Privacy Policy
1. What this policy covers
This Privacy Policy describes what information MacroSquad ("we," "us," "our," operated by Karan Sharma (sole proprietor)) collects, how we use and disclose it, the third parties that process it on our behalf, and your rights over it.
It applies to the MacroSquad mobile application, the MacroSquad website at getmacrosquad.com, and related services (collectively, the "Service").
This policy does not cover third-party services you reach through links, or the independent data practices of the app stores and platforms you use to access the Service (e.g., Apple).
2. The short version
- We collect only what we need to run the Service.
- We do not sell your personal information and we do not "share" it for cross-context behavioral advertising, as those terms are defined under California law.
- We use third-party processors (listed in Section 7) under contracts that restrict them to processing your data only on our instructions.
- Your meal photos are not analyzed by anyone. Photo-to-macros image recognition is switched off in the app you can install today, so a photo you attach is stored and shown to the friends you chose, and nothing else (Sections 5 and 6).
- We do not use your data to train AI models, our own or anyone else's.
- You can export or delete your data at any time (Section 9).
- Your friend graph is mutual-only. No public profiles. No discoverability without your action.
- Your address book never leaves your phone. Inviting people from contacts happens entirely on your device (Section 3.4).
- MacroSquad shows no advertising, on any tier (Section 8).
3. Information we collect
3.1 Information you provide
- Account info: email, username, optional display name, bio and profile photo. You sign in with Apple or with a six-digit code we email you. The app has no password to create, so there is no password for us to hold.
- Food / meal logs: food entries, macros, free-text notes, timestamps.
- Photos: meal photos you attach to a log, and an optional profile photo. Meal photos are stored and shown to the friends your privacy setting allows. They are not sent anywhere for analysis (Sections 5 and 6).
- Body metrics (health data): body weight, optional height, fitness goals (cut / recomp / bulk), and any other body metrics you choose to enter.
- Social content: friend connections, squads, reactions, comments.
- Subscription info: managed by Apple via RevenueCat; we receive subscription status and entitlement, not payment card details.
- Support communications: emails or in-app messages you send.
Contacts are not in this list, and that is deliberate. The app can open your contacts to help you send an invite, but it does so entirely on your device and sends us nothing. See Section 3.4.
3.2 Information collected automatically
The app carries no analytics SDK and no crash-reporting SDK. There is no third-party tracker in the build, and we do not record feature taps or sessions. What reaches us is limited to:
- Request metadata that any web request carries to our edge (IP address, approximate region, user agent, app version) plus your device's time zone, which the app sends so "today" means today where you are.
- Server logs of API requests, used to run and debug the Service. They are sanitized against an allowlist so meal contents and free text never enter them.
- Push notification tokens (only if you enable notifications).
3.3 Information from third parties
- Apple In-App Purchase / RevenueCat: subscription status, entitlement, and transaction IDs (no card numbers).
- Sign in with Apple (if used): only the email (or Apple private-relay proxy) and name you choose to share.
3.4 Contacts: your address book never leaves your phone
Contacts are the most sensitive permission the app asks for, so we describe exactly what happens:
- The feature is off by default. It runs only after you tap to invite someone from your contacts and grant the iOS contacts permission.
- Your phone opens a picker. You choose who to invite.
- The app builds an invite message containing your squad code and hands it to the iOS share sheet. You send it, through whichever app you pick.
- Nothing about your contacts is transmitted to us. No names, no phone numbers, no email addresses, and no hashes of any of them. There is no upload step in this feature, so there is nothing for us to store, match or retain.
- We never message or invite anyone on your behalf.
An earlier version of this policy described a contacts-matching service that hashed your contacts and sent the hashes to our server to find friends already on MacroSquad. That feature is disabled and the app does not do it. The server endpoint has been switched off since 2026-07-24 and the surface that called it does not render. If we ever bring it back, we will update this policy and the App Store privacy disclosures before it ships, not after.
4. What we do with it
- Operate the Service: log meals, look up foods and barcodes in the food databases in Section 7, sync your friends-only feed, run your squads, and deliver notifications you turned on.
- Improve the Service: debug faults from server logs, and evaluate changes to our estimation and recap logic using de-identified or synthetic samples.
- Communicate: account-related emails, support replies, and occasional product updates (you can unsubscribe from non-transactional messages).
- Safety & integrity: detect abuse, enforce our Terms, and protect users.
- Legal: comply with subpoenas, court orders, and regulatory requests.
We process the categories of data above on the legal bases described in Section 12 (for EU/UK users).
5. Photo handling
When you attach a photo to a meal:
- It is transmitted over TLS to our infrastructure (Cloudflare Workers + Supabase storage).
- It is stored, and shown to whoever your privacy setting for that meal allows. A meal you mark Private is visible to you alone.
- It is not sent to any image-recognition service, any AI provider, or any other third party. Nothing reads it but the people you shared it with.
Deletion. You can delete any photo at any time from the meal log, and deleting your account deletes your stored photos with it (Section 10).
A dormant cache. The Service contains a results cache for photo-derived nutrition estimates, keyed on the SHA-256 hash of the image bytes and holding no user identifier. While image recognition is off, nothing writes to it. If recognition is ever switched on, that cache becomes active and the paragraph above this one changes; we will update this policy in the same release.
6. AI, image recognition and model training (READ CAREFULLY: accuracy-sensitive)
Photo-to-macros is switched off in the app you can install today. The app has no working "point the camera at your dinner and get macros" feature. Your numbers come from the food you pick out of a database, a barcode you scan, or a value you type yourself, and a photo you attach is decoration on top of that. This is stated plainly on our home page too.
- No image-recognition provider receives your photos. The integration exists in our code but is disabled server-side, and the vendor scope it would need has not been granted to us.
- No general-purpose AI model provider is in the runtime path for anything. The weekly recap is a deterministic template, and confidence scores are computed by fixed local rules, not by a model.
- We do not train models on your personal data, and we never have. Any internal evaluation of our estimation logic uses de-identified, aggregated or synthetic data.
- If recognition is ever switched on, photos submitted for estimation would go to FatSecret's Image Recognition API and to no one else. FatSecret has confirmed in writing (2026-06-10) that customer-submitted images are processed for the requested output only and are not used to train or improve its models (FatSecret license agreement §2.4.3). We would update this policy and the App Store privacy disclosures before that ships, not after.
Nutrition values that come from a food database or from your own entry are still estimates and can be wrong. Check anything that matters for your health or an allergy.
7. Processors and disclosures (GDPR Art. 28 / CCPA service-provider framing)
We disclose personal information to the third parties below only as processors / service providers acting on our behalf. Each is engaged under a written contract (a Data Processing Addendum under GDPR Article 28, and "service provider" / "contractor" terms under the CCPA/CPRA) that: (a) limits the provider to processing data solely for the purposes we specify; (b) prohibits selling or sharing the data or using it for the provider's own purposes; (c) requires appropriate security; and (d) requires deletion or return of data on termination. Engaging any of these in a way that meets the CCPA "service provider" exemption means these disclosures are not a "sale" or "share."
| Processor | Data shared | Purpose | Contract status |
|---|---|---|---|
| Apple / RevenueCat | Subscription status, entitlement, transaction IDs (no card numbers) | Subscription management & billing | Data Processing Addendum / service-provider terms maintained |
| FatSecret | Food-name and barcode queries (no account identifiers). No photos, while image recognition is off (Section 6). | Food and nutrition database | Data Processing Addendum maintained; no-training confirmed in writing (§2.4.3) |
| Open Food Facts | Generic food / barcode queries (no account identifiers) | Open food-products reference data | Open public data source; queried for food data only under its public API terms |
| Supabase | All stored data (account, logs, photos, body metrics, social graph) | Backend hosting, database, object storage, auth | Data Processing Addendum maintained |
| Cloudflare | Request data, edge routing metadata | Edge compute (Workers), routing, CDN, security | Data Processing Addendum maintained |
| Expo Push (Expo Application Services) | Push notification tokens, notification payloads | Delivering push notifications (routes via Apple Push Notification service) | Data Processing Addendum / service-provider terms maintained |
| Expo Updates (Expo Application Services) | App version, update channel, and a device platform identifier sent when the app checks for an update | Delivering over-the-air updates to the app’s JavaScript bundle |
Not in this table, and why. Earlier versions listed Nutritionix as a restaurant and branded-food database processor. We never contracted with Nutritionix and the Service does not query it; it was removed from our stack on 2026-09-02 and the row is gone. Earlier versions also listed USDA FoodData Central. Our software can query it, but the running Service holds no USDA credential and does not call it today. Neither of them receives anything about you.
We do not disclose personal information to advertising networks, data brokers, or analytics resellers. We do not use any of them.
8. What we don't do
- We don't sell your personal information, and we don't "share" it for cross-context behavioral advertising (as defined under California law).
- We don't share your friend graph with third parties.
- We don't share individual meal content with anyone other than the friends you've added and your squads, within the privacy setting you chose for that meal.
- We don't send your meal photos to any third party at all (Sections 5 and 6).
- We don't use your personal data to train AI models, ours or anyone else's.
- We don't show advertising. Not on the free tier, not anywhere, on any screen. There is no ad network and no advertising SDK in the app, so no advertiser receives anything about you. An earlier version of this policy said the free tier showed ads outside the logging flow. That was never true of the shipped app and the sentence has been removed.
- We don't receive your contacts. The invite feature runs on your device (Section 3.4).
- We don't put an analytics or crash-reporting tracker in the app (Section 3.2).
9. Your rights and how to exercise them
Depending on where you live, you have some or all of the following rights:
- Access / know: request a copy of the personal information we hold about you.
- Portability / export: export your data (Settings, then Account and data, then Export my data).
- Deletion: delete your account and associated data (Settings, then Delete account).
- Correction / rectification: correct inaccurate data.
- Object / restrict / withdraw consent: object to or restrict certain processing, and withdraw consent where processing is consent-based (for example push notifications, or the iOS contacts permission, either of which you can revoke in iPhone Settings).
- Non-discrimination: we will not discriminate against you for exercising your rights.
How to exercise: use the in-app controls above, or email support@getmacrosquad.com. We will verify your identity before fulfilling a request and respond within the timeframe required by applicable law (generally 30–45 days, extendable where the law allows). You may use an authorized agent where the law permits.
Appeals: if we decline a request, you may appeal by replying to our response or emailing support@getmacrosquad.com with "Appeal" in the subject line. We will respond to appeals within the timeframe required by applicable law.
10. Data retention and deletion
- Active accounts: data retained for the life of the account.
- Account deletion: when you trigger account deletion, your account record, meal logs, social content, and stored photos (including object-storage bytes, e.g., R2/Supabase storage) are deleted promptly (typically within minutes). Deletion is tracked verifiably in our
account_deletion_jobssystem. - Cache: the content-addressed estimate cache described in Section 5 is dormant while image recognition is off, so there is nothing in it about your photos. Any rows it holds are keyed on image bytes with no user identifier and are not personal data.
- Backups: nightly/transaction backups age out and are rotated within up to 90 days.
- Contacts: nothing to retain. Your address book is never sent to us (Section 3.4).
- Legal retention exceptions: transaction/tax records held for audit purposes (typically up to 7 years) are retained in de-identified form (no link to you) wherever feasible.
11. Security
We use industry-standard safeguards: TLS in transit, encryption at rest, restricted access controls, row-level database policies that keep one account out of another's data, dependency scanning, and incident response. Sign-in is handled by Apple or by a one-time code we email you, so there is no password to steal. Body-weight and other health metrics are treated as sensitive and access-restricted.
No system is 100% secure. If you suspect unauthorized access to your account, contact support@getmacrosquad.com immediately. In the event of a data breach affecting your personal information, we will notify affected users and regulators as required by applicable law.
12. Legal bases for processing (EU/UK / GDPR)
Where GDPR or UK GDPR applies, we process personal data on these bases:
- Contract: to provide the Service you signed up for (account, logging, food lookups, social feed).
- Consent: for optional features such as push notifications; you may withdraw consent at any time.
- Legitimate interests: to secure the Service, prevent abuse, and improve the product using de-identified data, balanced against your rights.
- Legal obligation: to comply with law and respond to lawful requests.
We are the controller of your personal data; the providers in Section 7 act as processors under Article 28 contracts. The controller of your personal data is Karan Sharma (sole proprietor).
13. International data transfers
Data is processed in the United States and may be processed in other regions where our providers operate. For transfers of EU/UK/Swiss personal data to the US or other countries, we rely on appropriate safeguards such as the EU Standard Contractual Clauses (and the UK Addendum / Swiss equivalents) and, where applicable, provider participation in the EU–US Data Privacy Framework.
14. Children (COPPA and minimum-age policy)
The Service is intended for users 13 and older and is not directed to children under 13. We do not knowingly collect personal information from anyone under 13. Because our minimum age is 13, the Service is not subject to COPPA's under-13 obligations. Users between 13 and 17 are subject to the additional terms in our Terms of Service (parental review and consent).
If we learn that we have collected personal information from someone under 13, we will delete it. If you believe a child under 13 has provided us information, contact support@getmacrosquad.com.
15. US state privacy rights (California CCPA/CPRA and other states)
California (CCPA/CPRA). California residents have the rights in Section 9, plus the right to know the categories of personal information collected, the purposes, and the categories of third parties to whom it is disclosed (see Sections 3 and 7). We do not sell or "share" personal information for cross-context behavioral advertising. We collect the categories: identifiers; customer records; commercial information (subscriptions); internet or other electronic network activity (the request metadata in Section 3.2); sensitive personal information (health metrics such as body weight). We use sensitive personal information only for permitted purposes and not to infer characteristics. We honor the Global Privacy Control (GPC) and other recognized opt-out preference signals where required.
Other US states (e.g., Virginia, Colorado, Connecticut, Utah, Texas, and others as enacted): residents have access, correction, deletion, portability, and opt-out rights as provided by their state laws; exercise them as described in Section 9.
16. Changes to this policy
We may update this Privacy Policy. Material changes will be communicated in-app or via email at least 30 days before they take effect (or sooner where the law requires immediate notice).
17. Contact
- Privacy questions / data subject requests: support@getmacrosquad.com
- Security: support@getmacrosquad.com
- General contact: support@getmacrosquad.com
Ann Arbor, Michigan, USA
EU representative (GDPR Art. 27): Not currently appointed; the Service is not actively offered to EU data subjects until a representative is appointed.
UK representative: Not currently appointed; the Service is not actively offered to UK data subjects until a representative is appointed.
Data Protection Officer / privacy contact: support@getmacrosquad.com
Change log: what version 2.2 corrected
Version 2.2 corrects places where this policy described more data collection than the app performs. Every change narrows what we say we do; none of them expands it, so none of them is a material change that needs advance notice under Section 16. In summary:
- Photos. Version 2.1 said meal photos were sent to an image-recognition provider. They are not. Image recognition is switched off and photos go nowhere but our own storage (Sections 5 and 6).
- Contacts. Version 2.1 described hashing your contacts and sending the hashes to our server. That endpoint is disabled and the app does not do it. Contacts stay on your device (Section 3.4).
- Advertising. Version 2.1 said the free tier showed ads. The app has never shown an ad and contains no ad network (Section 8).
- Analytics. Version 2.1 described usage analytics and crash reporting. The app carries no analytics or crash SDK (Section 3.2).
- Processors. Nutritionix has been removed: it was never contracted and is not queried. USDA FoodData Central is noted as not currently called (Section 7).
- Passwords. Sign-in is Apple or an emailed code. There is no password (Sections 3.1 and 11).
Effective date: July 2, 2026
Last updated: September 12, 2026
Version: 2.2