Privacy
Last updated 8 September 2026
CalorieSmart reads grocery and restaurant receipts so a fitness coach can see what a client actually eats. That means we handle a detailed record of what you buy. This page says exactly what we collect, who sees it, and how to get rid of it — in plain language, because a policy you cannot read is not consent.
Who is responsible
Yabsira Gugsa operates CalorieSmart and is the data controller. Contact for anything on this page, including deletion requests: privacy@caloriesmart.app.
What we collect
- Your account. Email address, a hashed password, your name, and whether you are a coach or a client. We never see your password in readable form. If you choose text messages in Settings, your mobile number too — verified by a code we text to it, kept where no one but you can read it, and removed the moment you remove it.
- Receipt images you upload. Stored in a private bucket that is not publicly reachable.
- What was on the receipt. Each line as printed, what we matched it to, the calories and macros of the matched product, and the verdict assigned to it.
- Who your coach is, if you are a client.
We do not use analytics, advertising, or third-party trackers. There is no tracking cookie on this site. The only cookies are the ones that keep you signed in, and the app does not work without them.
We do keep our own first-party record of how the app behaves for you — the pages you open, your uploads and how long they took, the lines you confirm or correct, and any error you run into — so that we can find and fix problems. It lives in the same database as your receipts, is never shared or sold, is included in your data download, and is deleted with your account.
Who can see your receipts
If you are a client, your coach can see every receipt you upload and every report card generated from it. That is the purpose of the product, and it is the single most important thing to understand before you upload anything. Your coach sees the items, the calories, and the verdicts.
No other coach can see your data. That is enforced in the database itself with row-level security, not merely hidden in the interface, and it is tested against the live system rather than assumed.
Who we send it to
We use a small number of processors, and they only ever get what they need to do their job:
- Anthropic — your receipt image is sent to Anthropic's Claude model to be read into a list of items. Where a line cannot be matched to a known product, the text of that line may also be sent to estimate it. Anthropic does not train models on this data.
- Supabase — hosts the database, the login system, and the private bucket your receipt images live in.
- Vercel — hosts and serves the application.
- FatSecret — receives product search terms (for example "shredded cheddar") to look up nutrition data. It does not receive your identity or your receipt.
- Resend — sends account emails such as password resets and the nudges above. It receives your email address and the message, and nothing else.
We do not sell your data, and we do not share it with anyone for advertising. Ever.
How long we keep it
Receipts and report cards are kept until you close your account, which you can do yourself from Settings. We do not currently delete old data automatically — if you have uploaded something you would rather we did not keep, email privacy@caloriesmart.app and we will remove it.
Your rights
You can download a copy of your data and delete your whole account yourself, from Settings, without asking anyone. To have something corrected, or for anything else, email privacy@caloriesmart.app and we will action it within 30 days.
Deletion is currently handled by a person rather than a button in the app. We would rather tell you that than imply a self-service flow that does not exist yet.
If you are in the UK, EU, or another region with data protection law, you also have the right to complain to your local supervisory authority.
Children
CalorieSmart is not intended for anyone under 16, and we do not knowingly collect their data.
Security
Receipt images sit in a private bucket that requires an authenticated, authorised request. Database access is restricted per account at the database level. Secrets used to reach the services above are held server-side and are never sent to your browser — this is verified against each build.
No system is perfect. If you find a security problem, please email privacy@caloriesmart.app rather than posting it publicly, and we will fix it.
Changes
If we change what we collect or who we send it to, we will update this page and change the date at the top. Material changes will be told to you directly, not left here to be discovered.