EatCam 卡路里相机 · 隐私政策
一句话版本
默认情况下,你的饮食日记和身体档案只存在你的手机里。餐食照片上传仅用于识别、识别完成后立即删除。仅当你开启「历史记录保存」(Pro 权益)时,记录与照片才会保存到你的订阅名下,并可随时清除。我们不出售任何数据。
生效日期与适用范围
生效日期:2026 年 9 月 24 日。本政策适用于 EatCam(卡路里相机)移动应用、官网 whaloom.com/eatcam 及其关联服务。首次使用前请阅读本政策。继续使用即表示你已知悉并同意本政策所述的处理方式。
数据控制者
EatCam 由个人开发者运营(以下称「我们」),Whaloom(忽然鲸)为本应用的发布品牌。就本政策项下个人信息处理相关的任何问题、请求或投诉,可通过 support@whaloom.com 与我们联系。
我们处理哪些信息,为什么
- 餐食照片:为完成 AI 菜品识别而上传至服务器,识别完成后立即删除,不用于模型训练。仅当你主动开启「照片云备份」(可选,默认关闭)时,照片才会加密存储于云端,详见下节。处理依据:履行服务所必需 / 你的同意。
- 匿名设备标识符:首次启动时随机生成的 UUID,用于统计每日免费识别次数、防滥用、统计识别成功率(记录每次识别请求的时间与结果,不含照片),以及下文所述的匿名使用统计;它无法关联你的真实身份。处理依据:正当利益(服务运营、防滥用与改进产品)。
- 身体档案与饮食记录:身高、体重、目标及每餐记录默认仅存储在你的设备本地。仅当你开启「历史记录保存」(可选,Pro 权益)后,这些记录会保存到我们的服务器,供你在新设备上取回;关闭即停止保存。处理依据:你的同意。
- 订阅标识:本应用不设账号。开启「历史记录保存」时,我们以 Apple App Store / Google Play 签发的匿名订阅交易标识作为你保存数据的主键——它不含姓名、邮箱或任何可识别你身份的信息,仅用于把同一订阅下的设备对应到同一份数据。处理依据:履行服务所必需。
- 健康数据(Apple 健康 / Health Connect):仅在你明确授权后,我们读取你的运动消耗(活动能量)用于在首页展示净热量收支,并写入你记录的餐食营养(热量、蛋白质、碳水、脂肪)和体重。健康数据只在你的设备与系统健康应用之间流转,不会上传至我们的服务器,不用于广告或任何其他目的。你可随时在系统设置(iOS:设置 → 健康 → 数据访问与设备;Android:Health Connect → 应用权限)撤销授权。处理依据:你的同意。
- 条码扫描:扫描包装食品条码时,条码号经我们的服务器向开放食品数据库 Open Food Facts 查询营养信息,不附带任何个人信息。若你为未收录的商品拍摄营养成分表或手动填写整包量,识别出的营养数值与整包量会以匿名形式汇入商品库供其他用户查询(不含照片、不含任何身份信息)。处理依据:正当利益(完善公共商品数据)。
- 匿名使用统计:App 会记录少量使用事件并连同匿名设备标识发送给我们:首次打开、打开订阅页(及从哪个入口打开)、点击订阅或免费试用按钮、购买结果(成功、取消或失败)。每条事件附带时间、App 版本、系统平台、系统语言/地区和时区。我们用它了解整体上有多少人安装、试用和订阅,以改进产品;其中不含照片、饮食记录或健康数据,不用于广告,也不与第三方共享。处理依据:正当利益(了解与改进产品)。
- 安装来源(仅 Android):首次打开时,App 会读取 Google Play 提供的安装来源信息——例如你是通过我们官网的哪个页面或推广链接、还是在 Google Play 内搜索下载的,点击与开始安装的时间,以及安装应用的商店——连同匿名设备标识发送给我们,其中不含你的个人信息。iOS 不提供此类信息,Apple 只向我们提供汇总、匿名的统计。处理依据:正当利益(了解用户如何找到本应用)。
- 订阅信息:付款由 Apple App Store / Google Play 处理,我们不接触你的支付方式或平台账号。我们会从 Apple / Google 获取与你的匿名交易标识对应的订阅状态:是否开始免费试用、续订、关闭自动续订、出现账单问题、到期或退款,以及对应的时间、方案、价格、币种、商店所在国家/地区和是否为测试购买。这些信息用于解锁功能,并与匿名设备标识和安装来源一起用于统计有多少人开始试用和订阅。处理依据:履行服务所必需 / 正当利益。
- 官网访问与下载按钮:访问 whaloom.com 时,服务器会保留标准访问日志(IP 地址、时间、访问页面、来源页面、浏览器类型)最长 14 天,用于安全防护和生成不含 IP 的汇总访问统计(例如多少访问来自搜索引擎)。点击官网下载按钮时,我们会在跳转到 App Store / Google Play 之前记录这次点击:哪个按钮和页面、来源网站、设备类型和浏览器语言。点击记录不保存 IP 地址,只保存一个无法还原的单向编码,用于统计当天的独立点击数;Google Play 按钮还会附带一个随机点击编号,App 首次打开时随安装来源一并回传,用于统计点击后有多少人完成安装。官网不使用 Cookie,也不接入第三方统计工具。处理依据:正当利益(了解哪些页面帮助用户找到本应用)。
- 应用商店汇总统计:Apple 与 Google 会向我们提供汇总、匿名的统计数据(例如商店页浏览量、下载量及其来源类型),其中不含任何可识别个人的信息。
- 我们不集成任何第三方广告、统计或跨应用追踪 SDK,上述统计均由我们自己的服务器完成;不收集姓名、电话、通讯录或精确位置。
照片的完整生命周期
默认情况:照片经 TLS 加密传输至我们的服务器,仅在内存中用于本次识别,不写入持久存储。识别产生的文字结果(菜名与营养估算)返回你的设备后,服务器侧的照片数据即被丢弃。
开启「历史记录保存」后(可选,默认关闭,Pro 权益):餐食照片会加密传输并存储于阿里云对象存储(OSS),仅用于在你的设备间恢复照片,不用于识别之外的任何目的、不用于模型训练。你可以随时关闭备份。在 App 内删除某条记录会同步删除对应的云端照片;在设置中「清除已保存的记录」会删除全部云端照片。保存在你手机相册或 App 内的照片副本始终由你自己控制。
存储、保留与删除
饮食记录与身体档案保存在设备本地数据库中:你可以在 App 内逐条删除,卸载 App 将清除全部本地数据(如启用系统云备份——iOS 的 iCloud 或 Android 的 Google 备份——备份副本受相应平台条款约束)。若你开启了「历史记录保存」,云端保存你的记录快照与照片,用于在新设备上取回。在 App 内删除记录会同步更新云端;你可以在 App 内直接清除(设置 → 历史记录保存 → 清除已保存的记录),全部云端数据将即时删除,关闭开关则停止保存。也可联系 support@whaloom.com 申请,我们将在 30 天内完成。服务器侧另保留以匿名设备标识关联的用量计数、识别记录、使用事件、安装来源和下载按钮点击记录,保留期不超过 12 个月;订阅状态记录在订阅存续期间及其后不超过 12 个月内保留;官网访问日志保留不超过 14 天。不含 IP 地址或设备标识的汇总统计可长期保留。
第三方处理者
为提供服务,我们使用以下处理者:阿里云(AI 视觉模型推理,以及云同步与照片备份的服务器与对象存储,均依其数据处理协议处理),Open Food Facts(条码商品营养数据的公开查询),以及你下载本应用的分发平台(Apple App Store / Google Play,负责应用分发与订阅支付)。我们不出售个人信息,也不与任何第三方共享个人信息用于广告目的。
你的权利
你可随时在 App 内查看、更正或删除自己的数据。依据你所在地法律(包括欧盟/英国 GDPR、加州 CCPA/CPRA 等),你可能还享有访问、可携带、限制处理、反对处理及投诉监管机构的权利。行使权利请联系 support@whaloom.com,我们将在法定期限内响应。由于我们不持有可识别你身份的数据,部分请求可能仅能对设备本地数据由你自行完成。
未成年人
本服务不面向 13 周岁以下(或你所在地规定的同等最低年龄)的儿童。我们不会有意收集儿童个人信息。如你认为儿童在未经监护同意的情况下使用了本服务,请联系我们处理。
政策变更与联系方式
本政策可能不时更新:重大变更将在 App 内显著提示,继续使用即视为接受更新后的版本。历史版本与完整文本见 whaloom.com/eatcam/privacy。联系方式:support@whaloom.com(Whaloom / 忽然鲸)。本政策以英文版本为准,中文文本为方便阅读提供。
EatCam · Privacy Policy
TL;DR
By default your food diary and body profile stay on your phone, and meal photos are deleted immediately after recognition. Only if you turn on "Save history" (a Pro feature) are your log and photos kept under your subscription — and you can clear them at any time. We never sell data.
Effective date & scope
Effective 24 September 2026. This Policy applies to the EatCam mobile application, its website whaloom.com/eatcam, and related services. Please read it before first use; continued use signifies that you understand and accept the practices described here.
Who we are
EatCam is operated by an individual developer ("we", "us"); Whaloom is the brand under which the app is published. For any question, request or complaint regarding the processing of personal data under this Policy, contact support@whaloom.com.
What we process, and why
- Meal photos: uploaded to our server to perform AI dish recognition and deleted immediately afterwards — never used for model training. Only if you actively enable "Photo cloud backup" (optional, off by default) are photos stored encrypted in the cloud, as described below. Basis: necessity to perform the service / your consent.
- Anonymous device identifier: a random UUID generated at first launch, used to meter the daily free quota, prevent abuse, measure recognition success (the time and outcome of each recognition request, never the photo), and produce the anonymous usage statistics described below; it cannot identify you. Basis: legitimate interest (operations, abuse prevention and improving the product).
- Body profile & food diary: height, weight, goals and meal records are stored on your device by default. Only if you turn on "Save history" (optional, a Pro feature) are they stored on our servers so you can restore them on a new device; turning it off stops saving. Basis: your consent.
- Subscription identifier: the app has no accounts. When "Save history" is on, we use the anonymous subscription transaction identifier issued by the Apple App Store / Google Play as the key for your saved data — it contains no name, email or anything that identifies you, and serves only to map devices under the same subscription to the same data. Basis: necessity to perform the service.
- Health data (Apple Health / Health Connect): only after your explicit authorization, we read your active energy burned to show a net calorie balance on the home screen, and write the nutrition of meals you log (calories, protein, carbs, fat) and your body weight. Health data moves only between your device and the system health app; it is never uploaded to our servers and never used for advertising or any other purpose. You can revoke access at any time in system settings (iOS: Settings → Health → Data Access & Devices; Android: Health Connect → App permissions). Basis: your consent.
- Barcode scanning: when you scan a packaged food, the barcode number is looked up through our server in the open database Open Food Facts, with no personal information attached. If you photograph the nutrition label of an unlisted product or enter its package size manually, the recognized nutrition values and package size are added anonymously to the product library for other users (no photo, no identifying information). Basis: legitimate interest (improving public product data).
- Anonymous usage statistics: the app records a small set of events and sends them with the anonymous device identifier: first launch, opening the subscription page (and from where), tapping the subscribe or free-trial button, and the outcome of a purchase (completed, cancelled or failed). Each event carries its time, app version, platform, system language/region and time zone. We use them to understand, in aggregate, how many people install, try and subscribe, so we can improve the product. They never contain photos, food logs or health data, are not used for advertising and are not shared with third parties. Basis: legitimate interest (understanding and improving the product).
- Install source (Android only): on first launch the app reads the install information provided by Google Play — for example which page or link on our website, or a search in Google Play, led to the download, when the link was tapped and the install began, and which store installed the app — and sends it with the anonymous device identifier. It contains no personal information. iOS provides no such information; Apple gives us only aggregated, anonymous statistics. Basis: legitimate interest (understanding how people find the app).
- Subscriptions: payment is handled by Apple App Store / Google Play; we never see your payment details or platform account. For your anonymous transaction identifier, Apple and Google give us the subscription status — whether a free trial started, renewed, auto-renew was turned off, a billing issue occurred, it expired or was refunded — with the time, plan, price, currency, store country/region and whether it was a test purchase. We use this to unlock features and, together with the anonymous device identifier and install source, to count how many people start a trial and subscribe. Basis: necessity to perform the service / legitimate interest.
- Website visits and download buttons: when you visit whaloom.com our web server keeps standard access logs (IP address, time, page, referring page, browser type) for up to 14 days, for security and to produce aggregate visit statistics that contain no IP addresses (for example, how many visits came from search engines). When you tap a download button we record the click — which button and page, the referring site, device type and browser language — before sending you to the App Store or Google Play. Click records do not store your IP address, only a one-way code that cannot be reversed, used to count unique clicks per day. Google Play buttons also carry a random click reference that the app returns with its install source on first launch, so we can count how many clicks led to an install. The website uses no cookies and no third-party analytics. Basis: legitimate interest (understanding which pages help people find the app).
- Aggregated store statistics: Apple and Google provide us with aggregated, anonymous statistics (such as store page views and downloads by type of source); they contain no information that identifies you.
- We integrate no third-party advertising, analytics or cross-app tracking SDKs — the statistics above are produced by our own servers — and collect no name, phone number, contacts or precise location.
Photo lifecycle
By default: photos travel over TLS, are processed in memory for the single recognition request, and are never written to persistent storage. Once the textual result (dish names and nutrition estimates) is returned to your device, the server-side photo data is discarded.
With "Save history" enabled (optional, off by default, a Pro feature): meal photos are transferred encrypted and stored in Alibaba Cloud Object Storage (OSS), used solely to restore your photos across your devices — never for anything else, never for model training. You can turn backup off at any time; deleting an entry in-app also deletes its cloud photo, and "Clear saved history" in Settings erases all cloud photos. Copies in your camera roll or inside the app remain under your control.
Storage, retention & deletion
Diary and profile data live in a local database on your device: you may delete entries individually in-app, and uninstalling the app removes all local data (system cloud backups, if enabled — iCloud on iOS or Google Backup on Android — are governed by the respective platform's terms). If "Save history" is on, the cloud holds your diary snapshot and photos so you can restore them on a new device; deleting entries in-app updates the cloud accordingly, and you can clear everything directly in-app (Settings → Save history → Clear saved history) — all cloud data is erased immediately; turning the switch off stops saving. You may also email support@whaloom.com and we complete deletion within 30 days. Server-side we additionally retain usage counters, recognition records, usage events, install source and download-click records keyed by the anonymous device identifier for no longer than 12 months; subscription status records for the life of the subscription plus no longer than 12 months; and website access logs for no longer than 14 days. Aggregated statistics that contain no IP address or device identifier may be kept indefinitely.
Third-party processors
We rely on: Alibaba Cloud (AI vision model inference, plus the servers and object storage behind cloud sync and photo backup, all under its data-processing agreement), Open Food Facts (public lookup of barcode nutrition data), and the distribution platform you obtained the app from (Apple App Store / Google Play — app distribution and subscription billing). We do not sell personal information, nor share it with any third party for advertising purposes.
Your rights
You can view, correct or delete your data in-app at any time. Depending on where you live (including under EU/UK GDPR and California CCPA/CPRA), you may also have rights of access, portability, restriction, objection, and to lodge a complaint with a supervisory authority. To exercise them, contact support@whaloom.com; we will respond within statutory deadlines. Because we hold no data that identifies you, some requests may only be completable by you on your own device.
Children
The service is not directed to children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect children's personal information; if you believe a child has used the service without guardian consent, please contact us.
Changes & contact
We may update this Policy from time to time; material changes will be prominently announced in-app, and continued use constitutes acceptance. The full and historical text is available at whaloom.com/eatcam/privacy. Contact: support@whaloom.com (Whaloom). The English version of this Policy is authoritative.