Summary
Lazy Calories is a food-tracking app that can estimate calories and macronutrients from food photos or text. Core meal records are stored locally on your device. The app sends information off the device only for specific network features, including hosted AI analysis, approximate location context, purchase verification, and any optional integrations you enable.
Data the app handles
Photos and food entries
With Android photo permission, the app reads photo metadata and content from the device media library. You may grant access to all photos or only selected photos, depending on your Android version and choice. The app stores references to photos, meal timestamps, calorie and macro estimates, food descriptions, stack and serving information, notes you enter, and on-device food-labeling results. It does not copy full photo files into its Room database.
ML Kit image labeling can classify likely food photos on the device. If hosted AI analysis is requested or enabled for a detected food photo, the app resizes the relevant image and sends it with useful context. A grouped meal may include several selected images, such as different angles, a menu, or a receipt. Text-only entries and food-evaluation photos are handled in the same way when you use those features.
Profile and food preferences
The app can store birth year, biological sex, height, weight, unit preference, and dietary preferences. These values are used to calculate a calorie budget and tailor food suggestions. They are stored locally and may be included in a hosted request only when needed for the feature you invoke. The app does not create a conventional user account or request your name.
Approximate location
The app may request city and country from ipapi using the device’s public IP address. It does not request precise GPS location or Android location permission for this feature. City and country are cached in encrypted app preferences for up to seven days and may be included as context in AI food analysis or suggestions. ipapi necessarily receives the network IP address and handles it under its own privacy policy.
Installation and usage information
On first use, the app creates a random installation identifier. It is not an advertising ID and is not derived from your name, email address, hardware serial number, or photo content. The app sends authenticated requests using a project-scoped, one-way fingerprint of that identifier. TokenGate records the fingerprint with request time, model, token counts, estimated cost, plan and quota status, and security results. It does not store the food prompt, photo, or AI response.
Optional Health Connect information
If you choose to connect Health Connect and grant permissions, the app can read total and active calories burned and the latest weight. It uses this information to adjust calorie budgets and may update your local weight setting. The app can also write nutrition records that include calories, meal time, meal type, and a food description. Health data is not used for advertising and is not sold. Lazy Calories does not send Health Connect records to TokenGate or the AI provider as health records, although locally calculated daily budget or food-summary context may be part of an AI suggestion request.
Purchases
If you buy LazyCalories Pro, Google Play handles payment details. The app receives purchase status and a purchase token. The purchase token, product identifier, and an installation binding are sent to TokenGate for verification with Google Play. TokenGate stores a keyed digest of the purchase token, not the raw token, together with subscription status, plan dates, product and base-plan identifiers, acknowledgement state, and installation binding. We do not receive your card or bank details.
Diagnostics and website use
The app can write ordinary diagnostic messages to the Android system log. Lazy Calories does not include an advertising SDK or a third-party analytics SDK. This public website does not use analytics, advertising pixels, cookies, local storage, or a contact form. Like most hosting services, its infrastructure may process basic request information such as IP address, time, requested path, and browser details for delivery and security.
How the data is used
- Show and organize a local food timeline and calculate daily progress.
- Identify likely food photos on the device.
- Provide requested AI calorie, macro, meal-grouping, food-evaluation, and suggestion features.
- Personalize calorie budgets using information you enter and optional activity data.
- Synchronize nutrition records with Health Connect when you enable that option.
- Measure hosted AI usage, enforce plan limits, prevent abuse, and verify Pro purchases.
- Maintain reliability, investigate errors, and protect the service.
We do not sell personal information and do not use food photos, health information, or meal records for targeted advertising.
Service providers
Information is disclosed only as needed to operate a feature:
- TokenGate: authenticates the app, applies plan limits, verifies purchases, and routes hosted AI requests. See the TokenGate privacy policy, terms, and trust page.
- OpenRouter and Google Gemini: TokenGate currently routes Lazy Calories AI requests through OpenRouter to a Google Gemini model. These services process request content to return a result. Their own terms and retention rules apply, including security and abuse-monitoring practices. See OpenRouter privacy and Gemini API terms.
- Google: provides Android, ML Kit, Health Connect, Google Play Billing, and purchase-verification services. On-device ML Kit labeling does not require sending your food photo to Lazy Calories’ hosted AI service.
- ipapi: converts a public IP address into approximate city and country information when that context is requested.
- Amazon Web Services: hosts this static website and its delivery network.
We may also disclose information when legally required, or when reasonably necessary to protect users, the service, or the public. We do not permit providers to use app data for advertising on our behalf.
Storage, backup, and retention
On the device
Meal metadata, profile information, food preferences, cached fitness totals, and app settings are stored in the app’s local Room database or preferences. The installation identifier and approximate-location cache are stored in encrypted preferences. Clearing the app’s storage or uninstalling it removes this local app data, subject to Android and storage-provider behavior.
Android automatic cloud backup and device-to-device transfer are configured to exclude the Room database and encrypted preferences. This means meal records and the installation identifier are not restored through Android’s automatic app-data transfer. Some ordinary settings may transfer according to Android backup behavior.
User-created backups
If you configure backups, Lazy Calories writes an unencrypted ZIP file to a folder you choose through Android’s storage picker. A backup contains meal and profile records, photo references, food preferences, and cached fitness totals. It does not include the photo files themselves, the installation identifier, or TokenGate credentials. Automatic backup housekeeping keeps daily backups for up to seven days and one weekly backup for the following three weeks, for a retention window of up to 28 days. A storage provider you choose may sync or retain those files under its own policy. Delete unwanted backup files from that provider.
Hosted records
TokenGate processes AI request content in memory and does not store prompts, images, or responses. Detailed usage records tied to an installation fingerprint are normally retained for 90 days. Fingerprint-free monthly usage totals are retained for up to 24 months. An inactive installation fingerprint is normally removed after 90 days, except where a security block or custom quota must remain. Short-lived infrastructure security logs may be kept for up to seven days during an incident and are configured to exclude content and credentials. Purchase records are kept while needed to provide, transfer, reconcile, or defend the subscription and to meet legal obligations.
AI providers, Google Play, Health Connect, ipapi, your chosen backup provider, and website hosting providers maintain information under their own retention rules.
Your choices and deletion controls
- Limit photo access to selected images, revoke photo permission in Android settings, disable background food detection, or stop using AI features.
- Edit calorie values and meal context, exclude photo entries from calorie totals, and delete text-only entries in the app.
- Clear app storage or uninstall the app to remove the local database and preferences.
- Delete user-created ZIP backups from the folder or cloud-storage provider you selected.
- Revoke Health Connect permissions and separately review or delete records written by Lazy Calories in Health Connect. Clearing or uninstalling Lazy Calories does not necessarily delete records already written to Health Connect.
- Manage or cancel a Pro subscription through Google Play. Cancellation does not itself delete local or server usage records.
- Email us to request deletion of TokenGate records linked to the current installation. We may need a non-secret installation reference shown by the app or other reasonable information to identify the record.
Deleting a source photo in another app may make it unavailable to Lazy Calories, but it is not a substitute for clearing the app’s local records or deleting a user-created backup.
Security
Network requests use HTTPS. Sensitive app preferences use Android encrypted storage, TokenGate credentials are not included in user backups, and purchase tokens are stored server-side only as keyed digests. TokenGate requests use app and device-integrity checks where available. No system can guarantee absolute security. Keep your device and any chosen backup location protected, and do not place information in meal notes that you do not want processed.
Children
Lazy Calories is not directed to children under 13, or a higher minimum age where local law requires it. We do not knowingly collect personal information from a child through an account system. A parent or guardian who believes a child has provided information through the app can contact us to request review and deletion.
International processing and policy changes
Service providers may process information in countries other than your own. Their laws may differ from those where you live. We may update this policy when the app, providers, or legal requirements change. The effective date and the policy available at this stable URL will be updated.
Contact
Questions, privacy requests, and deletion requests can be sent to salvadoraceveskz@gmail.com. Please do not email food photos, health details, purchase tokens, or other sensitive information.