Legal
Privacy Policy
1. Summary
Mackros is a goal-driven home-cooking app: you plan meals that hit your macros, cook them, and track them. To do that we store your account, the nutrition/goal profile you give us, what you cook and log, and — only if you opt in — social activity. We don’t sell your personal data, we don’t show third-party advertising, and we don’t surface weight or calories on any social or leaderboard surface. We use a small set of service providers (listed in §6) to run the app.
2. Information we collect
You give us:
- Account: email address, name, and authentication credentials (handled by our auth provider, Supabase — we don’t store your password).
- Nutrition & goal profile (health-related): height, weight and weigh-ins, age/birth info, sex, activity level, goals (lose/maintain/gain) and the macro targets derived from them, dietary preferences, diet type, allergens, and dislikes.
- Activity you create: meals and foods you log, recipes you create/adapt/favorite, cook events and cook photos, pantry items, shopping lists, weigh-ins, and fasting windows (if enabled).
- Social content (only if you use social features): profile/handle/bio, friends and follows, cook posts and captions, group membership and group chat messages, potluck/party events, and leaderboard participation (opt-in, off by default).
- Kids mode (Family tier): a child’s first name and birth year that a parent enters to create a picture-menu profile, plus the child’s meal votes and curated learning progress. Kids do not have their own accounts or social access. See §8.
- Payments (when billing is live): handled by our payment processor (Stripe); we receive subscription status, not full card numbers.
From your device (with your permission):
- Health & fitness data (if you connect Apple Health or Google Health Connect): we read the data you allow — steps, active energy, sleep, and body weight — to adjust your calorie/activity targets, show your activity, and (only if you opt in) detect supportive patterns. We store a daily summary of these values. We do not use Apple Health or Health Connect data for advertising or marketing, do not sell it, and do not share it with third parties for those purposes.
- Camera & photos (with your permission): you can scan a product barcode (we read the barcode number to look the product up), photograph a finished dish to attach to a cook, and — where offered — photograph a meal or your pantry so the app can identify items. We never access your camera or photo library without your action. A photo you save is stored (§6); if you use a photo-recognition feature, that image is sent to our AI provider (§4) to identify the food or items.
Collected automatically: basic device/app info and diagnostics (app version, OS, crash and error reports) to keep the app working.
From third parties: nutrition facts for foods you look up come from public/licensed databases (see §6); these are lookups about foods, not about you.
3. How we use your information
- Provide the core product: compute your TDEE/macros (deterministically, in our code — not by an AI), plan meals, track consumed-vs-target, compile shopping lists, and surface allergen-safety warnings.
- Power features you turn on: household pairing, friends/feed, groups, leaderboards, events, Kids picture-menu, and the behavior-change/learning surfaces.
- Personalize the experience: from what you log, cook, and rate — and, if connected, your activity and sleep — we build a taste profile and look for patterns (e.g. “protein-forward breakfasts tend to precede on-track days”) to tailor suggestions and gentle nudges. These are assistive suggestions, not automated decisions with legal or similarly significant effects, and you can turn pattern recognition off in Settings.
- Generate content you request (e.g. AI recipe generation) — see §4.
- Maintain, secure, debug, and improve the app, and communicate with you about your account.
- Comply with law and enforce our terms.
We process this data to perform our contract with you, on the basis of your consent (for optional features like social/leaderboards), and for our legitimate interest in operating and securing the app.
4. AI features
Some features generate content from a model — e.g. AI recipe generation, recipe adaptation, and daily-moment copy. To do this we send the minimum necessary prompt (such as ingredients, your macro targets, and dietary/allergen constraints) to our AI gateway provider (OpenRouter and the model it routes to). We request providers that do not retain or train on the request where the option is available. Nutrition numbers you rely on are always computed deterministically in our code, never produced by the AI. Don’t enter anything in free-text fields you wouldn’t want sent to a model.
Where you use a photo-recognition feature — identifying a meal or your pantry items from a picture — the image is sent to our AI provider to recognize what’s in it; as above, the nutrition numbers are still computed in our code.
5. How we share information
We do not sell your personal data and do not share it for cross-context behavioral advertising. We share data only with the service providers below (as our processors, to run the app), with other users only for the social content you choose to post, with authorities where legally required, and with a successor in the event of a merger or acquisition.
6. Service providers (sub-processors)
- Supabase — database, authentication, file storage (your photos), realtime.
- OpenRouter (and the routed model providers) — AI generation (§4).
- Vercel — application hosting and delivery.
- Sentry — crash/error monitoring.
- Resend — transactional email.
- Stripe — payment processing (when billing is enabled).
- Nutrition data sources — USDA FoodData Central, Open Food Facts, FatSecret, MenuStat (food/nutrition lookups).
- Grocery / health integrations you connect — e.g. Kroger (grocery), Withings (weight), and Apple Health / Google Health Connect (activity, sleep, and weight read from your device), if and when you link them.
This list may change as the product evolves; we’ll keep it current here.
7. Data retention
We keep your data while your account is active. You can delete your account at any time (§9), which removes your profile and associated personal data; some records may persist briefly in backups and where retention is legally required. Aggregated or de-identified data (e.g. a shared food’s average macros) is not personal data and may be retained.
8. Children's privacy
Mackros is intended for users 18 and older. Kids mode is a parent-controlled feature: a parent on the Family tier adds a child’s first name and birth year to create a number-free picture menu; the child has no account, no social access, no macros, and no calorie data (by design, to avoid disordered-eating patterns). The parent controls and can delete that profile at any time. We do not knowingly collect personal information directly from children. If you believe a child has provided us information improperly, contact us and we will delete it. Where required (e.g. COPPA / similar laws), Kids-mode data is collected under verifiable parental control.
9. Your rights and choices
Depending on where you live (e.g. GDPR/UK GDPR, CCPA/CPRA), you may have the right to access, correct, delete, or export your data, and to object to or restrict certain processing. In the app you can: edit your profile and goals, edit/delete logged meals, control post visibility (private/friends/public), opt in/out of leaderboards, and delete your account. To exercise any right, use the in-app controls or contact us at sandiaflow.ops@gmail.com. We won’t discriminate against you for exercising these rights.
10. Security
Data is encrypted in transit (HTTPS). Group chat messages are encrypted at rest at the column level. Access is restricted via row-level security and least-privilege service access. No system is perfectly secure, but we work to protect your information and will notify you of a breach where required by law.
11. International transfers
We and our providers may process data in the United States and other countries. Where required, we rely on appropriate safeguards for cross-border transfers.
12. Changes to this policy
We’ll update this policy as the app changes and revise the effective date. Material changes will be communicated in-app or by email.
13. Contact
Questions or requests? Email sandiaflow.ops@gmail.com.