Krilo is an AI-powered calorie, macro, meal-planning, recovery, and Apple Watch tracking app built and operated by Nicholas Gittings ("Krilo", "we", "us"). This Privacy Policy explains what information we collect, how we use it, when we share it with service providers, and the choices you have.
Our separate Consumer Health Data Privacy Policy describes our health-data practices and the rights available under Washington's My Health My Data Act and Nevada consumer health data law.
September 9, 2026 update: We have clarified Australian and New Zealand privacy rights, operator identity, and overseas processing, and corrected descriptions of AI usage and subscription record retention.
Information We Collect
Account Information
Krilo supports Sign in with Apple and email/password accounts. When you use Sign in with Apple, Apple provides a stable Apple user identifier and, if you choose to share it, your email address. We do not receive or store your Apple ID password. When you create an email account, we collect your email address, verification status, and password authentication data. Passwords are stored using secure password hashing rather than plaintext.
We use account information to create and authenticate your account, sync data across devices, protect sessions using JWT access and refresh tokens, provide password reset and verification emails, and link subscription status.
Food, Nutrition, Goals, and Body Data
Krilo stores food entries and planned meals you create, including food names, serving details, ingredients, calories, protein, carbohydrates, fat, dates, meal type, entry source, favorites, barcode values, and related nutrition goals. Krilo also stores body-goal and onboarding inputs you choose to provide, such as sex, birth date, height, weight, activity level, weight goal, desired pace, calorie and macro goals, drink goals, sleep goals, step goals, distance goals, and flights-climbed goals.
Entries are saved locally on your device first and may sync to Krilo's backend when you use account-based sync. Weight entries, planned meals, favorite foods, nutrition goals, and account profile data may also sync to the backend.
Meal Photos, Text, and AI Features
Gemini-assisted features are limited to users 18 years or older. Before Krilo first shares information for a Gemini-assisted feature, the app asks for your permission in a disclosure that names Google Gemini and describes the information involved. If you allow it, data travels through Krilo's server solely to produce the result you requested. You can withdraw permission at any time under Account → AI Data Sharing. Withdrawal blocks new Gemini requests, although a request already submitted cannot be recalled.
When you use photo logging after allowing Gemini features, the app compresses the image and sends it to Krilo's backend. The backend proxies the request to Google Gemini to identify foods and estimate nutrition. The Gemini API key is stored server-side and is not included in the iOS app. AI results are shown to you for review before anything is saved as a food log.
Krilo may also send text meal descriptions, food-search queries, meal-plan prompts, nutrition goals, planned meal names, and shopping-list items to the backend for server-side AI processing. These features include text meal analysis, AI meal-plan generation, food-search fallback estimates, and AI ingredient decomposition for shopping lists. A meal-plan calorie target may include an active-energy adjustment calculated on your device.
A meal photo you submit is held in memory only for the single request to Google Gemini and is discarded once that request completes; Krilo does not store your meal photos. Once a photo is analyzed and you confirm the resulting food entry, only the nutrition data you save (not the image) is kept with that entry or favorite. AI job payloads for queued meal plans and shopping lists may be retained temporarily so the app can recover pending results.
Apple Health Data
If you grant permission, Krilo can read selected Apple Health data to power calorie adjustments, Trends, workout maps, Recovery, Sleep, and Strain features. The requested read categories may include Active Energy Burned, body mass, step count, exercise time, walking and running distance, flights climbed, stand time, workouts, workout routes and associated location, activity summaries, resting and workout heart rate, heart rate variability, respiratory rate, sleeping wrist temperature, and sleep analysis.
Apple Health samples, workout routes, and associated location are processed on your device and are not synced to Krilo's backend. When you separately allow a Gemini feature that uses goals or derived context, only the information described in that Gemini disclosure is sent for the requested result.
Apple Health access is optional, read-only in Krilo, and can be revoked in iOS Settings. Krilo does not write nutrition, workout, or other health data back to Apple Health. Apple Health data is used to provide app features directly to you. We do not sell Apple Health data or use it for advertising, marketing, or data mining.
Subscription and Purchase Data
Subscriptions are managed by Apple through StoreKit and the App Store. Krilo receives purchase validation information needed to determine whether your account has an active subscription, grace period, billing retry, revocation, or expiration. Payment card details are handled by Apple and are not provided to Krilo.
Feedback and Support Data
If you send feedback or a bug report, we collect the category, description, app version, operating system version, and account identifiers needed to respond, debug, and improve Krilo.
How We Use Information
- Provide food logging, macro tracking, meal planning, shopping-list generation, Trends, Recovery, Sleep, Strain, Apple Watch features, and cloud sync.
- Authenticate accounts and protect sessions using JWT-based authentication.
- Send verification, password reset, account, and support messages.
- Verify subscription status and enable paid features.
- Analyze meal photos, text meal descriptions, meal-plan prompts, food-search queries, and shopping-list inputs through server-side AI features when you request them.
- Look up nutrition through Open Food Facts, USDA FoodData Central, curated reference data, and AI fallback estimates.
- Maintain, secure, debug, and improve Krilo.
Third-Party Services
Krilo uses limited third-party services to operate the product:
- Google Gemini for AI photo analysis, text meal parsing, meal-plan generation, food-search fallback estimates, and ingredient decomposition through Krilo's server-side proxy.
- Open Food Facts for barcode and food-search nutrition lookup.
- USDA FoodData Central for food-search nutrition lookup.
- Apple for Sign in with Apple, StoreKit subscriptions, App Store subscription management, App Store server notifications, and optional Apple Health access controlled by iOS permissions.
- Resend to send account and transactional emails. Resend is not sent food logs, prompts, goals, weights, or Apple Health samples.
- Render to host backend services and the production PostgreSQL database.
These providers process information to deliver the services described above. Their handling of information is also subject to their applicable terms and privacy policies.
We Do Not Sell or License Your Data
Krilo does not sell or license your personal data, food data, or health data, and there is no active data-sharing or data-licensing program today. We share only what is needed to provide the features you request through the service providers described above and in our Consumer Health Data Privacy Policy.
If we ever introduce a program that shares anonymized data with outside organizations, it will be strictly opt-in: it will require your explicit, revocable consent, we will describe what is included before you opt in, and we will update this Privacy Policy with notice before it goes live. Nothing you do in the app today enrolls you in such a program.
Storage and Security
Food, planned meal, favorite, weight, profile, goal, subscription, and feedback data may be stored locally on your device and/or synced to Krilo's backend. Krilo’s backend services and production PostgreSQL database are hosted in the United States by Render. Authentication uses JWT access and refresh tokens, and the iOS app stores tokens in the Keychain. Network requests to Krilo's backend use HTTPS.
No system can guarantee perfect security, but we use technical and organizational safeguards designed to protect account, nutrition, and subscription data.
Retention
We retain account, food log, planned meal, favorite, weight, profile, goal, subscription, and feedback data while your account is active or as needed to provide Krilo. AI job payloads for queued meal plans and shopping lists are pruned after a limited period, and AI usage records (including feature name, model name, and token counts) are retained for up to 90 days for cost, security, and abuse monitoring. While retained, these usage records remain linked to your account until health-data erasure or account deletion removes that link; deidentified usage records may remain for the rest of that retention period.
Delete My Data in the app erases your synced health data while keeping your account active. Our Consumer Health Data Privacy Policy lists exactly what this removes and what is retained.
Krilo's production database has a three-day point-in-time backup window and no long-lived archive. Deleted data can remain recoverable in those backups for up to three days. If a backup is restored, Krilo's documented restore procedure requires every erasure fulfilled during the restored window to be reapplied before normal operation resumes.
Google's paid Gemini terms state that prompts and responses are not used to improve its products and may be logged for a limited period for abuse monitoring and required disclosures. Google does not publish a fixed maximum for that log, and Krilo cannot recall or selectively delete an already-submitted Gemini request. Google's separate optional developer logging supports 7, 14, 28, or 55 days and defaults to a maximum of 55 days if enabled.
You can also delete your account in the app. Account deletion removes the account and associated synced data, including Krilo's associated subscription, transaction, and receipt records, from Krilo's active systems. Health-only erasure keeps those subscription records so your account and subscription can continue. Apple independently retains purchase and billing information under its own policies and legal obligations; deleting data from Krilo does not delete Apple's records. Deleting Krilo data or the account does not cancel an App Store subscription. Manage cancellation and App Store refund requests through Apple; this does not limit statutory remedies against Krilo described in our Terms.
Your Choices and Rights
- Use Apple Health only if you choose to grant permission, and revoke it in iOS Settings at any time.
- Allow or decline Google Gemini sharing before it begins, and withdraw that permission under Account → AI Data Sharing.
- Review and edit AI-generated food entries before saving them.
- Manage or cancel subscriptions through Apple.
- Download a JSON copy of your account and health data using Account → Download My Data.
- Delete synced health data while keeping your account using Account → Delete My Data.
- Delete your Krilo account in the app.
- Edit entries in the app to correct them, or contact support to request access to other personal information we hold or corrections beyond the in-app controls. You do not have to use the export or editing tools before contacting us.
Children's and Minors' Privacy
Krilo is not intended for children under 13. We do not knowingly collect personal information from children under 13. Users under 18 should use Krilo only with permission from a parent or guardian. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it. Krilo's AI features are restricted to users 18 and older, and Krilo does not knowingly send content to Google Gemini on behalf of anyone under 18. If we learn that a user under 18 has enabled AI Data Sharing, we will disable it and delete the associated records where practicable.
International Users
Krilo is operated from the United States. If you use Krilo from another country, your synced information is hosted in the United States. Service providers may also process information overseas in locations where they operate. Privacy laws in those locations may differ from those in Australia or New Zealand. Contact our privacy contact below for information about overseas processing. This disclosure does not waive any rights or obligations under applicable privacy law.
Australia and New Zealand
You may request access to personal information we hold about you, ask us to correct it, or make a privacy complaint by emailing support@krilohealth.com, our privacy contact for Nicholas Gittings, operator of Krilo. Describe the information or concern and the outcome you seek. We may ask for information reasonably necessary to verify your identity. These requests can cover information beyond the in-app export and editing controls.
Australia: We respond to access and correction requests within a reasonable period, generally 30 calendar days, consistent with OAIC guidance. If circumstances reasonably require longer, we will explain the reason and expected response date; this is not an automatic extension or a change to the reasonable-period requirement. If we refuse access or correction, we will provide written reasons (except where the law permits us not to) and complaint options. If a correction is refused, you may ask us to associate a statement that you consider the information incorrect.
New Zealand: We will decide access and correction requests as soon as reasonably practicable and generally within 20 working days after receipt, calculated under the Privacy Act 2020. If access is granted, we will provide the information without undue delay. We may extend a deadline only where the law permits, such as where necessary consultations prevent a timely response or a large access request would unreasonably interfere with operations, and only for a reasonable period. We will notify you within the original 20 working days of the extension, its reasons, its duration, and your right to complain to the Privacy Commissioner. If we decline a correction, you may request that a statement of the correction sought but not made be attached so it is read with the information. We will explain any refusal and your complaint rights. See the Privacy Commissioner's access guidance.
Complaints: Please contact us first so we can investigate and respond to your concerns. If you are dissatisfied with our response or handling of your request, you may complain to the Office of the Australian Information Commissioner (OAIC) or the New Zealand Office of the Privacy Commissioner, as applicable, following their complaint procedures. The access and correction decision periods above are not deadlines for completing a complaint investigation.
Applicable regional statutory rights take precedence over any inconsistent wording in either privacy policy. The Washington/Nevada 45-day procedure, twice-yearly free-access wording, and Washington appeal route in our Consumer Health Data Privacy Policy do not limit Australian or New Zealand rights, response periods, or complaint routes.
Changes to This Policy
We may update this Privacy Policy as Krilo changes. When we make material changes, we will update the effective date above and provide notice where appropriate.
Contact
For privacy questions, rights requests, or help using the in-app controls, contact Nicholas Gittings through our privacy contact, support@krilohealth.com.