Legal
This Policy describes how the Macros application ("app", "we") handles information when you use it. By using the app, you agree to the practices described here.
The party responsible for processing the data (the "controller", under Brazil's General Data Protection Law — LGPD, Law No. 13,709/2018) is Marcus Gustavo Costa da Silveira, contact contato@macrosapp.com.br.
Macros was designed with privacy as a priority. Your day-to-day entries (food, water, workouts) and your body metrics are stored locally on your device. The app does not send this history to a server.
To sign in to the app, however, an authentication account is created. The data for this account (an identifier, and when available, name and email) is stored with our backend provider, described in item 4. The other situations in which data leaves the device are also covered in item 4 (third-party services).
To use the app you sign in with Sign in with Apple or Google. From the provider we receive an account identifier and, when you allow it, your name and email, used to identify you in the app and personalize the greeting. With Sign in with Apple, you may choose to hide your email; in that case we receive only an anonymous relay address from Apple. When signing in with Google, we may also receive the URL of your profile photo, which is downloaded once and kept only on your device.
If you authorize it, the app reads information from Apple Health/HealthKit such as workouts, active calorie burn, steps and body data (for example, weight). The app only reads this data — it does not write anything to Apple Health. This data is used on the device to feed your calculations and is not used for advertising.
When you use AI food search, the text you type or the photo you take of the food is sent for processing (see item 4) to generate the portion and macro estimate.
When you scan the barcode of a packaged product, that code's number (GTIN/EAN) is sent, through our backend functions, to look it up in a food database (see item 4.4). The barcode identifies a product, not a person: we do not send along your name, your body metrics, your location or any other personal data.
We use Supabase as our backend provider for authentication (login) and to broker AI search, with infrastructure in a region in Brazil. Supabase processes, on our behalf, the account data described in item 3.1. This processing follows Supabase's terms and privacy policy, available at supabase.com/privacy.
AI food search uses the Gemini API, from Google. The text or image of the food you submit is sent, through our backend functions, to Google solely to process that request and return the nutritional estimate. We do not send along your name, your body metrics or other personal data beyond the content needed for the query.
Google's processing of this data follows Google's own terms and privacy policy. We recommend reading it at policies.google.com/privacy.
App distribution and Sign in with Apple are operated by Apple, which may process data in accordance with its own policies.
Barcode scanning queries the public, non-profit Open Food Facts database to obtain the product's nutritional information. We send only the barcode number, and the query originates from our servers — not from your device —, so Open Food Facts does not receive your IP or any data from your device. The returned information is used only to fill in the food entry in your diary. Open Food Facts' processing follows the platform's own privacy policy, available at world.openfoodfacts.org/privacy.
We do not sell your data and we do not use it for targeted advertising.
Processing relies, as applicable, on the consent you provide (for example, when you authorize Apple Health or send a food to the AI), on the performance of the service you request (for example, authenticating your access) and on the legitimate interest in operating and improving the app, always respecting your rights.
Under the LGPD, you may request: confirmation of processing, access, correction, anonymization or deletion of data, portability, information about sharing, and withdrawal of consent.
Since your entries stay on your device, you can edit or delete them directly in the app, and uninstalling the app removes the local data. To delete your authentication account and the associated data, or for any other requests, reach out to contato@macrosapp.com.br.
Local data remains on your device for as long as the app is installed. Account data remains until you request its deletion. Content sent to AI providers is retained in accordance with those providers' policies.
We adopt reasonable technical measures to protect the information — for example, communication over encrypted channels (HTTPS), storage of session credentials in the device's secure keychain (Keychain), and limiting the data that leaves the device to the minimum necessary. No system is perfectly secure, but we work to reduce risks.
The app is not intended for children under 13 years of age. We do not knowingly collect data from children.
We may update this Policy. Significant changes will be indicated by the "last updated" date at the top of this page.
Questions about privacy or exercising your rights: contato@macrosapp.com.br.