We built KaleWay to be a different kind of weight loss app — one that respects you, including your right to know what we do with your information.

This is the most readable Privacy Policy we could write while still telling you the truth. The full policy follows. It is long because privacy is detailed work; we owe you the detail.

The short version

  • We collect what we need to make KaleAI work for you — your goals, your dietary preferences, your health context, your conversations with KaleAI.
  • We share specific information with specific service providers (named below), including Anthropic, who powers KaleAI.
  • We never sell your information. We never share it with advertisers.
  • You can ask us what we have, ask us to delete it, or close your account at any time.
  • If you have questions, write to support@kaleway.com and a real person will answer.

01Who we are

KaleWay is a mindful weight loss app built around an AI companion called KaleAI. The app is operated by Granviex, LLC, a Florida limited liability company doing business as "KaleWay" (referred to in this Policy as "KaleWay," "we," "us," or "our"). When this Policy refers to "you" or "your," it means the person using KaleWay.

If you have questions about this Policy, you can reach us at support@kaleway.com.


02What this Policy covers

This Policy describes how we collect, use, store, share, and protect your personal information when you:

  • Download, install, or use the KaleWay mobile app on iOS or Android
  • Visit kaleway.com or any related KaleWay website
  • Communicate with us by email
  • Interact with us in any other way (for example, replying to a survey)

This Policy covers all of these uses except where another notice applies. In particular:

When the same topic is mentioned in this Policy and in one of those notices, the more specific notice controls.


03The information we collect

We organize the information we collect into seven categories.

3.1 — Information you give us directly

Account information: your email address, password (stored as a hashed value — we cannot read it), and your first name. If you sign up using Apple, we receive an anonymous identifier from Apple and (if you choose to share it) your email.

Profile information: your age, gender, height, current weight, goal weight, activity level, and the state or region you live in. (See Section 3.2 for how your country is initially detected.)

Food allergies (medical, sensitive): the FDA Big-9 allergens you select (milk, eggs, fish, shellfish, tree nuts, peanuts, wheat, soy, sesame) plus up to 3 free-text “Other” entries (max 30 characters each). We treat allergies as zero-tolerance medical constraints in your meal plans and in every KaleAI conversation.

Cuisine preferences: up to 10 cuisines you select (American, Italian, Mexican, Asian, Mediterranean, Japanese, Indian, French, Middle Eastern, Brazilian) or “Surprise me”. Used to personalize meal plan generation.

Health context: dietary restrictions and preferences (for example, vegetarian, gluten-free, dairy-free), health conditions you choose to share with us through the app's profile (for example, pregnancy, breastfeeding, menopause, polycystic ovary syndrome (PCOS), thyroid conditions), and other context you provide that affects your meal plan.

My Why List: the personal motivations you write down or that KaleAI suggests and you accept. We treat these as the most sensitive emotional content in your account and reference them only in motivational moments (the Help Me Now flow, paywall recap, occasional reminders).

Trap Cards content: behavioral coping cards generated either by KaleAI or by you. Each card has a category, situation, sabotaging thought, response, and action.

Conversations with KaleAI: the messages you send to KaleAI and the responses she provides. We treat these conversations as private to your account.

Mood logs (sensitive emotional data): optional one-tap mood entries (e.g., “great”, “okay”, “hard”) tied to a date. Used to surface patterns and trigger empathy in KaleAI.

Behavior Wins: pillar-tagged events when you log a workout, mark a meal as eaten, log your weight, and similar in-app actions. Used to power the streak counter.

Meal status logs: per-meal-type, per-date markers (“eaten”, “skipped”, “pending”) for your generated meal plan.

Mind Moments completion: date-stamped tracking of which Mind Moments you've completed (so we don't repeat them).

Off-plan food diary entries: when you log food outside the meal plan via KaleAI's log_food tool, we save the description, calories, macros, source (“fatsecret_grounded” or “ai_estimate”), confidence, and date.

Customer support information: if you email us, we receive your email address and the content of your message.

3.2 — Information we collect automatically

When you use the app, we and our service providers automatically collect:

Device and technical information: device model, operating system version, app version, language settings, time zone, IP address, and a randomly generated device identifier we use to operate the app.

Country (ISO 3166): we auto-detect your country code from your device's regional settings on first sign-in (using Expo Localization), and you can change it anytime in Profile. KaleWay V1 supports 14 countries: US, BR, PT, GB, DE, ES, FR, IT, MX, IN, AU, CA, IE, NZ. Country drives grocery store names, units (metric or imperial), and meal plan availability.

Usage information: which screens you visit, which features you use, and how long you spend on different parts of the app. We use this only to understand how to improve KaleWay; we do not use it to identify you to third parties.

Review-prompt state: if we asked you to rate the app, we record whether you said yes/no, when we asked, how many times we've asked, and whether you've opted out of being asked again.

3.3 — Information from Apple HealthKit (only if you grant permission)

If you grant the permission, we read only the following from your Apple HealthKit:

  • Your weight history
  • Your daily step count and active energy data

We do not write to your HealthKit. We do not access any other category of HealthKit data. HealthKit data is used only to personalize your nutrition and movement plans within the app, in compliance with Apple's HealthKit terms.

We do not share HealthKit data with any third party, including Anthropic, our analytics provider, or our marketing partners. HealthKit data is processed and stored only on your device and on our backend (Supabase), and it is not used for any purpose other than personalizing your KaleWay experience.

3.4 — Information from Sign in with Apple (only if you choose this method)

If you sign up using Apple, we receive an anonymous user identifier from Apple. You can choose whether to share your email address; if you do not, you will receive a private relay email from Apple, which we use only to communicate with you about the service.

3.5 — Subscription information

When you start a trial or subscribe to a paid plan, the transaction is processed by Apple (on iOS) or Google (on Android). We never see your full payment information. We receive only:

  • A subscription identifier
  • Your subscription state (trial, active, canceled, expired)
  • The plan you selected

We use a service called RevenueCat to manage subscription state across platforms. See Section 5 for details.

3.6 — Information you choose to share

If you opt in, we may collect:

  • Your email address for our newsletter (entirely optional)
  • In-app feedback. When you submit feedback via the post-rating dialog or the Profile → Send Feedback row, we store the category you picked (nutrition, movement, mindset, kaleai, app_speed, other), the body of your message (max 500 characters), and the source channel. Feedback is insert-only on our backend — we cannot edit it on your behalf.
  • Feedback you submit through a survey
  • A photo or screenshot you choose to send us for support purposes (we do not require photos)

3.7 — Information from third-party sources

We do not buy lists of users or pull your data from advertising partners. The only "third-party source" we use is Apple HealthKit, described in Section 3.3.


04How we use your information

We use the information we collect to:

Provide the service. Generate your meal plan, build your workout program, power KaleAI's conversations with you, track your weight, manage your subscription, and let you log in.

Personalize your experience. Adjust meal recommendations based on your preferences and feedback, suggest workouts that fit your stated energy and time, and help KaleAI remember context from earlier conversations.

Communicate with you. Send you transactional emails (account confirmations, password resets, subscription receipts), respond to your support requests, and — if you opted in — send you the newsletter.

Keep KaleWay safe. Detect and prevent abuse, fraud, and unauthorized access. Enforce our Terms of Service.

Improve KaleWay. Understand how the app is used (in aggregate, never tied to your identity) so we can build better features. We do not log identifying health information to our analytics.

Comply with the law. Respond to legal requests, comply with court orders, and meet our regulatory obligations.

We do not use your information for advertising or for "people-based" marketing targeting on third-party platforms. We do not sell your information.


05Who we share your information with

We share specific categories of information with specific third parties, only for the purposes described below. Each one is a service provider acting on our instructions, not an independent recipient of your data for their own purposes.

Anthropic, PBC United States
Receives
The messages you send to KaleAI, relevant context about your goals and dietary preferences, and the engineered prompts we use to instruct the AI.
Why
To power KaleAI's responses and AI-generated meal plans and Trap Cards.
How long
Anthropic deletes the inputs and outputs from their backend within approximately 7 days of receipt. Anthropic does not use this data to train their AI models, because we are a commercial API customer subject to Anthropic's Commercial Terms.

For a more complete description of how AI processing works in KaleWay, see our AI Privacy Notice.

Supabase, Inc. United States
Receives
All of your account data — profile, health context, conversations, weight logs, subscription state.
Why
To operate our backend database and authentication system. Without Supabase, your account would not work.
How long
For as long as your account is active, plus a brief deletion window after you close your account (see Section 9).
RevenueCat, Inc. United States
Receives
An anonymous user identifier and your subscription state.
Why
To manage your trial, subscription, and billing across iOS and Android.
How long
Per RevenueCat's data retention policy.
FatSecret Platform API US & Australia
Receives
Food queries — what you searched for or what KaleAI is looking up — without information that identifies you personally.
Why
To provide nutritional information about foods.
How long
Per FatSecret's data retention policy.
Apple Inc. App Store · HealthKit · Sign in
Receives
Subscription transaction information when you subscribe through the App Store. If you use Sign in with Apple, your authentication is handled by Apple. HealthKit is read-only on the device and not transmitted by us — Apple receives no new data from KaleWay through HealthKit.
Why
To process subscriptions, authenticate you, and integrate with Apple's health platform if you choose.
How long
Per Apple's privacy policy and terms.
Google LLC Google Play · future
Receives
Subscription transaction information if you subscribe through Google Play.
Why
To process Android subscriptions.
How long
Per Google's privacy policy.
PostHog, Inc. European Union (eu.i.posthog.com)
Receives
Pseudonymous behavioral events (which screens you visit, which features you use, which paths through onboarding) tied to a random user identifier. Personally identifying fields — your name, email, weight, height, age, biological sex, health conditions, Why List content, trap scores — are scrubbed by KaleWay before any data leaves your device.
Why
To understand how women use KaleWay so we can improve the product. Aggregate analytics only.
How long
13 months of historical events, plus the duration of your active account. Session Recording is disabled in this version of the app.
Sentry / Functional Software, Inc. United States (sentry.io)
Receives
Crash reports, errors, and unexpected-behavior traces. Like PostHog, all personally identifying fields are scrubbed by KaleWay before any data leaves your device.
Why
To detect and fix bugs in the app.
How long
90 days for error events, per Sentry's standard retention. Session Replay is disabled in this version of the app.
Resend, Inc. United States
Receives
Your email address and the body of the transactional email being sent (welcome message, password reset, account-related notification). Resend also backs Supabase Auth's outbound SMTP, so the same applies to authentication emails. Sender is hello@kaleway.com.
Why
To deliver transactional emails reliably.
How long
Per Resend's standard retention. Newsletter unsubscribe stops further sends immediately.
Meta Platforms, Inc. (iOS app only) United States · advertising measurement
Receives
When KaleWay's iOS app fires a small set of measurement events — Install, CompleteRegistration (account creation), InitiateCheckout (paywall reached, only for users who go on to purchase), StartTrial, and Subscribe — it sends a record of that event to Meta. Each event includes:
  • A SHA-256 hash of your email (lowercased + trimmed)
  • A SHA-256 hash of your KaleWay user ID
  • Your IP address
  • The name of the event (e.g., “StartTrial”)
  • The purchase amount in USD (StartTrial and Subscribe events only)
  • Your IDFA (Apple advertising identifier)only if you granted Apple's “Allow Tracking” prompt

What we never send to Meta: your conversations with KaleAI, mood logs, weight, HealthKit data, allergies, dietary restrictions, health conditions, or any behavioral or health information.

How it travels
Some events are sent through Meta's iOS SDK on your device (react-native-fbsdk-next). Others are sent server-to-server from our backend (Supabase Edge Functions) or from RevenueCat directly to Meta's Conversions API. Both paths use the same data fields above. Tracking domains declared in our app's Privacy Manifest: graph.facebook.com, connect.facebook.net, b-graph.facebook.com.
Why
Advertising measurement only — install attribution and subscription conversion tracking, so we can spend our marketing budget responsibly. Not used for retargeting or behavioral ad targeting on KaleWay's side.
Your control
When you first reach the paywall and grant AI consent, KaleWay shows Apple's “Allow Tracking” prompt (App Tracking Transparency). If you tap Ask App Not to Track, KaleWay still works fully — we send measurement events without your IDFA, which makes attribution less precise but does not change any feature. You can revoke this anytime via iOS Settings → Privacy & Security → Tracking → KaleWay, or by deleting your account. See Section 8 for the full opt-out walkthrough.
How long
Meta retains app event data per its Business Help Center policy. KaleWay does not control that retention.
Note (V1.0.2+)
Starting in V1.0.2, KaleWay also uses AppsFlyer as a Mobile Measurement Partner that forwards the same standard advertising-measurement events to Meta (see the AppsFlyer entry below). During the V1.0.2–V1.0.x window, both paths run in parallel; Meta deduplicates the events server-side using a shared event ID. In a near-future release, the direct Meta SDK path will be retired and AppsFlyer will become the sole source of Meta measurement events. The fields sent to Meta will not change.
AppsFlyer Ltd. (iOS app only, V1.0.2+) Israel / EU · multi-network ad measurement
Receives
Starting with V1.0.2, KaleWay's iOS app uses AppsFlyer as a Mobile Measurement Partner (MMP) — a service that helps us understand which ad campaigns (across Meta, TikTok, Apple Search Ads, Google, and ~5,000 smaller ad networks) bring people to KaleWay so we can spend our marketing budget responsibly. AppsFlyer is the single integration that fans out attribution signals to those networks; it does not show ads itself and is not an advertiser.

Each event includes:

  • AppsFlyer's internal device identifier (an opaque per-install ID it generates — not Apple's IDFA)
  • Your KaleWay user ID (the same internal UUID we use; not your email)
  • The name of the event (e.g., af_complete_registration, af_start_trial)
  • Event parameters limited to non-personal fields like paywall_variant or plan_type
  • Your device model and OS version
  • Your IP address (used for SKAdNetwork postback routing and to detect whether DMA/EEA consent rules apply)
  • Your IDFAonly if you granted Apple's “Allow Tracking” prompt
  • For subscription events, the purchase amount and currency — forwarded server-to-server by RevenueCat to AppsFlyer, which then forwards to the relevant ad networks

What we never send to AppsFlyer: your conversations with KaleAI, mood logs, weight or HealthKit data, allergies, dietary restrictions, health conditions, or any other consumer health data. The Customer User ID we link to your install is a randomly-generated UUID — it is not your email address.

How it travels
The AppsFlyer iOS SDK on your device (react-native-appsflyer) sends the install + standard events. The AppsFlyer Purchase Connector forwards subscription/trial events server-to-server from RevenueCat to AppsFlyer with no app-side code. Tracking domains declared in our app's Privacy Manifest: appsflyersdk.com, app.appsflyer.com, events.appsflyer.com.
Why
Multi-network advertising measurement — install attribution + subscription conversion tracking across Meta, TikTok, Apple Search Ads, Google, and 5,000+ other partners through a single MMP integration. Not used for retargeting or behavioral ad targeting on KaleWay's side.
Onward sharing
AppsFlyer forwards the same measurement events to Meta, TikTok, Apple Search Ads, Google, and any other ad network you tapped on before installing KaleWay. The downstream sharing is governed by AppsFlyer's Privacy Policy and each ad network's own privacy practices. See the Meta entry above for what Meta receives, and assume similar — though typically more limited — data flows to TikTok / Google / Apple Search Ads.
EU / EEA users
If your device's region is in the EEA (EU 27 + Iceland + Liechtenstein + Norway) or the United Kingdom, KaleWay applies AppsFlyer's “limited consent” mode by default. This blocks AppsFlyer from sharing your individual event data with Meta / TikTok / Google for ad personalization, while still allowing aggregated install-attribution measurement to flow. We do this silently (without an additional consent banner) because the EEA's Digital Markets Act and GDPR allow such “legitimate interest” measurement processing when no personalized targeting follows.
Your control
Same Apple ATT prompt as for Meta. Tap Ask App Not to Track to stop your IDFA from reaching AppsFlyer or any of its downstream networks. Revoke anytime via iOS Settings → Privacy & Security → Tracking → KaleWay. See Section 8 for the full opt-out walkthrough.
How long
AppsFlyer retains app event data per its Customer Data Processing Addendum. KaleWay does not control that retention but can request deletion of your data via support@kaleway.com.

Apple Search Ads & app attribution providers (limited)

We may receive aggregated installation attribution data from Apple Search Ads or similar attribution services. This data does not identify you personally and is used only to understand which marketing channels work.

Customer support tools

If you write to support@kaleway.com, your email is processed by Google Workspace.

Government, law enforcement, or legal process

If we are required by law to share information — for example, in response to a subpoena, court order, or other valid legal request — we will. We will only share what we are legally required to share and will, where legally permitted, notify you first.

Business transfers

If KaleWay is acquired, merged, or sold, your information may be transferred to the new owner along with the rest of the business. If this happens, the new owner will be bound by the commitments in this Privacy Policy or will notify you of changes.


06What we do not do with your information

This list is as important as the list above.

  • We do not sell your personal information. Ever. Under any definition — including “sale” or “share” under California Civil Code §1798.140, or sale or transfer under the GDPR. Not for analytics, not for advertising, not for any purpose. The advertising measurement we do (Meta install + subscription attribution — see Section 5) does not constitute a sale.
  • We do not train AI models on your data — ours or Anthropic's. KaleWay is a commercial API customer of Anthropic; under Anthropic's Commercial Terms, your KaleAI inputs and outputs are not used to train Anthropic's models. We also do not train any KaleWay-side models on your conversations, profile, or behavior. (See our AI Privacy Notice for the contractual no-training commitment.)
  • We do not record or replay your screen interactions. PostHog Session Recording and Sentry Session Replay are both disabled in this version of the app. If we ever enable them in a future version, this Policy will be updated and we will require renewed consent before turning them on.
  • We never use your KaleAI conversations, mood logs, My Why List, Trap Cards, weight history, health conditions, allergies, dietary restrictions, or any HealthKit data for advertising. The advertising measurement events the iOS app sends to Meta are strictly scoped: install, account creation, paywall reached (purchasers only), free trial started, and subscription started — with hashed identifiers and (only with your ATT consent) IDFA. No conversation content, no health data, no behavioral patterns. See Section 5 (Meta Platforms) for the full field list.
  • We do not place third-party tracking scripts on kaleway.com. No Meta Pixel, no Google Analytics, no other web trackers on the marketing site or on the parts of the site that display health information. (The iOS app's Meta App Events SDK is a separate, in-app integration disclosed in Section 5.)
  • We do not share your conversations with KaleAI with anyone outside Anthropic (the AI provider, who processes them and then deletes them — see Section 5) and Supabase (where we store your chat history within your account).
  • We do not share your HealthKit data with any third party. Not Anthropic, not analytics, not Meta, not anyone. HealthKit data stays between your device and our backend.
  • We do not share your information with your employer, your insurance company, your healthcare provider, or data brokers unless you specifically ask us to and we have built that integration. We have not built any such integration; we have no B2B program.

07How long we keep your information

We keep different categories of information for different lengths of time, based on what's necessary to operate KaleWay and meet our legal obligations.

Account information: for as long as your account is active.

Health profile and behavior data: for as long as your account is active.

Mood logs, Trap Cards, Mind Moment completions, My Why List, Behavior Wins: for the duration of your active account. Deleted within 30 days of account deletion (with backup propagation to follow per the schedule below).

Conversations with KaleAI: stored on our backend for as long as your account is active. Anthropic deletes their copies within approximately 7 days of receipt or generation.

In-app feedback (app_feedback) submissions: up to 3 years from submission, for product-improvement and dispute-resolution purposes. Deleted earlier on request.

Review-prompt state: persists with your account. Reset only if you delete your account or successfully request a review-state reset via support.

Subscription records: for as long as required by tax and accounting laws (typically 7 years), even after you close your account.

Customer support correspondence: for up to 3 years after the conversation ends, to help us serve you better if you contact us again.

Backups: when you delete your account or specific data, the data is removed from our active systems immediately and from our routine backups within approximately 30 days.


08Your rights and choices

You have rights to your information. The exact set of rights depends on where you live, but the following rights apply to all KaleWay users regardless of location.

Universal rights

Access. You have the right to ask us what personal information we have about you.

Correction. You have the right to update or correct inaccurate information. You can do this directly in the app's profile settings, or by writing to support@kaleway.com.

Deletion. You have the right to ask us to delete your information. You can delete your account directly from the app's profile screen (the "Delete My Account" option), or by writing to support@kaleway.com.

Withdrawal of consent. Where we rely on your consent to process your information, you can withdraw that consent at any time. Withdrawing consent for AI features is described in our AI Privacy Notice.

Account closure. You can close your KaleWay account at any time. When you do, we delete your information from our active systems and notify our service providers (including Anthropic) to do the same.

How to exercise rights

To exercise any of these rights — including access, correction, deletion, or data portability — email support@kaleway.com with the subject line “Privacy Request” and your registered email address. We may need to verify your identity before responding so your information is not given to someone else; we will explain what verification we need.

We respond within 30 days for users covered by the GDPR (per Art. 12(3)) and within 45 days for California residents (per CCPA §1798.130(a)(2)(B)). Either window can be extended once if your request is complex, with notice to you within the original window.

California residents who wish to use an authorized agent can do so by emailing the address above; we will provide instructions for the agent to verify their authorization. We do not discriminate against users who exercise privacy rights.

Opt out of Meta advertising measurement (iOS only)

The first time you reach our paywall and grant AI consent, the iOS app shows Apple's App Tracking Transparency (ATT) prompt. Tap Ask App Not to Track — KaleWay continues to work fully without your advertising identifier (IDFA). You can revoke this decision at any time in iOS Settings → Privacy & Security → Tracking → KaleWay.

Even with ATT off, the iOS app still sends a small number of measurement events to Meta (without your IDFA) so we can attribute installs at the campaign level. The fields sent in that no-IDFA case are listed in Section 5 (Meta Platforms). If you want those events to stop entirely, delete your account — once your account is gone, no further measurement events fire from your device or our backend.

Region-specific rights

If you live in California

You have the rights described above, plus the following under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):

  • Right to know. A list of the categories of personal information we collect, sources, business purposes, and third parties we share with — described above in Sections 3, 4, and 5.
  • Right to limit use of sensitive personal information. You can ask us to limit our use of sensitive personal information (which, in your case, includes health information) to providing you the service. We already follow this principle as our default — we do not use sensitive information for advertising or profiling.
  • Right to non-discrimination. We will not deny service, charge different prices, or provide a different level of quality because you exercised a privacy right.
  • Right to no sale. We do not sell your personal information. You can review our Do Not Sell My Personal Information page for confirmation.

If you would like to designate an authorized agent to exercise rights on your behalf, contact support@kaleway.com.

If you live in Washington

You have rights under the Washington My Health My Data Act regarding your consumer health data, described in our Consumer Health Data Privacy Notice. That Notice explains what consumer health data we collect, who receives it, how to exercise your rights, and how to appeal a denial.

Other U.S. states

States including Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Tennessee, Montana, Iowa, and others have passed privacy laws that grant you rights similar to those described above for California. These rights typically include access, correction, deletion, and the ability to opt out of certain types of processing. To exercise any of these rights, write to support@kaleway.com.

EU · UK · GDPR-aligned regions

You have additional rights under the General Data Protection Regulation (GDPR) and related laws:

  • Right to access the personal data we hold about you
  • Right to rectification of inaccurate data
  • Right to erasure ("right to be forgotten")
  • Right to data portability — to receive your data in a machine-readable format
  • Right to restrict processing
  • Right to object to processing based on legitimate interests
  • Right to lodge a complaint with your local data protection authority

The legal bases on which we process your data are: consent (for AI features and for newsletter), contract performance (to provide the service you signed up for), legitimate interests (security and product improvement), and legal obligation (when required by law).

We do not currently have a designated Data Protection Officer because of our small size. For data protection inquiries from the EU, UK, or similar regions, write to support@kaleway.com.


09Account deletion in detail

When you delete your KaleWay account:

Immediately
Your access to the app is revoked, your account is marked for deletion, and you are signed out.
Within 7 days
All of your account data is removed from our active production database. This includes your profile, health data, conversations with KaleAI, weight logs, and any other personal data.
Within 30 days
Your data is removed from our routine backups.
Anthropic
Within approximately 7 days of any individual conversation with KaleAI, Anthropic deletes the corresponding inputs and outputs from their backend. Account deletion does not change this — it is the standard policy for our commercial API use.
Sign in with Apple
If you authenticated with Apple, we revoke our session token with Apple's identity service.
Subscriptions
Active subscriptions must be canceled separately through the App Store or Google Play. Deleting your KaleWay account does not automatically cancel an active App Store or Google Play subscription. We cannot cancel App Store subscriptions on your behalf — Apple and Google control that flow.

Some information must be retained after account deletion:

  • Subscription transaction records (kept for tax and accounting purposes, typically 7 years).
  • Records related to legal disputes or investigations, until resolved.
  • Aggregated, de-identified data that no longer identifies you (for example, "we had X total active users last month").

10How we protect your information

We take reasonable and appropriate measures to protect your information, including:

  • Encryption in transit: all communication between your device and our servers, and between our servers and our processors (Supabase, Anthropic, PostHog, Sentry, Resend), uses TLS 1.3.
  • Encryption at rest: your data is encrypted when stored in our database (AES-256, Supabase Postgres default).
  • Access controls: only authorized personnel can access user data, and only when necessary for support, debugging, or legal compliance.
  • Authentication: access to administrative systems requires multi-factor authentication.
  • Monitoring: we monitor our systems for unusual activity.
  • Vendor diligence: we choose service providers with strong security practices.

No system is perfectly secure. If we discover a breach that affects your personal information, we will notify you in accordance with applicable law, including the Federal Trade Commission's Health Breach Notification Rule (within 60 days where required) and any applicable state breach notification laws.

Data residency

Your account data is stored on Supabase in the us-east-1 region (Northern Virginia). KaleAI conversations are processed by Anthropic in the United States. Product analytics events go to PostHog in the European Union (Frankfurt). Crash reports go to Sentry in the United States. Transactional emails are sent through Resend in the United States.

If you access KaleWay from the EU or UK, your data crosses jurisdictional boundaries on the way to most of these processors. We rely on the EU–US Data Privacy Framework (effective July 2023) and on Standard Contractual Clauses where applicable. If the Framework is invalidated or a processor's certification lapses, we will move that processor onto SCCs within 30 days and update this Policy.


11Children's privacy

KaleWay is rated for users 17 years and older. We do not knowingly collect personal information from children under 13 (or under 16 in jurisdictions where that age applies). If we learn that a person under the applicable minimum age has created an account, we will delete that account and any associated data.

If you believe a child has provided us with personal information, please contact support@kaleway.com.


12International data transfers

KaleWay's servers and our service providers' systems are located in the United States. If you use KaleWay from outside the United States, your information will be transferred to and processed in the United States. By using KaleWay, you consent to this transfer.

For users in regions that require additional safeguards for international transfers (such as the EU and UK), we rely on Standard Contractual Clauses with our service providers and on each provider's own compliance frameworks (for example, Anthropic's published policies and Supabase's compliance documentation).


13Third-party links and integrations

The KaleWay app and website may contain links to third-party websites or services. This Policy does not apply to those third parties — they have their own privacy policies. We are not responsible for the practices of third parties we link to.

If you choose to integrate KaleWay with a third-party service (for example, by granting HealthKit permission, or in the future by linking another app), the integration is governed by what we describe in this Policy plus the third party's own terms.


14Changes to this Policy

We may update this Privacy Policy from time to time as KaleWay grows or as laws change. When we make a material change, we will:

  • Update the "Last updated" date at the top
  • Post a notice in the app
  • For significant changes, send an email to your account email address before the change takes effect

Your continued use of KaleWay after a change becomes effective means you accept the updated Policy. If you do not agree with a change, you can close your account at any time.

Recent updates

  • v1.3 — May 11, 2026. Added Section 5 disclosure of AppsFlyer Ltd. as an additional recipient of advertising measurement events from the iOS app, used as a Mobile Measurement Partner to attribute installs across multiple ad networks (Meta, TikTok, Apple Search Ads, Google, and ~5,000 other partners). Added a cross-reference paragraph in the Meta entry acknowledging the AppsFlyer-Meta overlap during the V1.0.2–V1.0.x transition window. Disclosed the EEA “limited consent” default for AppsFlyer downstream personalization sharing (GDPR / DMA legitimate-interest basis).
  • v1.2 — May 5, 2026. Added Section 5 disclosure of Meta Platforms as a recipient of advertising measurement events from the iOS app (install + subscription attribution via Meta App Events SDK and Conversions API). Removed two outdated bullets in Section 6 that no longer reflected the iOS app's measurement integrations and replaced them with scoped truth-claims that distinguish marketing-site practices from in-app measurement. Added Section 8 opt-out path for Apple App Tracking Transparency (ATT).
  • v1.1.1 — May 4, 2026. Lockstep version bump alongside AI Privacy Notice and Terms of Service. No content change to this Policy.
  • v1.1 — May 4, 2026. Section 3 expanded with twelve explicit data categories the app now collects; Section 5 named PostHog, Sentry, and Resend as processors; Section 6 tightened with explicit no-sale, no-AI-training, no-session-recording commitments; Section 7 added retention rows for behavioral data, in-app feedback, and review-prompt state; Section 8 clarified rights-exercise channels (30 days GDPR / 45 days CCPA); Section 10 added data residency and the EU–US Data Privacy Framework; CCPA Appendix A expanded with the Internet activity row.

15Contact us

For any question about this Privacy Policy, your rights, or how we handle your information:

Email

Subject line "Privacy Request" if it is a rights request.

Mailing address
Granviex, LLC
4700 NW Boca Raton Blvd #202
Boca Raton, FL 33431
United States

ACategories of personal information collected (CCPA disclosure)

For California residents, the CCPA requires us to organize the categories of personal information we collect using the California categories. The following table maps the CCPA categories to the information described in Section 3 of this Policy:

CCPA category
What this means for KaleWay
Where
Identifiers
Email, account ID, IP address, device identifier
§3.1, 3.2
CA Customer Records
Name, contact information
§3.1
Protected classification
Age, gender (collected for personalization, not for discrimination)
§3.1
Commercial information
Subscription history
§3.5
Internet or other electronic network activity (Cal. Civ. Code §1798.140(v)(1)(F))
Page views, button taps, feature usage, in-app search queries, FAQ entries you expanded. Collected directly when you use the app. Recipients: PostHog (pseudonymous events, EU region) and Sentry (errors only, US region). Not sold. Retention: active account plus up to 13 months of historical events.
§3.2, §5
Geolocation data
State or region only (not precise location)
§3.1
Sensory data
Not collected
Professional / employment
Not collected
Education
Not collected
Inferences
Personalization signals derived from your input (for example, KaleAI's understanding of your preferences)
§3.1, 3.2
Sensitive personal information
Health data, including weight, dietary restrictions, and health conditions; account credentials
§3.1, 3.3

We collect information from the sources, for the business purposes, and disclose to the categories of third parties described elsewhere in this Policy.