TDEE Calculator: Burn · A Campflame app
Burn privacy policy
Your personal records stay on your device. Optional sharing, online searches and purchases have separate data flows and choices.
Effective 13 September 2026.
Who is responsible
TDEE Calculator: Burn is a Campflame app. Contact burn.support@campflame.dev with support or privacy questions. This policy explains the iPhone app and this information website. Feature availability can vary by app version. A service described as optional is used only when the feature is available and the relevant conditions below apply.
Your food, weight and Health records
Your profile, food diary, saved foods, meals, recipes, weights and review history are stored on your device. Burn does not require a Burn account and does not upload your personal diary to its analytics, crash-reporting or purchase providers. Its personal-record database does not use CloudKit synchronization and is excluded from automatic device backups. Export a Burn backup if you want a recovery copy.
Connecting Apple Health is optional. Burn requests read access to weight and dietary energy and saves imported copies and source information locally. It does not write to Apple Health. Disconnect stops refreshes while keeping imported copies; Remove imported Health copy removes Burn’s copies without deleting the originals in Apple Health. Restoring a backup does not reconnect Health.
Backups and local history
You choose where to save exported Burn backups and CSV files. They may contain personal information, including imported Health records. Your chosen storage provider may synchronize or retain them. Deleting records in Burn does not delete exported files.
Importing a backup replaces current personal records. Burn separately retains the latest 50 successful restore receipts on the installation, including dates, format, time zone and record counts. Receipts do not contain individual food or weight values or the backup filename. They survive later restores, are excluded from portable backups, can be exported separately, and are cleared by Delete all Burn records.
Camera, label recognition and food searches
Camera access is optional. You can choose an existing label photograph or enter values manually. Label text recognition runs on your device. Burn saves the food values you confirm, rather than attaching the photograph or raw recognized text to the saved food. Selecting a photo does not delete the original in Photos.
Typing a food name searches on your device. When online search is available, pressing Search or Search online sends your search words to Burn’s food-search service hosted by Cloudflare. Your diary, profile, weight and advertising identifier are not included. Burn does not intentionally log raw search text in its Worker application logs. Connection information, including your IP address, is processed to deliver and protect the service.
When online barcode lookup is available, the barcode is sent to Burn’s product service, which requests product information from Open Food Facts. Your photograph and diary are not sent with that request. Product results may be cached by Burn and its service. Checking for an available food-catalog update downloads catalog information and data over HTTPS without sending your personal records. These online services are separate from optional analytics consent.
Optional usage statistics
Usage statistics and crash reports are separate choices, off by default. Reporting remains paused until adult guidance or diary use is confirmed and while using Support and resources. Burn works with sharing off.
If you enable usage statistics and the service is available, PostHog receives a limited set of feature-use events, such as opening the app, saving food, viewing a review or purchase screen, and purchase or restore flow outcomes. Events include time, app version and random installation and event identifiers. Search events describe the outcome, not the words searched. Review events do not include your target or recommendation. Recipe events do not identify the recipe. Logging-time events use broad ranges.
Burn does not send food descriptions, calories, macros, weights, photographs or Health records in these events. It does not record your screen, create PostHog person profiles, or request location enrichment. Network services still process connection metadata. Turning usage sharing off clears unsent events and resets Burn’s usage identifier; it cannot recall an already delivered event.
Optional crash reports
If you enable crash reports and the service is available, Firebase Crashlytics processes technical crash information, such as installation and session identifiers, crash time, app version, operating system and device details, stack traces and exception information. Burn does not add custom user IDs, diary values, photographs or raw application errors to reports. Burn does not use Firebase Analytics.
Previously queued reports may be shared on a later launch when your saved sharing choice is enabled. Newly enabling sharing discards previously pending reports through the SDK. Turning sharing off stops future sharing decisions but cannot recall a batch already accepted for delivery. Firebase states that removal of Crashlytics data from live and backup systems begins after 90 days; this is not a guarantee that all copies disappear on day 90.
Purchases and subscription access
When purchases are available, Apple and RevenueCat process product, purchase, restore and subscription-access information. RevenueCat creates a random anonymous App User ID and processes purchase receipts, subscription status and technical app/device information. “Anonymous” here means you do not need to create a Burn login; the purchase record still has an identifier. RevenueCat may determine country from transactions or an IP address and states that it drops the raw IP after determining country.
Burn does not provide custom subscriber attributes or enable automatic device-identifier collection in its RevenueCat configuration. Purchase verification is separate from optional usage/crash sharing and may occur when the app becomes active. Deleting Burn’s local records does not cancel an Apple subscription or erase Apple’s or RevenueCat’s purchase records. Manage subscriptions through Apple.
Reminders, widgets and ratings
Optional daily reminders request notification permission. Their text does not contain food, weight or calorie values. When widget access is available, Burn shares a limited daily summary with its own widget extension, including calories, protein, target, completeness and timing information. Anyone who can see your widget may see that summary.
Burn keeps small local records of logging days and rating-request attempts to avoid asking too often. They are excluded from exported backups and are not sent to analytics providers. Apple controls its rating prompt; Burn does not receive your rating from that prompt.
Retention, deletion and your choices
Your personal records remain on your device until you remove or replace them. Delete all Burn records removes personal records and imported Health copies, clears the product cache, resets reminders and rating history, invalidates the widget summary, and turns off optional sharing. Burn reports a cleanup or saving problem rather than claiming success. Exported files, original Apple Health records and provider-held information are separate.
Temporary usage events are held in memory with age and queue limits. Product-cache age limits are checked during use and are not a promise of immediate physical erasure. Provider-held data follows the applicable service arrangements and retention policies. PostHog’s event retention depends on the plan and whether retention enforcement is active; we do not promise a shorter fixed Burn-specific deadline. RevenueCat purchase retention and Cloudflare network-information retention do not have one universal deletion deadline established by this policy.
Email burn.support@campflame.dev to request information, correction or deletion of information we hold or to ask about your privacy choices. We may need enough information to locate a record and verify the request. Do not send your entire diary, backup, Health records, password or identity documents in your initial message. With random installation identifiers, we may be unable to associate an analytics record with your email alone. Deleting provider purchase history does not cancel an Apple subscription. Applicable law and necessary security or transaction obligations may affect what can be removed.
Providers and this website
Burn uses the providers described above for the relevant available features. They may process information in countries outside your own, under their applicable service and privacy arrangements. We do not sell your personal diary or use Health data for advertising.
These privacy and support pages are part of campflame.dev, hosted by Sevalla. We add no analytics script, advertising tracker, contact form or account system to these pages. The hosting provider processes connection and security information needed to deliver the website. See the Campflame website privacy policy. Emailing support shares your email address, message and any attachments you choose to send with our support mailbox provider.
Adults, estimates and contact
We may update this policy when Burn’s features or data practices change. The current version and effective date appear on this page. For privacy or support questions, contact burn.support@campflame.dev. Burn’s guidance features are intended for adults; Support and resources provides a non-prescriptive alternative. Calorie targets and expenditure estimates are guidance, not medical advice or a diagnosis. Ask a qualified clinician about dietary changes for a medical condition.