Legal
Privacy Policy
Effective date:
This policy explains how BullTech Core DMCC (Kalo, we, us) handles personal information when you use the Kalo mobile app, kalo-app.com, and related support services. It describes the current app and website; a feature mentioned here may be unavailable on your device or in your region.
Kalo is a nutrition and wellness service. Its estimates and AI responses are for information, not medical diagnosis or treatment. The information you enter, and information read from connected health services, can reveal sensitive facts about your health.
Jump to a section
1. Information we handle
Account and profile
We process your account identifier, email address, sign-in method, and information you add to your profile, such as name, date of birth, biological sex, height, weight, goals, activity level, dietary preferences and restrictions. Apple or Google may provide account information when you choose their sign-in option.
Diary and wellness information
We process meals and food descriptions, nutritional estimates and edits, daily totals, weight entries, workouts, sleep and activity information, and the results you choose to save. Some information is cached on your device and some is saved to your Kalo account so it can be used by account features and synchronized.
Images, voice and AI requests
When you choose an AI feature, its request may include a meal image, menu image, audio recording, text, a saved entry or relevant profile and diary context. Kalo processes these inputs to return an analysis, transcription, edit or Summary. A result you save is an account record; it is not the same as a temporary upload.
Subscriptions, usage and communications
Apple and Google handle your store payment details. We receive subscription status, product and transaction identifiers, and information needed to validate purchases, restore access, account for refunds and manage partner offers. If analytics is enabled in the app, we process an installation identifier and a limited set of product-usage and subscription events. We also process messages you send to support and an email address you submit for a newsletter, if you choose to subscribe.
2. Sources and purposes
Information comes from you, the app and your device, the Apple or Google services you authorize, the app stores for subscriptions, and our service providers when they return the result of a request. We use it to create and secure your account; show your diary, goals and wellness information; synchronize saved records; provide AI features you request; validate subscriptions and partner offers; answer support and privacy requests; detect abuse and failures; improve app reliability and understand limited product usage; and meet applicable legal obligations.
You can use some parts of Kalo without connecting a health service or requesting AI Summary. Features that need a specific input or permission may be unavailable if you do not provide it.
3. Apple Health and Health Connect
With the device permissions you grant, Kalo reads supported health and activity information through Apple HealthKit on iOS or Health Connect on Android. Supported categories depend on the platform and feature. Some raw measurements and derived views are processed or cached on your device. Your account health profile, saved diary and certain derived or selected values are also processed by Kalo's servers for account features; health information does not categorically remain on the device.
When you approve AI Summary, the selected day's meal and workout details, calorie totals and relevant profile information pass through Kalo's servers to the AI provider identified before approval. This may include descriptions and times, workout source or device information, age, body measurements, goals, biological sex and dietary needs. This does not mean every raw health-service measurement is uploaded.
You can change Apple Health or Health Connect access in your device settings. Kalo account deletion does not remove the original records held by those services.
4. AI features and your choice
Kalo sends the information needed for an AI request through its backend to OpenAI or Google Gemini, according to the feature and current provider configuration. OpenAI also processes audio submitted for speech-to-text. Inputs can still be personal or sensitive when direct identifiers are omitted. AI estimates can be inaccurate, so review them before relying on or saving them.
Before a new AI Summary is generated, Kalo identifies the provider and asks you to approve sharing the disclosed diary and health-profile context. Declining or dismissing the explanation prevents that request. Approval is saved for your account, the stated purpose and provider. You can withdraw it at Settings → Kalo personality → AI Summary data sharing. Withdrawal prevents later Summary requests until you approve again; it cannot recall a request already sent or stop one already in progress. Other AI features are initiated separately and are not controlled by this Summary setting.
For OpenAI Responses requests, Kalo asks that normal Response storage be disabled. AI Summary does not use web search. These choices do not prove that providers hold no abuse-monitoring records, cached data or backups, or that they delete all inputs immediately. Provider retention depends on their terms and the settings and agreements in effect for Kalo's accounts.
5. Product analytics
Kalo uses PostHog for limited app usage, experiment and subscription analytics when configured. The app uses an installation-scoped identifier and restricts event names and properties. It is designed to exclude meal content and health measurements from analytics events. An installation identifier is pseudonymous, not necessarily anonymous. The current app configuration disables automatic lifecycle capture, session replay and person profiles. Server-side subscription events may also be sent through a delivery queue.
The AI Summary sharing setting does not control PostHog. Contact us if you wish to exercise a privacy right relating to analytics. Information already sent to the provider is governed by the provider's retention and deletion processes.
6. Legal grounds
Where EU or UK data protection law applies, we rely on the grounds appropriate to each activity: providing the service and subscription you request; your consent for optional access or sharing where required; our legitimate interests in service security, reliability and limited product measurement, balanced against your rights; and compliance with legal obligations. Health information receives additional protection under applicable law. Apple Health or Health Connect permissions control access to those device services, and the separate AI Summary approval controls that particular sharing. These are specific controls for their stated purposes.
Withdrawing consent does not make earlier processing unlawful. A feature that depends on the withdrawn permission or approval may stop working. Other laws may provide different rights or legal grounds.
7. Recipients and service providers
- Amazon Web Services hosts Kalo's backend, account storage and operational infrastructure.
- OpenAI and Google Gemini process AI requests as described above; the provider used for Summary is named before you approve it.
- PostHog receives the limited analytics events described above when configured.
- Apple and Google provide sign-in, health-service access or store subscription functions that you choose to use.
- beehiiv may receive your email address if you opt in to a Kalo newsletter.
We may disclose information to professional advisers, authorities or another party where required by law or necessary to protect legal rights. We do not sell health data or use health-service data for advertising. Each service has its own technical systems and retention rules; Kalo remains responsible for its choice and management of providers under applicable law.
8. Processing outside your country
Kalo and its service providers may process information outside the country where you live, including outside the European Economic Area or the United Arab Emirates. Where transfer safeguards are required, we use the applicable contractual or other legal mechanism and can provide information about it on request. The precise locations and safeguards depend on the provider and service configuration.
9. How long information is kept
Saved account, profile and diary records are kept while your account is active or until you remove an individual record, subject to the deletion process below. Temporary AI uploads, processing files and service logs have different lifecycles from saved records. They are kept for the time needed to complete the request, handle failures, protect the service or meet a legal duty, then removed under the relevant system's retention controls. Provider copies follow the provider's applicable terms and Kalo's account settings; we do not promise immediate deletion of every copy after a response.
When you delete your account, active account records enter a resumable deletion process. Some purchase, refund, tax, security, dispute or audit records may be retained where required or justified; Kalo's financial records are pseudonymized during account deletion rather than erased at that step. Logs, backups and analytics copies follow their own retention and deletion procedures. Backup copies expire through normal rotation and are not normally available in the live app. Retention periods or criteria vary by record and legal requirement; contact us about a particular category.
10. Account deletion
You can start account deletion in Kalo at Settings → Account → Delete Account. If you cannot access the app, use the account-deletion page below to request it by email. We verify ownership before acting on an email request. Account deletion closes access and starts removal of active account data, including profile information and saved food entries. Server cleanup retries if a step cannot finish immediately.
The requesting device also attempts to remove its account-specific local data. If that cleanup cannot finish, the app keeps a protected retry record and reports that local cleanup is pending. Data on another device that is offline is not remotely erased by this step. Deleting your Kalo account does not cancel a subscription billed by Apple or Google, and does not erase original Apple Health or Health Connect records. Certain financial records, provider copies, logs, analytics history and backups may remain as described above.
11. Your rights and controls
Depending on your location and the reason we process particular information, you may ask to access, correct, export, restrict or erase it, object to processing, or withdraw consent. You can edit or remove some saved information in the app, change device health permissions, withdraw AI Summary approval in the app, or request account deletion. You may also contact us for help with those rights. We may need to verify your identity and may have to retain information where law permits or requires it.
If you are in the EU or EEA, you may complain to your local data protection supervisory authority. Please contact us first if you would like us to investigate a concern.
12. Website information
The website stores a language preference in your browser's local storage. Our hosting and delivery services may process ordinary request information such as IP address, browser details, page requested and time for delivery, security and diagnostics. If you use a partner or offer page, Kalo's public API receives the information needed to look up or redeem that offer. An email you send to support is processed to answer your request. We do not describe app analytics settings as a website cookie choice.
13. Security and age limits
Kalo uses access controls and encryption for protected account data and network communication. No system is completely secure. Please protect access to your account and device, and contact support if you believe your account has been misused.
Kalo is intended for adults aged 18 or older. The app's onboarding checks the date of birth supplied by a user. If you believe a minor has provided information, contact us so we can review and take appropriate action.
14. Changes and contact
We may revise this policy when our services, providers or legal requirements change. The date above identifies this version. We will give any additional notice required by law for material changes.
BullTech Core DMCCEmail: support@kalo-app.com
Address: Uptown Tower, Level No 11, Dubai, United Arab Emirates