Effective date: July 30, 2026
CalTrack (“the app”) is published by NGN Consulting Corp. (“we”, “us”) and is built privacy-first. This policy explains what data the app handles, where it is stored, and who can see it.
Everything you enter in CalTrack — your name, calorie goal, weight, and every meal you log — is stored on your device. We operate no servers and have no accounts, ads, analytics, or trackers, so your data is never sent to us and we cannot see it.
Three things can send or place data outside the app, and none of them gives us your personal data: Android’s own system backup to your Google account, a backup file you create yourself with Export data, and — if you choose to buy the optional Pro upgrade — the purchase itself, which is handled by Google Play. All three are explained below.
The app stores the following locally on your phone:
None of this is transmitted to us or stored on any server we operate — we do not operate any.
CalTrack offers an optional paid upgrade. If you buy it:
If you never buy anything, the app performs no billing checks at all.
Like most Android apps, CalTrack permits Android’s built-in backup service. If backup is enabled for your device (Android Settings → Google → Backup), Android may copy the app’s data to your own Google account and restore it automatically when you reinstall CalTrack or set up a new phone. This is what keeps you from losing your logging history when you change devices.
What this means:
The Profile screen includes Export data, which writes all of your CalTrack data to a single .json file and lets you save or send it wherever you choose — your own storage, a cloud drive of your choice, or another device. Import data restores from a file you previously exported, replacing what is currently in the app.
Both are free features and always will be — getting your own data out of the app is never behind a payment, and it keeps working whether or not you have a Pro purchase, and whether or not a subscription has lapsed.
The export file is created on your device and goes only where you send it; it is never uploaded to us. Anyone who obtains that file can read the data in it, so keep it somewhere you trust.
Apart from the purchase check described above, the only network requests the app makes are to Open Food Facts (world.openfoodfacts.org), a non-profit, open food products database, in two situations:
These requests contain no account identifier, no name, no device identifier added by us, and no logged-meal history. The app does identify itself in each request, with its name, version and a developer contact address, because Open Food Facts’ API guidelines ask callers to be reachable — that identifies us, not you. They are used solely to return results and are not stored by the app anywhere except on your device (as part of a meal, if you log it). Open Food Facts’ own privacy practices are described at world.openfoodfacts.org/privacy
Like any request made over the internet, these requests necessarily include your device’s IP address, which Open Food Facts’ servers receive in order to send a response back to you. We do not receive, log, or store this address ourselves — it is visible only to Open Food Facts, under their own privacy practices (linked above).
Requests are made over HTTPS (encrypted in transit).
The camera permission is used exclusively to scan product barcodes on the scanner screen. No photos or video are captured, stored, or transmitted. The camera is active only while the scanner screen is open.
CalTrack is a general-audience app and is not directed at children. It does not knowingly collect personal information from anyone — including children — because it does not collect personal information at all: everything you enter stays on the device it was entered on.
In the United States, this means the app is not subject to COPPA’s parental-consent requirements, because no personal information is collected in the first place. In the EU/UK, GDPR sets the age at which a child can consent to their own data processing at 16 by default, though individual member states may set it as low as 13 — this doesn’t change anything for CalTrack either, because no consent to processing is required when no data is collected or transmitted to us at all.
To remove your data:
There is nothing for us to delete and no request to send us: we operate no servers and hold no copy of your data. Records of a purchase are held by Google as part of your Google Play account history, and are governed by Google’s policies; we cannot delete those, and we may be required to keep the corresponding sales records for tax and accounting purposes.
Because CalTrack does not operate a server and does not collect your personal data, we do not process it under any lawful basis ourselves — there is nothing for a lawful basis to apply to. The narrow processing that does happen occurs outside the app, by other parties, each under their own basis:
If you are located in the European Economic Area or the United Kingdom, data protection law (the GDPR, and the UK GDPR) gives you a set of rights over your data. Because CalTrack stores your data on your own device rather than on any server we operate, most of these are already available to you directly, through the app itself, without needing to ask us:
.json file) you can move to another device or service, at any time, free of charge.You don’t need to submit a formal request to exercise the access, rectification, erasure, or portability rights above — they’re already available to you directly in the app, at any time. If you have a question about any of this, you can still reach us at the contact address below.
If the app’s data practices ever change (for example, if optional cloud features are added), this policy will be updated and the effective date revised before those changes take effect.
Questions about this policy: firefly.express.sales@gmail.com
NGN Consulting Corp., Illinois, United States — the publisher of CalTrack and the party responsible for this policy.