KALCIUS_

Privacy

How your data is handled_

Kalcius holds some of the most personal data an app can hold. This page says what is stored, who else ever touches it, what the AI is allowed to see, and the controls you hold — in plain words, each one describing what the system actually does.

The short version

  • Your data is yours. A complete export and a full, immediate deletion are each one tap in the app — no email to write, no waiting period, no retention games.
  • Nothing is sold. No advertising, no data brokers, no third-party analytics or tracking scripts. This site sets no cookies at all.
  • The AI features are off until you switch them on, and they see the minimum the feature needs — listed below, exactly.
  • Partner tracking is consent-first on both sides: you choose what is shared before an invite goes out, and she is shown everything that is shared, always — nothing about her is collected behind her back.
  • Kalcius is not a medical device and nothing in it is medical advice.

What Kalcius stores

Your account. Email address, display name, and a password — stored only as an argon2 hash, which means we cannot read it back. If you sign in with Apple, the connection to your Apple ID instead. Plus the operational facts an account needs: whether the email address is verified, when the account was created, coarse last-activity.

What you log. Semen analysis results, vitals (weight and sleep — typed in, or imported from Apple Health if you connect it), daily moods, day notes, habit check-ins on the levers board, key dates, date nights, playbook entries, the medications-and-supplements ledger, self-exam check-ins (the outcome, and any note you write about what you noticed — shown only back to you), badges and streaks, crew invites, and any feedback you send.

The Clip. When paired: skin temperature readings with their timestamps, battery level, and wear sessions. That is the whole telemetry — the device has no microphone, no location, no motion tracking.

Cycle tracking. Period dates, flow, mood observations and notes. In solo mode this is your own journal. When accounts are linked, her account is a real account with its own standing — see the next section.

Operational records. Notifications sent to you, push-notification registrations (browser or iPhone), your subscription's status, and a log of which kinds of email went out when — never the content of them.

The partner link

The link between accounts is built as an act of transparency, not surveillance, and the rules are enforced server-side: you choose which categories are shared before the invite is sent; the invite tells her exactly what is on and what is off before she accepts; everything shared with you is shown to her unabridged, with anything withheld named as a category; changes to the deal are announced to her, never silent; and either side can end the link at any moment, no negotiation, no explanation owed.

The full statement of how her side works is on the front page.

What the AI sees

Every AI feature sits behind one consent switch — off by default, revocable in one tap from the same surfaces that use it, with the grant and the revoke both dated. Until you say yes, nothing you log is ever sent to a model. When you do, each feature sends the minimum it needs:

  • The writer sends what you typed into the form, plus her first name as you saved it.
  • The daily plan sends labels only — cycle code, mood words, key-date names. Never your notes.
  • The weekly insight sends weekly averages and mood words from a fixed vocabulary. Free text cannot enter the fact sheet by construction.

Requests carry no account identity — no email address, no user id. The model runs at a third-party provider configured server-side; what it receives is the fragments above and nothing else. Our own log of AI calls stores metadata only — which feature, which model, how long it took, how big the text was — never the text itself and never whose it was.

Who else touches your data

Each of these sees the minimum its job needs:

  • Stripe handles Kalcius Plus payments on the web. Card details go straight to Stripe's own checkout — they never touch our server. Stripe holds your email address for receipts; we store the subscription's status and Stripe's reference ids.
  • Apple handles Plus bought on the iPhone (we verify the App Store receipt, Apple keeps the payment relationship), Sign in with Apple if you use it, and push notification delivery.
  • Our email server sends the transactional mail — verification links, password resets, invites, security heads-ups, the daily brief if you have it on.
  • GitHub holds our build board. Feedback you send is mirrored there so it gets tracked and fixed — the words and the category only, never your name or email address. It also stores our nightly database backup — encrypted before it leaves our machine, to a key GitHub does not have, so what it holds is ciphertext it cannot read. Each backup expires within 30 days.
  • Hosting is a virtual machine we operate on Microsoft Azure. The database lives on that machine — your data is not spread across a third-party data platform.

What never happens

  • No selling of data, no advertising, no data brokers — not as a business model we're delaying, as one we refuse.
  • No third-party analytics, no tracking pixels, no cookies. Sign-in state lives in your own browser's storage and goes no further.
  • Health data never drives product recommendations or affiliate links. That firewall is a standing design rule.
  • The admin tools we run on our own product see metadata only — counts, statuses, latencies. No admin screen can open what you log — your journal, notes, moods or results; we declined to build one. The feedback box is the deliberate exception: what you type there is a message to the team, and the team reads it.

Security, stated honestly

Passwords are hashed with argon2. Every emailed link — account verification, password reset, email change, partner invite — is single-use, time-limited (a day, half an hour, an hour, and seven days respectively) and stored only as a SHA-256 hash, so a copy of the database alone cannot use one.

Sessions are short-lived tokens: access expires in 15 minutes, refresh in 30 days. You can sign out every device from Profile → Sessions (or Settings on the iPhone), and changing or resetting your password does it automatically — every session except the one you're holding ends.

Everything travels over TLS, and production is checked every half hour by an independent monitor that raises an alarm the hour something goes wrong.

The database is backed up nightly, and again immediately before any change to its structure. Backups are verified, encrypted before leaving the machine, and kept for at most 30 days — they exist so your data survives a disaster, not as an archive.

The honest line: no system is unbreakable, and we won't pretend otherwise. What we can promise is the construction above, adversarial audits of our own new work — the changelog records what those audits have found and fixed — and plain words here when anything changes.

The controls you hold

  • Export. Everything the account holds, as one file, one tap: Profile on the web, Settings → Privacy & AI on the iPhone.
  • Deletion. Immediate and complete — every table, one transaction, no soft-delete limbo. Our build fails if a new table is added without a decision about what deletion does with it. If someone has linked you as their partner, deleting your account detaches you from that link; what they logged themselves remains theirs. The one honest asterisk: encrypted disaster-recovery backups rotate out on their own schedule, so a deleted account is gone from the live system at once and from every backup within 30 days.
  • Consents. Health data, the partner link, AI processing, marketing — each granted and revoked from the surface that uses it, each dated, each checkable.
  • Sharing scopes. What the partner link shares is yours to narrow or widen at any time — and every change is announced to her.

On marketing: there is none. Kalcius sends no marketing email today at all. If that ever changes it will be opt-in first — the consent slot already exists and sits unset.

Who we are

Kalcius is a small product, early in its life. This page is written from the code that enforces it and changes only through the same review that ships the product — it is the engineering truth, kept current. A formal legal privacy notice naming the legal entity and a regulatory contact route will stand alongside this page before general launch; until then, questions and challenges are welcome through the feedback box in the app, and every one of them is read.

Last updated 23 August 2026.