1. Controller
The controller responsible for processing personal data in connection with MacroSensei is:
Sriraam Sinnarajah
Bahnhofstraße 44
23843 Bad Oldesloe
Germany
Email for privacy enquiries:
Support:
A data protection officer has not currently been appointed.
2. Scope
This Privacy Policy applies to the MacroSensei app on iOS and Android, its associated website and related online services.
MacroSensei is an app for managing and analysing nutrition, calories, macronutrients, fitness, training, activity, sleep and other information entered or authorised by the user. It also includes social features such as friends, chats, shared content and a rewards system.
MacroSensei is not intended for people under the age of 16. The date of birth entered in your profile is used, among other purposes, for calculation features. It is not independent age verification; the current app has no separate server-side 16+ access check.
3. Principles of data processing
We process personal data to operate MacroSensei, provide the features selected by the user, protect the service and fulfil legal obligations, and for processing to which the user has consented.
Health and fitness data are processed for the respective tracking, analysis, synchronisation and rewards features. Section 6 describes HealthKit and Health Connect permissions and data flows; section 24 describes the legal bases.
Health data are not used for advertising profiles or personalised advertising.
4. Registration and user account
Depending on the chosen sign-in method, the following data in particular may be processed:
Email address, telephone number, username, display name, authentication and session information, and technical account IDs.
MacroSensei supports or is preparing the following sign-in methods:
Email address and password, telephone number/SMS verification, Sign in with Apple and Google Login.
When signing in with Apple or Google, the respective provider may transmit identification data and, depending on the permissions granted by the user, their name or email address to MacroSensei.
MacroSensei does not store passwords in plain text.
Other users generally do not see your email address or telephone number. In social features, your chosen username or display name is used in particular.
5. Profile, body and nutrition data
MacroSensei may process the following information in particular:
Body weight, height, date of birth, gender or the sex value used for calculations, activity settings, stride length, goals, desired weight change, calorie and macronutrient targets, food diary, meals, foods, quantities, portions, calories, protein, carbohydrates, fat, water, weight history, dietary preferences, exclusions and allergens.
These data serve in particular to provide the tracking, statistics, goals and calculation features requested by the user.
Other ordinary users have no general access to your private body, nutrition or health records. Shared content and the social rewards information described in section 11 are separate from these private records.
6. HealthKit and Health Connect
If you grant access through the operating system permission, MacroSensei can read health and activity data from Apple HealthKit or Android Health Connect. You can decline the connection and use the app without it. The current app provides the operating system read permission; it does not provide an additional separate account-bound Health consent dialogue.
The current functionality includes steps and sleep data. Heart rate, heart rate variability, respiratory rate and oxygen saturation may also be processed for certain sleep analyses where those data are available and access is granted.
MacroSensei currently does not write any data back to Apple Health or Health Connect.
Imported step entries are stored locally. When private synchronisation is enabled, they may be transmitted to the MacroSensei backend together with activity, profile and other private settings. Raw sleep stages and vital-sign data are processed on the device for analysis and are currently not stored by MacroSensei as a complete permanent raw dataset. Derived sleep duration, day assignment and evidence identifiers may be stored locally and transmitted when private synchronisation is enabled.
For the rewards system, signed-in accounts also transmit daily progress, step and sleep task values, evidence identifiers, and observation day and time to the backend. This rewards data flow is independent of private synchronisation and may occur when private synchronisation is switched off. Raw sleep stages and vital signs are not transmitted in this rewards data flow. Badges generated from this information may show other users the goal achievements described in section 11.
You can revoke health permissions at any time through your operating system settings. Revocation prevents future access but does not automatically delete data previously stored in or derived by MacroSensei. You can send deletion requests to privacy@macrosensei.com; section 28 describes account deletion.
Health and fitness data are not used for personalised advertising.
7. Training and fitness
When using the training features, training plans, exercises, sets, weight, repetitions, duration, rest periods, RPE, notes, training history, manually entered energy values and media added by the user may be stored in particular.
These data serve training planning, documentation, statistics and the provision of recommendations requested by the user.
During shared training, only the information necessary for the shared feature is disclosed to the participating users.
8. Own foods, recipes and images
Users can create their own foods, meals and recipes.
Personal notes and private images are generally intended only for the respective user unless the user deliberately shares them with others.
Product information created by users may be added to the shared MacroSensei food database. These shared product records remain linked to the creator's account in the backend and are removed when that account is deleted. Copies already imported by other users or saved outside MacroSensei may remain.
The public product view does not show other ordinary users the original creator's name or email address.
9. Open Food Facts and external food sources
MacroSensei uses external food data sources, including Open Food Facts.
During online searches, search terms, barcodes, language and the selected food market in particular may be transmitted to MacroSensei servers or directly to the respective data provider. For direct requests, the external service may also technically receive your IP address.
MacroSensei does not transmit HealthKit or Health Connect data to Open Food Facts in this process.
10. Camera, photos and videos
Following an explicit user action, MacroSensei may access the camera or selected media, for example for:
Barcode scans, profile pictures, food images, recipe images, chat photos, chat videos, training media, support screenshots or importing food information from screenshots.
Access occurs only when the user uses the respective feature and grants the operating system permission.
Barcode camera images are not transmitted to Open Food Facts as complete camera images. The recognised barcode is used for the product search.
According to the current technical implementation, screenshot text recognition takes place locally on the device or locally in the browser, rather than through a generative AI service.
11. Friends, profiles and social features
MacroSensei provides features for finding, adding and managing friends.
Depending on the feature and friendship status, other users may see in particular your username or display name, profile picture, streak or reward information and selected badges.
Step and sleep badges may show, for example, that at least 5,000 steps or at least six hours of sleep were achieved on a certain number of days. Such goal achievements derived from health data may be visible on the social profile. This does not publish raw health values, sleep stages or vital signs.
Your real first and last name do not have to be displayed publicly; your chosen username or display name is used for social features.
12. Chat and shared content
MacroSensei provides direct and group communication.
Depending on the feature, text messages, photos, videos, foods, meals, recipes or training content may be sent.
Messages and media are stored on the server and are not end-to-end encrypted.
When deleting content "for me", the content is hidden from the user who deletes it. When deleting content "for everyone", the content is made inaccessible to participants in the chat view. These actions do not always immediately physically remove all original data and media from the backend.
Successful account deletion removes direct messages, the user's own group messages and shared records linked to the deleted profile from the active backend. Independent moderation cases, including secured evidence copies, may remain. Content already imported, downloaded or copied outside MacroSensei by recipients cannot technically be recalled.
13. Reports and moderation
Users can report inappropriate profiles, messages or shared product information.
In this process, the reported content, the reporting user, the reported user, the time, the reason for reporting, screenshots and internal moderation notes in particular may be stored. Reported media may be secured as a private evidence copy.
These data serve to handle reports, protect users, prevent abuse and, where applicable, assert or defend legal claims. Closing a moderation case currently does not trigger automatic deletion after a fixed number of months. Deleting the reporting account removes that account's cases. Deleting a reported account does not automatically remove independent reports submitted by other users or their associated evidence copies. See sections 27 to 29 for retention criteria and deletion requests.
14. Support
If you contact us by email or through a support feature, we process in particular your contact information, the content of your enquiry and any attachments or technical information you provide.
In-app support cases and related messages are stored in the backend and linked to the account. Closing an enquiry currently does not trigger automatic deletion after a fixed number of months. Account-linked in-app support cases are removed upon successful account deletion. Support emails are outside this app deletion process; their deletion can be requested through privacy@macrosensei.com. See section 27 for retention criteria.
Support emails are processed through Microsoft 365.
15. Push notifications
If you enable push notifications, MacroSensei processes technical push tokens or installation identifiers.
Push notifications may be used, for example, for chats, friend requests, support, reminders, streaks, training, nutrition or water.
Depending on the platform, Apple Push Notification Service, Expo or Google services, among others, may be used for technical delivery.
Push notifications can be disabled at any time in the device settings.
16. Advertising with Google AdMob
The native MacroSensei app includes the Google AdMob SDK. The current signed preview versions are configured for official Google test ads; production advertising has not been enabled.
Depending on consent, region, platform and AdMob configuration, Google may process in particular technical information such as IP address, device and advertising identifiers, advertising interactions, and diagnostic and performance data.
The native app requests privacy status through Google UMP. Depending on region, status and Google configuration, a consent message may appear where you can consent, decline consent or manage individual options. You can reopen privacy options through the corresponding app settings where Google makes them available. If the request fails, the app offers the option to continue without advertising.
The Google SDKs may store or access consent information and technical identifiers on the device. More information about Google's use of data is available at https://policies.google.com/technologies/partner-sites and https://policies.google.com/privacy.
The app does not request advertising when the relevant consent status does not permit it. Where the status and configuration permit it, non-personalised or restricted advertising formats may be used.
MacroSensei does not transmit HealthKit, Health Connect, weight, sleep, vital-sign, training, nutrition or chat content to AdMob as targeting content.
Server-side verification of voluntary rewarded ads has currently not been deployed or enabled in the production backend. This production verification data flow therefore does not currently operate. The Policy will be updated before activation to describe the identifiers, verification and reward data actually transmitted at that time.
17. Ramen Energy and rewards system
MacroSensei processes data relating to rewards, daily progress, streaks, badges and virtual items.
These include task values such as step counts or derived sleep duration, evidence identifiers, tracking days and observation times. Signed-in accounts transmit these data to the backend for the rewards system; this data flow does not require private synchronisation to be enabled.
These data serve to provide the rewards system and prevent duplicate or abusive rewards. Selected badges may be visible on the social profile; see sections 6 and 11.
18. Statistics and improvement of MacroSensei
MacroSensei may use fully anonymised statistics to improve the service.
Identifiable or pseudonymised health and fitness data are used for cross-user model improvement or comparable research or optimisation purposes only where the user has given separate explicit consent.
Names, email addresses, private chat messages and private images are not used as training data for such models.
Such optional consent must not be a prerequisite for normal use of MacroSensei.
19. Artificial intelligence
MacroSensei currently does not transmit user photos, voice recordings, chats or health data to external OpenAI, Gemini or Anthropic services for AI processing.
If MacroSensei uses external AI services in the future, for example to analyse food photos or voice input, this Privacy Policy will be updated before those features are activated. Users will be informed about the relevant processing and the respective provider.
20. Payments and Pro subscription
Where paid Pro subscriptions are offered, payments are processed through the Apple App Store or Google Play.
MacroSensei receives only the purchase, product, transaction or status information necessary to manage the subscription.
MacroSensei does not process users' complete credit card or bank details.
Technical store verification is currently still in preparation.
21. Private synchronisation and Supabase
MacroSensei uses Supabase for authentication, database functions, storage, synchronisation, social features and server-side functions, among other purposes.
When private synchronisation is enabled, private MacroSensei data and historical revisions may be stored on servers of the backend provider. These include food diaries, recipes, training data, preferences, activity data, profile and body data, weight history, steps, derived sleep information, private media references and settings, among other things.
The production Supabase project's primary region is eu-west-1 (Ireland). This identifies the primary project location and does not exclude processing by providers, subprocessors, support or other infrastructure outside that location. Supabase publishes information about its subprocessors at https://supabase.com/legal/customer-resources/subprocessor-list.
Private synchronisation settings do not control all online features: authentication, social features, support and the rewards system have separate backend data flows.
For local use and offline opening, MacroSensei stores app data on the device or in local browser storage. These local data are separate from server-side account storage. Authentication information is managed using protected device storage in the native app and the respective browser storage in the web version.
22. Website
The MacroSensei website is provided through Cloudflare.
When the website is accessed, Cloudflare may process in particular IP address, URL, browser and network information, and technical error reports.
At present, the MacroSensei website itself does not use its own analytics or advertising tracking scripts.
The public website, including this Privacy Policy, does not set its own cookies or local tracking storage. Cloudflare information is available at https://www.cloudflare.com/policies/privacy/.
23. Marketing
Service emails relating to accounts, login, security, support and essential contractual or feature information may be necessary and do not require marketing consent.
Newsletters, email advertising or other marketing communication take place only with separate consent where legally required.
Marketing consent, once given, can be withdrawn at any time with effect for the future.
24. Legal bases
Depending on the processing, we rely in particular on:
Article 6(1)(b) GDPR for performance of the user relationship and provision of requested features,
Article 6(1)(a) GDPR for processing based on consent,
Article 9(2)(a) GDPR for processing special categories of personal data based on explicit consent, in particular the relevant health data,
Article 6(1)(f) GDPR for security, abuse prevention, error analysis, protection of our services, and assertion and defence of legal claims,
Article 6(1)(c) GDPR for legal obligations.
Where processing is based on consent, that consent can be withdrawn at any time with effect for the future. Section 6 describes the current Health permissions and data flows.
25. Recipients and service providers
Depending on the feature used, personal data may be processed in particular by the following categories of recipients:
Supabase for authentication, database, storage and backend functions; Google for Google Login, AdMob/UMP and Google Play; Apple for Sign in with Apple, HealthKit, App Store and push services; Expo for app updates and certain push features; Microsoft for email services; Cloudflare for website delivery and network services; Open Food Facts and other food sources for product searches.
Data may also be deliberately disclosed to other MacroSensei users when the user uses a sharing, chat, friends or shared training feature.
26. International data transfers
MacroSensei is offered worldwide and uses providers whose processing may partly take place outside Germany or the European Economic Area. The primary Supabase project location in Ireland does not exclude such additional processing locations.
Providers publish their own information about international transfers and intended safeguards, such as adequacy decisions and standard contractual clauses. Supabase information is available at https://supabase.com/legal/customer-resources/data-processing-addendum and https://supabase.com/legal/customer-resources/subprocessor-list. That provider information does not describe all individual MacroSensei settings and agreements.
You can request information about a specific processing operation or transfer through privacy@macrosensei.com.
27. Storage period
Storage periods depend on the respective processing purpose, whether the account remains active, the handling of open enquiries or reports and, where applicable, legal retention obligations or necessary legal defence.
Account data and private synchronised data are generally stored until account deletion. Closed in-app support and moderation cases are currently not automatically deleted after a fixed number of months solely because they have been closed. Sections 13, 14 and 28 describe account-linked deletions and the independent moderation cases that may remain.
Security, audit and deletion-operation data may remain stored separately from the user account. The technical account deletion record continues to contain the account ID, a hash of the random deletion receipt, and creation and completion times; the file deletion list is cleared after successful completion. No automatic fixed deletion period is currently configured for these receipt data.
Account deletion does not immediately remove data from all provider logs, backups, email inboxes, other devices or copies saved outside MacroSensei. Retention in those systems depends on the respective system and provider; this Policy does not promise a particular backup or log deletion period. Copies already transmitted to or saved by other users may remain.
You can send deletion requests and questions about retention to privacy@macrosensei.com.
28. Deletion of the user account
Users can initiate deletion of their MacroSensei account through the designated app feature or contact privacy@macrosensei.com.
The technical deletion process removes account-owned files from the active backend, deletes the authentication account and dependent account records, and clears account-linked local app data on the device on which the process is completed. An interrupted deletion can be retried using the secret deletion receipt created beforehand.
Before removing reported original media, the process secures necessary evidence copies for independent reports submitted by other users. Such moderation cases and evidence copies, as well as certain security, audit and deletion receipt data, may remain; see sections 13 and 27.
Direct messages, the user's own group messages, shared backend records and the user's own shared product records linked to the account are removed from the active backend. Copies already imported, downloaded or saved outside MacroSensei by other users may remain.
Account deletion does not delete the source data in Apple Health or Health Connect or automatically delete support emails, provider logs, backups or copies on further devices.
29. Users' rights
Where the statutory requirements are met, you have in particular the rights of access, rectification, erasure, restriction of processing, data portability, objection and withdrawal of consent you have given.
Requests can be sent to privacy@macrosensei.com.
Users in the European Economic Area also have the right to lodge a complaint with a competent data protection supervisory authority.
Depending on your place of residence, additional regional privacy rights may apply. MacroSensei will also respect such statutory rights for users outside the EEA where the respective laws apply.
30. Sale and disclosure for advertising purposes
MacroSensei does not sell personal data for money.
Depending on the applicable law, personalised advertising may, however, be classified as "sharing", "targeted advertising" or a comparable disclosure.
Where such rights exist, users can withdraw their consent or object to such use through the privacy and advertising settings.
31. Security
MacroSensei implements technical and organisational measures to protect personal data.
These include authentication, access controls, Row Level Security, private storage areas, encrypted network connections and protected local storage for authentication information, among other measures.
Chats and app content synchronised on the server are currently not end-to-end encrypted.
No technical measure can guarantee complete protection against all risks.
32. Changes to this Privacy Policy
This Privacy Policy will be updated when features, providers used or legal requirements change.
In particular, it will be updated before future features such as address book access, voice messages or microphone use, external AI processing or additional health data imports are activated.
Users will be informed in an appropriate manner of material changes.