1. Overview
HIPAA Compliance: Caloria is committed to protecting your health information in accordance with applicable privacy laws, including HIPAA where applicable.
No Third-Party Sharing: We never sell, rent, or share your personal health data with third parties for marketing purposes.
Data Minimization: We only collect and process data necessary to provide our nutrition tracking services.
Caloria ("we," "our," or "us") provides AI-powered nutrition tracking services through Telegram. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.
By using Caloria, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, do not use our services.
5. Data Security
5.1 Technical Safeguards
- Encryption: All data transmitted and stored is encrypted using industry-standard protocols
- Access Controls: Strict role-based access controls limit who can view your data
- Secure Infrastructure: Our servers are hosted in secure, HIPAA-compliant data centers
- Regular Audits: Periodic security assessments and vulnerability testing
- Data Backup: Secure, encrypted backups with disaster recovery procedures
5.2 Organizational Safeguards
- Employee training on privacy and security practices
- Signed confidentiality agreements for all staff
- Incident response procedures for potential breaches
- Regular privacy impact assessments
5.3 Data Retention
We retain your personal data only as long as necessary to provide our services and comply with legal obligations:
- Active Users: Data retained while your account is active
- Inactive Users: Data deleted after 3 years of inactivity
- Legal Compliance: Some data may be retained longer to comply with legal requirements
6. Your Rights
6.1 Data Subject Rights (GDPR)
If you are in the European Union, you have the following rights:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your personal data
- Portability: Receive your data in a machine-readable format
- Restriction: Limit how we process your data
- Objection: Object to certain types of processing
- Withdraw Consent: Remove consent for data processing
6.2 How to Exercise Your Rights
To exercise any of these rights, contact us at:
- Email: privacy@caloria.vip
- Telegram: Send "DELETE MY DATA" to our bot
- Admin Panel: Request data deletion through our interface
We will respond to your request within 30 days (or as required by applicable law).
7. Telegram Integration
7.1 How It Works
Caloria operates through Telegram using the official Telegram Bot API. When you interact with our bot:
- Your messages are processed through secure Telegram Bot APIs
- Food photos and voice messages are analyzed by our AI systems (Google Gemini Vision)
- Responses are sent back through Telegram's encrypted channels
- All data processing follows Telegram's privacy and security standards
- Subscription payments are processed through Telegram Stars payment system
- Educational podcasts are delivered as native Telegram voice messages
7.2 Telegram's Role
Telegram acts as a data processor for messages sent to our bot. Their privacy policy applies to:
- Message transmission and delivery
- Telegram account information and user IDs
- Message encryption and security
- Payment processing through Telegram Stars
- Voice message delivery and storage
We recommend reviewing Telegram's Privacy Policy for complete information.
8. New Features Data Handling
8.1 Eat the Rainbow Challenge
For our gamified nutrition tracking feature, we collect and process:
- Color Detection Data: AI analysis of food colors from photos and descriptions
- Progress Tracking: Daily color collection status and achievement records
- Streak Information: Consecutive days of rainbow completion
- Achievement Data: Milestones reached and rewards earned
- Engagement Metrics: Participation rates and feature usage patterns
8.2 Educational Podcast System
For our educational content delivery, we process:
- Delivery Status: Whether episodes were successfully sent to users
- Language Preferences: User's preferred language for content delivery
- Subscription Status: Eligibility for podcast access based on subscription tier
- Episode Progress: Which episodes have been delivered to each user
- Engagement Data: User interaction with educational content
8.3 Weekly Statistics and Analytics
For comprehensive weekly reporting, we analyze:
- Aggregated Nutrition Data: Weekly trends and patterns in eating habits
- Goal Progress Analysis: Achievement rates and consistency metrics
- Behavioral Patterns: Meal timing, frequency, and dietary preferences
- Comparative Analysis: Week-over-week changes and improvements
- Personalization Data: Information used to customize recommendations
8.4 Data Retention for New Features
Data related to new features is retained according to the following schedule:
- Rainbow Challenge Data: Retained for the duration of active participation plus 1 year
- Podcast Delivery Records: Retained for subscription management and compliance (2 years)
- Weekly Statistics: Aggregated data retained for trend analysis (3 years), individual data follows standard retention
- Achievement Data: Retained as long as the user account is active
9. Cookies and Tracking
8.1 Website Cookies
Our website (caloria.vip) uses cookies for:
- Essential Functions: Login sessions and security
- Analytics: Understanding website usage patterns
- Preferences: Remembering your settings
8.2 Telegram Bot
Our Telegram bot does not use cookies, but may collect:
- Message interaction data for service improvement
- Usage patterns for personalization
- Error logs for technical support
8.3 Your Choices
You can control cookies through your browser settings. Disabling cookies may affect website functionality but will not impact the Telegram bot service.
10. Children's Privacy
Caloria is not intended for use by children under 13 years of age. We do not knowingly collect personal information from children under 13.
For users aged 13-18, we recommend parental supervision and guidance when using nutrition tracking services.
If we become aware that we have collected personal information from a child under 13, we will take steps to delete such information promptly.
11. International Data Transfers
Your information may be transferred to and processed in countries other than your own, including the United States, for the purposes described in this policy.
We ensure appropriate safeguards are in place for international transfers:
- Standard Contractual Clauses (SCCs) for EU data transfers
- Adequacy decisions where applicable
- Encryption and security measures during transfer
- Compliance with local data protection laws
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make significant changes:
- We will notify you through Telegram or email
- We will post the updated policy on our website
- We will update the "Last updated" date
- Continued use constitutes acceptance of changes
We encourage you to review this policy periodically to stay informed about how we protect your information.