Consumer Health Data Privacy Policy
Version: VERSION · Effective date: EFFECTIVE DATE Published by: LEGAL ENTITY NAME, REGISTERED ADDRESS Requests and questions: PRIVACY CONTACT EMAIL · in the app: Settings → Data & Privacy
Who this is for
This document is for consumers in Washington State, Nevada and Connecticut, and for anyone else who wants the plainest statement of what ZMacros does with health information. It sits alongside our general Privacy Policy and does not replace it. Where the two could be read differently about consumer health data, this document governs.
1. The consumer health data we collect
"Consumer health data" means personal information that is linked or reasonably linkable to you and identifies your past, present or future physical or mental health status. In ZMacros that is:
| Category | What exactly |
|---|---|
| Weight | Every weigh-in you record, with its date |
| Age | Your year of birth (never a full date of birth) |
| Food logs | Your food diary: foods, amounts, meals and times, and the calories, macronutrients and micronutrients shown for each entry; saved meals, presets, favourites and custom foods |
| Body details and goals | Sex, height, activity level, goal, goal weight, rate of change, calorie and nutrient targets, and past targets |
| Exercise | Workouts and training sessions you log; walks, runs, rides and hikes you record, including distance and pace |
| Data read from a health app | From Apple Health: steps, active energy, exercise minutes, sleep, workouts. From Health Connect: steps, active calories, exercise sessions, sleep. Only the types you allow |
| Location during an activity | GPS positions and route while you record an activity you started |
| Meal photos | A photo you choose to scan with the AI scanner |
| AI corrections | What the AI suggested for a photo and what you changed it to |
| Inferences | Estimates we calculate from the above, such as your estimated energy needs. These are estimates from published equations, not measurements |
We do not collect biometric identifiers (we do not analyse faces or bodies), genetic data, information about reproductive or sexual health, gender-affirming care, diagnoses, prescriptions or treatments, or any data from a healthcare provider. We use location only while you record an activity you started.
No other services. ZMacros reads only from Apple Health and Health Connect, and only with your permission. It does not connect directly to Google Fit, Fitbit, Garmin, Strava, Oura or any other fitness service.
2. Why we collect and use it
Each category is collected only to provide the app's own features that you ask for: showing your diary and trends back to you, estimating targets and energy, recording activities, syncing your own data to your own devices if you have an account, recognising the foods in a photo you choose to scan, applying fair-use limits and keeping the service secure.
We do not use consumer health data for advertising, for profiling for marketing, for research, to train AI models, or to make decisions about you such as credit, insurance or employment.
3. Where it comes from
- From you, when you enter it.
- From Apple Health or Health Connect, with your permission, which you can withdraw in your phone's settings. We only read. We never write anything back.
- From your phone's location sensor, only while you are recording an activity you started.
- Calculated by us from the above.
4. Consent
We ask for your consent before collecting consumer health data: at sign-up ("Track my food, weight and activity"), in the phone's permission screen for Apple Health, Health Connect and location, and separately before the first AI photo scan and before any coach can see your data. You can withdraw consent at any time in Settings → Data & Privacy → Privacy and consents, or by stopping use and deleting your data.
5. We do not sell it
We do not sell consumer health data, and we never have. Under the My Health My Data Act a sale would need your separate, signed, time-limited authorisation. No such authorisation exists because we do not sell. We do not share it for advertising of any kind.
No geofencing. We do not set up any virtual boundary around a place that provides health care services (or anywhere else) to identify, track, collect data from or send messages or ads to people. ZMacros has no feature that could.
6. Who receives it
6.1 Our processors (they act only on our instructions)
| Processor | What they receive | Why |
|---|---|---|
| Supabase (on AWS, United States) | Your account's own rows, protected so no other account can read them | To store and sync your data |
| OpenAI (United States) | One meal photo per scan, with no name, account ID, diary or body data | To name the foods in the photo. We never store the photo; we ask OpenAI not to retain it, and OpenAI may still hold it for up to 30 days for abuse monitoring under its API terms |
| Sentry (United States) | Crash reports with health fields removed, if you turn crash reports on | To fix crashes |
| RevenueCat (United States) | Your ZMacros account ID (a random identifier) and your purchase events. No health data | To know whether your plan is active |
6.2 Sharing (only when you choose it)
| Who | What | When |
|---|---|---|
| A coach you choose | Only the categories you switch on: daily calorie and macro summary, meals and foods, nutrition history, weight summary, each weigh-in, goal progress. Plus your display name and time zone | Only while you stay connected. Change or stop it any time |
A coach is a real person outside ZMacros and is not our processor. Before you connect, the app shows who the coach is and asks you to confirm each category. A record is kept each time a coach views your data.
6.3 Others
Apple and Google receive your purchase as the store, but no health data from us. Data read from Apple Health or Health Connect is never uploaded anywhere; it stays on your phone.
We may disclose data if the law compels us to, and we will tell you unless we are forbidden from doing so. Nobody else receives consumer health data: no data broker, advertising network or third-party analytics vendor.
7. How long we keep it
On your phone, until you delete it or remove the app. On our servers, until you delete it or your account. Exceptions, stated plainly:
Your profile row is scrubbed rather than deleted at once. The personal fields are emptied and a minimal moderation record remains, so a suspension or ban survives an account being deleted and recreated. It holds no health data, and it goes when the sign-in account is removed.
A barcode match you contribute (a planned feature) would stay in the shared barcode database with your identifier removed. It is a barcode and a food, and contains nothing about you. Today, scanning a barcode only looks it up.
Records of coach access (who viewed which category, and when) are kept for 12 MONTHS / backend, not yet deployed, and security and staff-audit records for up to 6 YEARS, including after deletion, to show what happened and defend legal claims. They do not contain your diary, weight or other health values.
OpenAI may keep a scanned photo for up to 30 days, as above.
8. Your rights, and how to use them
You have the right to:
- Know whether we collect, share or sell your consumer health data, and to see the list of third parties and affiliates that received it (section 6), and to get a copy: Settings → Data & Privacy → Export, or write to PRIVACY CONTACT EMAIL for a full copy including what is held only on our servers.
- Withdraw consent to collection or sharing at any time: Settings → Data & Privacy → Privacy and consents, or disconnect a coach. It takes effect immediately.
- Delete it: Settings → Account → Delete account, or delete individual entries. We delete it from our servers, subject to the exceptions in section 7, and tell our processors to delete their copies. [WEB DELETION PAGE: DELETION URL]
- Not be discriminated against for exercising these rights.
How long we take. We respond within 45 days, and may extend by a further 45 days where reasonably necessary, telling you why before the first period ends (RCW 19.373.040). Deletion from backups may take up to six months.
Appeals. If we refuse, reply to our decision or write to PRIVACY CONTACT EMAIL with "Appeal" in the subject. We answer within 45 days with our reasons. If we refuse the appeal, you may complain to the Washington State Attorney General (https://www.atg.wa.gov/file-complaint), the Nevada Attorney General (https://ag.nv.gov/) or the Connecticut Attorney General (https://portal.ct.gov/ag). Washington consumers also have a private right of action under the Consumer Protection Act for violations of the My Health My Data Act.
Verification. We may need to confirm a request is really yours before acting, using the account the data belongs to, and we ask for no more information than that needs. If we cannot verify a request, we say so.
9. Security
We use encryption in transit, database rules that restrict each account to its own rows, restricted and logged staff access, and minimal collection. See the Security Policy. If a breach affects your consumer health data, we will notify you and the authorities as the law requires, including under the US Federal Trade Commission's Health Breach Notification Rule where it applies.
10. HIPAA does not apply to ZMacros
ZMacros is a consumer app you use yourself. We are not a health plan, a health care clearinghouse or a health care provider that bills electronically, so we are not a "covered entity" under the US Health Insurance Portability and Accountability Act (HIPAA), and we do not process data on behalf of one as a "business associate". That means HIPAA does not protect data in ZMacros. The laws described here, the FTC Act and the Health Breach Notification Rule do. If a coach you connect is a HIPAA-covered provider, your decision to share with them is yours, and HIPAA may apply to what they hold.
11. Changes to this document
When we change it, the effective date changes, and we tell you in the app before a material change takes effect. Where a change alters what you agreed to (a new recipient, a new purpose, a longer retention), we ask for your consent again.
12. Contact
LEGAL ENTITY NAME, REGISTERED ADDRESS Privacy and health data requests: PRIVACY CONTACT EMAIL
Annex for counsel: the health-data laws considered (verified 2026-09-23 unless marked)
| Law | Status | Applies to ZMacros? |
|---|---|---|
| Washington My Health My Data Act, RCW ch. 19.373 | In force for regulated entities since 31 Mar 2024; small businesses since 30 Jun 2024. Private right of action via the Consumer Protection Act. First class action: Maxwell v. Amazon.com (W.D. Wash., filed 10 Feb 2025) | Very likely: no revenue or volume threshold; covers any entity doing business in Washington or targeting Washington consumers |
| Nevada SB 370 (2023) | In force since 31 Mar 2024. AG enforcement only codification in NRS ch. 603A: UNVERIFIED — confirm with counsel | Likely, same logic |
| Connecticut Data Privacy Act, consumer health data provisions (added by SB 3, 2023) and SB 1295 (2025) | SB 1295 amendments from 1 Jul 2026, which apply the sensitive-data duties to any controller processing sensitive data, whatever its size secondary sources; UNVERIFIED — confirm with counsel | Likely |
| Maryland Online Data Privacy Act (MODPA) | Effective 1 Oct 2025 applies to processing from 1 Apr 2026: UNVERIFIED — confirm. Collection of sensitive data only where "strictly necessary" to provide the requested product; sale of sensitive data banned | Only above its thresholds (35,000 Maryland consumers, or 10,000 with 20%+ revenue from sales) |
| New York Health Information Privacy Act (S929) | Vetoed by the Governor on 19 Dec 2025. Not law | No |
| FTC Health Breach Notification Rule, 16 CFR 318 | Amended rule effective 29 Jul 2024 | Very likely a vendor of personal health records |
| FTC Act s.5 (health privacy enforcement: GoodRx, BetterHelp, Premom, Flo) | Ongoing | Yes |
| HIPAA | Not a covered entity or business associate | No (section 10) |