Cal AI's very bad quarter: a breach in March, pulled from the App Store in April
Within roughly eight weeks the calorie-scanning app was acquired, breached, and removed from the App Store over its own paywall design. Each event is ordinary. Together they describe a set of priorities.
MyFitnessPal acquired Cal AI in March 2026. That same month, a breach exposed roughly 2.8 million unique email addresses along with eating habits, body measurements and fitness goals. In April 2026 Apple removed the app from the App Store over deceptive billing design — a weekly price shown more prominently than the real charge, an obscured auto-renewal toggle, and a second purchase flow after users declined the first. It was reinstated after changes.
The facts, in brief
| Acquisition | MyFitnessPal acquired Cal AI, March 2026 |
| Breach | Disclosed March 2026 — ~2.8M unique email addresses |
| Data exposed | Emails (~1.2M via Apple private relay), eating habits, body measurements, fitness goals |
| App Store removal | April 2026, for deceptive billing design |
| Specific findings | Weekly price shown over true cost; obscured auto-renewal; second purchase flow after decline |
| Outcome | Fixed and reinstated |
| Context | Built by two high-school founders; roughly $50M ARR before acquisition |
What did Apple object to?
Three things, all of which sit in our dark-pattern taxonomy. The paywall displayed a lower weekly price more prominently than the amount users would actually be charged. A free-trial toggle obscured key information about automatic renewal. And declining the first subscription offer produced a second, different purchase flow.
That last one is the tell. A single aggressive paywall is a design choice; a fallback paywall for people who said no is a strategy.
What was in the breach?
Around 2.8 million unique email addresses, with roughly 1.2 million using Apple's private relay. Alongside them: eating habits, body measurements and stated fitness goals. That combination is more sensitive than an email dump, because it describes a person's relationship with food in a way that is genuinely difficult to un-publish.
Why we're treating these as one story
Because billing design and data handling come from the same place. Both are decisions about whether the user's interests or the company's win when they conflict, and organisations rarely get one right and the other wrong by accident. We score them on separate axes — Price & value and Data rights — and they correlate more than almost any other pair in our database.
Cal AI has fixed the billing flow and remains available. We scored it 52 and named this episode in our comparison.
email addresses exposed, alongside eating habits, body measurements and fitness goals — a data set that describes something people rarely choose to publish.Breach reporting, March 2026
Applandica's read
Tomás Villaseca · Data & Privacy LeadI want to be careful here, because the company fixed the billing flow and the founders were teenagers when they built this. Neither of those facts changes what the record shows.
The reason we log this rather than let it go is that a paywall is the most honest artefact a company produces. Marketing copy is aspirational; the checkout screen is what they actually decided. When a platform holder has to intervene to make that screen accurate, it tells you what the internal argument sounded like — and it's reasonable for a reader deciding where to put their health data to know that.
Frequently asked questions
Was Cal AI removed from the App Store?
Yes. Apple removed it in April 2026 over deceptive billing design and reinstated it after the developer made changes.
Was Cal AI breached?
Reporting in March 2026 described a breach exposing roughly 2.8 million unique email addresses along with eating habits, body measurements and fitness goals.
Who owns Cal AI?
MyFitnessPal acquired the app in March 2026. It was built by two high-school founders and had reached roughly $50 million in annual recurring revenue.
Sources
- TechCrunch — Apple's Cal AI crackdown signals it's still policing the App Store, 21 April 2026. Accessed 1 Sep 2026
- MacRumors — Apple pulled Cal AI for deceptive billing design, 21 April 2026. Accessed 1 Sep 2026
- HackRead — MyFitnessPal-owned Cal AI hit by data breach affecting 3M users. Accessed 1 Sep 2026
FTC sues Hims & Hers over health data sent to Meta and Snap
The complaint pairs the two failures we log most often — advertising trackers on sensitive health data, and a…
AnalysisFDA steps back from wearables and AI health software
A January guidance shift means many wearables and AI health tools can reach the market without formal device review.…