Privacy Policy — Macro Notes
Last updated: 16 August 2026
Macro Notes is a food diary for iPhone, developed by Warren Day ("we", "us"). This policy explains exactly what the app collects, what leaves your phone, who else touches it, and what you can do about it.
Contact: warren@overstacked.io
The short version
- Your diary stays on your phone. What you eat, your targets and your notes are stored locally on your device. We do not have a copy and cannot read them.
- We ask for no personal details. No name, no email address, no date of birth, no weight. Sign in with Apple is used, and we deliberately request no scopes from it.
- There is no analytics, no advertising and no tracking. The app contains no analytics SDK, no ad network, no crash reporter and no third-party tracker. We do not track you across apps or websites, and we do not sell or share personal data with anyone for advertising.
- We never sell your data.
The rest of this document is the detail behind those four lines.
What stays on your device
The following is held in a private database inside the app on your iPhone and is not uploaded to us:
- your daily diary — every line of text you type, the meals you organise it into, and the calorie and macro figures worked out for each line;
- your calorie and macro targets, and your meal-time settings;
- your pantry list and the foods you use most often;
- links you make between a line and a specific food, and a local cache of food data so the app keeps working offline.
Deleting the app deletes this data from your device.
What your phone syncs to your own iCloud
Foods you create or save yourself are synced through Apple's CloudKit to the private iCloud database of your own Apple Account, so they follow you to a new phone. This is storage Apple provides to you, under Apple's privacy policy. We have no access to it and no ability to read it. You can turn it off by disabling iCloud for Macro Notes in iOS Settings.
What is sent to our server, and why
Our server exists to hold a food composition database and price the lines you type. Here is every case in which your phone talks to it.
1. Looking up food
When you type a line, the text of that line is sent to our service so it can be matched against the food database and priced. This request carries no account identifier and no device identifier, and the text is not stored against you — it is used to answer the request and then discarded.
One narrow exception: if the text names a food our catalogue does not yet cover, the food term alone is added to a review queue so we know what to add. That row is the term, a count, and the dates it was first and last seen. It carries no user identifier, no link between one line and another, and nothing that could reconstruct a day.
2. The assistant (premium feature)
If you use the AI assistant, the following is sent to our server and passed on to the AI model provider so the assistant can answer:
- the message you typed and the earlier messages in that conversation;
- the day you are looking at — its meals, its lines, and the calorie and protein figures for each;
- your calorie and macro targets, your pantry, the foods you commonly eat, and roughly the last two weeks of your diary as plain text;
- your locale (for example,
en-GB).
We do not store any of it. It is held in memory for the length of the request and then gone. The only thing written down is a usage counter — an identifier, the month, how many turns you used, and what they cost — which is what enforces the monthly allowance. It contains no message content and no diary content.
The model is operated by Google and reached through OpenRouter. No account identifier, name or email is sent with the request — the provider receives the text above and nothing that identifies you to them. Their handling is governed by OpenRouter's privacy policy and Google's privacy policy.
If you never open the assistant, none of this ever happens.
3. Your account
Signing in is required before the assistant and food submissions can be used. We use Sign in with Apple and request no scopes at all — not your name, not your email address. Your account record is:
- Apple's opaque identifier for you against this app (a random-looking string that means nothing anywhere else);
- the date the account was created;
- a private-relay email address, only in the case where Apple volunteers one without being asked. Where present it is stored and never read or used to contact you.
That is the entirety of what we know about a person.
4. Subscriptions
Purchases are made through Apple; we never see your payment details. Subscriptions are managed by RevenueCat, who tell our server when a subscription starts, renews, or ends. We store the date your access runs until, which store the purchase came from, and the event history RevenueCat sends us so we can answer questions about your access.
5. Food label submissions
If you scan a barcode for a product we do not have and choose to submit it, we store the barcode, the product name, the serving size and the nutrition figures from the packet, along with your account identifier — the identifier is there so that repeated submissions of the same packet from the same person count once. When enough people independently agree on a label, the food joins the shared catalogue without any personal data attached.
6. The camera
Barcode scanning and nutrition-label reading happen entirely on your device using Apple's on-device Vision framework. No photograph or camera image is ever uploaded, stored or seen by us. Only the resulting numbers leave your phone, and only if you choose to submit them.
Who else is involved
| Who | What they do | What they get |
|---|---|---|
| Apple | Sign in with Apple, iCloud sync, App Store purchases | Your account identity; your own iCloud data; payment details (we never see these) |
| RevenueCat | Subscription management | Your account identifier and subscription status |
| OpenRouter + Google | The AI assistant model | The assistant request described above, with no identifier attached |
| Heroku (Salesforce) | Hosting for our service and database | Hosts everything described above, in the EU |
We use no other processors. There is no analytics provider, no advertising network and no crash-reporting service.
Where your data is stored
Our service and its database run on Heroku in the European Union (Ireland). Apple and our other providers may process data elsewhere, including the United States, under their own published safeguards.
How long we keep it
- Diary content: never stored by us at all.
- Assistant messages: never stored — discarded at the end of the request.
- Usage counters: one row per month, kept while your account exists.
- Account and subscription records: kept while your account exists.
- Food terms in the review queue: kept indefinitely; they identify nobody.
- Submitted food labels: kept as the record of how a shared food entered the catalogue.
Your rights
You can, at any time:
- Delete your account and everything attached to it, from within the app. This removes your account record, your subscription history, your usage counters and the link between you and anything you submitted. Foods already added to the shared catalogue remain, because they contain no personal data and other people rely on them.
- Delete everything on your device by deleting the app, and remove the synced copy through iCloud settings.
- Ask us for a copy of what we hold, ask for it to be corrected, ask us to restrict or stop processing it, or object to that processing. Write to warren@overstacked.io and we will respond within one month.
If you are in the UK or the EEA, we are the data controller for the information described here and process it on the basis of performing the service you asked for and our legitimate interest in keeping the food catalogue accurate. You have the right to complain to a supervisory authority — in the UK, the Information Commissioner's Office.
If you are a California resident: we do not sell or share personal information, and we do not use it for cross-context behavioural advertising. You have the right to know what we hold, to delete it and not to be discriminated against for exercising those rights.
A note on health information
What you eat can reveal something about your health, so we treat your diary as sensitive. That is the reason it is designed to stay on your device rather than in an account with us.
Children
Macro Notes is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has provided us with information, contact us and we will delete it.
Security
Traffic between the app and our service is encrypted in transit (HTTPS). Sign-in tokens are verified against Apple's published keys rather than trusted from the app. Access to our database is restricted to the service itself. No system is perfectly secure, but the strongest protection here is structural: most of what a food diary knows about you never leaves your phone.
Changes to this policy
If this policy changes materially, we will update the date at the top and, where the change matters, say so in the app.
Contact
Questions, requests, or anything else: warren@overstacked.io