Last updated 9 October 2026
Privacy Policy
This policy explains what personal data the Dalo app and dalo-app.com collect, why, who processes it and the choices you have. We wrote it to be read, not skimmed past. The short version: we collect what we need to run the app, we never sell your data, we show no ads and we don't track you across other companies' apps or websites.
Who we are
Dalo is provided by Pixelated Vectors LLC, a mainland company licensed in Dubai, United Arab Emirates ("we", "us"). We are the controller of the personal data described here. Contact us about anything in this policy at support@dalo-app.com.
What we collect
- Account. When you start, Dalo creates a guest account identified by a random ID. If you choose Sign in with Apple, we receive an Apple user identifier and, if you share them, your name and email address (which may be an Apple private relay address).
- Profile and plan answers. Your goal, age, sex, height, weight, activity level, training experience, schedule, available equipment, units and any injuries or limitations you tell us about, plus the name you ask Dalo to use.
- Food. Meals you log: food items, portions, calories and macros, time, and the meal photos you take or choose.
- Training and recovery. Your plans, sessions, sets, reps, weights, rest times, equipment changes, routines you complete, and daily check-ins (sleep, soreness, energy and the readiness score derived from them).
- Apple Health (HealthKit). Only with your permission, Dalo reads steps, heart rate, heart-rate variability, active energy, sleep and weight, and writes workouts, meals (nutrition) and weight. Most Health data is used on your device. Values needed for your plan to adapt across devices — such as sleep duration, heart-rate variability and the readiness score in a check-in, and weights you log — are stored with your account.
- Motion. If you turn on movement nudges, motion data is used on your device to notice long periods of sitting. It is not sent to us.
- Subscription. Apple processes your payment; we never see your card. We receive the subscription status, product, purchase and expiry dates and transaction identifiers from Apple, via our subscription provider RevenueCat.
- Support. What you send us when you email support.
- Technical data. Our hosting provider keeps short-lived server logs (IP address, time, request and error details) to keep the service secure and working. The app also stores your settings and a local cache on your device.
We do not collect precise location, contacts, browsing history or advertising identifiers.
How we use it, and our legal bases
- To provide the app — estimate meals, build and adapt your plan, show your history, sync between your iPhone and Apple Watch, run your subscription (performance of our contract with you).
- Health information — your body measurements, food, training, check-ins and Apple Health data are health data. We process them only with your explicit consent, which you give when you enter them or grant Health permissions, and which you can withdraw at any time (GDPR Art. 9(2)(a)).
- Security, abuse prevention and fixing problems — for example the fair-use limit on photo analysis (legitimate interests).
- Legal obligations — tax and accounting records, responding to lawful requests.
We do not use your data for advertising, we do not build advertising profiles, and we never use Apple Health data for marketing or sell it. We do not make decisions about you that have legal or similarly significant effects based solely on automated processing; plan suggestions are recommendations you can change.
Meal photos and AI
When you photograph a meal, the photo is uploaded to a private storage area that only your account can read. Our server sends the photo, with the language you use the app in, to Anthropic's Claude model to identify the food and estimate portions. The result is matched against nutrition databases (Open Food Facts and USDA FoodData Central) and shown to you to review before anything is saved. Your name, email and Health data are not sent with the photo. When you describe an injury or limitation in your plan setup, that text may be sent to the same model to adapt your plan.
Anthropic acts as our service provider: under its commercial terms it does not use our requests to train its models and deletes them after a limited period (currently up to 30 days) unless it must keep them longer for safety or legal reasons. Estimates from photos can be wrong; always check them.
Barcode numbers and food searches are sent to Open Food Facts and USDA to look up products. They are not linked to your identity.
Who processes your data
We share personal data only with service providers that process it on our instructions, under data-processing agreements:
- Supabase — database, authentication and file storage. Your data is stored on servers in Mumbai, India (AWS ap-south-1).
- Anthropic (United States) — meal photo analysis and plan text, as described above.
- RevenueCat (United States) — subscription status.
- Apple — Sign in with Apple, App Store payments, and Apple Health on your device, under Apple's own privacy policy.
- Our email provider, for support conversations.
We do not sell personal data and we do not "share" it for cross-context behavioural advertising as those terms are defined in California law. We may disclose data if the law requires it, to protect rights and safety, or to a successor if Dalo is sold or merged, in which case this policy continues to apply.
International transfers
Your data is stored in India and processed by providers in the United States. Where data from the European Economic Area, the UK or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum) with additional safeguards such as encryption in transit and at rest.
How long we keep it
- Account, profile, meals, photos, training and check-in data: for as long as your account exists. You can delete individual meals, with their photos, at any time.
- When you delete your account, your data and photos are erased from our live systems immediately and from backups within 30 days.
- Guest accounts that have not been used for 12 months are deleted.
- Subscription and transaction records: as long as tax and accounting law requires (usually up to 10 years), then deleted.
- Server logs: up to 30 days. Support emails: up to 2 years after the conversation ends.
Your rights and choices
Wherever you live, you can:
- Delete your account in the app: Settings → Account → Delete account. This erases your data from our servers. It does not cancel your Apple subscription — cancel that in your Apple Account settings.
- Turn off Apple Health access in the iPhone Settings app → Health → Data Access & Devices → Dalo, and turn off camera, photos, motion or notifications in Settings → Dalo.
- Ask us for a copy of your data, to correct it, or to delete it, by emailing support@dalo-app.com. We answer within one month (45 days for California requests) and may need to confirm the request comes from the account holder.
EEA, UK and Switzerland: you have the rights of access, rectification, erasure, restriction, data portability and objection, and the right to withdraw consent at any time without affecting earlier processing. You can complain to your local data protection authority.
California and other US states: you have the right to know, access, correct and delete personal information, and to opt out of its sale or sharing (we do neither). We use sensitive personal information (health data) only to provide the service you asked for. We will not discriminate against you for using your rights. You can use an authorised agent.
Security
Data is encrypted in transit (TLS) and at rest. Every row in our database and every stored photo is protected by access rules that let only your account read it. API keys for our AI and nutrition providers live on our server, never in the app. No system is perfectly secure; if a breach affects you, we will tell you and the authorities as the law requires.
Children
Dalo is not intended for anyone under 16 and we do not knowingly collect data from them. If you believe a child has given us data, email us and we will delete it.
This website
dalo-app.com is a static site. It sets no cookies and uses no analytics. Fonts are loaded from Google Fonts, which receives your IP address to deliver them. Our host keeps standard access logs for security.
Changes
If we change this policy we will update the date above, and tell you in the app before material changes take effect.