Effective August 13, 2026

Privacy Policy

Macro Tracker is a general-wellness nutrition tracker. This policy describes the reference service operated at https://macrotracker.reciplan.pro.

Information we process

Account information includes your email address, password-derived credential, rotating session records, and account identifiers. Your synchronized app state includes your onboarding profile, nutrition targets, saved foods, food logs, body measurements such as weight and body fat percentage, and daily activity summaries such as steps, active calories, distance, exercise time, and workout count.

If you explicitly connect a supported system health service and grant its permissions, the app reads only the health categories you approve. Imported weight and daily activity summaries become part of your synchronized Macro Tracker state. The integration does not write data to the health service. Connection preferences and health permission controls remain on the device.

If you use Circle, we process your chosen display name and optional profile photo, friendship and invitation records, sharing preferences, blocks, reports, preset encouragement, buddy challenges, private personal challenge targets, and derived progress snapshots. Your display name and profile photo are visible to mutual friends and intended invitation recipients. Friends receive only the general progress categories you enable. For a nutrition challenge, the other participant receives only successful-day counts; for a weight challenge, they receive only normalized percentage progress and whether you reached your target. Your exact challenge targets, weights, calorie or macro totals, food items, meal photos, body measurements, email, and raw app state are not shared through Circle.

If you request a photo estimate or revision, the selected image and any feedback you add are sent through the Macro Tracker server to its AI provider. If you request a text or voice meal proposal, the description or in-memory recording and resulting transcript are sent to the AI provider. The reference server does not save image files, photo feedback, recordings, submitted descriptions, or transcripts. Operational metadata such as request time, status, model, provider request identifier, token counts, and estimated provider cost may be retained to enforce allowances and prevent abuse.

If you subscribe, your app marketplace processes the purchase. RevenueCat associates store subscription status with your Macro Tracker account identifier and provides product, entitlement, expiration, and store-management information. Macro Tracker does not receive your payment-card details.

How information is used

We use this information to authenticate accounts, synchronize devices, calculate and display tracking trends, search the hosted food catalog, provide requested AI estimates, verify subscription access, meter trial and paid feature allowances, operate private Circle features, prevent abuse, respond to reports, and maintain service security.

Service providers

Infrastructure providers process data needed to host the API and PostgreSQL database. OpenAI processes images, photo feedback, typed meal descriptions, voice recordings, and transcripts submitted for requested AI food estimates under the configured service account. RevenueCat processes account identifiers and store subscription status. Your app marketplace processes store purchases. USDA FoodData Central receives generic-food search terms, and the separately hosted Open Food Facts-derived catalog receives branded-food and barcode search terms; those food sources do not receive your account state.

Retention and deletion

Account and synchronized data are retained while your account exists. Session, metering, subscription-status, and operational records may expire or be removed as part of service maintenance. Image files, photo feedback, voice recordings, submitted descriptions, and transcripts are not retained by the reference server. You can leave Circle without deleting tracking data, or permanently delete the account in the app. Account deletion removes the login, synchronized state, sessions, AI and barcode usage records, subscription-status cache, profile photo, and associated Circle records from the application database. Store subscription cancellation is managed separately through your app marketplace account.

Your choices

You can stop future health imports, manage health permissions in system settings, export tracking state, change Circle sharing fields, remove friends, block accounts, report concerns, leave Circle, or delete the account in the app. Disconnecting a health integration does not silently delete records already imported; clear tracking data or delete the account to remove synchronized imports. Circle is optional and currently limited to adults age 18 and older.

Security and accuracy

Credentials are hashed or stored as opaque-token hashes on the server, and native session credentials use the device’s secure credential store. No system is perfectly secure. Nutrition databases and AI estimates can be wrong; Macro Tracker is not medical advice.

Contact

Questions, privacy requests, and safety concerns can be sent to support@reciplan.pro.