Version 2026-08-26

MacroTrack — Privacy Policy

Drafted: 2026-08-26 Applies to: MacroTrack for iOS, and the MacroTrack web app. Status of the product: free, publicly available, with a daily limit on AI-assisted logging. No payments, no subscriptions, no advertising, no analytics and no third-party SDKs of any kind.

The version number and the "Applies to" line above are generated from docs/legal/controller.json when this document is published — see scripts/build-legal.mjs. Change them there, not here.


1. Who is responsible for your data

The controller of your personal data is:

Neal Gysemans, Belgium Contact for anything in this policy, including privacy requests: support-mt@physiqueatlas.com

There is no Data Protection Officer. MacroTrack is built and run by one person, and that person answers privacy requests directly at the address above.


2. The short version


3. Please do not describe other people

When you type or speak a meal description, write only about yourself.

Your meal description is free text, so it can contain anything you put in it. It is sent to our AI provider (Google) for processing. Please do not include:

"200g chicken and rice" is all the app needs. If you include information about another person, you are the one making that disclosure, and we have no way to detect or remove it before it is processed.


4. What data we collect, and where it comes from

# Category Specifically Where it comes from
1 Account data Your email address; the account identifier your sign-in provider returns; a MacroTrack user ID (a random UUID); the display name and profile picture your provider returns (Apple returns a name only, and can give us a private relay address instead of your real email); sign-in timestamps From Google when you tap "Continue with Google", or from Apple when you use Sign in with Apple (iOS app only)
2 Meal and nutrition data (see the health flag below) Everything you log: food names, quantities in grams, calories, protein, carbohydrates, fat, meal type (breakfast/lunch/dinner/snack), the date and time of each entry, and a cache of foods you log often You, through the app
3 Meal descriptions (free text) The sentence you type, e.g. "two scrambled eggs and a black coffee" You, through the app
4 Voice recordings The audio clip you record when you use the microphone button, and the transcript the AI produces from it so you can check what was heard. Recordings are capped at 60 seconds You, through the app (microphone)
5 Goal data Your daily targets for calories, protein, carbohydrates and fat You, during setup
6 AI usage records For each AI request: your user ID, the type of request, the model used, token counts, how long it took, whether it succeeded, and — if it failed — a short error category (a code such as provider_timeout, never the content of your meal or recording) Generated automatically by our server
7 Technical and connection data IP address, approximate location derived from it, device and browser type, and timestamps, recorded in the server logs of our hosting and database providers Automatically, when the app connects
8 Beta tester data (Android beta only) If you receive the Android beta build through Firebase App Distribution: your email address, and device and installation information From you / from Google when you accept a tester invitation

The health flag

Categories 2, 3, 4 and 5 — what you eat, how you describe it, your voice describing it, and your nutrition goals — are treated in this policy as health-related data and are handled with extra care.

A record of everything a person eats, tracked daily against a calorie and macro target, says a great deal about their body, their habits and possibly their health. The app can also generate a weekly written analysis of your eating patterns against your goals; that insights feature is currently switched off. We therefore treat this information as sensitive, whether or not a court would classify every field as "data concerning health" under Article 9 GDPR.

What we do not collect


5. Why we use your data, and our legal basis

Purpose Data used Legal basis (GDPR Art. 6) Extra basis if health data (Art. 9)
Create and run your account; keep you signed in 1 Art. 6(1)(b) — performance of a contract (our Terms)
Store and show your meal log, daily totals and progress against your goals 2, 5 Art. 6(1)(b) — this is the service you asked for Art. 9(2)(a) — explicit consent
Convert what you type into food items and macros by sending it to our AI provider 3 Art. 6(1)(a) — consent, obtained before the first AI request Art. 9(2)(a) — explicit consent
Convert what you say into food items and macros: transcribe and parse your recording 4 Art. 6(1)(a) — consent (you must also grant the microphone permission) Art. 9(2)(a) — explicit consent
Produce your weekly nutrition insights (feature currently switched off) 2, 5 Art. 6(1)(a) — consent, given by requesting the insight Art. 9(2)(a) — explicit consent
Reuse foods you have logged before, so repeat meals stay consistent and cost nothing 2 Art. 6(1)(b) — part of the service Art. 9(2)(a) — explicit consent
Measure what AI requests cost us, size a future free allowance and prevent abuse 6 Art. 6(1)(f) — legitimate interest in running a viable, non-abusable service
Keep the service secure and available; investigate faults 6, 7 Art. 6(1)(f) — legitimate interest in security and reliability
Run the closed beta and send you the test build 1, 8 Art. 6(1)(a) — consent, given by accepting the tester invitation
Comply with legal obligations (e.g. answering a supervisory authority) any Art. 6(1)(c) — legal obligation

Where we rely on consent, you can withdraw it at any time — by turning off the relevant feature, or by writing to support-mt@physiqueatlas.com. Withdrawing consent does not affect processing that already happened. If you withdraw consent for AI processing, the free-text and voice logging features stop working; you can still use the app by picking foods you have logged before or entering macros by hand.

Where we rely on legitimate interests, you have the right to object (section 10), and we have balanced our interest against your rights: the AI usage records contain no meal content — only a user ID, request type, token counts and timings.


6. Who we share your data with

We use the following service providers ("processors"). Each acts on our instructions. We do not sell your data and we do not share it with advertisers or data brokers.

Provider Legal entity What it does for us What it receives Where it is processed
Google — Vertex AI (aiplatform.googleapis.com) Google Ireland Limited / Google LLC (United States), under the Google Cloud Data Processing Addendum Turns your meal description into structured nutrition data; transcribes your voice recordings; writes your weekly insights (currently switched off) Your typed meal description; your voice recording; the transcript it produces; for insights, seven days of your daily nutrition totals, your food names and your macro goals. No name, email or account identifier is sent with it Google's global infrastructure, including the United States — the Vertex global endpoint is not pinned to a region. See section 7
Supabase Supabase, Inc. (United States), infrastructure on Amazon Web Services Our database, sign-in system and server functions — everything the app stores All stored data: account, meal log, goals, AI usage records, connection logs Database and server functions: AWS eu-north-1, Stockholm, Sweden. Supabase staff support access may occur from the United States
Google — Sign in with Google Google Ireland Limited / Google LLC (US) Signs you in; we never see or store a password Your sign-in request. Google returns your email address, account identifier and profile details to us Google's global infrastructure, including the US
Google — Firebase Hosting Google Ireland Limited / Google LLC (US) Serves the app itself (the web files) Your IP address, device/browser type and request timestamps, in standard web server logs Google's global infrastructure, including the US
Google — Firebase App Distribution (Android beta only) Google Ireland Limited / Google LLC (US) Delivers the Android beta build to invited testers Your email address, device and installation information Google's global infrastructure, including the US

Other recipients. Apple and Google also process data in their own right as independent controllers when you download the app or join a test through the App Store, TestFlight or Google Play. On iOS you can sign in with Apple instead of Google: Apple processes that sign-in under its own terms and returns to us your email address (or a private relay address, if you choose to hide yours), a name if you share one, and an account identifier. That processing is governed by their own privacy policies, not this one. We may also disclose data if we are legally required to, or to establish or defend legal claims.

Our build and deployment tooling (GitHub Actions) never receives user data.


7. Sending data outside the EU

Your stored data lives in the EU (Sweden). However, some of the providers above are US companies or process data on global infrastructure, so some of your data is transferred outside the European Economic Area.

You can ask us for a copy of the safeguards we rely on by writing to support-mt@physiqueatlas.com.


8. How long we keep your data

Data How long
Account data and meal log For as long as your account exists. Deleting your account deletes all of it
Meal descriptions you type / voice recordings Sent to the AI provider and used to produce your result. We do not store the audio, and we do not store the raw text as a separate record — only the resulting food items land in your log. Google may retain the request briefly for abuse monitoring under its own terms
Voice transcript Shown to you so you can correct it. Not written to our database
AI usage records 24 months, then deleted. Not yet enforced — see the gap report
Server and connection logs Retained by our providers under their own schedules, typically a few days to a few weeks
Backups up to 30 days after deletion from the live database
Inactive accounts if you have not signed in for 24 months, we notify you at your registered email and delete the account 30 days later

9. Security

No system is perfectly secure. If a breach occurs that is likely to result in a high risk to your rights, we will notify you, and we will notify the Belgian Data Protection Authority within 72 hours where required by Article 33 GDPR.


10. Your rights

Under the GDPR you have the right to:

How to use them. Write to support-mt@physiqueatlas.com. We answer within one month. You can also do some of this yourself in the app:

Complaining to a supervisory authority

If you think we have handled your data unlawfully, you have the right to lodge a complaint with your local data protection authority. In Belgium that is:

Gegevensbeschermingsautoriteit (GBA) / Autorité de protection des données (APD) Drukpersstraat 35, 1000 Brussels, Belgium +32 (0)2 274 48 00 — contact@apd-gba.behttps://www.gegevensbeschermingsautoriteit.be

You may also complain to the authority in the EU country where you live or work. Complaining to an authority does not stop you from also going to court.


11. Automated processing and AI

MacroTrack uses an AI model to estimate the nutritional content of what you describe. This is an estimate, not a measurement, and it can be wrong.


12. Children

MacroTrack is not intended for anyone under 16, and we do not knowingly collect data from children. Calorie and macro tracking is not appropriate for children and adolescents without professional supervision.

If you are a parent or guardian and believe your child has created an account, write to support-mt@physiqueatlas.com and we will delete it.


13. Reserved: Paid subscription

This section is intentionally empty during the free beta.

MacroTrack is currently free and processes no payment data. Before any paid plan, subscription or in-app purchase launches, this policy will be updated to cover at minimum:

We will notify you in the app before any of this takes effect, and no payment data will be collected under this version of the policy.


14. Changes to this policy

If we make a significant change — a new processor, a new purpose, or a new category of data — we will tell you in the app and by email before it takes effect. The version number and date at the top of this document always reflect the current version.


15. Contact

Questions, requests, or complaints: support-mt@physiqueatlas.com.