Krilo is an AI-powered calorie, macro, meal-planning, recovery, and Apple Watch tracking app. This Privacy Policy explains what information we collect, how we use it, when we share it with service providers, and the choices you have.
Information We Collect
Account Information
Krilo supports Sign in with Apple and email/password accounts. When you use Sign in with Apple, Apple provides a stable Apple user identifier and, if you choose to share it, your email address. We do not receive or store your Apple ID password. When you create an email account, we collect your email address, verification status, and password authentication data. Passwords are stored using secure password hashing rather than plaintext.
We use account information to create and authenticate your account, sync data across devices, protect sessions using JWT access and refresh tokens, provide password reset and verification emails, and link subscription status.
Food, Nutrition, Goals, and Body Data
Krilo stores food entries and planned meals you create, including food names, serving details, ingredients, calories, protein, carbohydrates, fat, dates, meal type, entry source, favorites, barcode values, and related nutrition goals. Krilo also stores body-goal and onboarding inputs you choose to provide, such as sex, birth date, height, weight, activity level, weight goal, desired pace, calorie and macro goals, drink goals, sleep goals, step goals, distance goals, and flights-climbed goals.
Entries are saved locally on your device first and may sync to Krilo's backend when you use account-based sync. Weight entries, planned meals, favorite foods, nutrition goals, and account profile data may also sync to the backend.
Meal Photos, Text, and AI Features
When you use photo logging, the app compresses the image and sends it to Krilo's backend. The backend proxies the request to Google Gemini to identify foods and estimate nutrition. The Gemini API key is stored server-side and is not included in the iOS app. AI results are shown to you for review before anything is saved as a food log.
Krilo may also send text meal descriptions, food-search queries, meal-plan prompts, nutrition goals, planned meal names, and shopping-list items to the backend for server-side AI processing. These features include text meal analysis, AI meal-plan generation, food-search fallback estimates, and AI grocery ingredient decomposition for shopping lists.
If you confirm and save a photo-based entry or favorite, Krilo may store a compressed thumbnail with that entry or favorite for account restore and cross-device sync. Bulk sync strips image data. AI job payloads for queued meal plans and shopping lists may be retained temporarily so the app can recover pending results.
Apple Health Data
If you grant permission, Krilo can read selected Apple Health data to power calorie adjustments, Trends, Recovery, Sleep, and Strain features. The requested read categories may include Active Energy Burned, body mass, step count, exercise time, resting heart rate, heart rate variability, respiratory rate, sleeping wrist temperature, heart rate, walking and running distance, flights climbed, stand time, sleep analysis, workouts, and activity summaries.
Apple Health access is optional, read-only in Krilo, and can be revoked in iOS Settings. Krilo does not write nutrition, workout, or other health data back to Apple Health. Apple Health data is used to provide app features directly to you. We do not sell Apple Health data, use it for advertising or marketing, use it for data mining, or include it in marketplace exports.
Subscription and Purchase Data
Subscriptions are managed by Apple through StoreKit and the App Store. Krilo receives purchase validation information needed to determine whether your account has an active subscription, grace period, billing retry, revocation, or expiration. Payment card details are handled by Apple and are not provided to Krilo.
Feedback and Support Data
If you send feedback or a bug report, we collect the category, description, app version, operating system version, and account identifiers needed to respond, debug, and improve Krilo.
How We Use Information
- Provide food logging, macro tracking, meal planning, shopping-list generation, Trends, Recovery, Sleep, Strain, Apple Watch features, and cloud sync.
- Authenticate accounts and protect sessions using JWT-based authentication.
- Send verification, password reset, account, and support messages.
- Verify subscription status and enable paid features.
- Analyze meal photos, text meal descriptions, meal-plan prompts, food-search queries, and grocery-list inputs through server-side AI features when you request them.
- Look up nutrition through Open Food Facts, USDA FoodData Central, curated reference data, and AI fallback estimates.
- Maintain, secure, debug, and improve Krilo.
Third-Party Services
Krilo uses limited third-party services to operate the product:
- Google Gemini for AI photo analysis, text meal parsing, meal-plan generation, food-search fallback estimates, and grocery ingredient decomposition through Krilo's server-side proxy.
- Open Food Facts for barcode and food-search nutrition lookup.
- USDA FoodData Central for food-search nutrition lookup.
- Apple for Sign in with Apple, StoreKit subscriptions, App Store subscription management, App Store server notifications, and optional Apple Health access controlled by iOS permissions.
- Email and hosting providers to send account emails, host backend services, store production data, and operate Krilo.
We require service providers to process data only for the services they provide to Krilo and to protect user data appropriately.
Optional Anonymized Data Marketplace
Krilo includes an opt-in data consent feature for anonymized nutrition data exports. Only users who explicitly consent are included. If you do not opt in, your data is excluded from marketplace exports.
Exported marketplace records are limited to nutrition rows and include fields such as a per-export anonymized user hash, a per-export food-name hash, calories, protein, carbohydrates, fat, entry source, and timestamp rounded to the hour. Exported data does not include raw user IDs, names, email addresses, meal photos, thumbnails, Apple Health data, body-profile data, weight entries, feedback reports, subscription records, or Open Food Facts/barcode-derived rows.
Exported data uses HMAC-SHA256 identifiers derived from export-scoped salts to reduce cross-export linkage. Marketplace recipients are expected to use exported data only under their agreement with Krilo and not attempt to re-identify users. No anonymization method can guarantee that data can never be re-identified, especially if combined with other data sources.
You can opt out or revoke consent through account controls when available or by contacting support. Revocation excludes your data from future exports. Previously completed exports may not be retractable from recipients unless required by law or contract.
We do not sell personally identifiable data.
Storage and Security
Food, planned meal, favorite, weight, profile, goal, subscription, feedback, and marketplace-consent data may be stored locally on your device and/or synced to Krilo's backend. Backend production storage uses PostgreSQL. Authentication uses JWT access and refresh tokens, and the iOS app stores tokens in the Keychain. Network requests use HTTPS, and the app includes certificate pinning for backend communication.
No system can guarantee perfect security, but we use technical and organizational safeguards designed to protect account, nutrition, and subscription data.
Retention
We retain account, food log, planned meal, favorite, weight, profile, goal, subscription, feedback, and consent data while your account is active or as needed to provide Krilo. AI job payloads for queued meal plans and shopping lists are designed to be pruned after a limited period, and AI provider usage telemetry is retained for cost, security, and abuse monitoring for a limited period.
You can delete your account in the app. Account deletion is intended to permanently delete your account and associated synced data from Krilo's active systems, including food logs, weight entries, goals, profile data, subscription records, receipts, marketplace consent, and outstanding authentication records. Some records may be retained for a limited period where required for security, fraud prevention, legal compliance, accounting, dispute handling, or backup integrity. Deleting your Krilo account does not cancel an App Store subscription; subscription cancellation and refund requests must be handled through Apple.
Your Choices and Rights
- Use Apple Health only if you choose to grant permission, and revoke it in iOS Settings at any time.
- Review and edit AI-generated food entries before saving them.
- Manage or cancel subscriptions through Apple.
- Opt in or out of anonymized data marketplace participation.
- Delete your Krilo account in the app.
- Request access, correction, export, or deletion of your account data by contacting support.
Children's Privacy
Krilo is not intended for children under 13. We do not knowingly collect personal information from children under 13. Users under 18 should use Krilo only with permission from a parent or guardian. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.
International Users
Krilo is operated from the United States. If you use Krilo from another country, your information may be processed in the United States or other locations where our service providers operate.
Changes to This Policy
We may update this Privacy Policy as Krilo changes. When we make material changes, we will update the date above and provide notice where appropriate.
Contact
For privacy questions or requests, email support@krilohealth.com.