Lively Graphics, LLC ("Company," "we," "us," or "our") operates the Calimento iOS mobile application and the calimento.io website, including all related information, content, features, tools, and services (collectively, the "Services"). Calimento is a recipe management and meal planning application. All paid subscriptions are billed exclusively through Apple In-App Purchase; we operate no e-commerce store, sell no physical products, and never collect or store your payment card information. Our marketing website and these policy pages are hosted on Cloudflare, Inc., which serves solely as our website host and content delivery network.
This Privacy Policy describes how we collect, use, disclose, and safeguard your personal information when you use the Services or otherwise communicate with us. If there is a conflict between our Terms of Use and this Privacy Policy, this Privacy Policy controls with respect to the collection, processing, and disclosure of your personal information.
This Privacy Policy is designed to comply with applicable law, including but not limited to: Apple's App Store Review Guidelines, the Washington My Health MY Data Act (RCW 70.372), the Washington Consumer Protection Act (RCW 19.86), the California Consumer Privacy Act (CCPA/CPRA), and the federal Children's Online Privacy Protection Act (COPPA).
When we use the term "personal information," we are referring to information that identifies or can reasonably be linked to you or another person. We may collect or process the following categories of personal information depending on how you interact with the Services:
| Category | Examples |
|---|---|
| Contact details | Name and email address; phone number if you choose to provide it in correspondence with us |
| Account information | Username, password, security questions, preferences and settings |
| Payment information | We never collect or store your payment card details. All subscription payments are processed entirely by Apple through In-App Purchase. We receive only Apple transaction identifiers, subscription status, and purchase confirmations from Apple |
| User-Generated Content (UGC) | Recipe text and ingredients you type or import, cooking instructions, personal notes, comments, profile information, and photographs or images you upload (including images of recipe cards submitted to the AI Vision scanner) |
| Dietary, meal plan, and nutrition data | Saved recipes, meal plans, grocery lists, dietary preferences, food allergies, and health-related dietary restrictions you enter into the App, as well as nutrition information (such as calories and macronutrients) extracted from recipes you scan (see Section 4 for Washington MHMDA disclosures and Section 5 for AI processing) |
| Subscription status data | Whether your account is in the no-cost access period, active paid subscription, complimentary, lapsed, or trial-expired state; subscription and trial start and end dates; the date premium access lapsed or was transferred, if applicable; Apple In-App Purchase transaction identifiers; and any boolean flags our systems use to determine feature access entitlement |
| Lifecycle and engagement data | Account creation and last-update dates, the date you last opened the App, the number of recipes you have saved, and limited metadata for a single recipe (its title, image, and last-viewed date) used to personalize re-engagement email. This data is shared with our email provider as described in Section 5A |
| Communications with us | Information you include in customer support inquiries, feedback submissions, or other correspondence |
| Category | Examples |
|---|---|
| Device information | Device type, model, operating system version, browser type (website visits only), and IP address. The App does not access the Apple Identifier for Advertisers (IDFA) and does not track you across other companies' apps or websites |
| Usage information | How and when you interact with or navigate the Services, features accessed, search queries within the App, items added to meal plans or shopping lists. Screen views and interface interactions within the App are measured through our product-analytics provider, HeyCatch, as described in Section 5B |
| Subscription transaction information | Your subscription purchase, renewal, and cancellation history, as reported to us by Apple In-App Purchase |
| Website cookies | Session and preference cookies used on our marketing website at calimento.io, plus the analytics identifiers set by HeyCatch (see Sections 5B and 7). The iOS App itself does not use cookies (see Section 7) |
We may also receive personal information from the following sources:
Depending on how you interact with us or which Services you use, we may use your personal information for the following purposes:
We use your personal information to provide you with the Services, including to: perform our contract with you; verify your subscription status as reported by Apple In-App Purchase; remember your preferences; send account-related notifications; create and manage your account; enable recipe creation, meal planning, and grocery list features; and personalize your experience, such as recommending recipes related to your activity.
We send lifecycle, promotional, and product-update email about Calimento — including welcome and onboarding messages, re-engagement reminders, and win-back messages if your access lapses. These emails are delivered through our third-party email provider, Customer.io, as described in Section 5A. You may opt out of marketing email at any time as described in Section 12.4.
This is first-party marketing only. The App contains no advertising: we do not display ads in the App, do not use your data for third-party or cross-app targeted advertising, do not share your data with advertising networks or data brokers, and do not track you across other companies' apps or websites.
We use your personal information to authenticate your account, provide a secure experience, detect and investigate possible fraudulent or malicious activity, protect public safety, and secure our services. You are responsible for keeping your account credentials confidential.
We use your personal information to provide customer support, respond to inquiries, and maintain our business relationship with you.
We use your personal information to comply with applicable law, respond to valid legal process (including requests from law enforcement or government agencies), participate in civil discovery or litigation, and enforce or investigate potential violations of our terms or policies.
When you submit UGC to the App — including recipe text, ingredient lists, cooking instructions, photographs, and images of recipe cards — we process that content to provide the core functionality of the App (organizing your recipe collection, generating meal plans, and populating your grocery lists). Images you upload for the AI Vision scanner are transmitted to Anthropic for text extraction as described in Section 5. We do not use your UGC to train our own AI models without your separate, affirmative consent.
The App also allows you to generate a formatted PDF of your grocery list that includes your first name and a "Powered by Calimento.io" brand banner. The generation of this PDF is processed within the App and the resulting file is stored temporarily on your device. See Section 3.7 below for important disclosures about how sharing this PDF affects your personal information.
Calimento allows you to share your grocery list as a branded PDF document via the iOS Share Sheet. This feature enables you to send the PDF through any channel available on your iOS device, including but not limited to: AirDrop, Messages, Mail, Save to Files, and AirPrint. The PDF document includes your first name in the document title and the "Powered by Calimento.io" brand banner.
User-Initiated Sharing — Your Control and Responsibility: When you share a grocery list PDF via the iOS Share Sheet, you are making a voluntary, user-initiated decision to transfer that document — and the personal information it contains — to a channel, device, or recipient outside of Calimento's infrastructure. Once the PDF leaves the App via the Share Sheet, it is entirely outside the control of Lively Graphics, LLC. We cannot retrieve, delete, or control the subsequent handling of that document by its recipient(s), the recipient's device, or any intermediate service (such as an email provider or messaging platform).
No Transmission by Lively Graphics, LLC: The PDF sharing feature operates entirely through Apple's native iOS Share Sheet. Lively Graphics, LLC does not transmit, receive, copy, or store the shared PDF. We do not have visibility into which sharing channel you select, who you share the PDF with, or how the recipient handles the document. Your decision to share is between you and the destination channel.
Health Data Caution: If your grocery list includes items that could identify or be linked to a health condition — such as specialty dietary products, medical foods, or allergen-restricted items — that information will be present in the PDF you share. Please review the Washington My Health MY Data Act disclosures in Section 4 of this Policy and exercise caution when sharing PDFs containing health-related grocery items, as shared documents fall outside our ability to protect or delete.
Brand Disclaimer: The "Powered by Calimento.io" banner appearing on shared grocery list PDFs is a trademark attribution notice. Its presence on a shared document does not constitute any warranty, representation, or endorsement by Lively Graphics, LLC of the document's contents or of any use made of the document after sharing. Lively Graphics, LLC is not responsible for any use of shared PDFs by recipients.
Under the MHMDA, "consumer health data" is defined broadly to include personal information that is linked or reasonably linkable to a consumer and that identifies a consumer's past, present, or future physical or mental health status. In the context of Calimento, this may include:
We collect consumer health data that you voluntarily provide to us when you use the meal planning and dietary preference features of the App. We use this data solely to provide, personalize, and improve the App's functionality for you. We do not sell consumer health data to third parties, and we do not use consumer health data for advertising targeting purposes.
We share consumer health data only in the following limited circumstances, and only to the extent necessary for the stated purpose:
We do not sell, share for targeted advertising purposes, or otherwise disclose consumer health data to any other third party without your express, affirmative consent.
If you are a Washington State resident, you have the following rights with respect to your consumer health data:
To exercise any MHMDA rights, please contact us at admin@livelygraphics.com with the subject line "MHMDA Rights Request." We will respond within 45 days as required by law, with the possibility of a 45-day extension for complex requests.
Non-Discrimination: We will not discriminate against you for exercising your MHMDA rights. We will not deny you Services, charge different prices, or provide a different quality of service because you exercised your rights under this law.
Calimento includes an artificial intelligence feature called "AI Vision", which allows you to photograph or upload images of physical recipe cards, handwritten notes, cookbook pages, or other documents, as well as upload recipe PDFs. The AI Vision scanner uses machine learning optical character recognition (OCR) technology to extract and structure recipe content — including ingredients, measurements, preparation steps, and nutrition information (such as calories and macronutrients) where present — from your submitted images and documents.
Anthropic, PBC ("Anthropic") acts as a third-party service provider and sub-processor for our AI recipe scanning feature. We proxy your scan request to Anthropic's Claude API; Anthropic processes it on our behalf and returns the result to us. When you use the AI Vision recipe scanning feature, the following data processing occurs:
By using the AI Vision feature, you consent to this data transmission and processing. You should not submit images or documents containing sensitive personal information — such as medical records, government identification, financial account data, or other confidential information unrelated to recipes.
To review Anthropic's data and privacy practices: https://www.anthropic.com/legal/privacy
Calimento includes an automated grocery categorization feature that organizes the ingredients from your recipes into grocery-aisle categories (for example: Produce, Dairy, Meat, Pantry) when you generate a shopping list. This feature also uses Anthropic's Claude AI models.
When you use the grocery list or shopping list feature, the following data processing occurs:
The App may include additional AI-powered features such as personalized recipe recommendations, ingredient substitution suggestions, or nutritional estimates. These features may process your recipe collection data and usage patterns locally within the App or through additional third-party AI services. We will update this Privacy Policy and provide in-App notice before introducing new AI data processing activities that involve transmission of personal data to third parties.
We do not sell the content of images, PDFs, or ingredient data you submit through our AI features, the text extracted or derived from those submissions, or any other data processed by Anthropic on our behalf, to any third party for advertising, data brokerage, or any other commercial purpose.
Calimento uses Peaberry Software, Inc. d/b/a Customer.io ("Customer.io") as a third-party service provider and sub-processor to send lifecycle and marketing email — for example, a welcome message at signup, reminders during your no-cost access period, re-engagement email if you have not opened the App recently, and win-back email if your access has lapsed. Customer.io processes this data on our behalf, under contract, solely to deliver our own first-party email.
Data we share with Customer.io. To operate these email campaigns, we share the following from your account record and derived engagement data:
Data we do NOT share with Customer.io. We do not send recipe contents or ingredients, meal plans, grocery lists, nutrition data, payment or card data, government identifiers, precise location, or any health or medical data. No recipe data beyond the single recipe's title, image, and last-viewed date described above is shared.
When it is shared. A profile is created or updated in Customer.io when you sign in, a one-time "account created" event is recorded at signup, and a nightly process refreshes the fields listed above.
Purpose and limits. This data is used solely to deliver our own first-party lifecycle and marketing email. We do not sell this data, do not share it with data brokers, and do not use it for third-party or cross-app targeted advertising. You can opt out of marketing email at any time as described in Section 12.4; the unsubscribe process applies to Customer.io-delivered messages.
Win-back email and data retention. If your access lapses, we may send win-back email reminding you that your saved recipes are being retained for a limited period before deletion. Those retention periods — 90 days for users who never subscribed and one year (365 days) for former subscribers — are the same windows described in Section 13.2, and we honor them as stated.
Calimento uses HeyCatch, Inc. ("HeyCatch"), a Delaware corporation, as a third-party service provider and sub-processor for product analytics — measuring how the App and our website are used so we can improve them, and measuring which of our own marketing channels bring new users. HeyCatch processes this data on our behalf, under a data processing agreement, solely to provide analytics reporting to us.
Data we share with HeyCatch from the App. When you use the App, the following is transmitted to HeyCatch:
Data we do NOT share with HeyCatch. We do not send recipe contents, titles, or ingredients; meal plans; grocery-list contents; nutrition data; dietary preferences or restrictions; photographs; the contents of anything you type into the App; payment or card data; government identifiers; precise location; or any health or medical data. Screen names and interface labels are generic and contain no user content.
On our website. The HeyCatch analytics script on calimento.io measures page views, clicks, the referring site or campaign link that brought you to us, and standard browser and device information (including IP address), and sets the analytics identifiers described in Section 7.
Purpose and limits. This data is used solely for our own first-party product analytics and first-party marketing measurement. We do not sell this data, do not share it with advertising networks or data brokers, and do not use it to track you across other companies' apps or websites. HeyCatch states that it does not sell personal data and does not use customer data to train AI models. To review HeyCatch's privacy practices: https://heycatch.ai/privacy.
Calimento requests access to the following device capabilities on your iOS device. We request each permission only when the relevant feature is first used, and we explain the reason at the time of each prompt. You may grant or deny each permission, and you can change permissions at any time in your device Settings.
Calimento does not track you. The App contains no advertising and does not access the Apple Identifier for Advertisers (IDFA). The App uses a product-analytics service (HeyCatch, described in Section 5B) that acts solely as our service provider: it measures how you use Calimento itself, for our own product improvement and marketing measurement, and does not link your data with data from other companies' apps or websites for targeted advertising, and does not share your data with data brokers. Because the App does not track you across apps or websites owned by other companies, it does not present Apple's App Tracking Transparency (ATT) permission prompt — no tracking permission is needed because no tracking, as Apple defines it, occurs.
If we ever introduce a feature that involves tracking as defined by Apple's ATT framework, we will update this Privacy Policy in advance and the App will present the required ATT permission prompt before any tracking begins.
If you choose to sign in to Calimento using "Sign in with Apple," Apple will authenticate your identity and share your name and email address (or a private relay email address) with us. We will use this information solely to create and manage your Calimento account. Please review Apple's Privacy Policy at https://www.apple.com/legal/privacy for details on how Apple handles your data during this process.
Cookies are used only on our marketing website at calimento.io (hosted on Cloudflare). The iOS App itself does not use cookies, pixel tags, web beacons, or any similar tracking technologies (see Section 5B for the App's product-analytics disclosure). The disclosures in this Section 7 apply solely to visits to our website.
Some web browsers transmit "Do Not Track" (DNT) signals to websites. Because there is currently no industry-wide standard for how to respond to DNT signals, our website does not currently alter its data collection practices in response to DNT signals. We will revisit this position if and when a universally accepted standard is adopted.
In certain circumstances, we may disclose your personal information to third parties for legitimate purposes subject to this Privacy Policy. Such circumstances may include:
Our marketing website and these policy pages at calimento.io are hosted and delivered through Cloudflare, Inc. ("Cloudflare"), which provides content delivery and hosting infrastructure. Cloudflare's role is limited to website hosting and delivery: Cloudflare does not process Calimento App subscriptions, does not handle any App payments (all payments are processed by Apple In-App Purchase), and does not receive data from the iOS App itself.
When you visit our website, Cloudflare — as the hosting and content delivery provider — may log standard website visit information such as your IP address, browser type, and pages viewed, for security and delivery purposes. For that website hosting data, Cloudflare acts as a service provider on our behalf, subject to its own privacy practices.
To learn more about Cloudflare's data practices, please visit the Cloudflare Privacy Policy at https://www.cloudflare.com/privacypolicy/.
The Services may provide links to websites or other online platforms operated by third parties. If you follow links to sites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such sites, including the accuracy, completeness, or reliability of information found on these sites.
Information you provide on public or semi-public venues, including information you share on third-party social networking platforms, may also be viewable by other users of the Services and/or users of those third-party platforms without limitation as to its use by us or by a third party. Our inclusion of links does not, by itself, imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the Services.
The Services are not intended to be used by children under the age of 13, and we do not knowingly collect personal information from children under 13 in violation of the Children's Online Privacy Protection Act (COPPA). Users between the ages of 13 and 17 should use the Services only with the involvement and consent of a parent or legal guardian.
If you are the parent or guardian of a child who has provided us with their personal information without your consent, please contact us at admin@livelygraphics.com, and we will take prompt steps to delete that information from our systems.
As of the Effective Date of this Privacy Policy, we do not have actual knowledge that we "share" or "sell" (as those terms are defined in applicable law) personal information of individuals under 16 years of age.
Depending on where you live, you may have some or all of the rights listed below in relation to your personal information. These rights are not absolute, may apply only in certain circumstances, and in certain cases we may decline your request as permitted by applicable law.
If you are a California resident, you have the rights described above plus the following additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
To submit a CCPA/CPRA request, please contact us at admin@livelygraphics.com. We will verify your identity before processing your request.
Washington State residents have additional rights with respect to consumer health data as described in Section 4 of this Privacy Policy.
We may send you lifecycle and promotional email, delivered through Customer.io (see Section 5A). You may opt out at any time by using the unsubscribe link included in every marketing email, or by contacting us at admin@livelygraphics.com. We honor unsubscribe requests promptly and within the time required by applicable law. If you opt out of marketing email, we may still send you non-promotional messages necessary to the service, such as those about your account, subscription, or security.
To manage push notification preferences, navigate to Settings > Notifications > Calimento on your iOS device.
We implement commercially reasonable administrative, technical, and physical security measures designed to protect the personal information we maintain about you. These measures include encryption of data in transit (TLS/SSL), access controls, and regular security assessments. However, no security measures are perfect or impenetrable, and we cannot guarantee absolute security. We recommend that you use strong, unique passwords and do not use unsecured channels to communicate sensitive information to us.
The following retention schedules apply to personal data we hold in connection with your Calimento account. Retention periods run from the triggering event described below.
Automated deletion under the schedules above will be preceded by advance notice to the email address registered to your account, where technically feasible.
You may delete your account and all associated personal data at any time using the Delete Account function in the App (Settings > Account > Delete Account), or by contacting us at admin@livelygraphics.com. User-initiated deletion is permanent and immediate. It triggers the following actions:
We are based in King County, Washington, United States. Your personal information may be transferred to, stored, or processed in countries other than the country in which you reside, including the United States. These countries may have data protection laws that are different from — and in some cases less protective than — the laws of your country.
If we transfer your personal information out of the European Economic Area (EEA) or the United Kingdom, we will rely on recognized transfer mechanisms such as the European Commission's Standard Contractual Clauses, or any equivalent contracts issued by the relevant competent authority of the UK, unless the data transfer is to a country that has been determined to provide an adequate level of protection.
We may update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will post the revised Privacy Policy on our website and within the App, update the "Last Updated" date, and provide notice as required by applicable law. For material changes — particularly changes that affect how we handle consumer health data, AI processing, or your privacy rights — we will provide more prominent notice (such as an in-App notification or email) and, where required, seek your fresh consent.
Your continued use of the Services following notice of changes constitutes your acceptance of the revised Privacy Policy.
If you have any questions, concerns, or complaints about our privacy practices or this Privacy Policy, or if you would like to exercise any of the rights available to you, please contact us at:
We will respond to privacy rights requests within the timeframe required by applicable law. For MHMDA requests, we will respond within 45 days, with the possibility of a 45-day extension for complex requests. For CCPA/CPRA requests, we will respond within 45 days, with the possibility of a 90-day extension.