LazyCal Privacy Policy
Effective August 8, 2026 · Last updated September 2, 2026
How LazyCal collects, uses, and protects your data.
LazyCal is operated by Talha Yousaf, an individual based in Ontario, Canada ("LazyCal," "we," "us," or "our"). "LazyCal" is the product and trade name, not a separate corporation. Talha Yousaf is the legal operator and the person responsible for LazyCal's privacy practices.
LazyCal is a food, workout, and body-progress tracker for iPhone that shows
your logged training on a 3D muscle anatomy model. This policy covers the
app, lazycal.app, the website waitlist, and support.
In summary
- we do not sell personal information, show ads, or use your data to train AI models.
- your logs live on your device first and sync through our backend when you are signed in. LazyCal is local-first, but not device-only.
- optional Scan meal sends a photo to Google's Gemini API to suggest foods, then matches them in our catalogue. Nothing is saved until you confirm or edit. We do not keep the photo on our servers after the suggestion returns.
- barcode scanning happens on your device. That camera image is never uploaded or stored.
- voice food search sends audio to Apple for transcription. LazyCal only receives the text.
- optional Apple Health support can read body weight, workouts, and active energy, and write nutrition, workout, and body-weight entries you log. What LazyCal reads from Apple Health stays on your device.
- website analytics are aggregate and cookieless. In-app product analytics are off by default and run only if you turn on App analytics in Settings; they never include your food, workout, health, or account details.
- if you contact us, we use your message only to reply and support you.
Information you give LazyCal
LazyCal stores the information you choose to enter, including:
- account details from Sign in with Apple or email sign-in, such as your email address, account identifier, and session information.
- subscription and entitlement status needed to provide paid access.
- profile details such as date of birth, gender, height, body weight, body-fat percentage, activity level, goals, unit preferences, and your calorie and nutrient targets.
- food entries, food search text, barcode values, calories, macro- and micronutrients, portions, custom foods, favourites, and notes.
- meal photos you choose to submit for Scan meal. Those images are sent to Google for identification, then discarded from our systems after the suggestion is returned. Confirmed foods become ordinary food entries.
- workouts, exercises, dates, sets, repetitions, load, duration, rest periods, workout plans, schedule, focus, intensity, preferences, and notes.
- body-weight entries and progress data.
- app preferences, onboarding status, local identifiers, and feature settings.
- support messages, feedback, bug reports, and anything you include when contacting us. Your waitlist email address and signup time, if you join the waitlist.
We also receive limited technical information automatically: app version, operating-system and device information, locale and time-zone settings, the IP address and request time visible to network services, authentication and security events, and error or service logs.
Some of this stays on your device. Some is sent to our backend when a feature needs it — account access, syncing, subscription checks, food search, barcode lookup, optional meal-photo identification, or troubleshooting.
Account and subscription
LazyCal offers Sign in with Apple and email authentication. If you use Sign in with Apple, we may receive your Apple-provided email address (or private relay address), identity token, and account identifier so we can create or authenticate your account.
Purchases are handled through Apple's App Store. LazyCal may receive subscription, product, trial, renewal, cancellation, restore, and purchase status information from Apple and RevenueCat so the app can grant access, restore purchases, prevent abuse, and troubleshoot purchase problems.
Apple processes your payment details. LazyCal never receives your payment-card number or bank-account information.
Permissions
LazyCal only asks for permissions that support a feature you chose to use:
- camera or photo library. Used when you scan a barcode, pick a photo containing a barcode, or use Scan meal. Barcode detection runs on your device with Apple's vision technology and that image is not uploaded. Meal photos leave the device only for the AI identification step described below.
- speech recognition and microphone. Used for voice food search. The audio goes to Apple for transcription; LazyCal receives the resulting text and uses it as the search term.
- Apple Health. Used only if you connect it. See below.
- notifications. Used for reminders you set. These are scheduled locally on your device — LazyCal does not register a remote push token for them.
You can change any of these in iOS settings. LazyCal does not ask for App Tracking Transparency permission, because it does no cross-app tracking and runs no attribution or advertising SDKs.
Food search and barcodes
When you search for food, LazyCal sends the search term to our backend, which queries the FatSecret Platform food database and our own catalogue (searched with Typesense Cloud) and returns matching results. When you scan a barcode, the barcode value goes to the same backend, which looks it up with FatSecret and our catalogue; if neither has the product, your device asks Open Food Facts as a final fallback.
Only the search term or the barcode is sent to these providers. Your account identifier, profile, and logs are not — a provider receives the words you typed or the digits you scanned, and nothing that identifies you.
Catalogue and community-maintained food data can be incomplete or wrong. Check the product label when accuracy matters, and edit entries in the app as needed.
AI photo logging
Scan meal is optional. If you use it:
- you take a photo of a meal (or pick one from your library);
- LazyCal sends that image to Google's Gemini API so the model can suggest what is on the plate;
- LazyCal searches the food catalogues (FatSecret and our own, via Typesense Cloud) for matching items and shows you the suggestion;
- nothing is logged until you confirm or edit it.
We send the image for inference only — to identify foods in that request. We do not use meal photos or your food logs to train LazyCal models. Where Google's API terms allow, we configure the request so the content is not used to train Google's models. Google may still process the image under its own terms, including limited safety or abuse logging.
We do not keep the meal photo in our database or sync store after the suggestion is returned. Confirmed items become ordinary food entries and follow the retention for those logs. If Apple Health is connected, only entries you confirmed may be written there.
Suggestions are estimates. They can miss oils, sauces, mixed plates, portion size, or allergens. They are not medical nutrition advice. Do not photograph other people, identity documents, or medical records. LazyCal does not use photos for face recognition.
Workouts, goals, and the anatomy model
LazyCal stores your workout history, goals, plans, and progress so it can show your history, build plans, and render the 3D anatomy view. The muscles that light up on the model are derived from the exercises you logged, on your device and in your own account. The model is an artistic anatomical figure, not a medical reference.
Health, fitness, nutrition, and body-measurement data is sensitive. We use it to provide LazyCal's features. We do not sell it, share it for advertising, or have anyone review it to give you coaching.
Apple Health
Apple Health integration is optional. If you enable it and grant permission:
- LazyCal may read body weight, workouts, and active energy — workouts and active energy so an Apple Watch figure can replace our own estimate instead of double-counting the same session;
- LazyCal may write body-weight entries, workouts, and supported nutrition information you log, such as calories, macronutrients, and certain micronutrients.
Information LazyCal reads from Apple Health stays on your device and is never uploaded to our backend. Information you separately enter in LazyCal is your own data — it may sync through our backend and, if you enable the integration, be written to Apple Health.
Turning the integration off stops future access but does not remove entries already written to Apple Health. You can manage those in the Health app.
Analytics and diagnostics
Website. lazycal.app uses Plausible for aggregate, cookieless
measurement: page paths, referral and campaign information, browser and
device categories, approximate country or region, and two custom events
(waitlist_signup and turntable_grab). Plausible sets no cookies and
uses no persistent visitor identifier. We never attach your waitlist email,
a form field, or a LazyCal account to a Plausible event.
In the app. LazyCal includes optional product analytics through PostHog. It is off by default: nothing is sent, and the analytics SDK is not even started, until you turn on App analytics in Settings → Privacy. Turning it off stops collection on that device. When it is on, it is limited by design: a reviewed allowlist of events describing a general onboarding, sign-in or sign-out, subscription, restore, settings, feature-completion, or technical outcome, with limited low-cardinality details such as the sign-in method, an error code, whether a log entry was new or edited, or the number of items in a meal-photo estimate; a randomized installation identifier and a random session identifier, neither of which is your email or account ID, reset when you sign out or switch accounts; app version and build, analytics SDK version, operating-system version, device class, and language or locale; and a project on PostHog Cloud US configured to discard client IP addresses, with location lookup disabled for every event. Session replay, screen recording, automatic screen views, element autocapture, surveys, and automatic error capture are all disabled, and a final outbound filter drops anything not on the allowlist. LazyCal never sends it your name, email, birth date, body measurements, food or workout entries, notes, voice transcripts, photos, support messages, or anything read from Apple Health, and analytics consent is never required to use paid or core features.
LazyCal does not use session replay. It does not use analytics to track you across other companies' apps or websites, and it does not share personal information with data brokers.
Operational logs. The app, website, and backend keep limited logs needed to run and secure the service — authentication, subscription, sync, search, request, error, performance, and rate-limit events. The website holds an IP address in memory briefly to enforce anti-abuse limits on the forms; it is not written to our database. Backend food-search telemetry is designed to record things like query length, latency, and result count rather than your raw search phrase.
Website and contact data
The website and the support@lazycal.app mailbox are hosted through
Spaceship services, whose ordinary server logs and automated anti-spam
systems may process request and message information to keep them secure.
If you email us or use a form on the site, we receive your email address and whatever you include. We use it to respond, troubleshoot, and improve LazyCal. Please do not put medical records or other unnecessary sensitive information in a support message — a person reads support submissions to answer them.
How we use information
We use information to:
- create, authenticate, secure, and administer your account.
- save and sync your profile, goals, food logs, workout logs, plans, and settings across your devices.
- calculate and show the nutrition, fitness, progress, and anatomy views you asked for.
- search food catalogues, look up barcodes, and (if you use Scan meal) identify foods in a photo you submit, then show a catalogue match for you to confirm.
- provide optional Apple Health, speech, camera, photo-library, and reminder features.
- offer, validate, restore, and administer subscriptions.
- respond to support messages and diagnose problems.
- protect the app, website, and backend from abuse, and comply with law.
- send account emails — authentication, confirmation, password reset, security, and material service notices.
- send the launch message if you joined the waitlist. The waitlist is not a newsletter, and you can unsubscribe or ask for deletion at any time.
We do not use personal or health information for advertising, data brokerage, medical research, or training AI models.
Legal grounds
Canadian privacy law requires meaningful consent and limits collection to identified purposes. Because health, fitness, and body-measurement information is sensitive, LazyCal relies on clear choices and Apple's permission controls.
Where EU, EEA, or UK data-protection law applies:
| What we do | Legal ground |
|---|---|
| Provide accounts, sync, logging, search, subscriptions, and support | Performance of our contract with you |
| Process health or fitness data and use optional Apple Health, speech, camera, photo library, Scan meal, or notification permissions | Your consent, and explicit consent for special-category health data where required |
| Measure aggregate website use with Plausible | Our legitimate interest in knowing whether the site works, balanced against its cookieless design |
| Collect optional in-app product analytics through PostHog | Your consent |
| Protect accounts, prevent abuse, and answer support requests | Our legitimate interest in operating and securing the service |
| Keep transaction, tax, legal, or security records | Compliance with a legal obligation, or legal claims |
| Send the one-time waitlist message | Your consent, which you may withdraw |
You can withdraw consent at any time through the relevant device setting, by disabling a feature, by deleting your account, or by contacting us. Withdrawal does not affect processing that was lawful beforehand, and some features cannot work without the information needed to provide them.
Who we share information with
We share information only when it is needed to run LazyCal, and only with service providers acting on our instructions. Those providers fall into these categories:
- hosting, authentication, database, sync, and account deletion for your LazyCal account;
- subscription validation and entitlement administration, alongside Apple;
- food search and barcode lookup, which receive the search term or barcode value only;
- the optional Scan meal image analysis described above, which is provided by Google's Gemini API;
- optional in-app product analytics (PostHog), which receives only the allowlisted events described above, and only after you turn App analytics on;
- delivery of account and authentication emails;
- website hosting, the support mailbox, and aggregate, cookieless website analytics.
Third parties that process data on our behalf are contractually required to provide the same or equal protection of your data as described in this policy, and may use it only to provide services to LazyCal.
We also work with Apple for App Store distribution, Sign in with Apple, purchases and subscriptions, Apple Health, speech recognition, and device permissions. Apple handles that information under its own privacy policy.
We may also disclose information if reasonably necessary to comply with law or legal process, protect someone's safety, investigate fraud or a security incident, enforce our terms, or defend a legal claim. If LazyCal is ever reorganized, financed, sold, or transferred, information may be disclosed during that process with appropriate protections and any notice the law requires.
The two providers whose own terms govern data you send them directly are Apple and, for Scan meal, Google. We can tell you which other providers we use at any time — email support@lazycal.app.
We do not sell personal information, share it for cross-context behavioural or targeted advertising, show ads, or run remarketing. Because none of that happens, there is no sale or targeted-advertising activity to opt out of. If this ever changes, we will update this policy and get consent where required first.
Where your information is processed
LazyCal is operated from Ontario, Canada. Our providers may process information in Canada, the United States, the European Union, or other countries where they operate, which means it may be subject to another country's laws and lawful access requests.
As of this policy's effective date, our primary Supabase project is hosted in the United States (North Virginia). Plausible processes website analytics in the European Union. Optional in-app analytics, when you turn it on, is processed on PostHog Cloud US in the United States. Apple and other providers process information in the locations described in their own notices.
Where required, we rely on provider agreements and legally recognized safeguards for these transfers.
Retention
| Information | How long we keep it |
|---|---|
| Meal photos submitted for Scan meal | Processed to produce a suggestion, then not stored in our database or sync store |
| Inactive accounts | Deleted or de-identified after 3 years without sign-in, with an email warning about 30 days beforehand where possible |
| Account data after you request deletion in the app | Removed from active production systems within 30 days, except the limited records below |
| Sync deletion markers | Up to 90 days |
| Backup copies | Expire through the ordinary backup cycle within 90 days of deletion from active systems |
| Search, error, performance, and hosting logs | Up to 90 days |
| Authentication, security, and abuse-prevention logs | Up to 12 months |
| Plausible website analytics | Up to 24 months |
| Optional in-app analytics (PostHog) | Up to 12 months |
| Closed support messages | Up to 24 months after the request is closed |
| Waitlist email and signup date | Until the launch message is sent or you ask us to remove it; at most 90 days after launch or 24 months after signup, whichever comes first |
| Subscription records we control | For the subscription lifetime and up to 24 months afterward |
| Tax, accounting, and legally required transaction records | Up to 7 years, or as law requires |
| Records for a privacy request, dispute, or security incident | Up to 24 months after closure, unless law requires longer |
A shorter or longer period can apply if you request deletion, the information is no longer needed, the law requires something different, or a dispute puts a temporary legal hold on it.
Data on your device stays in LazyCal's app container until you delete it in the app or delete the app itself. Depending on your Apple settings, app data may also be included in an iCloud or computer backup — those copies are managed through Apple's backup tools, not by us. LazyCal does not use iCloud or CloudKit as its sync backend.
We do not retain camera images used for barcode detection. Meal photos used for Scan meal are sent to Google, processed to produce a suggestion, and not stored in our database afterward. Speech audio is processed by Apple, not stored by us.
Deleting your data
These are five separate actions, and doing one does not do the others:
- Delete your LazyCal account in the app — sends a deletion request to our backend and clears the local app container, subject to the retention above.
- Delete the app from a device — removes it from that device. It does not delete your backend account or synced records.
- Delete Apple Health records — manage anything LazyCal wrote to Apple Health in the Health app. Deleting your LazyCal account does not remove it.
- Delete a device backup — managed through Apple's settings. We cannot remove a single record from an Apple backup.
- Cancel your App Store subscription — managed in your Apple account. Deleting the app or your account does not cancel it.
For anything else, email support@lazycal.app or use lazycal.app/support.
Your privacy rights
Depending on where you live, you may have the right to know what we process, get access or a copy, correct it, delete it, withdraw consent, object to or restrict certain processing, receive it in a portable format, complain to a regulator, and receive equal service for exercising any of these.
You can edit most profile and log details in the app and start account deletion in account settings. For anything else, contact us. We may need to verify your identity and clarify the scope of a request first.
We aim to acknowledge requests within 7 calendar days and complete a verified request within 30 calendar days, unless the law requires sooner or allows a justified extension. We will explain any extension or refusal.
Canada. You may challenge the accuracy and completeness of your personal information and raise a concern about our practices. If we do not resolve it, you may contact the Office of the Privacy Commissioner of Canada.
EEA and UK. You may have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent, and may complain to the data-protection authority where you live or work. EU authorities are listed by the European Data Protection Board; in the UK, contact the Information Commissioner's Office.
United States. Where a state privacy law gives you rights, you may request access, correction, deletion, or portability, and appeal a refusal where that right exists. The categories above are what we collect and disclose for the purposes described here. We do not sell personal information, share it for cross-context behavioural advertising, or use sensitive personal information to infer characteristics for unrelated purposes.
Security
We use safeguards appropriate to how sensitive this data is: encrypted network connections, authentication and row-level access controls meant to keep cloud records reachable only by the signed-in user, authentication sessions stored in Apple's device Keychain, Apple's system permission controls, limited access, and deletion processes for local and cloud data.
No method of electronic storage or transmission is completely secure. Please protect your device, Apple account, email account, and credentials, and tell us if you suspect someone else has accessed your account.
Children and teenagers
LazyCal is intended for people aged 13 or older, and we do not knowingly allow an account for a child under 13. If you believe a child under 13 has given us personal information, contact us and we will investigate and delete it where appropriate.
If you are between 13 and the age of majority, you need permission from a parent or legal guardian. Privacy law in some countries requires verified parental consent up to an age between 13 and 16, especially for health information. LazyCal does not yet have a verified parental-consent process, so if you are below the digital-consent age in your country, please do not create an account until one is available. If we learn that required consent was not obtained, we may restrict or delete the account.
Automated decisions
LazyCal does not make decisions about you with legal or similarly significant effects through automated processing alone. Calorie targets, plans, search rankings, and progress views are product features — not medical, employment, insurance, or credit decisions.
Third-party content
Food information can come from third-party or community-maintained catalogues, and external services have their own privacy practices. This policy covers LazyCal's practices and does not replace another company's notice for data it controls itself.
Changes
We may update this policy as LazyCal, its providers, or the law change. We will update the "Last updated" date, and give additional notice in the app, on the website, or by email when a change is material or consent is required.
Contact
Operator: Talha Yousaf
Location: Ontario, Canada
Email: support@lazycal.app
Support: https://lazycal.app/support