A gentle health companion — and a careful one with your data.
Calla is a personal health companion for daily mood check-ins, symptoms, vitals, medications and refills, appointments, journaling, guided breathing, a supportive AI chat, and a family care circle. This policy explains what data the app handles and where it goes.
Calla is a wellness tool, not a medical device, and nothing in the app is medical advice.
Calla collects no location data, no contacts from your address book, and no usage analytics. Where ads are personalized only with your consent, and non-personalized otherwise — see Advertising below for exactly what Google receives.
Guest accounts. "Continue as guest" creates a real but anonymous account: it has an internal id but no email, password, or name, so there is nothing to sign back in with. Calla warns you before you sign out of a guest account, and Settings → Protect my account lets you attach an email address, Apple ID, or Google account at any time — after which the same data is recoverable normally.
Your entries are stored in Google Firebase (Firestore, Firebase Authentication, and Cloud Storage for photo attachments), which lets your data sync live across your devices. Firestore and Storage security rules restrict every record and every file to your own signed-in account. The only data another account can ever read is a care-circle share you create yourself — see Care circle.
Some data is also kept on your device: a cached copy of your entries so the app works offline, plus a small queue of check-ins and photo uploads that haven't reached the server yet. Android system backups are disabled for Calla, so this local data is not copied into Google Drive backups. It is removed when you delete your account or uninstall the app.
Demo mode: if you try Calla in demo mode, everything stays on your device only and is discarded when you leave the demo — no account is created and nothing is uploaded.
The care circle is the one feature that lets a different person read some of your data, and it only ever happens because you started it.
If a build of Calla is configured with crash reporting, an unexpected crash sends a diagnostic report to Sentry so the bug can be fixed. A report contains the error, the code path that produced it, your app version and device model, and an internal account id — not your health entries, journal, photos, or chats. Crash reporting is off when no reporting endpoint is configured for the build.
When you chat with the Calla companion, your messages are sent to Google's Gemini model via Firebase AI Logic to generate a reply. So the companion can respond helpfully, each request also includes a short summary of your recent entries — such as recent check-ins, symptoms, your medication list and latest vitals. Google processes those requests under its cloud terms; Calla does not use your chats for advertising or sell them to anyone.
For users in regions where Google services are not reachable (such as mainland China), chat and sync requests travel through a relay server operated by the developer in Hong Kong (Tencent Cloud). The relay passes your requests through to the same services and does not store your data; while in transit it is processed on Tencent Cloud's Hong Kong infrastructure.
The AI companion offers supportive conversation only — it is not a doctor and its replies are not medical advice. In an emergency, contact local emergency services.
Calla's free plan shows a small banner ad on a few everyday screens (such as Home, Trends, and the journal). Ads are provided by Google AdMob.
Health sync is off until you turn it on. When you do, Calla asks the system for read access to eight kinds of data from Apple Health (iOS) or Health Connect (Android):
Imported readings are stored alongside the vitals you log manually, in your own account.
Writing back. Calla can also put two things it created itself back into the platform store, so your other apps stay in step: the water you log in Calla, and the mindful minutes from Calla's breathing exercise (mindful sessions are iOS-only — Health Connect has no equivalent record). Write access is requested separately from read access and only when you enable it, so you can import without ever letting Calla write. Calla never writes any other kind of record, and never authors a reading it did not measure.
Medication, check-in, and appointment reminders are scheduled locally on your device. Your health data is not sent to a push-notification service.
Nothing is shared unless you choose to share it. Settings → Export builds a plain-text summary of your data that you can send wherever you like — for example to a doctor. The export happens through your device's own share sheet.
Settings → Privacy collects the choices that matter in one place:
Depending on where you live (for example under the GDPR or the UK GDPR), you have rights to access, correct, export, restrict, and erase your personal data, and to object to certain processing. Calla is built so you can exercise most of these yourself and immediately: Settings → Export produces a full copy of your data, every entry is editable in the app, and Settings → Delete account & data erases everything. For anything else — or to raise a complaint — write to wksunshine@gmail.com. You also have the right to complain to your local data-protection authority.
Calla's legal basis for handling your health entries is your consent, given by choosing to record them; for optional features (health sync, AI chat, care-circle sharing, personalized ads, crash reporting) it is the separate consent you give when turning each one on, which you can withdraw at any time by turning it back off.
Calla is intended for adults managing their own wellbeing and is not directed at children under 13.
If this policy changes, the updated version will be published at the same URL with a new effective date.
Questions about this policy: wksunshine@gmail.com
Effective date: 1 August 2026 (previous version: 17 July 2026)
溫柔的健康夥伴,也謹慎守護您的資料。
Calla 是您的個人健康夥伴,提供每日心情打卡、症狀記錄、生命體徵、用藥與補藥提醒、預約管理、日記、引導式呼吸、暖心的 AI 聊天,以及家庭關懷圈。本政策說明應用程式處理哪些資料,以及資料的去向。
Calla 是健康輔助工具,不是醫療器材,應用程式中的內容皆不構成醫療建議。
Calla 不收集位置資料、不讀取您的通訊錄,也沒有使用分析。個人化廣告僅在取得您同意後才會投放,否則一律為非個人化廣告 — Google 究竟會收到哪些資料,詳見下方「廣告」一節。
訪客帳號。「以訪客身分繼續」會建立一個真實但匿名的帳號:它有內部識別碼,但沒有電子郵件、密碼或姓名,因此沒有任何可用來重新登入的憑證。Calla 會在您登出訪客帳號前提出警告,您也可隨時透過設定 → 保護我的帳號綁定電子郵件、Apple ID 或 Google 帳號 — 綁定後即可正常復原相同的資料。
您的記錄儲存在 Google Firebase(Firestore、Firebase 驗證,以及儲存照片附件的 Cloud Storage),讓資料能在您的裝置間即時同步。Firestore 與 Storage 安全規則確保每筆記錄與每個檔案僅限您本人的帳號存取。其他帳號唯一能讀取的資料,是您自行建立的關懷圈分享 — 詳見關懷圈。
部分資料也會保存在您的裝置上:包括供離線使用的記錄快取,以及尚未送達伺服器的少量打卡與照片上傳佇列。Calla 已停用 Android 系統備份,因此這些本機資料不會被複製到 Google 雲端硬碟備份中。當您刪除帳號或解除安裝應用程式時,這些資料即會移除。
示範模式:若您以示範模式試用 Calla,所有資料僅存在於您的裝置上,離開示範模式時即會清除 — 不會建立帳號,也不會上傳任何資料。
關懷圈是唯一讓其他人能讀取您部分資料的功能,且一律由您主動開啟。
若某個 Calla 版本已設定當機回報,發生非預期當機時會將診斷報告傳送至 Sentry 以便修正問題。報告內容包含錯誤本身、產生錯誤的程式路徑、您的應用程式版本與裝置型號,以及一組內部帳號識別碼 — 不包含您的健康記錄、日記、照片或聊天內容。若該版本未設定回報端點,當機回報即為關閉狀態。
當您與 Calla 夥伴聊天時,您的訊息會透過 Firebase AI Logic 傳送至 Google 的 Gemini 模型以產生回覆。為了讓夥伴給出貼心的回應,每次請求也會附上您近期記錄的簡短摘要 — 例如近期打卡、症狀、藥物清單及最新生命體徵。Google 依其雲端服務條款處理這些請求;Calla 不會將您的聊天用於廣告,也不會出售給任何人。
對於無法連接 Google 服務的地區(如中國大陸)的使用者,聊天及同步請求會經由開發者在香港營運的中繼伺服器(騰訊雲)傳送。中繼伺服器僅將您的請求轉發至相同的服務,不會儲存您的資料;傳輸過程中資料會經過騰訊雲香港的基礎設施處理。
AI 夥伴僅提供陪伴式對話 — 它不是醫生,其回覆不構成醫療建議。如遇緊急情況,請聯絡當地緊急服務。
Calla 的免費方案會在部分日常畫面(如首頁、趨勢及日記)顯示小型橫幅廣告,廣告由 Google AdMob 提供。
健康同步預設為關閉,需由您主動開啟。開啟後,Calla 會向系統請求讀取 Apple 健康(iOS)或 Health Connect(Android)中的八類資料:
匯入的讀數會與您手動記錄的生命體徵一同儲存在您自己的帳號中。
寫回資料。Calla 也可將兩項由它自己產生的資料寫回平台,讓您的其他應用程式保持同步:您在 Calla 記錄的飲水量,以及 Calla 呼吸練習的正念分鐘數(正念記錄僅限 iOS — Health Connect 沒有對應的記錄類型)。寫入權限與讀取權限分開請求,且僅在您啟用時才會請求,因此您可以只匯入資料而完全不讓 Calla 寫入。Calla 絕不寫入其他任何類型的記錄,也絕不產生非它自己測量的讀數。
用藥、打卡及預約提醒都在您的裝置本機排程。您的健康資料不會傳送至推播通知服務。
除非您主動分享,否則不會分享任何資料。「設定 → 匯出」會產生一份純文字的資料摘要,您可自由傳送至任何地方 — 例如給醫生。匯出透過您裝置本身的分享功能進行。
設定 → 隱私將所有重要選擇集中在同一處:
依您所在地區的法規(例如 GDPR 或英國 GDPR),您享有存取、更正、匯出、限制及刪除您個人資料的權利,並可反對特定的資料處理行為。Calla 的設計讓您能自行且即時行使其中大部分權利:設定 → 匯出可產生您資料的完整副本,每一筆記錄都可在應用程式內編輯,而設定 → 刪除帳號與資料則會清除所有內容。其他事項 — 或提出申訴 — 請來信 wksunshine@gmail.com。您亦有權向當地的資料保護主管機關提出申訴。
Calla 處理您健康記錄的法律依據是您的同意,即您選擇記錄它們的行為;至於選用功能(健康同步、AI 聊天、關懷圈分享、個人化廣告、當機回報),依據則是您在開啟各該功能時另行給予的同意,您可隨時透過關閉該功能撤回。
Calla 是為管理自身健康的成年人設計,並非以 13 歲以下兒童為對象。
若本政策有所變更,更新版本將發布於相同網址,並附上新的生效日期。
關於本政策的問題,請聯絡:wksunshine@gmail.com
生效日期:2026 年 8 月 1 日(前一版本:2026 年 7 月 17 日)