Privacy Policy

1. What this policy covers

This Privacy Policy describes what information MacroSquad ("we," "us," "our," operated by Karan Sharma (sole proprietor)) collects, how we use and disclose it, the third parties that process it on our behalf, and your rights over it.

It applies to the MacroSquad mobile application, the MacroSquad website at getmacrosquad.com, and related services (collectively, the "Service").

This policy does not cover third-party services you reach through links, or the independent data practices of the app stores and platforms you use to access the Service (e.g., Apple).

2. The short version

3. Information we collect

3.1 Information you provide

Contacts are not in this list, and that is deliberate. The app can open your contacts to help you send an invite, but it does so entirely on your device and sends us nothing. See Section 3.4.

3.2 Information collected automatically

The app carries no analytics SDK and no crash-reporting SDK. There is no third-party tracker in the build, and we do not record feature taps or sessions. What reaches us is limited to:

3.3 Information from third parties

3.4 Contacts: your address book never leaves your phone

Contacts are the most sensitive permission the app asks for, so we describe exactly what happens:

  1. The feature is off by default. It runs only after you tap to invite someone from your contacts and grant the iOS contacts permission.
  2. Your phone opens a picker. You choose who to invite.
  3. The app builds an invite message containing your squad code and hands it to the iOS share sheet. You send it, through whichever app you pick.
  4. Nothing about your contacts is transmitted to us. No names, no phone numbers, no email addresses, and no hashes of any of them. There is no upload step in this feature, so there is nothing for us to store, match or retain.
  5. We never message or invite anyone on your behalf.

An earlier version of this policy described a contacts-matching service that hashed your contacts and sent the hashes to our server to find friends already on MacroSquad. That feature is disabled and the app does not do it. The server endpoint has been switched off since 2026-07-24 and the surface that called it does not render. If we ever bring it back, we will update this policy and the App Store privacy disclosures before it ships, not after.

4. What we do with it

We process the categories of data above on the legal bases described in Section 12 (for EU/UK users).

5. Photo handling

When you attach a photo to a meal:

Deletion. You can delete any photo at any time from the meal log, and deleting your account deletes your stored photos with it (Section 10).

A dormant cache. The Service contains a results cache for photo-derived nutrition estimates, keyed on the SHA-256 hash of the image bytes and holding no user identifier. While image recognition is off, nothing writes to it. If recognition is ever switched on, that cache becomes active and the paragraph above this one changes; we will update this policy in the same release.

6. AI, image recognition and model training (READ CAREFULLY: accuracy-sensitive)

Photo-to-macros is switched off in the app you can install today. The app has no working "point the camera at your dinner and get macros" feature. Your numbers come from the food you pick out of a database, a barcode you scan, or a value you type yourself, and a photo you attach is decoration on top of that. This is stated plainly on our home page too.

Nutrition values that come from a food database or from your own entry are still estimates and can be wrong. Check anything that matters for your health or an allergy.

7. Processors and disclosures (GDPR Art. 28 / CCPA service-provider framing)

We disclose personal information to the third parties below only as processors / service providers acting on our behalf. Each is engaged under a written contract (a Data Processing Addendum under GDPR Article 28, and "service provider" / "contractor" terms under the CCPA/CPRA) that: (a) limits the provider to processing data solely for the purposes we specify; (b) prohibits selling or sharing the data or using it for the provider's own purposes; (c) requires appropriate security; and (d) requires deletion or return of data on termination. Engaging any of these in a way that meets the CCPA "service provider" exemption means these disclosures are not a "sale" or "share."

Processor Data shared Purpose Contract status
Apple / RevenueCat Subscription status, entitlement, transaction IDs (no card numbers) Subscription management & billing Data Processing Addendum / service-provider terms maintained
FatSecret Food-name and barcode queries (no account identifiers). No photos, while image recognition is off (Section 6). Food and nutrition database Data Processing Addendum maintained; no-training confirmed in writing (§2.4.3)
Open Food Facts Generic food / barcode queries (no account identifiers) Open food-products reference data Open public data source; queried for food data only under its public API terms
Supabase All stored data (account, logs, photos, body metrics, social graph) Backend hosting, database, object storage, auth Data Processing Addendum maintained
Cloudflare Request data, edge routing metadata Edge compute (Workers), routing, CDN, security Data Processing Addendum maintained
Expo Push (Expo Application Services) Push notification tokens, notification payloads Delivering push notifications (routes via Apple Push Notification service) Data Processing Addendum / service-provider terms maintained
Expo Updates (Expo Application Services) App version, update channel, and a device platform identifier sent when the app checks for an update Delivering over-the-air updates to the app’s JavaScript bundle

Not in this table, and why. Earlier versions listed Nutritionix as a restaurant and branded-food database processor. We never contracted with Nutritionix and the Service does not query it; it was removed from our stack on 2026-09-02 and the row is gone. Earlier versions also listed USDA FoodData Central. Our software can query it, but the running Service holds no USDA credential and does not call it today. Neither of them receives anything about you.

We do not disclose personal information to advertising networks, data brokers, or analytics resellers. We do not use any of them.

8. What we don't do

9. Your rights and how to exercise them

Depending on where you live, you have some or all of the following rights:

How to exercise: use the in-app controls above, or email support@getmacrosquad.com. We will verify your identity before fulfilling a request and respond within the timeframe required by applicable law (generally 30–45 days, extendable where the law allows). You may use an authorized agent where the law permits.

Appeals: if we decline a request, you may appeal by replying to our response or emailing support@getmacrosquad.com with "Appeal" in the subject line. We will respond to appeals within the timeframe required by applicable law.

10. Data retention and deletion

11. Security

We use industry-standard safeguards: TLS in transit, encryption at rest, restricted access controls, row-level database policies that keep one account out of another's data, dependency scanning, and incident response. Sign-in is handled by Apple or by a one-time code we email you, so there is no password to steal. Body-weight and other health metrics are treated as sensitive and access-restricted.

No system is 100% secure. If you suspect unauthorized access to your account, contact support@getmacrosquad.com immediately. In the event of a data breach affecting your personal information, we will notify affected users and regulators as required by applicable law.

12. Legal bases for processing (EU/UK / GDPR)

Where GDPR or UK GDPR applies, we process personal data on these bases:

We are the controller of your personal data; the providers in Section 7 act as processors under Article 28 contracts. The controller of your personal data is Karan Sharma (sole proprietor).

13. International data transfers

Data is processed in the United States and may be processed in other regions where our providers operate. For transfers of EU/UK/Swiss personal data to the US or other countries, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum / Swiss equivalents) and, where applicable, provider participation in the EU–US Data Privacy Framework.

14. Children (COPPA and minimum-age policy)

The Service is intended for users 13 and older and is not directed to children under 13. We do not knowingly collect personal information from anyone under 13. Because our minimum age is 13, the Service is not subject to COPPA's under-13 obligations. Users between 13 and 17 are subject to the additional terms in our Terms of Service (parental review and consent).

If we learn that we have collected personal information from someone under 13, we will delete it. If you believe a child under 13 has provided us information, contact support@getmacrosquad.com.

15. US state privacy rights (California CCPA/CPRA and other states)

California (CCPA/CPRA). California residents have the rights in Section 9, plus the right to know the categories of personal information collected, the purposes, and the categories of third parties to whom it is disclosed (see Sections 3 and 7). We do not sell or "share" personal information for cross-context behavioral advertising. We collect the categories: identifiers; customer records; commercial information (subscriptions); internet or other electronic network activity (the request metadata in Section 3.2); sensitive personal information (health metrics such as body weight). We use sensitive personal information only for permitted purposes and not to infer characteristics. We honor the Global Privacy Control (GPC) and other recognized opt-out preference signals where required.

Other US states (e.g., Virginia, Colorado, Connecticut, Utah, Texas, and others as enacted): residents have access, correction, deletion, portability, and opt-out rights as provided by their state laws; exercise them as described in Section 9.

16. Changes to this policy

We may update this Privacy Policy. Material changes will be communicated in-app or via email at least 30 days before they take effect (or sooner where the law requires immediate notice).

17. Contact

Karan Sharma (sole proprietor)
Ann Arbor, Michigan, USA

EU representative (GDPR Art. 27): Not currently appointed; the Service is not actively offered to EU data subjects until a representative is appointed.
UK representative: Not currently appointed; the Service is not actively offered to UK data subjects until a representative is appointed.
Data Protection Officer / privacy contact: support@getmacrosquad.com


Change log: what version 2.2 corrected

Version 2.2 corrects places where this policy described more data collection than the app performs. Every change narrows what we say we do; none of them expands it, so none of them is a material change that needs advance notice under Section 16. In summary:


Effective date: July 2, 2026

Last updated: September 12, 2026

Version: 2.2