Privacy Policy
Last updated 20 September 2026
MacroSight is a calorie and macronutrient tracker. This policy explains exactly what the app collects, who else sees it, how long it is kept, and how to have it deleted. It is written to be specific rather than reassuring — where data leaves our systems, it says so.
The data controller is [CLIENT LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Questions and requests go to [CONTACT EMAIL].
What we do not do
MacroSight contains no analytics SDK, no advertising SDK and no crash-reporting SDK. We do not track you across other apps or websites, we do not build an advertising profile, we do not sell or rent your data, and we do not collect your location, contacts or any data from Apple Health or Google Fit.
What we collect
- Your email address. It is how you sign in and how we reach you about your account. We confirm it with a six-digit code before the account can be used, so nobody can sign up using an address that is not theirs.
- Your password, if you choose to set one. We never store the password itself — only a scrypt hash of it, which cannot be turned back into your password. If you sign in with Google instead, there is no password on your account at all.
- Your body and goal details: sex, date of birth, height, weight, activity level, goal type, target weight and weekly pace. These are used to calculate your calorie and macro targets and nothing else.
- Your food logs: meal names, foods, portions, calories, macronutrients and the time you logged them.
- Photographs of your meals, when you use the scan feature. These are stored in a private bucket that is not publicly readable.
- Notification settings: your reminder times, whether streak messages are on, your timezone, and a push token identifying your device.
- Subscription status: which product you bought, from which store, whether it is in trial, active, expired or cancelled, and the store's transaction reference. We never see your card details — payment is handled entirely by Apple or Google.
- Sign-in security records: session tokens, and the six-digit codes we email you to confirm your address or reset your password. Those codes are stored only as a hash, expire, and can be used once. We also count failed attempts, so the login cannot be guessed at.
- If you use Sign in with Google: the account identifier Google gives us and the email address on that Google account. We do not receive your Google password, your contacts, or anything else from your Google account.
Where your meal photographs go
This is the part most worth reading. When you scan a meal, the photograph is uploaded to our private storage and a copy is sent to Google's Gemini API, which returns an estimate of the foods and portions it recognises. The photograph leaves our systems to do this. Google processes it to answer that request.
The estimate is a guess, not a measurement. You can edit every item and portion before it is saved, and you should.
Who else processes your data
- Supabase — hosts the database and the private photo storage.
- Google (Gemini API) — receives meal photographs for recognition, as described above.
- Resend — receives your email address in order to deliver the confirmation and password-reset messages we send you.
- Google (Sign in with Google) — if you choose that sign-in method, Google tells us the email address and account identifier for your Google account. We only ask Google for those two things.
- Google Firebase Cloud Messaging — receives your device token and the content of push notifications we send you.
- USDA FoodData Central and Spoonacular — receive the food and recipe search terms you type. They are not told who you are.
- Apple and Google — process your payment and tell us whether your subscription is valid.
- Render and Vercel — host our API and our websites.
When our staff can see your data
Staff using our internal admin tools can see your account details, your subscription status and your food logs, and can correct an entry if you ask us to.
Your meal photographs are more restricted. Staff cannot browse your photo history. A photograph can only be opened when that scan is in the low-confidence review queue or has been reported to us, and every such view is recorded in an audit log naming the staff member. We do this so abusive or illegal uploads can be removed, not to look at your meals.
How long we keep it
Your food logs and meal photographs are kept for as long as your account exists, because the history and trends features are what they are for.
You can delete your account from inside the app, under your profile. This is a hard deletion: your account, profile, goals, meals, photographs, subscription records and notification settings are removed, not merely hidden.
One exception, stated plainly: when a staff member corrects or removes something, the audit record of that action is retained after your account is deleted, including a before-and-after snapshot of what was changed. We keep it so that our own staff remain accountable for actions taken on user data. It is not used for any other purpose.
Your rights
Under India's Digital Personal Data Protection Act, 2023, and comparable laws elsewhere, you may ask us to give you a copy of your data, correct it, delete it, or nominate someone to act for you if you are unable to. Deletion is available immediately in the app; for anything else, write to [CONTACT EMAIL].
If you are unhappy with how we have handled a request, our Grievance Officer is [GRIEVANCE OFFICER NAME], reachable at [CONTACT EMAIL]. You also have the right to complain to the Data Protection Board of India.
Children
If you are a parent or guardian and believe a child in your care has created an account you would like removed, write to [CONTACT EMAIL] and we will delete it.
Security
Traffic is encrypted in transit. Meal photographs live in a private storage bucket that is not publicly readable. The database denies access to client applications entirely — only our API can read it. Store transaction references are encrypted at rest. No system is perfectly secure, and we do not claim otherwise.
Changes
If this policy changes materially we will update the date at the top and, where the change affects how your data is used, tell you in the app before it takes effect.