionals.
4. Storage, retention, and security
- Account data, food log, reminder settings, push tokens, and subscription entitlements are kept as long as needed to provide the service. After you delete your account, we delete or anonymize account-linked data except where law requires otherwise. Subscription rows may be unbound from the user on account deletion; your relationship with Apple purchases remains under Apple’s rules.
- Analytics ≈ 90 days; cost / thumbnail logs ≈ 30 days; push fire logs are kept for a limited time for idempotency and debugging.
- We use reasonable technical and organizational safeguards. No internet transmission or storage is perfectly secure.
5. Third-party services
To operate the service we may use third parties such as (vendors may change with architecture; verify before launch):
| Category | Purpose (summary) |
|----------|-------------------|
| Apple (Sign in, App Store, StoreKit, APNs, ASSN) | Sign-in, subscription payment and receipts, push, subscription status notifications |
| Cloud hosting and databases | App backend and data storage (production API host example: api.mealnow.top) |
| LLM / vision recognition APIs | Meal recognition and diet-tip text (images or text summaries may be sent to model providers) |
| Vector search and embeddings (e.g. Qdrant and OpenAI-compatible embedding APIs) | Food catalog recall; mainly catalog data, not your identity |
| Google AdMob | Ads for free-tier users |
We share information only as needed to provide the service and require appropriate safeguards. Please also review Apple’s and Google AdMob’s privacy policies.
6. Sharing, transfer, and disclosure
We do not sell your personal information. Without your consent we do not share information that identifies you with third parties, except when:
- You give clear consent;
- Processing is delegated as needed to provide the service (under contract);
- Required by law, regulation, or legal process;
- Necessary to protect significant legitimate interests of users, us, or the public.
7. Your rights
Where applicable law allows, you may:
- Access and correct account and service data about you;
- Delete your account from App settings (server account-deletion API). Cloud food log and related data are cleaned with the account; on-device data requires uninstalling or clearing the App;
- Manage camera, photos, and notification permissions in system settings; manage scan reminders in the App; manage subscription cancel / refund through the App Store (Apple’s rules apply);
- Withdraw consent where processing is based on consent (this may limit features);
- Contact us about privacy questions at
support@mealnow.top.
We will respond within a reasonable time required by applicable law.
8. Children
The App is not directed at children under the minimum age required by applicable law. If you believe a child has provided personal information, contact us and we will take appropriate steps, including deletion where appropriate.
9. International transfers
Your information may be processed on servers outside your country/region (for example cloud hosts or model providers). Where required, we use appropriate safeguards for cross-border transfers.
10. Changes
We may update this policy. Material changes will be announced on the website or in the App. Continued use after the effective date means you accept the updated policy (unless law requires re-consent). In-app consent is tied to the version string at the end of this document; a version bump may require you to agree again.
11. Contact
Operator: KcalNow (brand placeholder)
Email: support@mealnow.top
Website: https://mealnow.top
Policy version: privacy-2026-10-10