Privacy Policy — Android App Addendum
Last updated: October 4, 2026
← Back to common Privacy Policy
This English translation is provided for reference only. The Japanese version is the authoritative and legally binding version.
This addendum covers privacy information specific to the kalori Android app (the "App"), in addition to the common Policy.
Article D1 (Android Permissions)
The App uses the following permissions, requested through the standard Android screens when you first use the related function:
- Camera: capturing meal and menu photos and scanning barcodes. Barcodes are read on your device
- Photo selection: the App uses the Android photo picker and receives only the photos you choose. It does not request access to all photos on your device
- Notifications (Android 13 and later): meal reminders, photo analysis results, and announcements (Article D6)
- Health Connect: with your permission, the App reads the information described in Article D2
- Location (while using the App): showing the map and choosing a nearby store (Article D9). The App does not collect location in the background or track your movements
You can revoke each permission at any time in Android Settings. A related function may become unavailable when its permission is disabled.
Article D2 (Health Connect)
Only if you allow the App to connect with Health Connect (Android's system for sharing health information), the App reads the following information from Health Connect. You grant permission for each data type in Health Connect and can revoke it at any time.
- Data read: steps, active calories burned, body weight, and body fat percentage. The App does not read records that the App itself wrote to Health Connect
- Purpose: steps and active calories burned are used as exercise-calorie records for each part of the day, and body weight and body fat percentage as weight records, for your records, goal calculations, and trend displays in the App. For this purpose, the values read are sent to our servers and stored as your exercise and weight records (weight for the last seven days, and on first connection, from 14 days before your registration date)
- Writing: the App currently does not write data to Health Connect. If we add such a function, we will update this addendum and ask for your permission again
- Disclosure and sharing: we do not sell information obtained from Health Connect, use it for advertising or marketing, or use it to determine creditworthiness, insurance eligibility, or employment. We share it with third parties only through your own actions and consent: (1) when you consent to share your records with a gym or trainer (Article 5 of the common Policy; shown as exercise and weight records), and (2) when you enable an integration with a chat AI or other external service and direct it to read your records (Article 3 of the common Policy). Values obtained from Health Connect are not sent for usage analytics (Article D3); only whether the connection succeeded is recorded
- Retention and deletion: imported records are kept until you delete them or delete your account (Article 8 of the common Policy). Revoking Health Connect permission does not delete records already imported. You can delete exercise records in the App, and you can request deletion of other records under Article 11 of the common Policy
- Security: data is encrypted in transit (HTTPS) and stored in encrypted storage on our servers. Access is limited to the personnel and systems that need it (Article 9 of the common Policy)
Article D3 (Usage Analytics and Diagnostics)
To improve quality, maintain security, and investigate technical issues, the App collects the following:
- Firebase (Google LLC): we use Google Analytics for Firebase to analyze screen views, actions, and other usage. Firebase collects a per-installation identifier, device model, operating system and language, app version, and approximate region inferred from the IP address. Usage information we send to Firebase may include part of a search term and values associated with record actions (weight, exercise, and goal values you enter, and purchased products and amounts). We do not send names or email addresses to Firebase and do not link Firebase data to your account. See How Google uses information from sites or apps that use our services
- Records on our servers: the same usage information is also recorded on our servers and, after sign-in, may be associated with your account
- Diagnostics: when the App crashes, stops responding, or fails to communicate, details (error type, location, device model, OS and app versions, and time) are sent to our servers
- Device identifier: an identifier created for each installation of the App (it changes when you reinstall) is attached to communications with our servers and used to detect unauthorized sign-ins and maintain security
Article D4 (Advertising)
The App currently does not use third-party advertising services, does not collect the advertising ID, and does not track activity across other companies' apps or websites for advertising. If this changes, we will update this addendum and request permission when required.
Article D5 (Purchases through Google Play)
Subscription purchases and renewals are processed through Google Play's billing system. We receive purchase and subscription-status information necessary to provide Premium features (information used to verify the purchase, the product, and the subscription status) from Google and use it to verify eligibility and prevent misuse. We do not receive card numbers or similar payment details.
When you make a purchase, we pass Google Play a value derived irreversibly from your account identifier, to prevent purchases from being improperly transferred to another account. Purchase records (product, amount, currency, and order number) are also recorded for usage analytics (Article D3).
Deleting your kalori account does not automatically cancel your Google Play subscription. Cancel it in the Google Play Store app under "Payments & subscriptions" → "Subscriptions".
Article D6 (Notifications)
With your permission, the App displays meal reminders and other notifications. Push notifications for announcements are delivered through Firebase Cloud Messaging (Google LLC); for delivery, your device's notification identifier is registered with our servers. You can turn off each type of notification in Android Settings.
Article D7 (On-Device Data Storage)
The App stores information on your device as needed to maintain sign-in state, save settings, improve display performance, and show home-screen widgets. Authentication information is encrypted with the key protection provided by Android (Android Keystore). This information is excluded from device backups and device-to-device transfers.
Article D8 (Meal Chat)
The App's "Meal chat" (a feature in beta) handles information as follows.
- Generating replies: replies are generated by Google's AI model that runs on your device (Gemini Nano). The text you enter, photos you attach, screen information (date, meal slot, products shown, and so on), and results of our tools (product search results and your meal, weight, goal, and other records) are processed on your device to generate replies and are not sent to Google. Google's ML Kit, which provides this function, sends Google usage information that does not include what you entered (such as device model, OS, processing performance, and error types)
- Tool calls: when needed to generate a reply, the App calls functions on our servers (searching products and reading or creating meal, weight, goal, and other records). The contents of these calls (search terms, target dates, and so on) are sent to our servers
- Photo analysis and nutrition estimates: when you choose "Analyze photo", or when nutrition is estimated from a dish name, information is sent to external AI providers contracted by the Company as described in Article 3 of the common Policy
- Stored photos: a photo you choose to analyze is stored on our servers at the time of analysis, together with the result, as one of your food records — even if you do not record a meal from it. You can delete the photo and result from Food Management in My Page. If you choose "Keep the photo" for a recorded meal, the photo is attached to that meal record and is deleted together with the meal. These photos are handled like any other meal photo; if you share your records with a gym or trainer, they are shown to them as described in Article 5 of the common Policy. A photo you only attach to the conversation is not sent to our servers.
- Saved conversations: to let you reopen conversations and to improve the quality of the Service, we store conversation history (your messages, the replies, and the record lists and summaries shown alongside replies) on our servers. Conversation history does not include photos; we record only that a photo was attached. Our staff may review conversation content, to the extent necessary, to improve quality. You can delete conversations one at a time from the history screen, and all of them are deleted when you delete your account. Deleting a conversation does not delete the meal or food records and photos created from it; you can delete those from their own screens.
- Usage information: to manage usage limits and improve quality, we record for each exchange the model used, its outcome, duration, and the number of tool calls. This record does not include conversation content. Calls to our tools made from the conversation (the tool called, search terms, result counts, and outcome) are kept in the same way as your other usage records.
Records are created, changed, or deleted only after you confirm on screen. This feature is in beta and available only on supported devices; its content and handling may change, and if so we will update this addendum.
Article D9 (Location and Maps)
- Use of location: with your permission, the App uses your device's location while the App is in use to show the map and choose a nearby store. The App does not continuously track your location (no background collection, no movement tracking). Precise coordinates are never sent to our servers
- Search records: to understand which area a search was made in, we store an approximate location (coarsened to roughly a 1 km square) alongside the search record. This coarse location is removed from the search record after 90 days, and search records are deleted entirely when you delete your account. If provided to third parties for statistics or analysis, it is first coarsened further (to roughly a 20 km square or larger) and shared only as aggregated values that cannot identify an individual
- Store information: when you choose a store on the map and record a meal, information identifying that store (its Google Maps place ID) is stored with the meal record
- Google Maps: the map is provided by Google Maps (Google LLC). When the map is shown, Google collects device information, the IP address, and similar information. Use of the map is subject to the Google Maps/Google Earth Additional Terms of Service and the Google Privacy Policy