This Policy describes how the Macros application ("app", "we") handles information when you use it. By using the app, you agree to the practices described here.

1. Who the controller is

The party responsible for processing the data (the "controller", under Brazil's General Data Protection Law — LGPD, Law No. 13,709/2018) is Marcus Gustavo Costa da Silveira, contact contato@macrosapp.com.br.

2. Where your data lives

Macros was designed with privacy as a priority. Your day-to-day entries (food, water, workouts) and your body metrics are stored locally on your device. The app does not send this history to a server.

To sign in to the app, however, an authentication account is created. The data for this account (an identifier, and when available, name and email) is stored with our backend provider, described in item 4. The other situations in which data leaves the device are also covered in item 4 (third-party services).

3. Data the app handles

3.1. Account data (login)

To use the app you sign in with Sign in with Apple or Google. From the provider we receive an account identifier and, when you allow it, your name and email, used to identify you in the app and personalize the greeting. With Sign in with Apple, you may choose to hide your email; in that case we receive only an anonymous relay address from Apple. When signing in with Google, we may also receive the URL of your profile photo, which is downloaded once and kept only on your device.

3.2. Data you provide

3.3. Apple Health data (optional)

If you authorize it, the app reads information from Apple Health/HealthKit such as workouts, active calorie burn, steps and body data (for example, weight). The app only reads this data — it does not write anything to Apple Health. This data is used on the device to feed your calculations and is not used for advertising.

3.4. Content sent for AI search

When you use AI food search, the text you type or the photo you take of the food is sent for processing (see item 4) to generate the portion and macro estimate.

3.5. Barcode (packaged products)

When you scan the barcode of a packaged product, that code's number (GTIN/EAN) is sent, through our backend functions, to look it up in a food database (see item 4.4). The barcode identifies a product, not a person: we do not send along your name, your body metrics, your location or any other personal data.

4. Third-party services

4.1. Backend and authentication (Supabase)

We use Supabase as our backend provider for authentication (login) and to broker AI search, with infrastructure in a region in Brazil. Supabase processes, on our behalf, the account data described in item 3.1. This processing follows Supabase's terms and privacy policy, available at supabase.com/privacy.

4.2. Artificial intelligence provider (Google Gemini)

AI food search uses the Gemini API, from Google. The text or image of the food you submit is sent, through our backend functions, to Google solely to process that request and return the nutritional estimate. We do not send along your name, your body metrics or other personal data beyond the content needed for the query.

Google's processing of this data follows Google's own terms and privacy policy. We recommend reading it at policies.google.com/privacy.

4.3. Apple

App distribution and Sign in with Apple are operated by Apple, which may process data in accordance with its own policies.

4.4. Food database (Open Food Facts)

Barcode scanning queries the public, non-profit Open Food Facts database to obtain the product's nutritional information. We send only the barcode number, and the query originates from our servers — not from your device —, so Open Food Facts does not receive your IP or any data from your device. The returned information is used only to fill in the food entry in your diary. Open Food Facts' processing follows the platform's own privacy policy, available at world.openfoodfacts.org/privacy.

5. What we use the data for

We do not sell your data and we do not use it for targeted advertising.

6. Legal basis (LGPD)

Processing relies, as applicable, on the consent you provide (for example, when you authorize Apple Health or send a food to the AI), on the performance of the service you request (for example, authenticating your access) and on the legitimate interest in operating and improving the app, always respecting your rights.

7. Your rights

Under the LGPD, you may request: confirmation of processing, access, correction, anonymization or deletion of data, portability, information about sharing, and withdrawal of consent.

Since your entries stay on your device, you can edit or delete them directly in the app, and uninstalling the app removes the local data. To delete your authentication account and the associated data, or for any other requests, reach out to contato@macrosapp.com.br.

8. Retention

Local data remains on your device for as long as the app is installed. Account data remains until you request its deletion. Content sent to AI providers is retained in accordance with those providers' policies.

9. Security

We adopt reasonable technical measures to protect the information — for example, communication over encrypted channels (HTTPS), storage of session credentials in the device's secure keychain (Keychain), and limiting the data that leaves the device to the minimum necessary. No system is perfectly secure, but we work to reduce risks.

10. Children

The app is not intended for children under 13 years of age. We do not knowingly collect data from children.

11. Changes to this policy

We may update this Policy. Significant changes will be indicated by the "last updated" date at the top of this page.

12. Contact

Questions about privacy or exercising your rights: contato@macrosapp.com.br.