Hondo CalFit Tracker Logo Hondo CalFit
Home Features FAQ GitHub Privacy Terms

Privacy Policy

Last updated: July 22, 2026

Hondo CalFit Tracker ("we", "our", "the app") is an iOS and Android app developed by Hondo Systems. This privacy policy explains how your information is handled across both platforms. In short: we don't have Hondo CalFit Tracker accounts, in-app analytics, behavioral tracking, Hondo CalFit Tracker-operated cloud sync, or ads. iOS offers an optional Tip Jar. Your app data is local-first except for operating-system backups or device transfers and the specific AI/STT requests, barcode lookups, update checks, health sync, purchases, exports, or sharing actions you initiate. (Earlier iOS versions offered an optional Hondo CalFit Tracker Premium proxy subscription; Premium has been discontinued and current versions are bring-your-own-key only.) On supported iPhones, eligible food descriptions can be processed locally by Apple Intelligence as the final fallback. The public website is statically hosted by Cloudflare and does not load analytics; Cloudflare, Google Fonts, and the cdnjs asset CDN may process standard request metadata needed to serve the pages and assets under their own privacy policies.

Information You Provide

  • Gender, date of birth, height, weight, and body fat percentage (entered during onboarding; body fat can be used locally for BMR and lean-mass protein target display)
  • Activity level, weight goal, target weight, weekly weight-change rate, and custom meal-time boundaries
  • One or more food photos taken within the app in a single capture session, plus any optional meal note you add before analysis
  • One or more food photos selected from your library through the system picker or shared into Hondo CalFit Tracker through the iOS Share Extension, plus any meal notes or text descriptions you submit for AI analysis
  • Images attached to Coach messages, including camera captures or photo-library selections where supported
  • Barcode values scanned for packaged-food lookup
  • Food entries and nutrition data you log, including manual entries and Review Food nutrition edits you save by logging the meal
  • Reviewed meal details and current daily macro totals when you tap What if? for an AI meal-impact suggestion
  • Weight log entries
  • Optional water entries, daily water goal, and water-reminder preference
  • Food and weight descriptions you provide through iOS Siri Shortcuts / App Intents
  • Body fat % readings logged over time, plus an optional goal body fat % (only collected if you opt into body-fat tracking during onboarding or later in Settings)
  • Voice recordings (when using voice meal input)
  • AI Coach chat messages (multi-turn conversation history)
  • AI provider and speech-to-text provider API keys (stored encrypted on device — see below)
  • App preferences: appearance mode, theme color, units (metric / imperial), week-start day, meal-time boundaries, notification times, speech-language preferences, Home nutrient-card choices, default grams, optional nutrient goals, Energy Burn Goals, Adaptive Goals, and optional water tracking

How We Use Your Information

  • AI Food Analysis: One or more food photos from a camera session or system photo picker, iOS Share Extension photos, optional meal notes, text descriptions, and the text produced from voice input are sent to your selected AI access path only after you choose to analyze them. Multiple photos selected together are included as separate images in the same analysis request; they are not merged into one image. In Bring Your Own Key mode, requests go directly from your device to your chosen AI provider (any of 13 supported: Google Gemini including Gemini 3.5 Flash-Lite and 3.6 Flash, OpenAI, Anthropic Claude, xAI Grok, OpenRouter, Together AI, Groq, Hugging Face, Fireworks AI, DeepInfra, Mistral, Ollama running locally, or a custom OpenAI-compatible endpoint you configure). For text descriptions, text produced from voice input, and Siri food logging on supported iPhones, Apple Intelligence may process the food description locally on-device only as the final fallback after BYOK provider/fallback attempts fail; photo analysis, Coach, and speech transcription continue using the configured AI access path. The onboarding and AI Access settings explain that AI analysis sends request content for processing; manual entry never sends anything to an AI provider. Custom AI Instructions (optional, Settings → AI Access → BYOK): if you fill in the Custom AI Instructions text box, that text is appended to every AI request so the model sees your context. The text stays local except when included in the AI request payload. Fallback AI Provider: in BYOK mode, if your primary provider returns an error, the request can retry with the secondary provider you configured. Note on OpenRouter openrouter/free: when you pick the free-tier default model on OpenRouter, OpenRouter itself selects the upstream provider that handles your request.
  • iOS Siri Shortcuts / App Intents: If you use Siri to log food, the spoken food description is handled as text input and sent through your selected AI access path to estimate nutrition; on supported iPhones it may use Apple Intelligence locally only as the final fallback after BYOK provider/fallback attempts fail. The resulting entry is logged locally and written to Apple Health if Health access allows nutrition writes. If you use Siri to log weight, the app parses the number locally, respects pounds/kilograms in the phrase or your unit setting, stores the weight locally, and writes it to Apple Health if authorized. If you ask Siri for today's calories, the app reads today's local totals and calorie goal. Phrase examples are shown under + → Describe Meal → Siri Phrases.
  • Meal What-If Suggestions: If you tap What if? on the Review Food screen, the app locally previews the meal's calorie/protein/carbs/fat impact. If it asks AI for a suggestion, it sends the reviewed meal name and macros, your current daily totals, daily goals, and minimal profile context through your selected AI access path. The meal is not logged until you tap Log.
  • Barcode Lookup: On iOS and Android, if you choose Barcode from the logging menu, the scanned barcode is sent from your device to the public Open Food Facts API. Hondo CalFit Tracker requests only product fields needed for nutrition logging, such as product name, brand, quantity, serving size, and nutriments. If Open Food Facts has no product or incomplete nutrition, the app reports that the product could not be used; you can instead photograph the packaging with Camera or Photos. Barcode lookup does not use your AI provider key.
  • AI Coach Chat: When you use the Coach tab, the app sends a slim system prompt (your profile, BMR/TDEE/macro formulas, weight forecast, current date/timezone, and a one-line "data available" snapshot) plus your conversation history through your selected AI access path. Coach can additionally call tool functions mid-turn to fetch relevant ranges of your weight, body-fat, calorie, food-entry, workout-plan, workout-preference, or completed-workout history when you ask about specific dates or training. If you attach an image to a Coach message, that image is included in the AI request. The fetched data is sent as part of the AI request and may include meal nutrients or workout exercises, sets, reps, weight, RPE, and calculated calorie burn when relevant. Full chat history is kept locally; only the last 20 messages are included in each LLM request to cap token cost.
  • Optional Nutrient Goal Estimation: If you tap the AI estimate button for detailed nutrient goals, the app sends the minimum profile context needed for that estimate, such as your goal, body measurements, activity level, and current calorie/macro targets, through your selected AI access path. Returned detailed goals such as fiber, sugar, fats, cholesterol, sodium, potassium, calcium, iron, magnesium, zinc, vitamins, folate, omega-3, and related nutrients are stored locally as settings and do not change the calorie/protein/carbs/fat calculator.
  • Speech-to-Text: If you pick the on-device option (Native iOS on iPhone, Native Android SpeechRecognizer on Android), voice recognition happens on your device and the selected language is passed as a local recognition hint when applicable. On Android, if the native recognizer reports that the selected language is unsupported or unavailable on-device, the app may retry native Android recognition with network/provider defaults before showing an error. In BYOK mode, if you pick a remote provider (Gemini Audio, OpenAI Whisper, Groq, Deepgram, AssemblyAI), a short audio recording is uploaded directly from your device to that provider and its text response is returned to the app. Groq (Whisper) and Deepgram are recommended alternatives when native Android speech is inconsistent on a specific phone. If you choose a fixed speech language or "Use Device Language" instead of Provider Auto, the corresponding language code may be sent with the audio so it can bias transcription.
  • Local Storage: All food entries, Siri-created food entries, saved Review Food nutrition edits, weight entries, Siri-created weight entries, body-fat readings, optional body-circumference measurements (waist, hips, neck, chest, arms, thigh, calf, wrist) you choose to enter, optional water entries and goals, workout plans and logged sets, workout preferences, calculated workout-burn history, user profile (including any goal body fat %), Coach chat history, food photos, cached thumbnails, optional nutrient goals, Adaptive Goals preferences, Home nutrient-card choices, meal-time boundaries, and app preferences are stored in the app's local container — primarily UserDefaults on iOS and DataStore Preferences on Android. Body-fat-aware protein target display, water progress, and workout-burn estimates are calculated locally from that data. Data leaves that container only through operating-system backup/transfer behavior or the specific requests and sharing actions described in this policy.
  • API Key Storage: On iOS, your API keys are stored in iOS Keychain using the app's private Keychain service and become available after the device is first unlocked. On Android, they are stored in EncryptedSharedPreferences using AES-256 with a master key managed by Android Keystore (hardware-backed when the device supports it).
  • Widgets and Apple Watch: To display today's calorie, selected nutrient, and optional water totals in iOS Home Screen widgets (Hondo CalFit Tracker, Hondo CalFit Tracker Protein, and Hondo CalFit Tracker Water), iOS Lock Screen widgets, Android Glance widgets (Calorie, Protein, Today, and Water), and Apple Watch, the main app writes a small snapshot of the relevant totals and goals into a shared container — App Group on iOS, the same DataStore on Android. iOS also sends a small nutrition snapshot to the paired Watch app through WatchConnectivity when available. These snapshots never leave your devices and contain only totals, goals, nutrient labels, theme choice, and whether water tracking is enabled — no food names, photos, account identifiers, or API keys.
  • Water Tracking and Reminders: Water tracking is off by default. If you enable it, the amounts you log, your freely chosen daily goal, and progress are stored and calculated locally. Optional water reminders are scheduled as local notifications and do not send your water history to a server, Apple Health, or Health Connect.
  • Operating-System Backups and Device Transfer: Hondo CalFit Tracker does not run its own cloud-sync service. Apple and Android may nevertheless include eligible app-container data in encrypted device backups, Google backup, or direct device transfer according to your platform and account settings. The iOS Keychain accessibility class used by Hondo CalFit Tracker also allows saved keys to migrate with an encrypted backup. These copies are controlled by Apple or Google, not by Hondo CalFit Tracker. Delete All Data clears the current app installation but cannot rewrite an older platform backup that already exists.
  • Exports and Shared Meal Links: Diary exports (JSON, Markdown, or CSV) are created locally and leave the app only when you save or share the resulting file. When you explicitly share a meal link, its meal names, nutrition values, serving details, and emoji are encoded in the link itself so the recipient can preview and import the meal. Anyone who receives or gains access to that link can read its contents; do not share it publicly if it contains information you consider private. The static add-meal.html page decodes the link in the recipient's browser and does not upload the payload to a Hondo CalFit Tracker backend, though the hosting provider may receive the requested URL as standard request metadata.
  • Apple Health (iOS) / Health Connect (Android): If you enable health integration in Settings, the app writes body measurements (weight, height, body fat percentage where supported), per-meal nutrition, and calculated workout calories to the platform's health store. Workout plans and individual set details stay in Hondo CalFit Tracker; only the calculated active-energy summary is synced. On iOS, the app also reads weight + body fat + height + date of birth + biological sex back into your profile, can automatically import external weight + body-fat samples from other Health-compatible apps, and can read active/total energy burned when you turn on Energy Burn Goals. On Android, Health Connect sync covers nutrition, weight, body fat, calculated workout active calories, and active/total energy reads for Energy Burn Goals, with permission reconciliation and backfill support. Adaptive Goals use local food, weight, and profile data to make small weekly calorie corrections and do not send that calculation to an AI provider. On first enable where supported, historical backfill pulls past weight/body-fat samples into Progress. After a reinstall or on a new phone, the app can read back the nutrition, weight, body-fat, and calculated workout-burn records it previously wrote (identified by its own record tags) to restore those Hondo CalFit Tracker summaries; workout diary plans and set details remain local app data. You can review or revoke access from the app's Health settings using Manage Access, from iOS Settings → Health → Data Access & Devices → Hondo CalFit Tracker, or from Health Connect on Android.
  • Notifications: If you enable streak, daily-summary, log-weight, log-body-fat, meal, or water reminders, they are scheduled locally via iOS local notifications or Android AlarmManager plus the POST_NOTIFICATIONS permission on Android 13+. Metric-aware reminders can skip on days you have already logged the corresponding item. No notification content is sent to a Hondo CalFit Tracker server.
  • App Update Checks: About can check whether a newer app version exists. On iOS, the app requests public metadata from Apple's iTunes Lookup API for the Hondo CalFit Tracker App Store ID. On Android, it asks Google Play through the Play In-App Update API whether an update is available for the installed app. The app does not send your food log, profile, API keys, or health data for update checks. If an update is available, tapping Update opens the App Store or Play Store listing.
  • Website Hosting and Assets: The marketing website is statically hosted by Cloudflare and does not load an analytics script. Cloudflare may process standard request metadata, such as IP address and browser information, to deliver and protect the site. Pages also request fonts from Google Fonts and icon CSS/font files from cdnjs; those services receive the normal technical metadata associated with an asset request. Shared-meal URLs may be visible to Cloudflare because the meal payload is part of the requested URL; the page sets a no-referrer policy so that payload is not sent as a referrer when a visitor follows an App Store, Play Store, or privacy link. Website processing is separate from the mobile apps and is not connected to a Hondo CalFit Tracker account because no such account exists.

Information We Do NOT Collect

  • We do not use any in-app third-party analytics, advertising, or crash-reporting SDKs
  • We do not track your behavior, location, or browsing activity
  • We do not sell your personal data
  • We do not operate Hondo CalFit Tracker accounts, in-app analytics, or tracking servers
  • We do not require an account, sign-in, or Hondo CalFit Tracker-operated cloud sync; operating-system backup and device-transfer features may still apply
  • We do not see your API keys; AI/STT requests go directly from your device to the provider you configure. Apple Intelligence fallback, when used for supported iOS text, voice-transcribed, or Siri food-description analysis, is processed on-device.

Tips (iOS In-App Purchases)

The iOS app offers optional, consumable Tip Jar purchases that support development and unlock nothing. Payment is processed entirely by Apple under your Apple ID; we never see your payment details. The app uses RevenueCat to fetch tip products and validate purchases — RevenueCat receives an anonymous app-generated identifier and the App Store receipt, never your food, health, or profile data. The Android app has no in-app purchases; its optional Ko-fi link simply opens in your browser.

Data Storage & Security

DataStorage Location (iOS)Storage Location (Android)Accessible By
Food entries, Siri food logs, and saved review nutrition editsUserDefaultsDataStore PreferencesYou only
Food photos and cached thumbnailsApp Support directoryfilesDir/hondo-food-images/ plus local thumbnail cacheYou only
Weight entries, including Siri weight logsUserDefaultsDataStore PreferencesYou only
Water entries, goal, and reminder preferenceUserDefaultsDataStore PreferencesYou only
Body-fat entries (history)UserDefaultsDataStore PreferencesYou only
Workout plans, logged sets, preferences, and calculated burn historyUserDefaultsDataStore PreferencesYou only; calculated burn summaries may also sync to Health when enabled
User profile (incl. goal body fat %)UserDefaultsDataStore PreferencesYou only
Coach chat history and attached thumbnailsUserDefaultsDataStore PreferencesYou only
Widget / Watch snapshot (today's totals and goals, including water when enabled)App Group container + paired Watch transfer when availableSame DataStoreYou only
App preferences (theme color, appearance, units, meal times, notifications, Home nutrient cards, optional nutrient goals, Adaptive Goals)UserDefaultsDataStore PreferencesYou only
API keys (LLM + STT)iOS KeychainEncryptedSharedPreferences (AES-256, AndroidKeystore-backed)You only
Barcode valuesSent to Open Food Facts only when you scan a barcode.Open Food Facts
Food photos, meal notes, and Siri food descriptions (for AI analysis)Sent to your BYOK provider directly. Supported iPhones can process text, voice-transcribed, and Siri food descriptions with Apple Intelligence on-device as the final fallback after BYOK provider/fallback attempts fail.Processed in transit, or on-device for Apple Intelligence fallback
Voice audio (remote STT)Sent directly to your chosen BYOK STT provider.Processed in transit
Coach chat messages and attached imagesSent to your BYOK provider directly.Processed in transit
Diary exports and shared meal linksCreated locally and disclosed only through the save/share destination you choose. Shared-link meal data is carried in the URL.You and recipients/services you choose
Tip purchases (iOS only)Processed by Apple; validated through RevenueCat using an anonymous identifier and the App Store receipt.Apple + RevenueCat
Health dataApple HealthKitHealth ConnectYou + apps you authorize

Third-Party AI Providers

When you send a request to an AI or STT provider, including food analysis, optional nutrient-goal estimation, Coach chat, or remote voice transcription, you are subject to that provider's privacy policy. Each provider handles data differently — some log prompts, some don't; some train on inputs, some don't. We recommend reviewing the policy of whichever provider you choose:

  • Google Gemini
  • OpenAI
  • Anthropic
  • xAI
  • OpenRouter
  • Together AI
  • Groq
  • Hugging Face
  • Fireworks AI
  • DeepInfra
  • Mistral
  • Deepgram
  • AssemblyAI

If you use Ollama or a custom OpenAI-compatible endpoint, requests go to whatever URL you configure — typically your own machine or a self-hosted server.

Barcode/Product Data Provider

Barcode lookup uses the public Open Food Facts API. When you scan a barcode, the barcode value is sent to Open Food Facts so the app can retrieve public product and nutrition data when available. Open Food Facts' own policies apply to that lookup.

  • Open Food Facts Privacy

Website Service Providers

  • Cloudflare Privacy Policy — static hosting and cdnjs assets
  • Google Privacy Policy — Google Fonts

Permissions Requested

  • Camera — for snapping food photos and scanning barcodes. Prompted on first use.
  • Microphone / Speech Recognition — for voice meal input. Prompted on first use.
  • Photo Library / Storage — to pick existing food photos. iOS uses PHPicker; Android uses the system PickVisualMedia photo picker — neither requires broad photo-library access.
  • Notifications — only if you enable meal, streak, daily-summary, weight, body-fat, or water reminders. On Android 13+, this triggers the runtime POST_NOTIFICATIONS permission prompt.
  • Health — only if you enable Apple Health (iOS) or Health Connect (Android) integration. The system sheet lists the requested read/write types. Energy reads are used for goal calculation only when Energy Burn Goals is enabled; active-energy writes are used only when you calculate and sync a workout burn.
  • Internet — required for AI/STT requests to your chosen providers and optional app-update checks. Implicit on iOS; declared in AndroidManifest.xml on Android.
  • Battery Optimization (Android, optional) — Settings exposes a deep-link to whitelist Hondo CalFit Tracker in Android's battery-optimization list. This is needed on aggressive OEM skins (OriginOS, MIUI/HyperOS, One UI) where exact alarms are killed otherwise. Whitelisting only affects local reminder reliability — it does not change anything about data handling.

MIT License

Hondo CalFit Tracker is available under the MIT License. You can review exactly what the app does — including every network call — at github.com/rounderone/hondo-calfit-tracker.

Data Retention & Deletion

  • Local app data remains on your device until you delete it in the app or remove the app, subject to operating-system backup and restore behavior.
  • Delete All Data (Settings → Delete All Data) wipes the app's local storage on both platforms: food log, weight log, body-fat log, water log, workout diary/plans/history, profile, Coach chat history, saved meals, optional nutrient goals, Home nutrient-card choices, widget / Watch snapshot, API keys, and preferences. It intentionally does not touch Apple Health or Health Connect — those samples are personal and survive the reset. If you want them removed too, on iOS go to Settings → Health → Data Access & Devices → Hondo CalFit Tracker; on Android use Health Connect's data management screen.
  • Clear Food Log (Settings → Clear Food Log) removes local food entries only; previously-synced Apple Health / Health Connect samples are kept.
  • Uninstalling removes the app sandbox, but Apple Health / Health Connect samples persist unless deleted separately. On iOS, Keychain items can also survive an uninstall by platform design; use Delete All Data before uninstalling if you want Hondo CalFit Tracker to explicitly remove its saved API keys.

Children's Privacy

Hondo CalFit Tracker is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal data, please contact us so we can assist.

Changes to This Policy

We may update this privacy policy from time to time as the app evolves. Changes will be reflected in the "Last updated" date above. Continued use of the app after changes constitutes acceptance of the updated policy.

Contact

For privacy questions or deletion requests, contact either of: admin@hondosystems.com or ad13dtu@gmail.com

Hondo CalFit Tracker Hondo CalFit Tracker

An iOS and Android calorie tracker that puts you in charge of the AI, the data, and the device.

Read

  • Features
  • Process
  • Screenshots
  • FAQ

Build

  • GitHub
  • Report Issue
  • Request Feature

Legal

  • Privacy Policy
  • Terms of Service
  • Sitemap
  • MIT License
© 2026 Hondo Systems · Set in Fraunces & Manrope Volume 03 · No. 01