Privacy Policy

Draft – not yet in effect. This document is being reviewed by our lawyers before ZMacros launches. Highlighted items are still to be confirmed.

Version: VERSION · Effective date: EFFECTIVE DATE Controller: LEGAL ENTITY NAME, REGISTERED ADDRESS Privacy contact: PRIVACY CONTACT EMAIL Data Protection Officer: DPO CONTACT, OR "NOT APPOINTED" EU representative (GDPR Art. 27): EU REPRESENTATIVE · UK representative: UK REPRESENTATIVE Security reports: SECURITY CONTACT EMAIL

1. The short version

2. What we collect, why, and where it goes

Which laws this policy is written for. This policy is designed to meet the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and the other US state privacy laws, Canada's PIPEDA and Quebec's Law 25, and the laws of the other countries where ZMacros is offered. Country-specific rights are in the Regional Supplements.

"Device" means storage private to the app on your phone, which is removed when you uninstall. Other apps cannot read it, but ZMacros does not add its own encryption on top of the phone's; protect your phone with a passcode. "Our servers" means our database, hosted by Supabase on Amazon Web Services in the United States (Oregon). Rows there are protected so that only your own account can read them, except where section 5 says otherwise.

2.1 Your account

Data Why Where
Email address and password (the password is stored only as a hash by our sign-in provider) Signing in, account recovery, account emails Our servers (Supabase Auth)
Sign-in session Keeping you signed in Your device's secure storage (iOS Keychain / Android encrypted storage). On the web version, the browser's storage
Display name Shown to a coach you connect with, and to staff handling support Device; our servers if you connect a coach
Region and time zone Units, the rules that apply to you, and when your day starts Device; time zone on our servers if you connect a coach
A random account identifier Linking your records, and your subscription (see 2.6) Our servers, RevenueCat

At launch, sign-in is by email and password only. Apple, Google and phone sign-in are not available and we do not collect a phone number.

2.2 Your body and goals

Data Why Where
Year of birth Applying the age rules, and working out your targets Device. Also our servers if you connect a coach, so the server can check coaches are only connected to adults
Sex, height, activity level, goal, targets Working out calorie and nutrient targets Device
Weight entries Tracking your trend Device and our servers
Target periods (your targets over time) Keeping history accurate when targets change Device and our servers

2.3 What you eat

Data Why Where
Food diary: foods, amounts, meals, times The core feature Device and our servers
Saved meals, quick-add presets, favourites, custom foods (private to you) Faster logging Device and our servers
Searches Finding foods Sent to the food databases in section 6; not stored with your account
Barcodes you scan Looking up the food Sent to Open Food Facts from your device (see section 6)
Meal photos you choose to scan AI food recognition See section 3. Not kept by us
Your corrections to AI results See section 3.4 Our servers

Barcodes and the shared database. Today, scanning a barcode only looks it up. A feature that lets you add a missing barcode-to-food match to a shared barcode database is planned. If it launches, the match you contribute will contain no information about you, and if you delete your account your identifier is removed from it and the match stays for others to use. The app will tell you before you contribute.

2.4 Your activity

Data Why Where
Workouts, programs and sessions you log Tracking training and energy Device and our servers
Data read from Apple Health (iPhone), if you allow it: step count, active energy burned, exercise minutes, sleep analysis, workouts Showing your daily activity and adjusting targets on workout days Device only. Never uploaded
Data read from Health Connect (Android), if you allow it: steps, active calories burned, exercise sessions, sleep sessions The same Device only. Never uploaded
GPS route and position during an activity you start Distance, pace and route map Device only

Apple Health and Health Connect. Connecting either is optional and needs your permission in the phone's own permission screen; ZMacros reads only the types listed above that you allow. It will never write to Apple Health or Health Connect (it requests no write permissions), never uploads what it reads, and never uses it for advertising or passes it to anyone. To disconnect: on iPhone, Settings → Health → Data Access & Devices → ZMacros (or Settings → Privacy & Security → Health); on Android, open Health Connect → App permissions → ZMacros. Turning it off stops future reads; figures already shown on your phone stay until you delete them.

No other services are connected. ZMacros does not connect directly to Google Fit, Fitbit, Garmin, Strava, Oura, Samsung Health or any other fitness service or wearable. If one of those apps writes its data into Apple Health or Health Connect, ZMacros may read that data from there, under the permissions above.

Location. ZMacros uses your location only while you are recording an activity that you started, including when the screen is off during that activity (this is why the phone may show "background location"). It stops when you stop the recording. Your route stays on your phone. We do not collect your location at any other time, and we do not use it for advertising. For users under 18, activity location is off until turned on.

2.5 Crash reports (optional)

If you turn on Send crash reports (off by default), the app sends error reports to Sentry: the error type, a cleaned-up message, the program location of the fault, the device model and OS, and the app version. Before anything is sent, the app removes user identifiers, locale and anything shaped like health data. It sends no screenshots and no record of what you tapped.

2.6 Subscriptions

If you buy a paid plan, Apple or Google processes the payment; we never see your card details. RevenueCat tells us whether your account has an active plan. It receives your ZMacros account identifier (a random ID, not your name or email), the purchases and renewals the store reports, and your device platform. We keep your subscription status and the store's purchase events on our servers. A copy of the terms you agreed to at purchase is kept on your device.

2.7 Coaches (optional)

If you connect a coach, you choose which of these they can see: daily calorie and macro summary, individual meals and foods, longer nutrition history, weight summary, each weigh-in, goal progress. While connected, they also see your display name and time zone. They never see your workouts, steps, location, Apple Health or Health Connect data, photos, email, age or height. You can change what they see, or disconnect, at any time, and it takes effect straight away. Each time a coach views your data, a record is kept that you can see. See section 5.

2.8 Creator codes (optional)

If you enter a creator's or coach's referral code, we record who referred you, and, if you choose to support a creator, which one. The creator sees only totals (for example how many supporters they have), never who you are or any of your data. IF CREATOR COMMISSIONS ARE LAUNCHED: we also use your plan type to work out what we pay the creator.

2.9 Support, feedback and bug reports

If you send feedback or a bug report, we keep what you write, the area of the app, the app version and your device type and OS version, linked to your account so we can reply and show you the status. We also count that a report was sent (feedback_submitted / bug_submitted) to understand how many people use the feedback form.

2.10 Safety and security records

To keep the service safe we keep: a record of any suspension or ban and the reason; a log of actions staff take on accounts; counts of your AI scans and food searches to apply fair-use limits; flags for unusual scan volumes, reviewed by staff; and short-lived rate-limiting records. BACKEND, NOT YET DEPLOYED: records of forced sign-outs and security signals; a salted, one-way hash of the IP address used to sign up, kept for one day to limit abuse.

2.11 First-party usage records

We keep a small record of certain in-app events on our own servers, linked to your account: today, only that you submitted feedback or a bug report, and when. It is not shared with any analytics company, and it is deleted with your account. IF EXTENDED UNDER #564: list the events, the purpose and the consent.

3. AI photo scanning

This is summarised here. The AI Features Notice has the detail.

3.1 What happens. When you take or choose a meal photo, the app sends it to our server, which forwards it to OpenAI [IF LIVE: or Google (Gemini API, paid tier)] to identify the foods and estimate amounts. The photo carries no location or camera data. We send no name, email, account ID or other data with it. The nutrition figures then come from our own food database.

3.2 What is kept. We do not keep the photo on our servers, and we do not log it. A photo taken with the in-app camera is deleted from your phone after the scan; a photo you chose from your library stays in your library. We ask OpenAI not to store it. OpenAI may still keep it for up to 30 days to check for misuse, as its API terms allow, and then deletes it unless the law requires otherwise. OpenAI's terms say it does not use API data to train its models by default. BACKEND, NOT YET DEPLOYED: the list of foods the AI returned, with no image, is kept for 15 minutes so a dropped connection does not lose your scan.

3.3 Your permission. Scanning asks for your explicit permission before the first photo is sent, names OpenAI and states the 30 days. You can withdraw it in Settings → Data & Privacy → Privacy and consents. Everything else works without it.

3.4 Corrections. When you change what the AI suggested, the app saves the AI's suggestion and your correction to your account on our servers. It contains no image and is not sent to OpenAI. We use it TO MEASURE AND IMPROVE HOW ZMACROS MATCHES SCANNED FOODS / PURPOSE TO BE CONFIRMED. The record is linked to your account. We do not use your photos to train AI models. OWNER TO DECIDE whether corrections may be used to improve estimates; if so, a separate consent is needed.

3.5 Region checks. BACKEND, NOT YET DEPLOYED To comply with sanctions and our provider's supported countries, our server checks your app's country setting and the approximate country of your IP address before a scan. The IP address is used only for that check and is not stored.

4. Why we process it: our legal bases

Where the law asks us to state a legal basis (for example the GDPR and UK GDPR):

Purpose Legal basis Health data condition (GDPR Art. 9)
Providing the tracker and syncing your logs Contract (Art. 6(1)(b)) Explicit consent (Art. 9(2)(a)), given at sign-up ("Track my food, weight and activity")
Reading Apple Health / Health Connect Contract Explicit consent, through the app and the phone's permission
AI photo scanning Consent (Art. 6(1)(a)) Explicit consent, given before the first scan
Sharing with a coach Consent Explicit consent, per category
Crash reports Consent None needed: health fields are removed
Subscriptions Contract; legal obligation (tax and consumer records, kept by the stores) Not applicable
Safety, fair-use limits, moderation, staff audit logs Legitimate interests (Art. 6(1)(f)): keeping the service secure and fair Not applicable (no health data used)
Support and feedback Legitimate interests; contract Not applicable, unless you include health information yourself
Keeping records to defend legal claims Legitimate interests; legal obligation Art. 9(2)(f), where needed

5. Who can see your data

We do not sell your personal information. We do not share it for cross-context behavioural (targeted) advertising. We do not allow any advertising network, data broker or analytics company to receive it.

6. Service providers and other parties

Full list: Service Providers and Sub-processors.

Provider What for Location
Supabase (on AWS) Database, sign-in, server functions United States (Oregon)
OpenAI Meal photo recognition, only if you use it United States
IF LIVE Google (Gemini API, paid tier) Meal photo recognition, second provider United States to confirm
Sentry Crash reports, only if you turn them on United States
RevenueCat Subscription status United States

Food databases. When you search or scan a barcode, your phone asks Open Food Facts directly, so Open Food Facts receives the search words or barcode and your IP address, as any website does, under its own privacy policy. Searches of the USDA FoodData Central database go through our server, which does not store the search words and sends no account information.

Apple and Google process data under their own terms when you download the app, buy a plan or connect Apple Health / Health Connect.

7. International transfers

We are based in COUNTRY. Our providers process data in the United States. Where the law restricts transfers (for example from the EU, UK, Switzerland, Brazil, Quebec or Turkey), we rely on the EU-US Data Privacy Framework and its UK Extension and Swiss framework, where the provider is certified / [the European Commission's standard contractual clauses, the UK Addendum, and the equivalent clauses required in other countries, which are not the same everywhere: Brazil needs the ANPD clauses, Japan needs your informed consent naming the US, Switzerland recognises only Swiss-US DPF-certified recipients, and Türkiye requires contracts to be notified to its regulator], with an assessment of the risks. #615 You can ask for a copy of the safeguards at PRIVACY CONTACT EMAIL. Country-specific details are in the Regional Supplements.

8. How long we keep it

Data Kept
Diary, weights, workouts, meals, custom foods, AI corrections Until you delete them or your account
Data on your device Until you delete it, sign out (for consents) or uninstall
Meal photos Not kept by us. OpenAI: up to 30 days
AI result list (no image) backend, not yet deployed 15 minutes
Coach access log 12 months — backend, not yet deployed; today until account deletion
Feedback and bug reports Kept after account deletion, with your identity removed
Moderation record See section 9
Staff audit log and security, subscription and consent-to-coach records backend audit store, not yet deployed 6 years, including after account deletion, unless a legal hold applies
Crash reports SENTRY RETENTION — owner to confirm the plan's setting, commonly 30–90 days
Rate-limit and abuse records From 1 day to PERIOD

The Data Retention and Deletion Policy has the full schedule.

9. Deleting your account

Settings → Account → Delete account deletes your account straight away. There is no recovery period. It deletes your diary, weights, workouts, meals, custom foods, AI corrections and usage records, coach connections and access logs, creator and referral records, subscription records held by us and analytics counts.

What remains, and why:

Deleting your account does not cancel a subscription. Cancel it in the App Store or Google Play first. [WEB DELETION PAGE: you can also ask us to delete your account at DELETION URL without reinstalling the app.]

10. Your rights and choices

Wherever you live, you can:

We reply within one month (45 days where US state law allows), and will tell you if we need longer. We may need to confirm it is your account. You will not be treated differently for exercising a right. The Regional Supplements list the additional rights and deadlines for your country, and how to appeal.

11. Children

ZMacros is not for children under 13, and in some countries the minimum age is higher: the local age of digital consent in the EU and EEA (13 to 16), and 18 in India. The app asks for your year of birth and does not let younger users in. We do not knowingly collect data from children under 13. If we learn that we have, we will delete it. Users under 18 get extra protections. See the Children and Age Policy. Parents can contact PRIVACY CONTACT EMAIL.

12. Security

We protect your data with encrypted connections (HTTPS) for everything the app sends, database access rules that limit each account to its own rows, staff access that excludes health data and is logged, and minimal collection. Our hosting provider encrypts stored data OWNER TO CONFIRM IN WRITING WITH SUPABASE. No system is perfectly secure. If a breach affects you, we will tell you and the authorities as the law requires. See the Security Policy.

13. Automated decisions

ZMacros calculates your targets and energy estimates automatically from formulas. These are suggestions you can change; they have no legal or similarly significant effect on you. Fair-use limits on AI scans are applied automatically; a staff member reviews any flag before an account is restricted. OWNER TO CONFIRM. We do not make decisions about you by computer alone that significantly affect you.

14. Changes

We will tell you in the app before a material change takes effect, and ask for your consent again where the law requires. Earlier versions are available at ARCHIVE URL.

15. Contact and complaints

LEGAL ENTITY NAME, REGISTERED ADDRESS, PRIVACY CONTACT EMAIL. If you are not satisfied, you can complain to your data protection authority; the Regional Supplements name them.