Legal

Privacy Policy

Effective date:

This policy explains how BullTech Core DMCC (Kalo, we, us) handles personal information when you use the Kalo mobile app, kalo-app.com, and related support services. It describes the current app and website; a feature mentioned here may be unavailable on your device or in your region.

Kalo is a nutrition and wellness service. Its estimates and AI responses are for information, not medical diagnosis or treatment. The information you enter, and information read from connected health services, can reveal sensitive facts about your health.

Jump to a section

1. Information we handle

Account and profile

We process your account identifier, email address, sign-in method, and information you add to your profile, such as name, date of birth, biological sex, height, weight, goals, activity level, dietary preferences and restrictions. Apple or Google may provide account information when you choose their sign-in option.

Diary and wellness information

We process meals and food descriptions, nutritional estimates and edits, daily totals, weight entries, workouts, sleep and activity information, and the results you choose to save. Some information is cached on your device and some is saved to your Kalo account so it can be used by account features and synchronized.

Images, voice and AI requests

When you choose an AI feature, its request may include a meal image, menu image, audio recording, text, a saved entry or relevant profile and diary context. Kalo processes these inputs to return an analysis, transcription, edit or Summary. A result you save is an account record; it is not the same as a temporary upload.

Subscriptions, usage and communications

Apple and Google handle your store payment details. We receive subscription status, product and transaction identifiers, and information needed to validate purchases, restore access, account for refunds and manage partner offers. If analytics is enabled in the app, we process an installation identifier and a limited set of product-usage and subscription events. We also process messages you send to support and an email address you submit for a newsletter, if you choose to subscribe.

2. Sources and purposes

Information comes from you, the app and your device, the Apple or Google services you authorize, the app stores for subscriptions, and our service providers when they return the result of a request. We use it to create and secure your account; show your diary, goals and wellness information; synchronize saved records; provide AI features you request; validate subscriptions and partner offers; answer support and privacy requests; detect abuse and failures; improve app reliability and understand limited product usage; and meet applicable legal obligations.

You can use some parts of Kalo without connecting a health service or requesting AI Summary. Features that need a specific input or permission may be unavailable if you do not provide it.

3. Apple Health and Health Connect

With the device permissions you grant, Kalo reads supported health and activity information through Apple HealthKit on iOS or Health Connect on Android. Supported categories depend on the platform and feature. Some raw measurements and derived views are processed or cached on your device. Your account health profile, saved diary and certain derived or selected values are also processed by Kalo's servers for account features; health information does not categorically remain on the device.

When you approve AI Summary, the selected day's meal and workout details, calorie totals and relevant profile information pass through Kalo's servers to the AI provider identified before approval. This may include descriptions and times, workout source or device information, age, body measurements, goals, biological sex and dietary needs. This does not mean every raw health-service measurement is uploaded.

You can change Apple Health or Health Connect access in your device settings. Kalo account deletion does not remove the original records held by those services.

4. AI features and your choice

Kalo sends the information needed for an AI request through its backend to OpenAI or Google Gemini, according to the feature and current provider configuration. OpenAI also processes audio submitted for speech-to-text. Inputs can still be personal or sensitive when direct identifiers are omitted. AI estimates can be inaccurate, so review them before relying on or saving them.

Before a new AI Summary is generated, Kalo identifies the provider and asks you to approve sharing the disclosed diary and health-profile context. Declining or dismissing the explanation prevents that request. Approval is saved for your account, the stated purpose and provider. You can withdraw it at Settings → Kalo personality → AI Summary data sharing. Withdrawal prevents later Summary requests until you approve again; it cannot recall a request already sent or stop one already in progress. Other AI features are initiated separately and are not controlled by this Summary setting.

For OpenAI Responses requests, Kalo asks that normal Response storage be disabled. AI Summary does not use web search. These choices do not prove that providers hold no abuse-monitoring records, cached data or backups, or that they delete all inputs immediately. Provider retention depends on their terms and the settings and agreements in effect for Kalo's accounts.

5. Product analytics

Kalo uses PostHog for limited app usage, experiment and subscription analytics when configured. The app uses an installation-scoped identifier and restricts event names and properties. It is designed to exclude meal content and health measurements from analytics events. An installation identifier is pseudonymous, not necessarily anonymous. The current app configuration disables automatic lifecycle capture, session replay and person profiles. Server-side subscription events may also be sent through a delivery queue.

The AI Summary sharing setting does not control PostHog. Contact us if you wish to exercise a privacy right relating to analytics. Information already sent to the provider is governed by the provider's retention and deletion processes.

7. Recipients and service providers

  • Amazon Web Services hosts Kalo's backend, account storage and operational infrastructure.
  • OpenAI and Google Gemini process AI requests as described above; the provider used for Summary is named before you approve it.
  • PostHog receives the limited analytics events described above when configured.
  • Apple and Google provide sign-in, health-service access or store subscription functions that you choose to use.
  • beehiiv may receive your email address if you opt in to a Kalo newsletter.

We may disclose information to professional advisers, authorities or another party where required by law or necessary to protect legal rights. We do not sell health data or use health-service data for advertising. Each service has its own technical systems and retention rules; Kalo remains responsible for its choice and management of providers under applicable law.

8. Processing outside your country

Kalo and its service providers may process information outside the country where you live, including outside the European Economic Area or the United Arab Emirates. Where transfer safeguards are required, we use the applicable contractual or other legal mechanism and can provide information about it on request. The precise locations and safeguards depend on the provider and service configuration.

9. How long information is kept

Saved account, profile and diary records are kept while your account is active or until you remove an individual record, subject to the deletion process below. Temporary AI uploads, processing files and service logs have different lifecycles from saved records. They are kept for the time needed to complete the request, handle failures, protect the service or meet a legal duty, then removed under the relevant system's retention controls. Provider copies follow the provider's applicable terms and Kalo's account settings; we do not promise immediate deletion of every copy after a response.

When you delete your account, active account records enter a resumable deletion process. Some purchase, refund, tax, security, dispute or audit records may be retained where required or justified; Kalo's financial records are pseudonymized during account deletion rather than erased at that step. Logs, backups and analytics copies follow their own retention and deletion procedures. Backup copies expire through normal rotation and are not normally available in the live app. Retention periods or criteria vary by record and legal requirement; contact us about a particular category.

10. Account deletion

You can start account deletion in Kalo at Settings → Account → Delete Account. If you cannot access the app, use the account-deletion page below to request it by email. We verify ownership before acting on an email request. Account deletion closes access and starts removal of active account data, including profile information and saved food entries. Server cleanup retries if a step cannot finish immediately.

The requesting device also attempts to remove its account-specific local data. If that cleanup cannot finish, the app keeps a protected retry record and reports that local cleanup is pending. Data on another device that is offline is not remotely erased by this step. Deleting your Kalo account does not cancel a subscription billed by Apple or Google, and does not erase original Apple Health or Health Connect records. Certain financial records, provider copies, logs, analytics history and backups may remain as described above.

Read how to delete your account

11. Your rights and controls

Depending on your location and the reason we process particular information, you may ask to access, correct, export, restrict or erase it, object to processing, or withdraw consent. You can edit or remove some saved information in the app, change device health permissions, withdraw AI Summary approval in the app, or request account deletion. You may also contact us for help with those rights. We may need to verify your identity and may have to retain information where law permits or requires it.

If you are in the EU or EEA, you may complain to your local data protection supervisory authority. Please contact us first if you would like us to investigate a concern.

12. Website information

The website stores a language preference in your browser's local storage. Our hosting and delivery services may process ordinary request information such as IP address, browser details, page requested and time for delivery, security and diagnostics. If you use a partner or offer page, Kalo's public API receives the information needed to look up or redeem that offer. An email you send to support is processed to answer your request. We do not describe app analytics settings as a website cookie choice.

13. Security and age limits

Kalo uses access controls and encryption for protected account data and network communication. No system is completely secure. Please protect access to your account and device, and contact support if you believe your account has been misused.

Kalo is intended for adults aged 18 or older. The app's onboarding checks the date of birth supplied by a user. If you believe a minor has provided information, contact us so we can review and take appropriate action.

14. Changes and contact

We may revise this policy when our services, providers or legal requirements change. The date above identifies this version. We will give any additional notice required by law for material changes.

BullTech Core DMCC
Email: support@kalo-app.com
Address: Uptown Tower, Level No 11, Dubai, United Arab Emirates