This Consumer Health Data Privacy Policy is provided by the independent developer who builds and operates Krilo. It applies only to consumer health data and is separate from Krilo's general Privacy Policy.
Consumer Health Data We Collect
- Food and nutrition activity: timestamped food logs, food names, meal type, serving details, ingredients, calories, protein, carbohydrates, fat, favorites, barcodes, entry source, and planned meals.
- Weight history: dated weight entries and the history they create.
- Body and demographic information: sex, birth date, height, weight, activity level, weight goal, and desired pace when you choose to provide them.
- Goals and goal history: calorie, macro, weight, hydration, sleep, step, distance, flights-climbed, and related goal values and periods.
- Content used for AI features: compressed meal photos, meal descriptions, food-search queries, meal-plan prompts, nutrition goals and planned-meal context, and shopping-list inputs. A meal photo is held in memory only for the single request to Google Gemini and is discarded once that request completes; Krilo does not store meal photos. Queued meal-plan and shopping-list request payloads may be stored temporarily to complete or recover the request.
If you permit Apple Health access, Krilo reads selected Apple Health activity, body, workout, route/location, heart, respiratory, temperature, and sleep samples to provide features on your device. Those Apple Health samples and routes are processed on-device only, are not synced to Krilo, and are not included in a Krilo data export.
Why We Collect and Use It
We collect and use consumer health data to provide the features you request: food and macro logging, history and cross-device sync, nutrition and body-goal calculations, planned meals and shopping lists, Trends, Recovery, Sleep, Strain, workout summaries, and optional AI-assisted photo, text, food-search, meal-plan, and shopping-list results. We also use the minimum data needed to maintain data integrity, prevent stale-device restoration after an erasure, secure the service, diagnose problems, enforce feature limits, and comply with law.
Sources of Consumer Health Data
- You and your devices: information you enter, save, scan, photograph, import, or generate by using Krilo.
- Apple Health, with your permission: selected samples that Krilo reads and processes on your device. Apple Health access is optional and can be revoked in iOS Settings.
Consumer Health Data We Share
Krilo does not sell or license consumer health data and does not share it for advertising, marketing, or research, and there is no active data-sharing or data-licensing program today. If we ever introduce one, it will require your explicit, revocable opt-in consent and advance notice through an update to this policy. We share only the categories needed to provide a feature you request or operate the service:
- AI feature input with Google Gemini after the app presents the AI Data Sharing disclosure and you consent.
- Barcode or food-search input with Open Food Facts, and food-search input with USDA FoodData Central, to return nutrition matches. A direct device request to Open Food Facts also exposes the device's IP address in the ordinary operation of the internet.
- Synced health data with Render, which hosts Krilo's backend and production database.
Third Parties and Contacts
- Google Gemini — AI processing: receives the photos, text, prompts, goals, or planned-meal/shopping context described in the consent disclosure for the feature you request. Contact Google through its Privacy Help Center.
- Open Food Facts — nutrition lookup: receives a barcode or food-search query. Contact contact@openfoodfacts.org or use its contact page.
- USDA FoodData Central — nutrition lookup: receives a food-search query from Krilo's backend. Use the FoodData Central contact form.
- Render Services, Inc. — hosting: hosts synced health data in Krilo's backend and PostgreSQL database. Contact privacy@render.com.
- Apple Inc. — authentication, billing, and on-device health permissions: Krilo does not send food logs, goals, prompts, or Apple Health samples to Apple. Apple processes Sign in with Apple and App Store subscription information and controls Apple Health permissions on your device. Use Apple's privacy contact.
- Plus Five Five, Inc. (Resend) — account email: receives the address and transactional content needed for account emails, not food logs, prompts, goals, weights, or Apple Health samples. Contact support@resend.com.
Krilo has no affiliates with which it shares consumer health data.
Your Consumer Health Data Rights
- Access and confirm sharing: use Account → Download My Data for a JSON copy of your profile and synced health data, related account records, consent history, and the list of third parties with which Krilo shares consumer health data.
- Delete health data without closing your account: use Account → Delete My Data. Krilo requires fresh reauthentication, deletes the health data from active systems, clears it locally without signing you out, and prevents older pending records on another device from being synced back.
- Withdraw consent: use Account → AI Data Sharing to stop future sharing with Google Gemini. You may also revoke Apple Health access in iOS Settings. Withdrawal cannot recall a Gemini request already submitted for processing.
If you cannot reach or use an in-app control, email support@krilohealth.com. We may ask for information reasonably necessary to authenticate your request. You do not need to create a new account, but we may require you to use an existing account. Access responses are free up to twice each year unless a request is manifestly unfounded, excessive, or repetitive.
Krilo will act without undue delay and within 45 days after receiving a request. When reasonably necessary because of the complexity or number of requests, we may extend once for up to 45 additional days and will tell you why within the initial 45-day period.
Deletion Scope, Retained Records, and Backups
Delete My Data removes synced food entries and ingredients, favorites, planned items, weight history, nutrition goals and goal periods, AI jobs and raw request payloads, credit-ledger events, bug reports, sync tombstones, and body-related profile fields. It also removes your account identifier from short-lived server error logs.
We retain the account email and authentication state so you can keep using the account; AI consent state and append-only consent history, which contain no prompts or health content; and Apple subscription, transaction, and receipt records needed for billing integrity, accounting, fraud prevention, and disputes. Deidentified AI usage rows containing only feature name, model name, and token counts may remain for up to 90 days for cost, security, and abuse monitoring; after erasure they are not linked to you.
Krilo's production database has a three-day point-in-time backup window and no long-lived archive. Deleted data can remain recoverable in those backups for up to three days. If a backup is restored, our documented restore procedure requires every erasure fulfilled during the restored window to be reapplied before normal operation resumes.
Google's paid Gemini terms state that prompts and responses are not used to improve its products and may be logged for a limited period for abuse monitoring and required disclosures. Google does not publish a fixed maximum for that log and offers no Krilo-accessible per-user deletion API, so Krilo cannot recall or selectively delete an already-submitted request. Google's separate optional developer logging supports 7, 14, 28, or 55 days and defaults to a maximum of 55 days if enabled. Withdrawal prevents future requests.
Appeals
If Krilo refuses to act on your request, we will explain the decision and how to appeal. Email support@krilohealth.com with the subject “Consumer Health Data Appeal” within a reasonable time after receiving the decision. We will respond in writing within 45 days and explain any action taken or not taken. If we deny the appeal, you may submit a complaint through the Washington State Attorney General's complaint process.
Nevada Residents
Krilo extends the same access, sharing-list, consent-withdrawal, and deletion rights described in this policy to Nevada residents under NRS Chapter 603A.
Changes to This Policy
We may update this Consumer Health Data Privacy Policy as Krilo changes. When we make material changes, we will update the effective date above and provide notice where appropriate, such as an in-app notice or a notice on this page. If we ever introduce new sharing of consumer health data beyond what this policy describes, it will require your fresh, explicit opt-in consent before it applies to data collected from you.