Calilog

Legal

Calilog Privacy Policy

Last updated: July 2026 · Version 2

This Privacy Policy explains what personal data Calilog ("we", "us", "Calilog") collects when you use the Calilog mobile application and related services (the "Service"), why we collect it, how it's stored and shared, and the rights you have over it. By using the Service you consent to the practices described below.

1. Who runs Calilog

Calilog is operated by Nordic Bytes AB (org. no. 559048-9406), a company registered in Sweden. Nordic Bytes AB is the data controller for the personal data described in this Policy. To exercise the rights described in section 9 or for any privacy-related question, email support@calilog.com.

2. Data we collect

We deliberately collect as little as we can while still running the Service. Concretely:

We do not collect:

3. Why we collect it

The legal basis for processing under EU/UK GDPR is contract performance for everything tied to running your account, legitimate interest for fraud prevention and crash reporting, and consent for optional product analytics and notifications. You can opt out of crash reporting and withdraw analytics consent in Settings at any time.

4. Who we share it with

We use a small number of third-party processors. We share only the minimum necessary for them to do their job, under data-processing agreements that bind them to use the data only to deliver the service to us.

We do not sell or rent your personal data to anyone, ever. We do not share your data with advertisers.

5. How long we keep it

6. Where it's stored

Calilog data is stored on Supabase infrastructure in the European Union. PostHog analytics and Sentry diagnostic data are configured for EU data residency. Some processors (including Apple, Google, and RevenueCat) operate globally; data routed through them may be processed in the United States or other regions. All cross-border transfers rely on Standard Contractual Clauses or equivalent safeguards.

7. Children

Calilog is not intended for children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, email support@calilog.com and we will delete it.

8. Cookies and tracking

The mobile app does not use cookies and does not perform cross-app tracking. Optional in-app product analytics is first-party product measurement only and is never used for advertising. The public Calilog website does not set tracking cookies; it stores only a theme preference in localStorage if you toggle dark mode. The authenticated admin area uses a strictly necessary secure session cookie.

9. Your rights

Depending on your jurisdiction (notably the EU/UK under GDPR and California under CCPA), you have the following rights:

Exercise these rights by emailing support@calilog.com.

10. Security

We follow industry-standard practices: TLS for transport, RLS-protected database access on Supabase, encryption at rest in Supabase storage, scoped service-role access for backend functions, and an explicit allowlist for administrator accounts. No system is perfectly secure; if we discover a breach affecting your data we will notify you and the relevant authorities as required by law.

11. Changes to this Policy

We will update this Policy from time to time. Material changes are surfaced inside the app via a re-acceptance prompt the next time you open it. The "Last updated" date at the top reflects the most recent revision.

12. Contact

Questions, complaints, or rights requests? Email support@calilog.com. If you are in the EU/UK and are not satisfied with our response, you have the right to lodge a complaint with your local data-protection authority.