Controller and Contact Details
The controller of personal data in Karafs is Joulino B.V., a company registered in the Netherlands. Address: Weidevogellaan 262, 2496PP Den Haag, Netherlands. KvK number: 94647615. Establishment number: 000060103701.
For any privacy or data protection request you can contact soheilazad.dev@gmail.com. We are responsible for deciding what data is processed and for which purposes.
Because the controller is a Dutch company, the EU General Data Protection Regulation (GDPR) governs this processing, regardless of which country you live in.
Scope: Which Apps This Covers
This document is the declared privacy policy for both of the following products, because this page's address is the one listed on both store listings: the Karafs iOS app (bundle ID celery.co.group.app, App Store app ID 1614419104) and the Karafs Android app on Google Play (package ir.eynakgroup.caloriemeter). The Karafs website and web version are in scope as well.
The two apps are two separate products of the same controller. The Android app is the earlier generation and its data is held on the older Karafs infrastructure; the iOS app is the new generation and runs on the current infrastructure (Supabase and Vercel). Your account and data do not move between them automatically.
A simple rule for reading this document: any feature that does not exist in the app you installed collects no data, and that part of this policy does not apply to you.
- In both apps: your account, personal and body details, goal, food logs, weight, and the data needed for meal planning and support.
- In the iOS app: AI food logging by photo, voice and text, reading step counts from HealthKit, water and exercise logging, the symptom tracker, the GLP-1 companion, the AI coach, push notifications, and the App Store subscription handled through RevenueCat.
- In the Android app: purchases and subscriptions through Google Play, and that app's own account and log data on the older infrastructure.
Data We Collect
We collect only the data needed to create an account, provide the service, personalise it, activate a subscription, maintain security, provide support and comply with the law. Depending on the app and the features you use, the following data may be processed.
- Account information: user ID, email, name or display name, sign-in method (Apple or Google), session data and information needed for authentication.
- Personal and body details: date of birth or age, gender, height, weight, goal, activity level and profile settings.
- Health and lifestyle data: pregnancy or breastfeeding status, medical conditions, allergies, dietary restrictions and preferences, food logs, water, weight, exercise, daily steps and meal-plan data.
- Symptoms: symptom-tracker entries, including symptoms you define yourself and the severity or note attached to each entry.
- Medication data: in the GLP-1 companion, the medication and dose you enter yourself, injection dates and reminder settings.
- AI inputs and their results: text you write, voice you record, food photos, processed versions of those photos, the transcript of your voice note, food candidates, estimated portions and calories, and coach output.
- Subscription data: subscription status and period, customer and transaction identifiers at RevenueCat or the store, entitlement state, and purchase and renewal events recorded internally to unlock access and measure how the product performs.
- Notifications: your device push token, device platform, your notification settings, and delivery records used to avoid sending the same message twice.
- Technical and security data: IP address, device type, error logs, security events and data needed to prevent abuse and keep the service stable.
- Support communications: messages, emails and information you send us for a support or privacy request.
Health Data and the Explicit-Consent Basis
We will state this plainly: much of the data in Karafs is special category data under Article 9 GDPR. Your weight, what you eat, your daily steps, exercise, physical symptoms and GLP-1 medication information are all health data, as are pregnancy or breastfeeding status, medical conditions and allergies.
Our lawful basis for that category is your explicit consent under Article 9(2)(a), not legitimate interests. Consent is obtained during signup before the data is collected, and we store the consent type, the version of the text you accepted and the time, so that we can demonstrate it.
You can withdraw consent at any time. Withdrawal does not invalidate processing that already happened, but from that point the core parts of the service can no longer be provided — in practice the account stops being useful and you can delete it.
We do not sell your health data, do not use it for advertising, and do not share it with any advertising network or data broker.
HealthKit and Health Connect Data
With your explicit permission, the iOS app reads your daily step count from HealthKit. The new-generation Android app will do the same through Health Connect once it is released. This permission is optional and can be withdrawn at any time in system settings; the rest of the app works without it.
Data read from HealthKit is used only to show your progress inside the app and to compute your daily activity. Daily step totals are stored on our server so they stay in sync between the app and the widgets.
As Apple requires and as our own commitment: we do not use HealthKit data for advertising, marketing or any similar purpose, we do not sell it, and we do not disclose it to data brokers or advertising platforms. We also do not send it to AI models.
Food Logging by Text, Voice and Photo
When you log food by text, voice or photo, that input is sent to third-party AI models to identify the food and estimate its nutrition. The request always goes through our server, and model API keys are never placed in the app.
Voice: the audio file is uploaded to private storage, sent to a model for transcription, and then deleted from storage once transcription completes. What remains is the transcript and the analysis result, not your recording.
Photos: a food photo and its processed variants are kept in private storage so they can be shown in your log history, and are sent to a model for analysis.
Some context needed for the analysis is sent along with the input — for example the unit or the portion you selected. We aim to keep that context minimal and do not put your email or identity into the prompt.
The model output is an estimate, not a measurement. You can correct it before logging, and it is your correction that gets saved.
Why We Use Your Data
Our purposes are limited and specific. Each purpose has its own lawful basis, listed in the next section.
- Service delivery: creating your account and profile, calculating nutrition needs, generating plans, and logging and displaying food, water, weight, steps and exercise.
- Health and nutrition personalisation: using body data, goal, restrictions, medical conditions and allergies to make suggestions more relevant.
- AI food analysis: recognising food from text, voice or a photo and estimating its nutrition.
- Symptom and medication tracking: providing the symptom tracker and the GLP-1 companion, and the reminders you set yourself.
- Subscription and access: determining whether a subscription is active, renewed, cancelled or expired, and unlocking paid features.
- Notifications: sending the reminders you enabled and essential account messages.
- Security and abuse prevention: protecting accounts, investigating errors and keeping the service stable.
- Support: answering your requests and handling privacy requests.
- Product improvement: reviewing aggregated or minimised data to improve the quality of suggestions and the user experience.
Lawful Basis for Each Purpose
Different purposes rest on different lawful bases. The distinction matters, because the rights you can exercise depend on the basis.
- Performance of a contract, Article 6(1)(b): creating your account, authentication, providing core features, managing your subscription and service-related support.
- Explicit consent, Article 9(2)(a): all health data — weight, food logs, steps, exercise, symptom entries and GLP-1 medication information — plus pregnancy, breastfeeding, medical conditions and allergies.
- Consent, Article 6(1)(a): reading steps from HealthKit or Health Connect, microphone and camera access for food logging, and push notifications. Each is separate and can be withdrawn at the system level.
- Legitimate interests, Article 6(1)(f): security, abuse prevention, debugging, internal measurement of product performance on minimised data, and defending our rights and those of our users, where your rights and freedoms do not override them.
- Legal obligation, Article 6(1)(c): keeping financial and tax records, responding to valid legal requests and complying with applicable rules.
Subscriptions and Payments
In-app purchases in the iOS app are processed entirely by Apple, and in the Android app by Google Play. The amount is charged to your Apple ID account or your Google account.
We never see or store your card details. What we receive is subscription state: whether it is active, the period, transaction identifiers, and renewal or cancellation events.
RevenueCat acts as a processor that receives subscription state from the stores and passes it to our server so your access is calculated correctly. For that, your Karafs user identifier and purchase events are sent to RevenueCat; no health data is sent to RevenueCat.
Web payment is not currently offered. Stripe infrastructure exists in the code but is configured for test mode only and no real web payment has ever been taken, so we do not treat Stripe as an active processor of your payment data. If that path is ever enabled, this page will be updated first.
Processors and Third-Party Services
We do not sell your personal data. Data is processed only as necessary, under a data processing agreement, by the providers below. This list describes the current infrastructure (the iOS app and the web).
- Supabase — authentication (Apple and Google sign-in), the database, and private storage for photos and audio.
- Vercel — application hosting, server-side execution and technical logs.
- RevenueCat — receiving and syncing subscription and entitlement state.
- Apple — App Store payments and subscriptions, Sign in with Apple, and notification delivery on iOS.
- Google — Sign in with Google, and Google Play payments and subscriptions for the Android app.
- Expo (Expo Application Services) — delivering push notifications to devices.
- OpenRouter and the downstream model providers behind it — running AI analysis on food text, voice and photos. We disable retention and training options wherever they are available.
- Langfuse — tracing and monitoring AI workflows to find failures, with minimised or redacted data.
- Inngest — running background jobs such as photo and voice analysis and report generation.
Push Notifications
Notifications are optional and are not sent until you allow them. To send them we store your device push token and platform, and the message is delivered to your device through a push service.
Some reminders are scheduled only on your device and never reach our server. You can withdraw notification permission at any time in system settings or inside the app.
Cookies and Measurement
We do not use advertising or marketing analytics tools such as Google Analytics, Meta Pixel or similar, and we have not embedded any advertising SDK in the apps.
The website and web version may use cookies or similar technologies that are necessary for sign-in, sessions, security and user settings.
We record purchase and renewal events internally, on our own infrastructure, so we can understand how the product performs. That data is not sent to advertising networks. If a non-essential analytics tool is ever added, this page will be updated first and separate consent obtained where required.
Data Retention
While your account is active we keep your account, profile, health data, logs, food photos and analyses, because that is what makes up your history and your personalisation.
Voice recordings are the exception: they are deleted once transcribed and are not retained.
Food photos and analysis results stay in private storage for as long as your account is active, unless you delete the individual entry or delete your account.
After account deletion your records are erased immediately, and your photos and audio files are removed from storage at the same time. The only exceptions are the items named in the next section.
Account Deletion
In the iOS app you can delete your account from inside the app. The deletion is immediate and complete: your profile, plans, food logs, weight, water, steps, exercise, symptoms, GLP-1 companion data, personal foods, notification devices, subscription records, AI logs, and the food photos and audio files held in private storage are all erased, and your sign-in identity is removed at the end. It cannot be undone.
What remains: a small record of the deletion itself, containing your user identifier and a salted hash of your email address (not the address), so we can demonstrate that the request was carried out; and server-only billing audit logs for the subscription, retained as financial and accounting records.
Deleting your Karafs account does not delete data Apple or Google must keep under their own financial rules, and it does not cancel an active subscription. To stop renewal you must go to your Apple or Google account.
If you use the Android app and want your account and data on the older infrastructure deleted, send the request to the contact address on this page and we will carry it out.
Your Rights
Under the GDPR you have the rights below, and exercising them is free. You can request any of them at the contact address on this page; we aim to respond within one month.
- Access: find out what data we hold about you and receive a copy of it.
- Rectification: correct data that is inaccurate or incomplete.
- Erasure: have your personal data deleted. In the iOS app you can also do this directly from inside the app.
- Portability: receive the data processed on the basis of consent or contract in a structured, machine-readable format.
- Restriction of processing: have processing restricted in the cases where that applies.
- Objection: object to processing carried out on the basis of legitimate interests.
- Withdraw consent: withdraw health-data consent, or HealthKit, microphone, camera or notification permission, at any time. Withdrawing health-data consent means the core parts of the service can no longer be provided.
- Complain: if you believe your request was not handled properly, you can complain to the Dutch data protection authority, Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl), or to the authority in your country of residence.
International Data Transfers
Karafs is offered to Persian speakers worldwide and uses international service providers, so your data may be processed outside your country of residence and outside the European Economic Area. This applies in particular to AI model providers and cloud services.
For transfers out of the European Union, the European Economic Area or the United Kingdom we rely, as needed, on appropriate legal mechanisms: data processing agreements, Standard Contractual Clauses, adequacy decisions or other applicable bases. You can contact us for more information about those mechanisms.
Data Security
We use appropriate technical and organisational measures: encrypted transport, row-level security on user-owned tables, server-only boundaries for sensitive logic, private storage for media files, keeping model API keys off the device, and security logging.
No method of internet transmission or storage is completely risk-free. If a breach occurs, we will notify the data protection authority within 72 hours where the GDPR requires it, and notify you directly in high-risk cases.
Children
Karafs is intended for users aged 18 or older, and we do not knowingly collect data from anyone below that age. The product is not designed, marketed or offered as a service for children.
If we learn that an account belongs to someone under 18, we delete the account and its data. If you are a parent or guardian and believe your child has created an account, contact us at the address on this page.
Non-Marketing Communications
We may send essential messages about your account, security, subscription, support, or material changes to the terms or this policy. These are part of the service, not marketing.
We currently have no plans for marketing emails or promotional messages. If any are added, opt-in or opt-out will be provided as the law requires.
Changes to This Policy
We may update this policy to reflect changes in the product, processors, payment paths, the law or security practices. The updated version is always published at this same address, because this address is the one listed on both store listings.
If we make material changes we will notify users through appropriate channels, and where the law requires it we will obtain new consent or a separate affirmative action.
Contact Us
For any question or request for access, rectification, erasure, portability, objection or withdrawal of consent, contact soheilazad.dev@gmail.com.
Controller information: Joulino B.V., Weidevogellaan 262, 2496PP Den Haag, Netherlands, KvK 94647615, establishment number 000060103701.
Questions about this page?
For legal, privacy or support matters, you can contact the Karafs team directly.
