Privacy Policy
Calori – app and website
Effective date: 22 September 2026 · Version 2.0 · Replaces the previous, undated version of this policy
This policy explains what personal data Lagom food Oy ("Calori", "we") collects when you use the Calori mobile app, the website at calori.health and our AI assistant Astre, why we collect it, who we share it with and what rights you have. It is written to meet the EU General Data Protection Regulation (GDPR), the Finnish Data Protection Act (1050/2018) and the Finnish Act on Electronic Communications Services, as well as the privacy requirements of the Apple App Store and Google Play.
If anything here is unclear, write to us at info@calori.health.
1. Who is responsible for your data
The data controller is:
Lagom food Oy (trading as Calori)
Business ID 3165571-2
Nihtisillantie 3 B, 02630 Espoo, Finland
info@calori.health · +358 50 382 9853
We have not appointed a statutory Data Protection Officer, as the GDPR does not require one for a business of our size. Privacy questions and requests are handled by Calori's management and answered from info@calori.health.
2. What this policy covers
This policy applies to:
- the Calori mobile app for iOS and Android, including the Astre assistant, meal logging, meal plans, deliveries and Apple Health / Health Connect integrations;
- the calori.health website, including ordering, the customer dashboard and the blog;
- emails, SMS and push notifications we send you;
- customer support through in-app and website chat and by email.
It does not cover third-party services you reach through links from our app or site (for example Wolt's own tracking page or Stripe's checkout page). Those services have their own privacy policies.
3. The personal data we collect
We collect only what we need to run the service. The categories below describe where each type of data comes from and what it is used for.
3.1 Account and identity data
When you create an account we collect your name, email address and phone number, plus a password (stored only as a one-way hash) or, if you sign in with Apple or Google, the identifier and email those providers share with us. If your sign-in provider offers a profile picture, we may store its address to show it in the app. We also store your preferred language, country and unit system (metric or imperial).
Source: you, or Apple / Google when you sign in with them. Purpose: to create and secure your account, to talk to you and to show the app in your language.
3.2 Delivery and contact data
To deliver meals we collect your delivery addresses (street, postal code, city, country, an optional apartment or entry note and the map coordinates of the address), a label for the address, and, for pickup orders, the pickup venue you selected.
If you allow it, the app may read your device location once, only while you are adding an address, to pre-fill the address form. Location is never collected in the background and is not stored beyond the address you save.
Source: you. Purpose: to deliver your orders and to let you pick nearby pickup points.
3.3 Subscription, order and payment data
We keep records of your subscription and its status, weekly meal selections, delivery choices, pauses, orders, invoices, credits, discount and referral codes, gift cards and wait-list entries, together with the amounts charged, currency and payment status.
Card payments are handled by Stripe. Your card number never reaches our systems; we store only Stripe's customer and payment-method identifiers and, where Stripe provides them, the card brand and last four digits so you can recognise your saved card. If you pay with Epassi employee benefits, Epassi tells us whether the charge succeeded and we store the charge references.
Source: you, Stripe and Epassi. Purpose: to fulfil your orders, take payment and keep the accounting records the law requires.
3.4 Health and fitness data (special category)
Calori personalises your nutrition targets and meal plan. For this we process data that the GDPR treats as health data. We do this only with your explicit consent, which you give in the app before any health data is collected, and which you can withdraw at any time (see section 9).
Data you enter yourself: date of birth, sex, height, weight and weight history, target weight, activity level, primary goal (for example weight loss or maintenance), dietary preference, food likes and dislikes, allergies and lactose tolerance.
Data read from Apple Health (iOS) or Health Connect (Android), only if you grant those permissions in addition to your consent: steps, active energy burned, heart rate samples, sleep, workouts (type, time, distance and energy), height and weight. On Android the app can also refresh this data in the background so that your daily summaries stay current. The exact list of types the app requests is shown to you in the Apple Health or Health Connect permission screen, and you can turn off any individual type there.
From these we derive daily nutrition targets, meal plans, meal-timing preferences, a weight-trend projection and daily activity summaries. Raw sensor samples (for example individual heart-rate readings) are aggregated into daily summaries shortly after they are received and the raw samples are then deleted; only the daily summaries are kept.
We do not collect medical diagnoses, medications or laboratory results at this time. If we add a way to enter such information in the future, we will ask for your separate consent first and update this policy.
We never use health or fitness data for advertising or marketing, never sell it, and never share it with third parties for their own purposes. It is shared only with the service providers listed in section 6 who process it on our behalf and under our instructions, and with Anthropic when you use Astre (section 5).
Source: you, and Apple Health / Health Connect with your permission. Purpose: to compute your nutrition targets, build and adapt your meal plan, and show you your progress. Legal basis: your explicit consent (GDPR Article 9(2)(a)).
3.5 Nutrition and food-logging data
When you log what you eat, we store the food items, portions, time of consumption, how the entry was made (typed, photographed or chosen from a list), the resulting nutrient values, and your ratings of meals. Foods that are not in our catalogue are saved as your own private catalogue entries so you can log them again quickly.
Source: you (directly or through Astre). Purpose: to track your intake against your targets and to improve your meal plan.
3.6 Astre conversations
When you chat with Astre we process the messages you write, any photos of food you send, and voice input you dictate. Voice is transcribed into text by your device's speech-recognition service (Apple on iOS, Google on Android), which may process the audio on the device or on Apple's or Google's servers under their own terms; we receive only the resulting text, never audio recordings. Astre may also look up the data described in sections 3.1 to 3.5 when it is needed to answer your question (see section 5 for exactly how).
Your conversation history is stored on your device. Our servers process each message while answering it and keep only technical logs (a request identifier, your user ID, timing and token counts). We do not store the content of your messages or photos on our servers.
Source: you. Purpose: to answer your questions about your plan, deliveries and nutrition and to carry out the actions you confirm.
3.7 Communication preferences and marketing
We store your choices about service emails (renewal, pre-delivery and post-delivery messages), marketing emails and marketing SMS, and the date and content of any consent you give. Service messages that are necessary to run your subscription (for example order confirmations, delivery notices and payment problems) cannot be switched off while you have an active account.
Source: you. Purpose: to send you the messages you want and to prove consent where the law requires it.
3.8 Device, diagnostics and usage data
To keep the app working we collect crash reports and performance data (device model, operating system version, app version, the error that occurred and what the app was doing at the time) through Sentry. For a small share of sessions and for every session that ends in an error, Sentry also records a replay of the screens shown in the app; text and images in these replays are masked so that their content is not readable. These reports include your IP address and user ID so that we can find and fix problems you report.
We also store push notification tokens for your device if you turn on notifications, and the language, time zone and unit settings of the app.
Our servers keep access logs (request path, timestamp, status and duration) for security and troubleshooting.
Source: your device. Purpose: to detect and fix bugs, keep the service secure and send notifications you have enabled.
3.9 Customer support data
When you contact us through the in-app or website chat (Intercom) or by email, we process your name, email, the content of the conversation and, for the in-app chat, your user ID and app language so we can find your account and help you.
Source: you. Purpose: to answer your questions and resolve problems.
3.10 Website cookies and similar technologies
The website uses strictly necessary cookies (session, language, consent choice) that work without your consent, and, only if you accept "all cookies" in the cookie banner, analytics and marketing tags (Google Tag Manager, Google Analytics and the Meta Pixel). Details are in section 10.
4. Why we process your data and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Creating and securing your account, signing you in | Account and identity data | Contract (Art. 6(1)(b)) |
| Taking orders, charging you, delivering meals, handling pauses, credits and refunds | Delivery, order and payment data | Contract (Art. 6(1)(b)) |
| Personalised nutrition targets, meal plans, progress tracking and activity summaries | Health and fitness data, nutrition data | Explicit consent (Art. 6(1)(a) and 9(2)(a)) |
| Astre assistant, including sending your questions and relevant profile data to our AI provider | Conversation data and the data Astre looks up | Explicit consent (Art. 6(1)(a) and, for health data, 9(2)(a)) |
| Service emails, SMS and push notifications about your orders and account | Contact data, preferences | Contract (Art. 6(1)(b)) |
| Marketing emails and SMS | Contact data, preferences | Consent (Art. 6(1)(a)); for existing customers, our legitimate interest (Art. 6(1)(f)) in telling you about similar Calori services, as Finnish law allows. You can opt out at any time |
| Customer support | Support data, account data | Contract and legitimate interest (Art. 6(1)(b) and (f)) |
| Crash reporting, performance monitoring, security, fraud and abuse prevention | Device and diagnostics data, access logs | Legitimate interest (Art. 6(1)(f)) in a stable and secure service |
| Website analytics and advertising measurement | Cookie data | Consent (Art. 6(1)(a)) via the cookie banner |
| Accounting, tax and other legal obligations | Order, invoice and payment records | Legal obligation (Art. 6(1)(c)) |
| Aggregated, non-identifiable statistics about how the service is used and how meals are rated | Order, rating and usage data, stripped of identifiers | Legitimate interest (Art. 6(1)(f)) in improving the service |
Where we rely on legitimate interest, we have assessed that the processing is what you would reasonably expect from a meal service and does not override your rights. You can object to it (section 9).
We do not use your data for automated decisions that have legal or similarly significant effects on you. Your nutrition targets and meal plan are personalised automatically from the data you provide, but you can change your goal and preferences at any time, and the plan does not restrict your access to the service.
5. Astre and third-party AI
Astre is Calori's AI assistant inside the app. This section describes exactly what happens to your data when you use it.
Who provides the AI. All AI features in Calori — Astre's conversational responses, the generated plan explanations and the meal-preference estimation described below — use large language models from Anthropic, PBC (San Francisco, USA) through Anthropic's commercial API. We use no other AI provider. Anthropic acts as our processor under a data processing agreement. Anthropic does not use data sent through its commercial API to train its models, and automatically deletes API inputs and outputs from its systems within 30 days.
What is sent to Anthropic. Every time you send a message, Astre sends Anthropic:
- the text of your message and the earlier messages in that conversation;
- any food photo you attach in that conversation;
- session details: your first name, your user ID, the current time and time zone, the app language and unit system, the screen you opened Astre from, and a short summary of your account state (whether deliveries are paused, the next delivery date, whether a payment card is on file);
- when, and only when, they are needed to answer your question, the results of Astre looking up your data in our systems. Depending on what you ask, this can include your health profile (body measurements, age, activity level, goals, latest weight, dietary preference, likes and dislikes, allergies), your synced activity history (daily steps, active energy, sleep, workouts), your nutrition targets and food log, your meal plan and meal details, your name, email and phone number, your delivery overview (upcoming and past orders, amounts, courier tracking status) and your pause state.
What is not sent. Your password, full card number and Stripe identifiers are never sent. Astre cannot read your Astre conversations from other sessions unless they are on your device and you continue them. Anthropic does not receive your raw heart-rate or other sensor samples, only the daily summaries.
Actions Astre can take. Astre can propose to log food, remove a food log, change your name or phone number, or add or edit a delivery pause. Nothing is changed until you confirm the proposed action in the app. Astre cannot change your meal plan, your targets or your payment details.
Your consent. Before you first use Astre, the app tells you that your questions and the related profile data will be processed by a third-party AI provider and asks for your permission. You can stop using Astre at any time; withdrawing your health-data consent also stops Astre from accessing health data. To delete conversation history, delete the conversation in the app (it is stored on your device).
Other automated text. Two short pieces of text in the app are also generated by Anthropic's models: the overview of your meal plan and the one-sentence note under each nutrient target explaining how it was tailored to you. To produce these we send your age, sex, height, weight, goal, activity level and the targets themselves. Your nutrition targets are computed by our own nutrition engine from established formulas, not by the AI; the AI only writes the explanation.
Nutrition engine. Our nutrition engine calculates your targets and builds your meal plan using deterministic formulas and an optimisation algorithm, not AI. It receives your profile under a pseudonymous token, not your name, email or user ID, and stores nothing itself. One step of the engine may use Anthropic's models: estimating how much you are likely to enjoy meals you have not yet rated, based on the names and tags of meals in our catalogue and the ratings you have given to other meals. That request contains no identity, body, health or goal data — only food names and your ratings.
Limits of Astre. Astre gives general nutrition information based on your plan. It is not a medical service and does not give medical advice. If you have a medical condition, consult a healthcare professional.
6. Who we share your data with
We do not sell your personal data. We share it only with the service providers below, who process it on our behalf under written agreements, and with authorities when the law requires it.
| Provider | What they do for us | Data they receive | Location |
|---|---|---|---|
| Supabase, Inc. | Database, authentication and file storage | All account, order, health, nutrition and preference data | EU (Stockholm, eu-north-1) |
| Google Cloud (Google Ireland Ltd / Google LLC) | Hosting of our backend services and scheduled jobs | All data processed by our backend, server logs | EU (Belgium, europe-west1) |
| Vercel Inc. | Hosting of the calori.health website | Website requests, session cookies | EU/USA |
| Anthropic, PBC | AI models behind Astre, plan explanations and meal-preference estimation (section 5) | Conversation content, photos and the profile data described in section 5; for preference estimation, meal names and your meal ratings only | USA |
| Stripe Payments Europe Ltd / Stripe, Inc. | Card payments, saved cards, subscription billing, gift cards, promo codes | Name, email, card details (entered directly with Stripe), payment amounts | EU/USA |
| Epassi Group Oy | Employee-benefit payments | Charge references and amounts | Finland |
| Wolt Enterprises Oy (Wolt Drive) | Courier delivery of your orders | Name, phone number, email, delivery address, coordinates and delivery note; they also send you a delivery SMS | Finland/EU |
| Intercom R&D Unlimited Company | Customer support chat in the app and on the website | Name, email, user ID, app language, conversation content | EU/USA |
| Functional Software, Inc. (Sentry) | Crash and performance monitoring, masked session replays | Device and error data, IP address, user ID | EU (Germany) |
| Expo (650 Industries, Inc.) | Delivering push notifications and app updates | Push token, device platform | USA |
| Apple Inc. and Google LLC | Sign in with Apple / Google, push delivery (APNs / Firebase Cloud Messaging), on-device speech recognition, Apple Health / Health Connect | Sign-in identifiers, push tokens; speech audio is processed by their speech services under their own terms | EU/USA |
| Mapbox, Inc. | Address search, map display and reverse geocoding when you add an address | Address text you type and the coordinates you select | USA |
| Resend, Inc. | Sending transactional and marketing emails | Name, email, email content | USA |
| Twilio Ireland Ltd | Sending SMS reminders and marketing SMS | Phone number, message content | EU/USA |
| Google Tag Manager, Google Analytics and Meta Pixel (Meta Platforms Ireland Ltd) | Website analytics and advertising measurement, only with your cookie consent | Cookie identifiers, pages visited, device information | EU/USA |
| Slack Technologies Ltd and Google Workspace | Internal tools our staff use to run kitchen and delivery operations | Order alerts may include your name and order number | EU/USA |
| Contentful GmbH | Hosting of blog content | No personal data | Germany |
Our own staff and contractors have access to personal data only to the extent their role requires (for example kitchen staff see meal selections and allergies, delivery staff see addresses, support staff see account details), and are bound by confidentiality.
We may also disclose data to public authorities, courts or law enforcement when legally obliged, and to professional advisers or a buyer in connection with a merger, acquisition or sale of the business, in which case we will make sure this policy continues to apply to your data.
7. Transfers outside the EU/EEA
Most of your data is stored in the European Union. Some providers listed above (Anthropic, Stripe, Intercom, Vercel, Expo, Mapbox, Resend, Twilio, Google, Meta, Apple) may process data in the United States or other countries outside the EEA. Where they do, we rely on the European Commission's Standard Contractual Clauses and, for providers certified under it, the EU–US Data Privacy Framework, together with additional safeguards such as encryption in transit and at rest. You can request a copy of the relevant safeguards at info@calori.health.
8. How long we keep your data
| Data | Retention |
|---|---|
| Account, profile, addresses and preferences | Until you delete your account, then deleted within 30 days (see below) |
| Health and fitness data and derived plans and targets | Until you withdraw consent or delete your account, then deleted within 30 days. Raw sensor samples are deleted within days of being aggregated into daily summaries |
| Food log and ratings | Until you delete the entries or your account, then deleted within 30 days |
| Astre conversation content | Not stored on our servers. Stored on your device until you delete it. Anthropic deletes API inputs and outputs within 30 days |
| Orders, invoices and payment records | 6 years from the end of the financial year, as required by the Finnish Accounting Act; personal data no longer needed is removed or anonymised before then where possible |
| Marketing consents and email/SMS preferences | For as long as the consent is valid and 3 years after withdrawal, as evidence |
| Customer support conversations | 2 years after the conversation is closed |
| Crash reports and session replays | 90 days |
| Server access logs | 30 days |
| Push tokens | Until you turn off notifications, sign out or delete your account |
| Website cookies | See section 10 |
Account deletion. You can delete your account from the app (Settings → Delete account). Your subscription is paused immediately, your login is disabled, and your personal data is deleted within 30 days, except that if you still have paid deliveries coming they are delivered first, and order and invoice records are kept for the accounting period above in a form that is no longer linked to an active account. You can also request deletion by email.
9. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- rectify inaccurate data — most of it you can edit directly in the app;
- erase your data ("right to be forgotten"), subject to the retention obligations in section 8;
- restrict processing in certain situations;
- object to processing based on legitimate interest, and at any time to direct marketing;
- data portability — receive the data you provided to us in a machine-readable format;
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
- not be subject to solely automated decisions with legal or similarly significant effects.
How to withdraw consent:
- Health data: by revoking Calori's access in Apple Health (Settings → Privacy & Security → Health) or Health Connect, which stops all further syncing, and by emailing info@calori.health to withdraw your consent to processing the health data you have entered. Withdrawing consent stops all further health-data processing and removes the derived plan personalisation; you can continue to use the delivery service with a standard plan.
- Astre / third-party AI: simply stop using Astre; you can also delete conversations from your device.
- Marketing emails and SMS: the unsubscribe link in any marketing email, the app's notification settings, the "Manage emails" page on calori.health, or by replying STOP to a marketing SMS.
- Push notifications: your device's notification settings.
- Website cookies: the cookie settings link in the website footer.
- App Tracking Transparency (iOS): Settings → Privacy & Security → Tracking.
To exercise any right, email info@calori.health from the address linked to your account, or use the settings in the app. We answer within one month, extendable by two further months for complex requests, and we may ask you to verify your identity. Exercising your rights is free unless requests are manifestly unfounded or excessive.
Complaints. If you believe we process your data unlawfully, you can lodge a complaint with the Finnish Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), Lintulahdenkuja 4, 00530 Helsinki, tietosuoja@om.fi, www.tietosuoja.fi, or with the supervisory authority in the EU country where you live.
10. Cookies and tracking
Website. When you first visit calori.health you can choose between necessary cookies only and all cookies.
- Necessary (no consent needed): authentication session cookies (Supabase), your language choice, your cookie choice, and Stripe's fraud-prevention cookies during checkout. These expire when you sign out or after at most 12 months.
- Analytics and marketing (only if you accept all cookies): Google Tag Manager loads Google Analytics, which uses cookies to measure how the site is used, and the Meta Pixel, which measures the effectiveness of our advertising on Meta's platforms. These providers may combine this data with data they hold about you under their own policies. You can change your choice at any time from the cookie link in the footer, and you can also opt out at tools.google.com/dlpage/gaoptout and in your Meta ad settings.
The in-app support chat (Intercom) sets its own functional cookies on the website to keep your conversation open.
Mobile app. The app does not contain advertising SDKs and does not track you across other companies' apps or websites. On iOS the app asks for App Tracking Transparency permission; if you decline, any calori.health pages opened inside the app run with analytics and advertising consent revoked, and nothing else about the app changes.
11. How we protect your data
All data is encrypted in transit (TLS) and at rest. Access to production systems is limited to named staff with multi-factor authentication, and database access is controlled by per-user row-level security so that the app can only read the data of the signed-in user. Health data is kept in a separate database schema with its own restricted service role. Card data is handled entirely by Stripe, which is PCI DSS Level 1 certified. We log access to our services, review our processors' security certifications and require them to notify us of security incidents. If a breach is likely to put your rights at risk, we will notify you and the supervisory authority as the GDPR requires.
12. Children
Calori is intended for adults. You must be at least 16 years old to create an account, and the app does not let you enter a date of birth that would make you younger. We do not knowingly collect data from anyone under 16; if you believe a child has given us personal data, contact us and we will delete it.
13. Changes to this policy
We will update this policy when our processing changes. Material changes — for example a new category of data, a new AI provider, or a new purpose — will be announced in the app or by email before they take effect, and where the law requires it we will ask for your consent again. The effective date at the top tells you when the current version started to apply. Earlier versions are available on request.
14. Contact
Lagom food Oy · Nihtisillantie 3 B, 02630 Espoo, Finland
info@calori.health · +358 50 382 9853
This policy is available in English, Finnish and Swedish. If the versions differ, the Finnish version prevails.
See also: Terms of Service