Privacy Policy
Effective date: September 30, 2026
Claim727 LLC ("Claim727," "we," "us," or "our") operates Cave Cals, a food and calorie tracking app. This policy explains what information Cave Cals processes, why we process it, when it is shared, and the choices available to you.
Information stored on your devices and iCloud
Your profile, calorie and macro goals, food diary and macros, saved foods, saved meals, and widget data are stored on your device and, when iCloud is enabled, in your private iCloud account using Apple CloudKit. We do not receive your iCloud credentials or control Apple's storage and security practices.
Calorie plans and weigh-ins
The optional calorie-plan setup uses the age, gender/reference selection, height, weight, activity, goal weight, and pace you enter to calculate a starting calorie estimate on your device. Saved plan answers and weigh-ins are kept in a protected local file excluded from device backups; they do not sync through our CloudKit diary or go to our backend, AI providers, or advertising services. Only the calorie goal you accept follows the diary and iCloud storage described above. The clinician-led-plan selection is temporary and is not saved as a diagnosis. Unfinished setup answers are discarded when the app exits.
Apple Health
Weight tracking and Apple Health sharing are optional, and each kind of sharing is off until you turn it on in the app and grant permission in Apple Health. With Weigh-ins sharing, Cave Cals writes your weigh-ins to Apple Health. With Calories & macros sharing, Cave Cals writes, for each food you log from the day you turn it on, the food's name, date and time, calories, and, when known, protein, carbohydrates, fat, and fiber; edits and deletions in Cave Cals update or remove those Health records. Cave Cals does not read any data from Apple Health. Health data written by Cave Cals is created on your device by Apple's HealthKit; it is not sent to our backend, AI providers, or advertising services, and it is never used for advertising or sold. Other apps may access those records only under the permissions you give them in Apple Health. Turning sharing off pauses future exports; existing Health records remain there. You can manage Health permissions and records in Apple's controls.
In You, Forget plan details removes saved plan answers while keeping your daily calorie goal and weigh-ins. You can edit or delete weigh-ins in the app. Deleting a weigh-in also queues removal of its Cave Cals-created Health copy; this needs sharing enabled and write access to complete. A pending deletion retains only the record identity and sync state, not the weight measurement.
Information sent to our services
When you search for a food, your search term is sent through our backend to FatSecret for food and restaurant nutrition information. Scanned barcodes are sent directly to Open Food Facts. Our backend processes your IP address and stores a daily hash and request counters for search rate limits; it does not store your food-search text in the database. Your diary is not sent to either food provider. When you choose AI meal photo or voice logging, the selected photo, video, or audio recording is uploaded to our backend and sent to OpenAI to identify foods, transcribe audio, and estimate portions, calories, and macros. When you use Siri or Shortcuts to log a food that Cave Cals cannot match on your device from your own history or saved meals, the words you said are sent to our backend and OpenAI to identify the food and estimate calories, like a voice log. When you request a macro estimate for a food, only that food’s name, portion and calorie amount are sent to our backend and OpenAI; your full diary is not sent. When you import a meal from a link, the public URL is sent to our backend and OpenAI so the page can be searched and converted into editable meal items. AI results are estimates; review and edit them before saving.
Our services process an anonymous internal identifier, device verification credentials, Apple purchase identifiers, subscription status, usage counters (including successful AI scans and an aggregate regular food-log count capped at 100), request timestamps, and technical logs needed for security, quotas, troubleshooting, and purchase validation. We do not require an email address, password, or social account to use Cave Cals.
Purchases and third parties
Apple processes payments and provides subscription transaction information. RevenueCat provides subscription offerings, paywall services, entitlement status, and purchase restoration; it receives an anonymous app identifier, purchase information, and paywall interactions. Vercel hosts our web and API services, Neon hosts service records, OpenAI processes selected AI media, food details for requested macro estimates, and public meal links, FatSecret provides food and restaurant nutrition data, and Open Food Facts provides barcode product data. Each provider processes information under its own terms and privacy policy.
Retention and deletion
We request deletion of uploaded media after processing. Temporary uploads, estimates, and upload records expire after 24 hours and scheduled cleanup normally removes them within 48 hours. Operational backups and logs may persist for a limited period for security and reliability. OpenAI, Apple, RevenueCat, Vercel, Neon, FatSecret, and Open Food Facts may retain information under their own policies.
Because Cave Cals does not require an account, we cannot identify a diary stored only on your device or private iCloud account. You can delete that data from the app or Apple device/iCloud controls. To request deletion of information held by Claim727, email phil@claim727.com and include enough detail to locate your records. We will verify the request and respond within a reasonable period.
Choices and permissions
Camera and microphone access are requested only when you use those features. Apple Health permission is requested only when you turn on Health sharing. Notification permission is requested after you have logged food on a few days; Cave Cals uses it only for a local morning reminder when nothing is logged yet, scheduled on your device, and you can turn reminders off in Settings. You can deny or revoke permissions in iOS Settings. You can use manual food and calorie logging without sending media to AI. You can manage or cancel subscriptions through your Apple ID subscription settings.
Security
We use encrypted transport, signed Apple purchase verification, device attestation, access-controlled temporary storage, and limited retention. No method of transmission or storage is guaranteed to be completely secure.
Children
Cave Cals is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact us so we can investigate and delete it where appropriate.
Changes and contact
We may update this policy as Cave Cals changes. We will post the current version and effective date at this URL. Questions, privacy requests, and support requests can be sent to phil@claim727.com.
Claim727 LLC
phil@claim727.com