Comprehensive Privacy Policy, Processing of Sensitive Data, and Informed Consent — Caloritrack Application
Effective Date and Last Updated: May 22, 2026 | Document ID: PRIV20260522EN
1. Introduction, Identity of the Data Controller, and Scope of the Document
Welcome to the CaloriTrack ecosystem! In strict compliance with international data protection legislation, including primarily the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP) of the United Mexican States, the General Data Protection Regulation (GDPR) of the European Union, and the California Consumer Privacy Act (CCPA/CPRA), this legal notice and privacy policy are hereby issued.
The primary legal entity, jointly liable, and absolute controller of the biometric database, as well as the creator and operational owner of the “CaloriTrack” application, is the commercial entity incorporated in Mexico under the corporate name Kai Studios, S.A.S. (hereinafter, the “Company”, “we”, “us”, “our”, or “CaloriTrack”).
This policy is a legally binding document that comprehensively, exhaustively, and without exception governs how we collect, process, store, encrypt, use, and protect your personal, biometric, health, behavioral, and usage information when you interact with our mobile application, our Application Programming Interfaces (APIs), the AI Coach (Kai), and our official website. By downloading, installing, registering, or using our services in any way, you grant your express, affirmative, and unequivocal consent for the processing of your data in accordance with the extensive terms described herein. If you do not agree with a single provision of this document, you must immediately refrain from using the App.
2. Detailed Inventory of the Information We Collect (Data Minimization Principle)
To provide the comprehensive experience that characterizes CaloriTrack’s five-pillar architecture (Health, Nutrition, Fasting, Wellness, and the AI Coach), it is operationally indispensable to collect certain categories of data. We strictly and auditably apply the principle of “Privacy by Design,” ensuring that we only collect the empirical information logically necessary for the provision of the service.
A. Information Provided Directly, Voluntarily, and Explicitly by the User:
- Authentication Credentials and Basic Profile: At the time of account creation, we collect your email address (used as the primary unique identifier) and an irreversibly encrypted version (cryptographic hash) of your password. We also collect your first name or a fictional nickname (intentionally omitting the request for surnames to favor pseudonymization), and your exact date of birth.
- Biometric, Anthropometric, and Special Category Data (Sensitive Health): For the proper functioning of our nutrition algorithms and safety threshold estimations, we collect data that international regulations classify as “special category” or “sensitive.” This includes your biological gender (strictly for the use of standardized metabolic formulas), exact height, current body weight, and goal weight.
- Longitudinal Logs of Habits and Nutrition: The App securely stores the detailed entries you make in your daily logs. This includes the natural ingredients and foods you consume, the exact timing of your intake windows and periods of voluntary caloric restriction (prolonged fasting), as well as the tracking of water intake and wellness routines.
- Generative Conversational Interactions (The “Kai” AI Coach): We collect, temporarily process, and store in your account history the text prompts, questions, reflections, and metadata of the conversations you have with our intelligent engine, Kai. This natural language ingestion is fundamental to provide conversational context and maintain the continuity of the personal guide service.
- User Multimedia Files: Should you voluntarily choose to personalize your account, we will collect and host the profile photograph you decide to upload to our cloud servers.
B. Information Ingested Through Third-Party Platforms and Wearables (With Prior Consent):
- Apple Health (HealthKit) and Garmin Connect Ecosystem: To materialize our holistic vision, CaloriTrack has the technical capability to connect via official APIs with the Apple and Garmin ecosystems. Subject exclusively and strictly to your affirmative authorization granted within the configuration menus of your device’s operating system, we will collect vital telemetric metrics. These may include, but are not limited to: total daily step count, duration and type of physical activity (workouts), detailed analysis of sleep architecture and phases, active and resting energy expenditure, and critical readings such as Heart Rate Variability (HRV).
C. Systemically and Automatedly Collected Information (Network and Device Telemetry):
- Session, Behavior, and Usage Data: We collect algorithmic metadata about your navigation within the App ecosystem. This includes screens visited, buttons pressed, retention time in specific modules (such as the Soundhealing or Breathwork sessions), use of informational tooltips, and goal completion rates.
- Device Technical Footprint and Network Infrastructure: Our internal logging servers automatically capture harmless but necessary technical information for bug diagnosis, which includes: the mobile device hardware model (e.g., iPhone 15 Pro), the underlying operating system version (e.g., iOS 18), the local time zone configuration, the system’s default language, and unique, anonymous device identifiers for the purpose of delivering system push notifications.
- Web Defensive Technologies (CDN/WAF): Requests directed to our cloud infrastructure (
caloritrack.com) pass through content delivery networks and firewalls that, to prevent distributed denial-of-service (DDoS) attacks, may temporarily log raw IP addresses and issue strictly technical and operational security cookies.
3. Exhaustive Purpose of Processing: How and Why We Use Your Information
The information described in Section 2 is not collected for idle accumulation, but is the necessary fuel that allows CaloriTrack to operate as an advanced proactive bioanalysis system. We use your data solely and exclusively for the following operational and foundational purposes:
- 1. Structural Operability and Provision of the Main Service: To create, maintain, authenticate, and protect your user profile. To mathematically process your diet entries and calculate personalized thresholds for macronutrients, micronutrients, and theoretical warnings about antinutrients (such as oxalates and lectins) exclusive to our natural database. To time your biological fasting phases and display visualizations on the Central Dashboard.
- 2. Deep Personalization of the AI Coach (“Kai” Conversational Engine): Our intelligent system uses Stoic philosophy and principles of Cognitive Behavioral Therapy (CBT) to teach you to reflect and promote self-knowledge. To achieve this, we process your exact date of birth along with your dynamic health data. This has no esoteric purposes; rather, it allows our algorithms to profile your preferred communication style and adapt the lexicon, tone, empathy, and directiveness of Kai’s generative responses, ensuring that every piece of advice is logically congruent with your current physical state and your fundamental personality traits.
- 3. Closed-Loop Biofeedback Correlation: We ingest HealthKit or Garmin data (such as HRV or sleep quality) to actively cross-reference them with your nutritional and fasting logs. The sole purpose is to generate in-app content recommendations (for example, suggesting a specific Breathwork session from the Wellness pillar if we detect a drop in your HRV).
- 4. Maintenance, Code Optimization, and Bug Resolution (QA): We use technical session data and crash reports stripped of personal identifiers so that our engineering team can audit the App’s stability, eliminate technical vulnerabilities, and plan updates under our agile methodology.
- 5. Non-Commercial Administrative Communications: We mandatorily use your email address to send transaction receipts (processed by Apple), critical notices of changes to these legal terms, urgent account security alerts, or to respond to your technical and legal support tickets.
4. The Unwavering Commitment to Non-Commercialization and Zero Advertising Profiling
FUNDAMENTAL STATEMENT OF CORPORATE ETHICS: KAI STUDIOS, S.A.S. maintains a radical, unwavering, and non-negotiable stance regarding data monetization. The user is not the product. Our business model is based exclusively on direct user subscriptions.
- Prohibition of Data Sales: We formally declare that WE DO NOT SELL, RENT, LICENSE, OR SHARE your personally identifiable information, your medical history, your biometric data, or your derived psychological profiles, with any third-party corporate entity, external company, business partner, mass data broker, health insurance company, credit risk agency, or pharmaceutical institution under any pretext, circumstance, or economic incentive.
- Zero Tracking Ad Policy: Unlike the toxic industry standard, the CaloriTrack App deliberately lacks advertising monetization infrastructure. We do not use your intake habits, your recipe book searches, or your stress levels captured by wearables to build behavioral profiles for the purpose of serving you targeted advertisements (neither within the App through third-party banners, nor outside of it on social networks).
5. Strict Guidelines for Integration with Apple HealthKit and Garmin Connect
Our integration with global health APIs is subject to the most severe scrutiny by application stores. KAI STUDIOS, S.A.S. explicitly and contractually guarantees the following:
- Restricted Use: Health and fitness data obtained directly or indirectly through the Apple HealthKit framework or the Garmin Health API will be used strictly, solely, and exclusively to provide services directly related to the core health, circadian rhythm analysis, and wellness functionality of the CaloriTrack App.
- Commercial Prohibition of APIs: Under the risk of immediate expulsion as official developers, we guarantee that data extracted from Apple HealthKit and Garmin Connect will never be used for digital marketing, advertising profiling, data mining, nor will it be transferred to third-party analytics platforms that are not intrinsically linked to the provision of the secure hosting service.
6. Legal Bases for Processing (GDPR and LFPDPPP Compliance)
For users residing in the European Economic Area (EEA) and analogous territories, data processing by CaloriTrack is inexcusably based on the following legal bases outlined by Article 6 of the GDPR:
- Explicit and Informed Consent (Art. 6.1.a and 9.2.a GDPR): The ingestion, cross-referencing, and algorithmic analysis of your “sensitive” health data (special category), as well as integration with wearable databases, rely absolutely and exclusively on your affirmative, free, and prior consent, granted via opt-in checkboxes during the App’s initial onboarding process.
- Contractual Necessity and Performance of a Contract (Art. 6.1.b GDPR): The processing of your basic profile (email, password) and telemetry data of interaction with the AI Coach is imperatively necessary to comply with the Terms and Conditions of Use of the service, create your account, and operate the platform you have requested to download.
- Compliance with a Legal Obligation (Art. 6.1.c GDPR): The retention in encrypted blockade of certain transactional records or formal objections (ARCO Rights) to respond to well-founded requirements from PROFECO, INAI, or judicial authorities, constituting an inescapable public obligation.
- Legitimate Interest (Art. 6.1.f GDPR): The use of anonymized usage metadata and crash logs for the continuous improvement of the software code, the protection of our cloud infrastructure against cyberattacks, and the structural prevention of computer fraud.
7. Corporate-Grade Cybersecurity, Cryptography, and Exceptional Disclosures
We understand that biological information is your most intimate asset. We have designed a relentless information security program:
- Cryptographic Measures: All data transmitted between your phone and our cloud mandatorily travels through secure, advanced encrypted tunnels (TLS 1.2 protocols or higher). At rest, sensitive data in our databases is protected using military-grade encryption algorithms (AES-256).
- Closed Infrastructure: Our servers operate on top-tier cloud providers with global security certifications (SOC 2, ISO 27001). No employee of KAI STUDIOS, S.A.S. has direct access to plaintext passwords, and access to production servers is heavily audited and limited by “least privilege” policies.
- Exceptional Force Majeure Disclosures: We will share information only in the following extreme situations:
- Third-Party Data Processors (Sub-processors): With our strictly selected server infrastructure providers, who operate under binding contracts that legally prohibit them from any secondary use of your data.
- Mandatory Legal Orders: If we are officially served with a court order, grand jury subpoena, or unappealable and valid government request requiring us to turn over information to comply with criminal or national security investigations.
- Vital Protection: When we reasonably and in good faith believe that disclosure of information to competent authorities is indispensable to prevent imminent physical harm, death, or to address severe child protection emergencies.
8. Sovereignty over Your Digital Footprint: Exercise of ARCO Rights and Equivalents
KAI STUDIOS, S.A.S. guarantees the preservation and proactive exercise of your legal prerogatives, granting you absolute control over your data (in accordance with Title Three of the Mexican LFPDPPP and Chapter III of the European GDPR). You have the fundamental right to:
- Right of Access: Request a detailed report on what categories of your personal data we are currently processing on our servers.
- Right of Rectification: Demand the immediate correction of bodily metrics or profile data that are inaccurate, outdated, or incomplete.
- Right of Erasure / Deletion (Right to be Forgotten): You have the irrevocable right to request the physical destruction or irreversible cryptographic anonymization of your account and your digital clinical history hosted on our system. The technical process for this consists of an immediate shutdown, followed by a temporary precautionary blocking period established by law, culminating in an irreversible and automated purge.
- Right to Data Portability: You have the power to demand a comprehensive export of your habits log, delivered in a structured, standard, and machine-readable electronic format (such as .CSV or .JSON files), to transfer your data to yourself or to other controllers without technological friction.
For the solemn exercise of any of these constitutional rights, the user must submit a formal, structured, and written request, which must inevitably be sent to our official and exclusive legal mailbox: [email protected]. Resolutions will be processed according to the imperative legal deadlines of your jurisdiction.
9. Strict Information Retention and Conservation Policy
Our conservation policy aligns strictly with the useful life cycle of your data and our tax obligations. We keep your profile and health information accessible and intact only as long as you maintain an active account on the service or as long as it is necessary for the functional provision of the AI Coach and the predictive algorithms of the daily logs.
Policy of Deletion due to Prolonged Inactivity: In order to minimize the risk of leaks, if your account enters a state of total abandonment and sustained lack of synchronization for a period of thirty-six (36) consecutive months, KAI STUDIOS, S.A.S. reserves the contractual right to execute, without further notice than this clause, the destructive deletion or deep anonymization of your relational database to make future re-identifications impossible.
10. Categorical Restriction of Access and Use by Minors (COPPA Compliance)
The comprehensive nature, the complexity of the bioanalysis metrics, and notably the metabolic risks inherent in the guided monitoring of caloric restriction and prolonged fasting, require biological and legal maturity.
Our application, services, web portal, and communication with the AI Coach (Kai) are strictly, categorically, and exclusively restricted to persons over eighteen (18) years of age. We do not direct marketing to, nor do we knowingly or deliberately solicit or collect personally identifiable information, nor health records from persons under the stipulated age, in strict compliance with regulations such as the Children’s Online Privacy Protection Act (COPPA) of the USA. If, through our systems or reporting by legal guardians, we gain factual knowledge that a minor user has bypassed our controls, we will proceed with the immediate cancellation, suspension of credentials, and destructive purge of the data from said profile without an appeal process.
11. International Transfers and Global Cloud Data Hosting
Considering that KAI STUDIOS, S.A.S. offers a global service to users in North America, Latin America (with a strong focus on Mexico and Argentina), and Europe, we expressly declare that the technological infrastructure, database clusters, and application servers may be physically located, operated, and maintained by cloud providers in cross-border data centers (such as in the United States of America).
By using CaloriTrack, the user acknowledges, understands, and actively consents to this international transfer of their data. We guarantee that any extracontinental transfer of personal data of European users will be protected under safeguard mechanisms legally recognized by the European Commission (such as Standard Contractual Clauses or EU-US Data Privacy Frameworks), ensuring that the required standard of protection travels intact along with the information, regardless of the final physical hosting jurisdiction.
12. Unilateral Right to Future Modifications to this Policy
Due to the inevitable fluctuations, technological disruptions, and relentless updates in the legal regulation of methodologies linked to artificial intelligences for medical-technological use and cross-border data protection, KAI STUDIOS, S.A.S. arrogates to itself, in a sovereign and inalienable manner, the exclusive administrative right to amend, rewrite, incorporate, and promulgate total or partial restructurings to this extensive Privacy Policy, at any time and according to our free business judgment.
Any minor amendment will come into effect immediately upon the alteration of the “Last Updated” identifier housed at the beginning of this document. However, if our Regulatory Compliance department dictates that the alteration constitutes a “material” and drastic legal and technical modification (i.e., a reform that structurally reduces the level of confidentiality previously guaranteed or that radically expands the scope of processing of the user’s clinical logs), we will notify our entire active database through the mandatory interposition of alerts via official emails, interactive pop-up screens, or intrusive banners on the native visual interface of the central Dashboard itself with a non-negotiable minimum of fifteen (15) calendar days prior to the effective effective date of the renewed document. Your decision, repetitive physical action, and inertia to continue navigating and registering biological health entries in the code after this peremptory period constitutes and assumes formally, legally, and tacitly, before local and international courts, your full ratification and full acceptance of the modified privacy bases.
13. Official Data and Administrative Contact Channel for Regulatory Compliance
Any complex query regarding the detailed regulatory framework herein, requests related to the inalienable exercise of rights (GDPR / LFPDPPP / CCPA), doubts of a structural nature regarding data encryption, or formal administrative notifications required by the state, must be directed imperatively and exhaustively through the only domain and legal channel operationally recognized by our entity in the Mexican Republic.
(Notifications sent through informal social networks such as Meta or “X” profiles, comment boards on the Apple App Store, or technical support Discord do not possess the minimum capacity, nor formal legal structure to be processed or operationally recognized as valid under this information processing contract).