Kalo (“we”, “us”) is an iOS and Android app published by Lumio Studio. This policy covers the app and its website, and explains what we collect when you use Kalo, how we use it, and the controls you have. If anything is unclear, email us at kalo@lumiostudio.co.
What we collect
- Account data. You can use Kalo anonymously. If you invite a peer, we prompt you to upgrade to Apple, Google, or email sign-in; at that point we store your display name, email, and a user identifier.
- Profile inputs. Age range, sex, height, weight, activity level, and daily kilocalorie goal — used only to compute your personalised target.
- Meal photos & entries. Photos you capture, dish classifications, estimated portions, calories, and macros.
- Peer content. Meal photos, calories, and reactions you choose to share with your connected friends.
- Device & diagnostic data. App version, OS version, crash logs, and basic analytics events.
How we use it
- Run the agentic AI pipeline (classify dish → estimate portion → reconcile nutrition) to return your meal’s calories and macros.
- Sync your meals across your devices and into your peer circle.
- Send push notifications you enabled (reactions, peer logs).
- Fix crashes, measure reliability, and improve the product.
We do not sell your data. Meal content is shared with the friends you connect with and processed by the service providers described below to operate Kalo.
Advertising measurement
If you installed Kalo after seeing one of our ads, we measure whether that ad worked. Kalo includes the TikTok App Events SDK for this.
What it receives is limited to two milestones: that an install finished onboarding, and that a meal was logged. It never receives your meal photos, your meal contents, your calories, your macros, your weight, or anything about your peer circle.
On iOS we ask for permission before using your device’s advertising identifier. Saying no is a normal answer, costs you nothing, and the app behaves identically. On Android we do not collect the advertising ID at all; attribution uses Google Play’s install referrer instead.
Subscription events used for advertising measurement are sent from our servers rather than from the app.
Peer sharing scope
You can connect with up to five friends and star one as your partner. Shared content includes meal photos, calories, and reactions. There is no public feed, leaderboard, or open social graph.
Where data is stored
Kalo uses Firebase (Firestore, Authentication, Cloud Messaging, Analytics, Crashlytics) and Google Cloud Storage for meal photos. AI inference runs through Google Vertex AI / Gemini models. Subscription state is managed by Apple StoreKit and Google Play Billing. Product analytics and crash reporting use PostHog, and advertising measurement uses TikTok as described above.
Third-party AI services
To estimate calories, Kalo sends a copy of your meal photo, voice recording, or typed meal description to Google’s Gemini large language model, accessed through Google Cloud Vertex AI. Specifically:
- What is sent. The meal photo (or up to three photos per meal), voice recording (as compressed m4a audio, max 90s), typed text description, and the locale you selected so we can prompt the model in your language.
- Who receives it. Google LLC, operating Vertex AI inside the Google Cloud project linked to Kalo’s Firebase project. The request is authenticated via Firebase App Check.
- How it is used. Google processes the data to identify the food and return structured nutrition estimates. Per Google’s Vertex AI Generative AI terms, customer data sent to Vertex AI is not used to train Google’s foundation models.
- Retention. Google logs API requests for 30 days for abuse monitoring per Vertex AI’s data governance. After that they are deleted.
- Your control. Kalo requests your explicit permission during onboarding before any data is sent. Without consent, no AI calls are made from the app.
This section describes the mobile app’s AI processing. App meal records are associated with your Firebase Auth user ID, and meal photos use Google Cloud Storage. The website demo uses the providers described below.
Website demo and analytics
When you choose a meal photo for the website demo, your browser resizes it and sends it to our demo service. The service uses OpenRouter and its selected model provider, or NVIDIA when configured, to generate an estimate. The demo does not create an account or save a meal history in our database. Provider processing and retention are subject to their policies; we do not promise immediate deletion by those providers.
See the OpenRouter privacy policy and NVIDIA privacy policy.
We use PostHog for website usage analytics and Google Analytics for acquisition and interactions such as demo and app-store link clicks. Our explicit conversion events include the page, language, store and campaign information, not meal photos or email addresses. Browser and network information is processed by the analytics providers according to their policies.
The first time you visit, a small banner asks whether analytics may use storage on your device. Until you answer, the Google tag stays on its denied default and sends only limited, cookieless measurement signals. If you allow it, analytics storage is enabled and your visit is measured normally. If you decline, the cookieless default stays in place and we also stop PostHog from capturing your activity. Advertising storage and personalized advertising remain disabled under either answer, because this website runs no advertising or remarketing.
Your answer is saved in your browser’s local storage under kalo_analytics_consent, not in a cookie and not on our servers. To change it, clear this site’s data in your browser and answer the banner again.
If you request an app download link by email, we use the address you provide to deliver that message through our email service.
Retention
Meal photos and entries are retained while your account is active. If you delete your account from in-app settings, we remove your profile, meal entries, photos, and peer invitations within 30 days. Aggregated and anonymised analytics may be retained longer.
Your rights
Depending on your region (GDPR / UK GDPR / CCPA), you may request access, correction, export, or deletion of your personal data. Email kalo@lumiostudio.co and we will respond within 30 days.
Children
Kalo is not directed to children under 13 and is not intended for use by children under 13. If we learn we have collected personal data from a child under 13, we will delete it.
Changes
If we make material changes we will update the “Last updated” date above and, where appropriate, notify you in the app.
Contact
Lumio Studio — kalo@lumiostudio.co