Privacy Policy
Last updated: March 2026
The legally binding version is the Hebrew version. This translation is provided for your convenience only.
Corefit Ltd. (Companies Registrar registration number: 517325544), which operates the application "Cali - AI Nutrition Tracker" (hereinafter: "Cali", "the Company", "we", "us" or "our"), available for download on the Apple App Store and Google Play, regards the protection of the privacy of its customers and of all users of its services as a matter of the utmost importance, whether through the application, the website or any other technological means (hereinafter: "the Service").
The Company undertakes to act in accordance with the provisions of the Protection of Privacy Law, 5741-1981 (hereinafter: "the Protection of Privacy Law"), including Amendment 13 to the Law and the regulations enacted thereunder, and in accordance with the provisions of the Protection of Privacy Regulations (Data Security), 5777-2017, as well as in accordance with the provisions of any other applicable law, in order to ensure the safeguarding of the personal information of data subjects and to protect their constitutional rights to privacy.
This policy describes how we collect, use, store, protect and share your personal information. Your continued use of the Service constitutes your consent to the terms set out in this Privacy Policy, and we therefore recommend that you read it carefully.
1. Definitions
"Personal Information": any data relating to an identified person or to a person who can be identified through reasonable effort, directly or indirectly, including name, age, gender, email address, physical data (weight, height), lifestyle data, fitness and nutrition goals, location data, online identifiers and Service usage data.
"Information of Special Sensitivity": as detailed in Amendment 13 to the Protection of Privacy Law, including information on health condition, location data, biometric details, financial data, opinions and beliefs, and more.
"Databases": a collection of items of personal information processed by digital means, excluding personal use that is not for business purposes.
"Information Processing": any action performed on personal information, including collection, recording, storage, organization, use, analysis, personalization, transfer, delivery, disclosure, deletion or destruction.
2. The Information We Collect
We collect the following types of personal information for the purpose of operating and improving the Service:
During your use of the Service, technical and operational information will also be collected through automated tools in order to characterize your use of the Service and improve the user experience. These tools collect general information about you and about your use of the Service.
- Personal details: first name, last name, email address, age and gender.
- Physical data: weight, height, and any additional physical data you provide with your consent.
- Lifestyle information: level of physical activity, fitness and nutrition goals, meal times and personal preferences.
- Step and activity data: daily step count, physical activity data and related health data, to the extent that you authorize synchronization with Apple Health, Google Fit or any other data source.
- Recipe data and dietary preferences: recipes you have saved, created or rated, dietary sensitivities and preferences (such as vegetarian, vegan, gluten-free) and personal cooking content.
- Community content: to the extent that you choose to participate in the community, the content you have posted, comments, likes, followers, and interactions with other users will be collected, as well as the display name and profile picture you have chosen.
- Device access: access to the camera for the purpose of taking photos of food, access to notifications for the purpose of reminders and updates, access to storage for the purpose of uploading photos, and access to health and activity sensors for the purpose of step tracking.
- Usage data: information about how the Service is used, including food logs, photos taken, analyses performed, progress toward goals and personal preferences.
- Technical and operational information: IP address, general geographic location, device type, operating system version, device identifiers, browsing details and duration of Service usage.
- Information from third-party connection: when connecting via a Google or Apple account, basic information such as name and email address is collected, in accordance with the settings you have approved with that provider.
3. How We Use the Information
The information collected is used by us for the following purposes:
- Providing the Service, including analyzing food photos, calculating nutritional values, a personal food log and tracking progress.
- Displaying personalized recipes and processing step and activity data for the purpose of presenting overall progress.
- Operating community features, including displaying content you have posted to other users, managing interactions between users and maintaining a safe environment free of offensive content.
- Providing recommendations and personalizations based on your input and your goals.
- Improving the user experience, developing new features and personalizing content.
- Ongoing operation of the Service, securing our systems and preventing misuse.
- Communicating with you, including operational messages, service updates, reminders and support inquiries.
- Sending marketing content, updates and promotions, subject to your consent and your right to remove yourself from the mailing list at any time.
- Complying with the provisions of the law, regulatory obligations and judicial orders, as may be required.
- Conducting statistical and aggregate analyses that do not allow personal identification, for the purpose of improving the Service and understanding usage trends.
4. Use of Cookies and Tracking Technologies
On the Service we use information files called "Cookies" and similar tracking technologies. These files help track user preferences, improve the usage experience, save details you have entered in various forms and offer you personalized content.
A user who does not wish to have information collected through cookies may block or restrict their operation by changing the relevant settings in the browser or on the device they are using. It is clarified that some cookies may expire when the browser or application is closed, while others may be retained in the device's memory.
It is clarified that blocking cookies may affect the full functioning of some of the services and the quality of the usage experience.
5. Sharing Information with Third Parties
We respect your privacy and take care not to transfer identifying personal information about you to third parties, except in the cases detailed in this policy or in accordance with the provisions of the law.
Technology service providers:
We do not sell, rent or trade your personal data with advertisers or third parties that are not connected to the provision of the Service.
Community content exposed to other users: it is clarified that content you choose to publish in the user community (including recipes, photos, comments and display name) will be visible to other users on the Service in accordance with the privacy settings you choose. Please take care not to include in this content sensitive personal information that you do not wish to be exposed to others.
The Company takes care not to transfer identifying personal information about you to third parties, except where one or more of the following cases applies:
- Google Gemini API: food photos uploaded to the Service are transferred to Google's Gemini API for the purpose of visual analysis and identification of nutritional values. We do not share additional identifying personal information with this service beyond what is required for the analysis.
- Open Food Facts API: barcodes of food products are transferred to the Open Food Facts API for the purpose of obtaining nutritional information. No identifying personal information is transferred through this service.
- Infrastructure and cloud services: user data is stored on secure cloud infrastructure and leading infrastructure providers, who are subject to confidentiality and data security commitments.
- Upon request or with your explicit consent, or upon registration for a particular service that may require it.
- In the event of a legal dispute between you and the Company that requires the disclosure of your details, or if you perform actions contrary to the law, or in the event that a judicial order is received directing this.
- For the purpose of conducting statistical analyses and transferring statistical or other information to third parties, in a manner that does not allow your personal identification.
- In the event that you breach one or more of the terms of the Service or perform actions contrary to the terms of use or to the provision of any law, or upon the demand of a competent authority under the law.
- In any case where the Company believes that disclosure of the information is necessary in order to prevent serious harm to a person's property or body.
- In the event that the Company is sold, transfers or merges its operations with another corporation, provided that the new recipient of the information assumes the provisions of this policy in full.
6. Storage and Security of the Information
The security of your information is a top priority for us. We employ advanced security measures in accordance with the provisions of the Protection of Privacy Regulations (Data Security), 5777-2017:
Despite our efforts to secure the information, it is clarified that absolute immunity against unauthorized intrusion cannot be guaranteed, and that use of the Service is at the user's sole responsibility.
- Secure storage: all personal information is kept in a secure MongoDB database, with advanced security measures, including data Encryption at Rest and encryption in transit (TLS).
- Application-level encryption: sensitive information, such as access tokens and keys, is encrypted at the application level before being stored in the database.
- Access controls: we implement role-based access control (RBAC) so that only authorized staff members can access the data, in accordance with their role and on a need-to-know basis.
- Backups: we perform periodic backups in order to prevent data loss and ensure service continuity.
- Monitoring and enforcement: we conduct ongoing monitoring, action logging, risk surveys and periodic penetration testing, in order to detect and prevent unauthorized access attempts.
7. Photo Retention Policy
For the purpose of managing storage and maintaining Service performance, food photos uploaded to the application are stored on our servers for a period of up to 14 days. Photos older than 14 days may be automatically deleted from our servers and will no longer be accessible. The nutritional data derived from the photos (such as the list of ingredients and nutritional values) will be retained in your food log even after the photo is deleted.
We recommend that users save locally any significant photo, in case you wish to keep it for the long term.
8. User Rights and Control Over Information
In accordance with the provisions of the Protection of Privacy Law, you have the following rights with respect to your personal information:
In order to exercise these rights, you may contact us at the email address appearing at the end of this policy.
- Right of access: you, or someone on your behalf or your authorized representative, may review the information about you held in the Company's database.
- Correction of information: if the information about you is not correct, complete, clear or up to date, you may contact us with a request to correct or delete it.
- Direct access and editing: you can view and edit your personal data at any time through the application settings.
- Account deletion: you may delete your account and the personal information associated with it through the application settings. Upon deletion, all of your personal information will be removed from our systems immediately, except for information that we are required to retain by law.
- Removal from mailing list: you may remove yourself from the mailing list at any time using the removal link attached to each message, or by contacting us directly.
- Right to object: you have the right to object to the processing of personal information for direct marketing purposes, as well as the right to receive transparent information about the purposes of collecting the information and the identity of the controller of the database.
9. Information Retention Period
We retain your personal information only for the period necessary to fulfill the purposes for which it was collected, and in accordance with our obligations under the law. After the end of the period, the information will be deleted or undergo an anonymization process, unless there is a legal obligation or a legitimate interest in retaining it.
In the event that you choose to delete your account, your personal information will be deleted from the system immediately. However, certain information may be retained for a limited period of time for the purposes of action logging, backups, compliance with legal obligations and fraud prevention.
10. Direct Mailing and Marketing Communications
Subject to your consent, the Company may contact you from time to time by direct mailing for the purpose of receiving updates by email, text messages (SMS), push notifications or by telephone, in accordance with Section 30A of the Communications Law (Telecommunications and Broadcasting), 5742-1982. A user who has provided their details to the Service is automatically added to the mailing list and confirms receipt of marketing content, advertising information and updates from time to time.
The user may remove themselves from the mailing list at any time using a dedicated removal link found in each message, or by contacting in writing the email address detailed at the end of this policy. The Company undertakes to remove the user from the mailing list within a reasonable time from the date the request is received.
The content within the mailing should not be regarded as an undertaking or promise of any result, and the user's reliance on advertising content is at their sole responsibility.
11. Use of Information for Security, Fraud Prevention and Compliance with Legal Requirements
The Company shall be entitled to collect, process and make use of the information provided by users, including personal information, for the purpose of securing its systems, protecting against intrusion or harm attempts, preventing unauthorized use, acts of deception or fraud, and for the purpose of complying with any legal obligation, regulatory requirement or judicial order.
The Company shall be entitled to share such information with competent authorities or with relevant third parties, to the extent that this is required for the purpose of safeguarding the security of users, preventing unlawful activity or complying with the provisions of the law.
12. Use of Artificial Intelligence (AI) Technologies
The Service makes use of advanced artificial intelligence technologies, including Google Gemini services, in order to provide its users with value-added services, such as analyzing food photos, identifying ingredients, calculating nutritional values and generating personal insights.
Personal information provided by the user, including food photos, may be transferred to these AI services solely for the purpose of providing the requested services, and in accordance with the privacy policy of the relevant service providers. The Company does not use this data for training models or for any other purpose not directly related to providing the Service to the user.
13. Limitation of Liability
It is hereby agreed and declared that use of the Service, of the content and of the information contained therein is at the user's sole responsibility. The Company, its directors, employees, representatives and those acting on its behalf shall not bear any liability of any kind, including tortious, contractual or other liability, for any damage, loss, harm or expense, whether direct, indirect, consequential, special or derivative, that may be caused to the user or to any third party, directly or indirectly, due to or in connection with the use of the Service, including due to the provision of personal information, its processing or its storage, and this is so even if the Company foresaw or could have foreseen the possibility of the occurrence of such damages.
14. Data Protection Officer (DPO)
In accordance with the provisions of Amendment 13 to the Protection of Privacy Law, the Company acts in accordance with all obligations that apply to it and maintains internal mechanisms for safeguarding the privacy of data subjects. The Data Protection Officer is authorized to oversee the Company's compliance with the provisions of the law, to advise management, to develop training and oversight programs, to serve as a point of contact with the Privacy Protection Authority and to handle the inquiries of data subjects.
It is clarified that the law grants the courts the authority to award compensation without proof of damage of up to NIS 10,000 for certain violations of the law, and also allows the Privacy Protection Authority to impose significant financial sanctions. The Company acts to prevent any risk of violating the provisions of the law.
15. International Transfer of Information
The Service is intended for use within the State of Israel, and the information is processed and stored in accordance with the Israeli Protection of Privacy Regulations. In the event that data is transferred to cloud infrastructure outside Israel for the purposes of operating the Service, the transfer will be carried out in accordance with the provisions of the law and through providers that meet accepted data security requirements.
16. Privacy of Minors
The Service is intended for people aged 16 and over. The Company does not knowingly collect information from minors aged 16 and under. In the event that it comes to our attention that personal information of a minor under the age of 16 has been collected, we will take immediate steps to delete the information from our systems.
Users aged 16 to 18 are required to obtain the consent of a parent or legal guardian prior to using the Service and providing personal details.
17. Changes to This Privacy Policy
The Company reserves the right to update this policy from time to time, including due to technological, business or regulatory changes. Any material change will be published on the Service, noting the date of the last update. Continued use of the Service after the policy is updated shall constitute consent to the updated version.
18. Governing Law and Jurisdiction
This Privacy Policy shall be governed solely by the laws of the State of Israel, which shall determine the interpretation and enforcement of the terms contained therein. Any dispute, claim or lawsuit that may arise between the user and the Company in connection with the use of the Service or with the provisions of this policy shall be heard and decided in the competent courts in the city of Tel Aviv-Yafo only, which shall have exclusive and sole jurisdiction over this matter.
The user may not assign or transfer their rights or obligations under this policy to any other party. The Company, on the other hand, may transfer its rights and obligations to third parties. Nothing in the provisions of this policy shall derogate from any right granted to the Company or to anyone on its behalf under any law, and it reserves to itself the full rights vested in it.
Contact Us
For any question, inquiry, request to exercise rights or report of a suspected violation of privacy, you may contact us via:
Email:
