freecals

Privacy policy

Effective 7 October 2026.

This policy explains what Freecals keeps about you, why, who receives it, how long it is kept, and how you control it. It covers the website at freecals.com, the MCP server at mcp.freecals.com, and the Freecals plugin in AI apps.

Who is responsible

Andrew Pashynnyk publishes and runs Freecals as an individual from Ukraine. Andrew Pashynnyk is the controller of your personal data: the person who decides how it is used. Contact: support@freecals.com.

The short version

  • Freecals stores the food journal that you and your AI apps write: meals, nutrition, saved foods, weigh-ins, goals and notes.
  • Freecals is free. It has no ads, sells no data, and does not use your data to train AI models.
  • Freecals runs no AI model of its own. It has no access to your chat history, and it accepts no image uploads. It receives only what your AI app includes in a tool call, such as records, notes, source links and feedback, and what you enter on the website.
  • You can export your whole journal or delete your account at any time on your account page.

What Freecals collects

Your account

When you sign in with Google, Freecals receives and keeps:

  • your name, your email address, and whether Google verified the email address;
  • the address of your Google profile picture;
  • your Google account ID, and the sign-in tokens that Google issues to Freecals.

Freecals asks Google only for your basic profile and email. It cannot read your Gmail, contacts, files or calendar.

Your journal

Your AI app writes these records when you ask it to. You can also add meals on the website.

  • Food entries: the date, time and time zone of a meal; its name; each food with its serving, weight in grams, calories, protein, carbohydrates, fat, and fiber and sugars when known.
  • The AI app's notes on an entry or a saved food: a short explanation of its estimate, and the web addresses and titles of its sources, such as a nutrition database page.
  • Saved foods: foods you eat often, with their name, brand, serving and nutrition.
  • Weigh-ins: your weight, the date, time and time zone, and an optional short note.
  • Your profile: your time zone, weight unit, daily calorie and macronutrient goals, target weight, and free-text notes that tell your AI app how you want it to work.
  • Details that Freecals adds: an ID for each record, when it was created and last changed, totals and the calories left for the day, when you last ate a saved food, a website link to each day and meal, and, in overview answers, the current date and time. Freecals also keeps the request IDs that apps send and copies of recent writes, so that a repeated request does not write twice.

Freecals does not store photos. When you show your AI app a photo of a meal or a food label, the app reads it and sends Freecals the food names, the numbers and its notes.

Food intake and body weight are information about your health. Freecals stores them only to keep your journal, and only after you agree to it.

Your consent

Before you or an app can read or write your journal, Freecals asks you to agree that it stores your health information. Freecals keeps your account ID, the version of the text you agreed to, and when you agreed, until you delete your account.

Feedback that your AI app sends

Your AI app can send feedback to the Freecals developers: when you ask it to, or on its own when it finds a bug or a tool description it had to guess at. Freecals keeps:

  • its ID and date, the kind of feedback, a summary, details, your own words when you asked for the feedback, the tool it is about, and the IDs of the records it is about;
  • whether you or the app started it, and whether you asked for a reply;
  • the app's ID, its user agent, the ID of the request, and the version of Freecals that answered.

Your account page shows the newest 100 feedback items that your apps sent for you. Ask support for older ones. Feedback is for technical problems: describe them with record IDs, and leave out health details.

Apps you connect

  • When you connect an AI app, Freecals stores the app's name, website and the addresses it uses to sign in, the permissions you gave it, and when you gave them.
  • When you create an API key, Freecals stores its name, its permissions, the first characters of the key, and when it was last used. Freecals stores the key itself only in a scrambled form that cannot be turned back into the key.

Technical data

  • Sessions: when you sign in on the website, Freecals stores your IP address and your browser's user agent, which names your browser or app, with the session.
  • Request logs and traces: for each request, Freecals records the time, the full address requested, the result and its duration, your IP address, your country, the Cloudflare data center, your browser's user agent, and, when the request has them, your account ID, the app or API key ID, the sign-in method, the tool name and its outcome. When a request fails, the log also holds the error. Logs also hold request IDs and the version of Freecals that answered, and traces record the steps Freecals took to answer. Freecals does not routinely log the content of tool calls, but a full address or an error can contain words from a request, an email address, a token or a sign-in code.
  • Abuse protection: for sign-in requests, Freecals counts requests per IP address and sign-in endpoint to stop attacks.

Why Freecals uses your data

  • To run the journal for you: to store what you record, show it on the website, and give it to the AI apps you connect. If the law where you live asks for a legal basis, this basis is our contract with you, the terms of service.
  • To keep health data: Freecals stores food and weight records only after you give your explicit consent, before you or an app first reads or writes your journal. You withdraw it by deleting your account.
  • To keep Freecals secure and working: sessions, logs and request counts let Freecals sign you in, find errors and block attacks. This is our legitimate interest in a safe service.
  • To improve Freecals: the developers read the feedback that apps send, to fix bugs and unclear tools. This is our legitimate interest in a working service.
  • To answer you and keep you informed: Freecals uses your email address and messages to answer support requests, and to send important notices, such as a shutdown or a change to these terms. This is our legitimate interest in supporting you.

Freecals does not use your data for advertising, does not build profiles of you for anyone else, and does not sell or rent your data.

Who receives your data

  • The AI apps you connect. An app that you approve, such as ChatGPT, Claude or Codex, receives the journal records it asks for, within the permissions you gave it. If you give an app the permission to know who you are, it can also read your account ID, your email address and whether the email address is verified. When a request fails, the app receives an error that can repeat the input it sent and name the record involved. What the app does with that data is covered by its own privacy policy, such as OpenAI's or Anthropic's.
  • Cloudflare, which hosts Freecals: the website, the server, the database and the logs. Cloudflare's privacy policy.
  • Google, when you sign in with Google. Google's privacy policy.
  • The email provider of support@freecals.com, for support emails and important notices.
  • Authorities, only when the law requires it.

If Freecals ever moves to another publisher, we tell you before your data moves, and you can delete your account first.

Where your data is kept

The Freecals database is currently placed in Cloudflare's Eastern Europe region. This is not a promise that data is processed only in the EU. Cloudflare serves the website and the server from data centers around the world, so a request can be handled in a country other than yours. Cloudflare processes the data for Freecals under its data processing addendum, which includes the EU standard contractual clauses and, for the UK, the UK addendum. Andrew Pashynnyk runs Freecals from Ukraine and opens the data from there, for example to answer a support request or to fix an error.

How long Freecals keeps your data

  • Your journal: until you delete a record, or your account.
  • Your account, your consent and the feedback your apps sent: until you delete your account.
  • Website sessions: a session stops working 7 days after it was last renewed. Freecals renews it at most once a day while you use the website. Signing out deletes it at once. Freecals deletes an expired session when it next sees it, and always when you delete your account.
  • App access: an app's access token works for 7 days, and its refresh token for 90 days; each refresh starts a new period. Disconnecting the app deletes its tokens and your approval at once. Expiry only stops a token from working: its record stays until you disconnect the app or delete your account.
  • API keys: a key works until you delete it.
  • Sign-in codes: the short-lived codes of a sign-in stop working after 10 minutes, or 30 minutes for an app that shows a code. Freecals deletes expired codes during later sign-ins. A code an app asked for and never used can stay until the app asks about it again.
  • Request logs and traces: Cloudflare deletes them after 7 days.
  • Request counts for abuse protection: Freecals deletes counts older than 1 day whenever a new sign-in request starts a count.
  • Database backups: Cloudflare keeps a history of the database for 30 days. After you delete your account, your data stays in this history until the period ends. Freecals restores this history only to recover from a failure.
  • Support emails: 12 months after the last message in the conversation, unless the law requires earlier deletion.

Your controls

  • See and change your journal: ask your AI app to read, correct or delete any record. The website shows your journal and adds meals.
  • Export: your account page downloads your whole journal as a zip file of JSON files, which you can import again. The same page lists the feedback your apps sent. For a copy of everything else Freecals holds about you, write to support.
  • Disconnect apps: the connected apps page shows each app with its permissions. Disconnecting an app removes its access at once. You can delete API keys on the same page.
  • Delete your account: your account page deletes your account, your journal, the feedback your apps sent, your sessions, your connected apps and your API keys at once. Freecals has no way to recover a deleted account. Some data stays for a while, under the expiry and cleanup rules above: request logs, request counts, unused sign-in codes, the database history, and support emails. Copies that an AI app already received are under that app's control; ask the app to delete them.

Depending on where you live, you can also have the right to access, correct, move or delete your data, to object to or restrict how Freecals uses it, and to withdraw consent at any time. To use these rights, write to support@freecals.com. We answer without undue delay, normally within one month. You can also complain to the data protection authority where you live, or to the Ukrainian Parliament Commissioner for Human Rights.

Cookies

The website uses only the cookies it needs to sign you in:

  • a session cookie, which keeps you signed in for up to 7 days;
  • a short-lived cookie during Google sign-in, which protects the sign-in from forgery and expires after 5 minutes;
  • a short-lived cookie when an app signs you out, which confirms the sign-out and expires after 5 minutes.

Freecals uses no analytics, advertising or tracking cookies.

Security

  • All traffic to Freecals uses HTTPS: plain HTTP addresses redirect to HTTPS.
  • Freecals stores API keys and app tokens in a hashed form, which cannot be turned back into the key or the token. It encrypts the Google access and refresh tokens it keeps, and the saved replies that let an app retry a token refresh.
  • Each app gets only the permissions you approved, and you can disconnect it at any time.

No service is perfectly secure. If Freecals has a breach that puts your data at risk, we tell you and the authorities as the law requires.

Children

Freecals is not for children under 13. If you learn that a child under this age has an account, write to support@freecals.com, and we delete it.

Changes to this policy

We publish every change on this page and update the date at the top. If a change affects how Freecals uses data that it already holds, we tell you on the website and by email before the change applies. If a change needs your consent again, we ask for it before we use your data in the new way.