Transparency

Data & Third-Party Services

This page summarizes the current production architecture reviewed from GitHub main for the September 25, 2026 website update. The Privacy Policy controls if this summary conflicts with it.

Current advertising status: no third-party advertising SDK, no health/fitness-data targeted advertising, and no current Firebase Analytics or Firebase Crashlytics dependency were found in the production dependency set reviewed for this release.
Data / featureWhy Calmacular uses itWhere it can goAfter account deletion
Account identitySign-in, account separation, security, legal acceptance, entitlement.Firebase Authentication; Google/Apple sign-in when chosen.Firebase Auth identity deleted; third-party identity-provider records remain controlled by that provider.
Nutrition, foods, meals, weight, settingsLogging, goals, weekly planning, trends, restore/sync.Local SQLite and supported Firebase cloud sync.User namespace deleted; local account DB cleanup attempted.
Workout/program/mesocycle dataTraining, history, progression, targets, analytics.Local database and supported Firebase cloud sync.User namespace deleted.
Steps, heart rate, active energy, workout, distance/floors contextUser-facing activity credit, wearable context, workout/activity history.Read from Health Connect/Apple Health with permission; relevant imported/derived Calmacular records can be stored locally and synced.Calmacular copies/derived account data deleted with user namespace; source platform retains its own health records.
Barcode lookupRetrieve packaged-food nutrition.Barcode/product request to Open Food Facts.Open Food Facts/network logs are controlled by that provider; saved Calmacular food copy is deleted with account namespace.
Support reportTroubleshooting and user support.Firebase support collections and support email delivery; includes report text, account identifiers, app/build/platform, recent diagnostics.User copy deleted; central support/mail copy can be retained for legitimate support/security/legal purposes subject to privacy rights.
Store purchase / subscriptionVerify Premium, prevent one purchase from unlocking multiple live accounts, cross-platform entitlement.Apple/Google + Calmacular backend entitlement metadata.Old UID removed from binding; one-way purchase ownership tombstone can remain. Store transaction history remains with Apple/Google.
Restore snapshotsPrivate account restoration/migration functions.Firebase Storage under the user account path.Deleted by the account-deletion backend.

What Calmacular does not use this data for

Permissions are purpose-limited

Camera access supports barcode scanning. Photo-library access can support selecting exercise images. Motion/physical-activity permissions support step/activity features. Health permissions support the connected-health features you choose to enable. Permission availability differs by platform and OS version.

Changes

If Calmacular adds new analytics, advertising, crash-reporting, health integrations, processors, or materially different data uses, the Privacy Policy and store disclosures should be revised to match the production binary.