Privacy Policy
SmaCalo (the "Service"), provided by Tech Linkage LLC ("we"), respects your privacy and handles personal information and Google user data as described below.
1. Information Collected
- Google account identifiers and authentication information obtained during authentication, including OAuth tokens
- Nutrition, activity and fitness data, steps, distance, calories burned, weight, and other health measurements read from Google Health
- Meal and nutrition data created, corrected, or deleted in Google Health at your direction
- Fitbit account information and authentication information required for the connection
- Meal information you provide, including text and images, and estimated food, nutrition, and calorie information
- Saved meal drafts, reusable menus, nutrition goals, preferences, and operation status
- Device and browser information and usage and security logs, such as access times and errors
2. Purpose of Use
We use collected information only for the following purposes:
- Authenticating you, connecting accounts, and maintaining connection status
- Estimating, recording, listing, correcting, and deleting meal and nutrition information and providing nutrition guidance
- Displaying exercise, weight, steps, distance, calories burned, and related daily health-management features to you
- Writing records to Google Health or Fitbit when you expressly direct the Service to do so
- Operating and securing the Service, troubleshooting, complying with law, and preventing fraud or abuse
3. Sharing and Disclosure
We may allow service providers to process information only as necessary to provide the Service, including cloud hosting, authentication, and AI-assisted meal analysis. We also exchange data with Google or Fitbit at your direction. Except where required by law, we do not sell, transfer, or disclose personal information or Google user data to third parties for purposes other than those described in this policy.
- We do not use Google user data for advertising, retargeting, personalized advertising, or interest-based advertising.
- We do not sell Google user data to data brokers or use it for creditworthiness or lending decisions.
- We do not use Google user data to train general-purpose AI or machine-learning models.
4. Security Measures
We use appropriate technical and organizational safeguards, including encryption in transit, access controls, encryption of stored authentication credentials, least-privilege access, and short-lived operational logs. We do not intentionally record OAuth tokens, authorization codes, meal content, or health information in operational logs.
5. Data Retention
We retain information only for as long as needed to fulfill the purposes described in this policy. Unless a longer period is required by law, we delete or securely destroy information after the applicable retention period ends.
- Google OAuth credentials are stored in encrypted form until you disconnect Google, request deletion, the credentials expire or are revoked, or the Service ends.
- Existing nutrition, exercise, weight, and daily activity data read from Google Health is used to respond to your request and is not persistently stored in our database. Meal drafts, meal operation status, menus, goals, and preferences that you create through the Service are retained until you request deletion or the Service ends.
- For authorization between the Service and a connected client, temporary authorization-flow data generally expires within 10 minutes, authorization codes within 2 minutes, access tokens within 1 hour, and renewable authorization credentials within 30 days.
- Operational and error logs are generally retained for 7 days.
- Records written to Google Health or Fitbit are retained by those services and are not deleted merely by disconnecting. Delete them in the applicable service or request deletion from us.
6. Disconnecting and Deleting Data
You may disconnect accounts or delete data at any time as follows:
- Using the Service's Google disconnect feature revokes Google credentials and deletes the credentials stored by us. You may also revoke access from the third-party apps and services page in your Google Account.
- Individual meal records created by the Service can be deleted using the Service's cancellation feature or in Google Health.
- To request deletion of meal drafts, operation history, menus, goals, preferences, credentials, or other personal data stored by us, email the address below and identify the Service and the information needed to verify your identity. After verification, we will delete the data within 30 days unless retention is required by law.
- Revoking access or disconnecting alone does not automatically delete existing records held by Google Health or Fitbit, or data stored by us other than the authentication credentials described above.
7. Google API Services User Data Policy
The Service's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google API Services User Data Policy
8. Contact and Deletion Requests
For privacy inquiries or data deletion requests, contact:
Last updated: September 17, 2026