Privacy Policy — Macro Notes

Last updated: 1 October 2026

Macro Notes is a food diary for iPhone, developed by Warren Day ("we", "us"). This policy explains exactly what the app collects, what leaves your phone, who else touches it, and what you can do about it.

Contact: warren@macronotes.app


The short version

  • Your diary is yours. What you eat, your targets and your notes are stored on your device and, if iCloud is on, in your own iCloud account. We do not have a copy and cannot read them.
  • We ask for no personal details. No name, no date of birth, no weight, and no email address unless you choose to add one in Settings. Sign in with Apple is used, and we deliberately request no scopes from it.
  • No tracking, no advertising network, no data sales. The app counts how its features are used (which screens, which buttons — never what you ate) through a product-analytics service hosted in the EU, and it lets Apple tell us when an install came from one of our own App Store ads. Neither joins your data with anyone else's, and neither follows you across other apps or websites. There is no ad network and no crash reporter.
  • We never sell your data.

The rest of this document is the detail behind those four lines.


What is stored on your device

The following is held in a private database inside the app on your iPhone and is not uploaded to us:

  • your daily diary — every line of text you type, the meals you organise it into, and the calorie and macro figures worked out for each line;
  • your calorie and macro targets, and your meal-time settings;
  • your pantry list and the foods you use most often;
  • links you make between a line and a specific food, and a local cache of food data so the app keeps working offline.

Deleting the app deletes this data from your device. The local cache of food data never leaves the device.

Apple Health

If you turn on Settings → Apple Health → Adjust for Activity, the app asks iOS for permission to read one figure: the active energy you have burned today. It is used, there and then, to work out that day's calorie target — 2,100 plus what you burned — and is then discarded.

  • The reading itself is never stored. What is written down is the calorie target it produced, which is a goal of the same kind as one you type in yourself.
  • The app never writes anything to Health, and asks for no permission to.
  • No health data is sent to our server, to the assistant, or to anyone else.
  • Turning the setting off stops the app reading Health. It leaves days you have already logged exactly as they were, because a day keeps the numbers it was tracked against.

You can withdraw access at any time in the Health app, under Profile → Privacy → Apps.

What your phone syncs to your own iCloud

Your diary — every line you type, your meals, targets and settings (including a day's calorie target where activity has been allowed for), your pantry, the portions the app remembers for you and the foods you create — is synced through Apple's CloudKit to the private iCloud database of your own Apple Account, so it follows you to a new phone. This is storage Apple provides to you, under Apple's privacy policy. We have no access to it and no ability to read it. You can turn it off by disabling iCloud for Macro Notes in iOS Settings; the app keeps working on the device.


What is sent to our server, and why

Our server exists to hold a food composition database and price the lines you type. Here is every case in which your phone talks to it.

1. Looking up food

When you type a line, the text of that line is sent to our service so it can be matched against the food database and priced. The request is signed with your session so the service knows it came from a signed-in app, and the text is not stored against you — it is used to answer the request and then discarded.

One narrow exception: if the text names a food our catalogue does not yet cover, the food term alone is added to a review queue so we know what to add. That row is the term, a count, and the dates it was first and last seen. It carries no user identifier, no link between one line and another, and nothing that could reconstruct a day.

2. The assistant (premium feature)

If you use the AI assistant, the following is sent to our server and passed on to the AI model provider so the assistant can answer:

  • the message you typed and the earlier messages in that conversation;
  • the day you are looking at — its meals, its lines, and the calorie and protein figures for each;
  • your calorie and macro targets, your pantry, the foods you commonly eat, and roughly the last two weeks of your diary as plain text — where a day's calorie target has been adjusted for activity, the assistant is told the adjusted goal, so that what it suggests fits the day you actually have. It is sent a calorie target, never a health measurement;
  • your locale (for example, en-GB).

We do not store any of it. It is held in memory for the length of the request and then gone. The only thing written down is a usage counter — an identifier, the month, how many turns you used, and what they cost — which is what enforces the monthly allowance. It contains no message content and no diary content.

The model is operated by Google and reached through OpenRouter. No account identifier, name or email is sent with the request — the provider receives the text above and nothing that identifies you to them. We instruct OpenRouter to route requests only to endpoints whose published policy is not to retain prompts or use them for training. Their handling is governed by OpenRouter's privacy policy and Google's privacy policy.

Nothing is sent until you agree. The first time you open the assistant, the app shows you what a question travels with and asks your permission; the assistant cannot be used until you give it. You can withdraw that permission at any time in Settings → Assistant, after which nothing further is sent unless you agree again.

If you never open the assistant, none of this ever happens.

3. Your account

Signing in is required before the assistant and food submissions can be used. We use Sign in with Apple and request no scopes at all — not your name, not your email address. Your account record is:

  • Apple's opaque identifier for you against this app (a random-looking string that means nothing anywhere else);
  • the date the account was created;
  • a private-relay email address, only in the case where Apple volunteers one without being asked. Where present it is stored and never read or used to contact you;
  • an email address, only if you add one in Settings → Email. It is optional and you can change or remove it there at any time. We use it to answer support questions and to find your account if we work with you as a creator, for example to give you free Pro. It is also passed to RevenueCat (section 4) so your account can be found there. We do not send marketing emails to it, and would ask for your separate consent before ever doing so.

That is the entirety of what we know about a person.

4. Subscriptions

Purchases are made through Apple; we never see your payment details. Subscriptions are managed by RevenueCat, who tell our server when a subscription starts, renews, or ends. We store the date your access runs until, which store the purchase came from, and the event history RevenueCat sends us so we can answer questions about your access.

5. Food label submissions

If you scan a barcode for a product we do not have and choose to submit it, we store the barcode, the product name, the serving size and the nutrition figures from the packet, along with your account identifier — the identifier is there so that repeated submissions of the same packet from the same person count once. When enough people independently agree on a label, the food joins the shared catalogue without any personal data attached.

6. The camera

Barcode scanning happens entirely on your device, using Apple's on-device Vision framework. No camera image is uploaded to scan a barcode.

Packet photos. When you scan a product we do not have yet, the app offers to fill it in from two photos: the front of the pack and its nutrition label. If you take them, each photo is sent to our server and from there to an AI model operated by Google, reached through OpenRouter, which reads the product's name and the figures printed on the label. No account identifier, name or anything else that identifies you is sent with a photo. We instruct OpenRouter to route requests only to endpoints whose published policy is not to retain or train on them.

The photo is read once and then discarded: we do not store it, and neither does our server's log. What we keep is a count — that a photo was read on your account, whether it worked, and what the read cost us — so that a daily limit can be applied. The figures that come back fill in a form on your phone; nothing is saved until you tap Save, and they reach us only as the food label submission described in section 5. You can always type the figures in instead.

7. Product analytics

The app sends a short record of certain moments to PostHog, a product-analytics service, hosted in the European Union. The moments are: the app was opened; which screen of the app or of the setup questions was shown (its name only, never your answers); a sign-in finished, failed or was cancelled, or a session ended; the diary was first tapped into; a diary line was logged, or a line was one the food database did not recognise (only that it happened and the kind of reason, never the words); a barcode was found or not found; a packet photo was read (which side, whether it worked and roughly how long it took, never what it said); a nutrition label was saved (and how many of its fields you changed); the food service could not be reached; the subscription offer was shown, closed, started, cancelled or had nothing to offer; the Apple Health adjustment was switched on or off; iCloud could not save or set up your diary, or recovered (an error number only); and the answer to a single optional "how did you hear about us?" question.

Each record carries your account identifier, the app version, the device model, the iOS version, the region your device is set to and whether the app came from the App Store or a test build. It never carries the text of a line, a food name, a weight, a calorie figure, a meal name or an assistant message. The events are used to see which parts of the app are used, where the food database has gaps, and how many people who install the app go on to use it. Deleting your account deletes them.

Before you sign in, these events are filed under a random identifier that the app generates; signing in joins them to your account. Signing out breaks the link on the device.

8. Apple Ads attribution

If you installed Macro Notes after tapping one of our ads in the App Store, Apple can tell us so. The app collects Apple's attribution token and passes it to RevenueCat, which asks Apple which campaign the install came from and records the answer against your subscription. The token says only whether an Apple Ads campaign led to the install and which one; it does not identify you to Apple in any new way, and it involves no other company's data. Apple treats this as attribution, not tracking, and no App Tracking Transparency permission is requested.

9. The website

macronotes.app uses the same analytics service, without cookies: a visit is counted for the length of the page and nothing is stored in your browser, so a return visit is a new visitor. We record the pages viewed, the campaign the visit came from (from the address you arrived on) and taps on the download button. A visit to the site is never joined to an app account.


Who else is involved

Who What they do What they get
Apple Sign in with Apple, iCloud sync, App Store purchases Your account identity; your own iCloud data; payment details (we never see these)
RevenueCat Subscription management Your account identifier, subscription status, and your email address if you added one
OpenRouter + Google The AI assistant model, and reading packet photos The assistant request and packet photos described above, with no identifier attached
Heroku (Salesforce) Hosting for our service and database Hosts everything described above, in the EU
PostHog Product analytics, hosted in the EU The events in section 7: your account identifier and the moments listed, never diary content

We use no other processors. There is no advertising network and no crash-reporting service. Every processor listed here is bound by its published terms to protect your data to at least the standard described in this policy, and none may use it for its own purposes.

Where your data is stored

Our service and its database run on Heroku in the European Union (Ireland). Apple and our other providers may process data elsewhere, including the United States, under their own published safeguards.

How long we keep it

  • Diary content: never stored by us at all.
  • Assistant messages: never stored — discarded at the end of the request.
  • Packet photos: never stored — discarded once read. The count of photos read is kept while your account exists.
  • Usage counters: one row per month, kept while your account exists.
  • Account and subscription records: kept while your account exists.
  • The email address you add in Settings: kept until you remove it or delete your account.
  • Food terms in the review queue: kept indefinitely; they identify nobody.
  • Submitted food labels: kept as the record of how a shared food entered the catalogue.
  • Analytics events: kept while your account exists, and deleted with it.

Your rights

You can, at any time:

  • Delete your account and everything attached to it, from within the app. This removes your account record (including any email address you added, which is also removed from RevenueCat), your subscription history, your usage counters, your analytics events and the link between you and anything you submitted. Foods already added to the shared catalogue remain, because they contain no personal data and other people rely on them.
  • Delete everything on your device by deleting the app, and remove the synced copy through iCloud settings.
  • Ask us for a copy of what we hold, ask for it to be corrected, ask us to restrict or stop processing it, or object to that processing. Write to warren@macronotes.app and we will respond within one month.

If you are in the UK or the EEA, we are the data controller for the information described here and process it on the basis of performing the service you asked for and our legitimate interest in keeping the food catalogue accurate. You have the right to complain to a supervisory authority — in the UK, the Information Commissioner's Office.

If you are a California resident: we do not sell or share personal information, and we do not use it for cross-context behavioural advertising. You have the right to know what we hold, to delete it and not to be discriminated against for exercising those rights.

A note on health information

What you eat can reveal something about your health, so we treat your diary as sensitive. That is the reason it is designed to live on your device and in your own iCloud rather than in an account with us.

Children

Macro Notes is not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has provided us with information, contact us and we will delete it.

Security

Traffic between the app and our service is encrypted in transit (HTTPS). Sign-in tokens are verified against Apple's published keys rather than trusted from the app. Access to our database is restricted to the service itself. No system is perfectly secure, but the strongest protection here is structural: most of what a food diary knows about you never leaves your phone.

Changes to this policy

If this policy changes materially, we will update the date at the top and, where the change matters, say so in the app.

Contact

Questions, requests, or anything else: warren@macronotes.app