Privacy Policy
Last updated: September 4, 2026
This English translation is provided for reference only. The Japanese version is the authoritative and legally binding version.
kalbi LLC (the “Company”) handles user information in kalori (the “Service”) under this Policy. This Policy applies to the iOS app and the Company’s websites, including kalori.jp and my.kalori.jp.
See the kalbi LLC Corporate Privacy Policy for our company-wide approach. Also review the following addendums for platform-specific practices.
Article 1 (Information We Handle)
The Service handles the following information:
- Account information: identifiers provided by an external authentication service, email address, and display name
- Profile and health information: height, weight, date of birth, sex, activity level, goals, and HealthKit information when permitted
- Records and inputs: meals, exercise, weight, goals, meal or menu photos, and text entered for AI analysis
- Location and store information: location used to find nearby stores and store information linked to a record
- Subscription and allowance information: subscription status and benefit or credit history. We do not receive card numbers or similar payment details
- Usage and device information: screens or pages viewed, actions, app, browser and device information, IP address, and access time
- Support information: feedback, inquiries, and contact information needed to respond
- Business customer contact information: for businesses subscribing to the gym / trainer service or the developer API, the name, email address, affiliation, and login and activity records of their contact persons, used to perform the contract, bill, and communicate. End-user identifiers sent by a business through the developer API are hashed on the business's side; we use them only to apply usage limits and count active users, never to identify individuals
Article 2 (Purpose of Use)
- Account creation and authentication
- Providing nutrition goals, meal logging, daily summaries, AI analysis, recommendations, and other Service functions
- Nearby store search
- Personalizing displays and suggestions
- Responding to inquiries and providing necessary notices
- Preventing misuse, maintaining security, and resolving technical issues
- Analyzing usage and improving the Service and AI analysis quality
- Complying with legal obligations
Article 3 (AI Analysis and External Integrations)
The Service may send meal photos, menu photos, or text you enter to external AI providers contracted by the Company, to the extent necessary to recognize food and estimate nutrition information. We limit the information sent to what is necessary and appropriately select and oversee our providers.
If you enable an integration with a chat AI or another external service, records you select may be sent to that service at your direction. The terms and privacy policy of the integration provider also apply to its handling of information.
Our nutrition search for chat AI clients can be used without signing in, and those searches are not linked to any account. Because knowing what people look for is essential to expanding our catalog and improving search quality, we retain search keywords, filter conditions, and result counts on an ongoing basis and use them to improve the Service. In this retained analytics data, IP addresses appear only as hashed values. Separately, to prevent misuse and investigate failures, we record request logs — including the IP address and browser information (user agent) — in short-lived operational logs that are automatically deleted after approximately seven days.
Article 4 (Service Providers and Third-Party Disclosure)
We may engage external providers for functions necessary to operate the Service, including system operations, AI analysis, authentication, payments, usage analytics, and support. We limit access to what is necessary and appropriately select and oversee those providers.
We do not disclose personal information to third parties except with the user's consent, as required by law, as necessary for service providers, in connection with a business succession, or as otherwise permitted by law.
Article 5 (Sharing Records with Gyms and Trainers)
If a user enters an invitation code issued by a gym, trainer, or similar business in the Service and consents to sharing, the Company displays the following information in that business's dashboard, to the extent necessary for the business to provide coaching to the user:
- Meal records (contents, calories, PFC, the date recorded, the date of the meal, and the time slot)
- Meal photos taken by the user and attached to a record
- Nutrition summaries (daily totals and targets, and summaries of nutrients such as salt equivalent, dietary fiber, vitamins, and minerals)
- Weight records
- Exercise records (calories burned and duration, including those derived from steps and workouts when Health is connected)
- Goal settings (goal type, target weight, and starting weight)
- Display name
The recipients are the business that issued the invitation code and the trainers who belong to it.
The user and the business can exchange comments on a per-day basis. The Company stores the content of those comments and their timestamps, and displays them to both parties. Because this exchange is a record of coaching and may serve as evidence in the event of a dispute over that coaching, the Company retains each comment for three years after it is sent — even if the account is deleted — and deletes it thereafter. During that period the record is accessed only where necessary for those purposes and is not shown in the ordinary screens.
Users may withdraw consent at any time from the trainer connection screen in the app. From the moment consent is withdrawn, the business can no longer view the user's records. Information the business viewed or recorded before withdrawal remains under that business's control.
The Company retains a log of access by such businesses (when, which trainer, and whose records were viewed). Users may request disclosure of the log relating to themselves under Article 11.
Article 6 (Processing Outside Japan)
User information may be processed outside Japan, for example when an external provider operates facilities in another country. We take contractual and other measures required by applicable law.
Article 7 (Statistical Information)
We may use information aggregated or processed so that individual users cannot be identified to improve the Service and AI analysis, understand usage trends, and prepare statistics. We may share non-identifiable statistical information externally, but we do not use HealthKit information for advertising or marketing and do not sell it.
Article 8 (Retention & Deletion)
We retain user information for as long as reasonably necessary to provide the Service, comply with law, maintain security, and serve other legitimate purposes.
When an account is deleted, account-linked information is removed from systems in ordinary use. Information needed for legal obligations, backups, or security records may be retained with restricted use for a limited period and deleted after the applicable retention period. Records of exchanges with gyms and trainers are retained for the period set out in Article 5. Non-identifiable statistical information may remain after account deletion.
An App Store subscription is not cancelled automatically when you delete your account; cancel it separately through the App Store. A web plan sold directly by the Company can be cancelled from the account screen on my.kalori.jp or through the payment provider’s customer portal. If you delete your Kalori account while a web plan is active, that subscription is cancelled at the same time (with no refund for the remaining period). See the Commercial Transactions Disclosure for details.
Article 9 (Security)
We take organizational and technical measures appropriate to the nature of the information, including access controls, protection of communications, and monitoring, to help prevent unauthorized access, loss, damage, alteration, or disclosure. We also appropriately oversee our personnel and service providers.
Article 10 (Children's Privacy)
This Service is not directed to children under 13. We do not knowingly collect personal information from children under 13.
Article 11 (User Rights)
You may request access, correction, suspension of use, or deletion of personal information held by us as provided by applicable law. You can delete your account using the account-deletion function in the Service. For other requests, contact contact@kalori.jp. We will verify your identity before responding.
Article 12 (Changes)
We may revise this Policy and its addendums to reflect changes in law or the Service. Material changes will be announced within the Service or by another appropriate method.
Article 13 (Contact)
For inquiries about this Policy, contact contact@kalori.jp.