calai.app, a mobile calorie and health tracking application, allegedly experienced a data breach that was disclosed on March 9, 2026. The incident was reported on a cybercrime forum. The breach reportedly resulted from security misconfigurations that allowed unauthorized access to subscription data and other user information.
The compromised data allegedly includes email addresses, first and last names, dates of birth, genders, height and weight metrics, exercise goals, logged meals and eating habits, purchased subscriptions, App Store transaction IDs, third-party integration metrics, and user referral code conversion information. Approximately three million user records are believed to have been exposed, including around one million Apple Private Relay addresses and 300,000 users with configured social profiles. The full extent of the compromised data and the number of affected individuals remain unclear. No official confirmation from calai.app or regulatory bodies has been publicly disclosed.
Details about this incident may emerge as investigations continue, and official notifications to consumers may be delayed.