Skip to content

Caldito

Privacy Policy — Effective June 2, 2026

🔒 Local-first · Optional sync in your own Drive

Caldito (“the App”, “we”, “us”) is a family logging and organization tool for symptoms, medication, and care, developed as a sole-developer project under Torhen. Contact: contactodhts@gmail.com.

1. Who We Are

  • Developer: Torhen (independent developer).
  • Data Controller: Torhen, acting as data controller under GDPR for the purposes of providing the App.
  • Contact: contactodhts@gmail.com.

2. What Data We Handle — and Where It Stays

Caldito follows a local-first model: all records you enter (symptoms, fever, medication, family profiles, photos) are stored primarily on the device where you use the App. There are two optional exceptions that only activate if you choose to:

  1. Google Sign-In (optional): if you connect your account, the App automatically backs up your data to your own Google Drive via Android Auto Backup. We don't access that backup. Android Auto Backup retains backups for up to 57 days after uninstall, after which Google deletes them automatically.
  2. Shared family (premium, optional): if you purchase a premium plan and share the family with other people, the shared data travels to Google Firestore under our Firebase project account, associated with your Google ID (UID), so the other members can see it.

The categories of data we may process:

  • Identity data: Google account email, public display name, profile photo URL, Google UID — only if you sign in.
  • Health-related data: family-member profiles (name, birthdate, allergies, chronic conditions, blood type, weight), symptoms, fever readings, medication administrations, illness episodes, free-text notes you write.
  • Photos: photos you attach to records live only on the device where they were added. They are never synced, never shared with your shared family, and never uploaded to our servers.
  • Technical data: for Firestore sync, Google logs the IP address of each request for security and rate-limiting purposes. We do not retain or analyze these IP logs ourselves.
  • Subscription data: if you purchase premium, RevenueCat processes your Google UID and subscription state (active, expired, refunded) to validate premium across devices.

3. Data We Do NOT Collect

  • We do not collect location.
  • We do not access your contacts.
  • We do not collect browsing or app history.
  • We do not use advertising with personal data.
  • We do not sell data to third parties or data brokers.
  • We do not use analytics SDKs (Firebase Analytics, Google Analytics, Mixpanel, etc.) in the App.
  • We do not use crash reporting tools (Crashlytics, Sentry, etc.) that send your data outside the App.
  • We do not perform automated decision-making or profiling that produces legal or similarly significant effects on you (GDPR Article 22). The App does not score, rank, or evaluate you.
  • We do not use cookies in the traditional web sense. Firebase uses authentication tokens stored locally on the device to keep you signed in; these are not transmitted to us as cookies.

4. Third-Party Services

The third parties integrated into Caldito are all infrastructure, not marketing. Each is governed by its own policy:

  • Google Firebase (Authentication + Firestore) — only if you sign in. Processes email, public name, profile photo, and synced data. Google's policy.
  • Google Drive — only if you sign in. Automatic backup of the local database to your own Drive via Android Auto Backup. Google's policy.
  • RevenueCat — only when purchasing a premium plan or the Founding Lifetime. Processes the user ID and the state of your subscription to validate premium across devices. RevenueCat's policy.
  • Google Play Billing — only when purchasing. Processes the payment directly with Google. We never receive your card data. Google Play policy.

5. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area, United Kingdom, or another jurisdiction with similar laws, we rely on the following legal bases:

  • Consent — for optional Google Sign-In and optional premium purchase. You give consent by signing in or by completing a purchase, and you can withdraw it at any time by signing out or canceling your subscription.
  • Performance of a contract — for delivering the premium services you purchased (Couple, Family, or Founding Lifetime), including syncing data with invited members.
  • Legitimate interest — for keeping your data secure (Firestore security rules, IP-based rate limiting) and preventing fraud or abuse of the invitation system (30-day cooldown).
  • Legal obligation — for complying with applicable laws, including tax reporting on premium revenue.

6. International Data Transfers

The third-party infrastructure we rely on (Google Firebase, Google Drive, RevenueCat) is operated by US-based providers. As a result, data you sync may be transferred to and processed in the United States or other countries where these providers operate data centers, including locations outside your country of residence.

These providers are subject to international data transfer frameworks (EU–US Data Privacy Framework, Standard Contractual Clauses) that ensure an adequate level of protection for personal data of users in the European Economic Area and similar jurisdictions. We do not transfer your data ourselves outside of these providers.

7. Data Retention

We keep your data only for as long as needed to provide the App and for the periods required by applicable law:

  • Local data on your device: retained until you uninstall the App or use the in-app delete options.
  • Google Drive auto-backup: retained by Google for up to 57 days after uninstall, then deleted automatically.
  • Firestore (shared family): retained while you are an active member of a family. When you leave a family or are removed by the owner, your synced records associated with your UID are removed from the server within 30 days.
  • Subscription state in RevenueCat: retained while your premium is active and for up to 5 years after the last subscription event, for accounting and refund-dispute purposes.
  • Support emails: retained for up to 3 years after the last contact, for follow-up and dispute resolution.

8. Shared Family (Premium)

If you purchase a premium plan and invite other people, the synced data is visible to invited members with limited permissions:

  • The owner (who purchased) has full control: invite, remove, edit medical profiles, and close episodes.
  • Guests can log and add members, but CANNOT delete others' records, edit medical profiles, or close episodes.
  • 30-day anti-abuse cooldown: if the owner removes someone and wants to invite a different person, they must wait 30 days from removal. Re-inviting the same person is immediate.
  • When you leave a shared family (you exit or the owner removes you), your personal data in that family stays accessible only to remaining members; the others stop seeing you as a participant.

9. Health Data

Caldito processes health-related data (symptoms, fever, medication, clinical photos, medical profile with allergies and chronic conditions). This data:

  • Is stored on your device and, optionally, on your Drive and/or Firestore (shared family).
  • Is NOT used to train AI models.
  • Is NOT sold to insurers, labs, pharmacies, or any third party.
  • Is NOT used to profile users for advertising.
  • Is NOT shared with employers, schools, or government agencies except where strictly required by a binding legal order.

Caldito is not a medical device and does not provide diagnoses or medical advice. See the Terms of Service for details.

10. Age Requirement and Children's Privacy

Caldito is intended exclusively for users aged 18 and older. We do not knowingly collect personal information from children under 13 (or under 16 in the EU/UK, depending on the country). The App's initial disclaimer requires confirming you are of legal age. If you are a minor, do not use this App.

Parents and legal guardians may use Caldito to log the health of their minor children as family members, but the App account itself must belong to an adult. If you believe a minor has created an account or provided us with personal data without parental consent, contact contactodhts@gmail.com and we will delete that information promptly (COPPA compliance).

11. System Permissions

Caldito only requests the minimum permissions needed to function:

  • Camera / Photo access: optional, only if you choose to attach photos to a record. Photos live in the App's private storage.
  • Internet: required for Firestore sync and Google Sign-In. If you don't sign in, the App works offline.

We do not request contacts, location, microphone, or external storage.

12. Subscriptions and Payments

Premium plans (Couple, Family, Founding Lifetime) are processed exclusively via Google Play Billing with RevenueCat as a subscription-management intermediary. We will never ask for payment information within the App. If anyone does so outside of Google Play, it's fraud.

13. Data Deletion

You can delete your data at any time:

  • Local data: uninstalling the App erases everything that lives on the device.
  • In Firestore (shared family): when you leave a family, your synced data associated with your UID is removed from the server.
  • Full deletion: write to contactodhts@gmail.com from the email associated with your Google account, and we will remove any trace associated with that account within 30 days, subject to legal-retention exceptions (e.g., tax records for premium purchases).

14. Your Rights

Depending on where you live, you have the following rights regarding your personal data. You can exercise them by writing to contactodhts@gmail.com from the email associated with your Google account. We will respond within 30 days (or the period required by the law applicable to you).

If you are in the European Economic Area, United Kingdom, or Switzerland (GDPR / UK GDPR):

  • Right of access — to obtain a copy of your personal data we process.
  • Right to rectification — to correct inaccurate or incomplete data.
  • Right to erasure (“right to be forgotten”) — to ask us to delete your data.
  • Right to restriction of processing — to ask us to limit how we use your data.
  • Right to data portability — to receive your data in a structured, machine-readable format.
  • Right to object — to oppose processing based on legitimate interest.
  • Right not to be subject to automated decision-making — we do not perform such decisions, but the right exists.
  • Right to withdraw consent — at any time, without affecting prior lawful processing.

If you are a California resident (CCPA / CPRA):

  • Right to know what personal information we collect, use, and disclose.
  • Right to delete personal information we collected from you.
  • Right to correct inaccurate personal information.
  • Right to opt-out of sale or sharing — Caldito does not sell or share personal information for cross-context behavioral advertising, but you can confirm this status.
  • Right to limit use of sensitive personal information — we only use sensitive data (health data) for the purposes described in this policy.
  • Right to non-discrimination — exercising your rights will not result in reduced quality of service.

If you are in Brazil (LGPD):

  • Confirmation that we process your personal data; access to that data; correction; anonymization, blocking, or deletion; portability; deletion of data processed by consent; information about sharing with third parties; right to revoke consent.

Residents of other jurisdictions (Argentina LPDP, Chile Ley 19.628, Mexico LFPDPPP, etc.) may have similar rights. Write to us and we will honor them where applicable.

15. Data Controller and Processors

  • Data Controller: Torhen (the developer of Caldito) determines the purposes and means of processing your personal data.
  • Data Processors acting on our behalf under written agreements:
    • Google LLC — Firebase Authentication, Firestore, Drive Auto Backup, Play Billing.
    • RevenueCat, Inc. — subscription-state validation.

These processors only handle your data following our documented instructions and their own privacy programs.

16. Security and Logging

We apply the following security measures:

  • Encrypted communication (HTTPS/TLS) on all server calls.
  • Local storage in the App's private area, not accessible to other apps on your device.
  • Firestore security rules that limit who can read and modify which data (3-layer enforcement: rules + server-side validation + client-side checks).
  • Google Play App Signing to verify the integrity of installed builds.

Google logs IP addresses of API requests on Firebase / Firestore for security, abuse prevention, and rate limiting. We do not retain or analyze these logs ourselves; Google retains them per its own policies.

No system is 100% secure. If you find a security issue, please write to us at contactodhts@gmail.com with the details.

17. Right to Lodge a Complaint with a Supervisory Authority

If you believe we have violated your data-protection rights, you have the right to lodge a complaint with the supervisory authority of your country or region:

  • European Union: the data-protection authority of your country of residence. List at edpb.europa.eu.
  • United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk.
  • California, USA: California Privacy Protection Agency — cppa.ca.gov.
  • Brazil: Autoridade Nacional de Proteção de Dados (ANPD) — gov.br/anpd.
  • Chile: Consejo para la Transparencia — consejotransparencia.cl.

We encourage you to contact us first at contactodhts@gmail.com so we can try to resolve the issue directly.

18. Changes to This Policy

If we make material changes, we will update the “Effective” date at the top of the document and, when appropriate, notify within the App. Continued use after changes implies acceptance of the updated policy. Older versions are kept on request for reference.

19. Contact

For any privacy question, data deletion, exercise of your rights, or to raise a complaint:

Torhen
Email: contactodhts@gmail.com

© 2026 Torhen — Caldito — All rights reserved.