Effective Date: August 26, 2026
Welcome to KaloCam, provided by FUNCONNECT PTE. LTD., a company incorporated in Singapore ("we", "us", or "our").
This Privacy Policy ("Policy") is to clearly explain how we collect, use, disclose, and protect your personal information, as well as the rights you have and to help you make appropriate choices. Your privacy matters to us, please do take the time to get to know and familiarize yourself with the policy and practices. We have used bold font to distinguish the terms in this policy that are (possibly) significantly related to your rights and interests. Please read them carefully.
In particular, we would like to draw the attention of underage users (especially children under the age of 13) and their guardians. We have specified Section 7. Children on the protection of underage users, please read it carefully.
It is important to note that this Policy does not apply to any products, services, websites, or content that are offered by third parties ("Third Party Services"), which are governed by their respective privacy policies. We encourage you to read and review the privacy statements of each Third-Party Service that you may choose to use.
We will follow the principles of what is rightful, legal and necessary to collect and use the personal information that you voluntarily provide to us, obtained by us from third parties and automatically collected during your use of our Platform and Services. If we want to process your personal information for other purposes not specified in this policy, or use the information we have collected for other purposes based on a particular purpose, we will notify you in a reasonable manner and seek your consent (when required by applicable data protection laws) again before using it.
Please note that some of the above-mentioned information alone cannot be used to identify a specific natural person, thus cannot be considered as Personal Information. Only when such non-personal information is used in combination with other information to identify a specific natural person, or when it is used in combination with Personal Information, will this information be regarded as Personal Information during such combination. In this case, we will anonymize and de-identify this type of information, unless with your consent or otherwise according to laws and regulations. The above-mentioned information is essential to the provision of the Service. If you choose not to provide them, we may not be able to provide you with our related services.
Apple Health and HealthKit data are optional. KaloCam may read steps, walking and running distance, active energy, workouts, and weight records from Apple Health only after you grant permission.
In this review build, Apple Health data is used only for activity history, weight trends, logged workouts, and the Today, Activities, and Weight views. Apple Health activity energy does not increase today's eating target. Weight records you choose to sync may update profile weight and may be used to recalculate BMR, TDEE, daily target, and macro targets.
KaloCam does not use Apple Health data for advertising, marketing, sale, use-based data mining, or training KaloCam or third-party AI models. Raw Apple Health records and samples are not included in third-party AI prompts in this review build.
You can manage Apple Health permissions in Apple Health or iOS privacy settings. If a future version uses raw Apple Health records or samples inside AI features, we will update this policy, consent copy, review notes, and code-level data filters to match that behavior before doing so.
We store your information as long as necessary to provide the services, fulfill the purposes outlined in this policy and other legitimate business purposes (such as service improvement, resolving disputes, safety or security), comply with legal obligations.
Retention periods vary based on factors such as information type, sensitivity, and legal requirements. For example, account, input, and payment information are retained while your account is active. Violation-related information is retained until the violation is resolved. Also, in some cases, the length of time we retain data depends on your settings.
Anti-abuse records. To prevent abuse of the sign-up service, such as automated bulk registrations, we retain a keyed, pseudonymized identifier derived from the network address used at registration for up to 30 days. This security record remains until that period ends even if you delete your account and does not directly identify you.
GLP-1 records. Structured GLP-1 settings, personalization markers, and the onboarding analytics event are generally retained while your account is active, until you change or delete them. Short-lived deletion receipts and hashed settings-mutation records are retained for up to 30 days to make deletion and settings requests idempotent and auditable. Account deletion removes these first-party GLP-1 records and ledgers.
Your personal information may be transferred to and stored on servers located outside your country of residence. We store the information we collect in secure servers. By accepting this Privacy Policy, you consent to the transfer of your personal information to third parties (if any), which may include the cross-border transfer of your information to any country where we have databases or affiliates.
When cross-border transfers are necessary, we will implement appropriate safeguards, consistent with applicable data protection laws, to ensure your information is protected for the purposes outlined in this policy.
However, we need to remind you that no method of transmission over the Internet, or method of electronic storage, is 100% secure. While we strive to use commercially acceptable means to protect your Personal Information, we cannot guarantee its absolute security.
We use your information to provide, maintain, improve and develop the services, including for the following purposes:
When sharing, transferring, and disclosing your Personal Information, we uphold the principles and requirements of minimization, necessity, and legality. We do not sell any personal information to third parties. Under normal circumstances, we do not share, transfer or disclose your Personal Information externally. However, to the extent permitted by applicable laws and regulations, we may share, transfer and disclose your Personal Information in the following situations:
You have the rights to access, rectify or update, transfer, delete your personal information as well as restrict how we process, withdraw your consent, lodge complaints before the competent authorities and potentially others.
You can exercise some of these rights directly through settings or through your account if you have logged in. Additionally, your device may offer settings that allow you to manage the information we collect.
GLP-1 choices. In Settings, you can update your GLP-1 status, stop GLP-1 personalization without deleting your status, or use the separate “Delete GLP-1 Data” action. Stopping personalization stops new target adjustments and new GLP-1 context sharing but retains your status and existing records. Deleting GLP-1 data removes the five structured GLP-1 account fields, GLP-1 fields from the frozen onboarding draft, the GLP-1 onboarding analytics event, GLP-1 adjustment markers in daily target snapshots, and GLP-1 alert records. It does not mean that every related historical trace is erased.
After “Delete GLP-1 Data,” six categories remain: (1) a deletion receipt containing the request identifier and time for up to 30 days; (2) a general settings-mutation record containing a hash and version, but not the setting value, for up to 30 days; (3) the general monotonically increasing settings-state version; (4) free text in Coach memories or conversation history that cannot be reliably identified as medication-related—you can delete Coach memories separately or delete your account; (5) historical daily protein, fat, and carbohydrate target numbers, while their GLP-1 adjustment markers are removed, because those numbers form part of your nutrition history; and (6) historical processing or inferences already completed by a third-party AI provider, which cannot be recalled. Non-GLP fields in your frozen onboarding snapshot also remain. Use account deletion if you want the broader deletion available for your account.
If you choose to cancel your account, this action is permanent and irreversible. You will lose access to any associated content or services, and we may not be able to restore data after deletion. We recommend exporting or saving any personal data or content before initiating account deletion.
When you delete your account, your email address and hashed password are deleted with your other account data, except for the hashed anti-abuse record described in Section 2, which is retained for up to 30 days for security purposes.
Please note that the services generate responses by analyzing a user's request and predicting the words that are most likely to follow. However, the most probable words may not always be factually accurate. As a result, you should not assume that the output from our services is factually correct. If you find that the output contains inaccurate information about you and you wish to request a correction or removal of that information, please contact us.
We are fully aware that the security and confidentiality of your personal information are of utmost importance to you. We will endeavor to avoid collecting irrelevant user information and will take reasonable technical and organizational measures to protect your personal information from unauthorized access, public disclosure, use, modification, damage, or loss, including but not limited to:
Please note that due to the limitations of technical and management means, we cannot guarantee absolute security. We strongly recommend that you take proactive security measures, such as refusing to lend accounts, disclose verification codes, or upload sensitive information.
We have developed a cybersecurity incident emergency response plan. In the unfortunate event of a personal information leak or other security incidents, we will immediately activate the emergency response plan and promptly inform you of the basic situation of the security incident, the potential impact, and the remedial measures we have taken.
Our Services are not directed to, or intended for, children under the age of 13 (or the minimum age required in your jurisdiction to provide valid consent to data processing). We do not knowingly collect personal information from children under this age. If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at wangwei01@funconnectsg.com. We will promptly review and, where appropriate, delete such information in accordance with applicable laws.
If you are at least 13 but under 18 years of age (or the age of majority in your jurisdiction), you must review this Privacy Policy with your parent or legal guardian. Your parent or guardian must consent to your use of the Services before you may use them.
We encourage parents and guardians to take an active role in their children's online activities and to help enforce this policy by instructing minors never to provide personal information without their permission.
We do our best to comply with data protection laws and regulations worldwide to protect users' personal data. At the same time, we are constantly updating our data protection work to ensure compliance with legislative requirements in various jurisdictions. Please give us feedback if there is any need for improvement or adaptation regarding our data protection you find in your daily use.
We may update this policy from time to time as required. When we do, we will publish an updated version and effective date on this page, or by providing any other notice required by applicable law. We recommend that you review the updated policy each time you access the services to stay informed of our privacy practices.
If you have any questions, suggestions, or concerns about this Privacy Policy or our data practices, or if you wish to exercise your rights regarding your personal information, you can contact us through the following methods:
We will review and respond to all requests or complaints in accordance with applicable data protection laws. Please note that for security and verification purposes, we may request additional information to confirm your identity before processing your request.
This Privacy Policy may be provided in multiple languages. In the event of any conflict, where permitted under local law, the English language version of this Privacy Policy shall prevail.
© 2026 FUNCONNECT PTE. LTD. All rights reserved.