Effective date: August 7, 2026 · Last updated: August 7, 2026
MadMacros is a personal nutrition, macro, and workout tracking app for iOS. This policy explains what data the app handles, how it is collected, how it is used, who it is shared with, how long it is kept, and how you can delete it. MadMacros does not use advertising, ad SDKs, or data brokers, and it does not track you across apps or websites.
Your use of MadMacros is also governed by our Terms of Service, which contain health disclaimers and limitations of liability. This Privacy Policy forms part of those Terms.
Most of what you enter never leaves your device. Your meal nutrition details (food names, calories, and macros), all workout data (splits, exercises, and logged sets), your weight-entry history, saved presets, saved restaurants, and cached lookups are stored locally using Apple's SwiftData.
These records are not uploaded to our servers, with two exceptions described below. The single current weight used to calculate your goals is synced as a body metric, and the names of your saved presets may be sent as context with an AI request.
MadMacros signs you in with an anonymous account: a random user ID carrying no name, email, phone number, or other real-world identity. That ID exists only to keep your synced data separate from other users'. A limited slice of your data is synced to our backend (Supabase) so it can power app functionality.
This synced data is tied to your anonymous ID only, is used solely to run the app for you, and is never sold or used for advertising.
Four features use AI: chat logging, restaurant menu generation, manual-entry estimates, and activity-level inference. When you use one, the text you type (a food description, a restaurant name, or an activity description) is sent through our secure server to one of several third-party large language model providers, which returns an estimate or a classification.
Alongside that text, the app may send limited context so the estimate is more useful: the names of your saved presets, and the cached menu for a restaurant you are currently viewing. Nothing identifying you is ever sent. No name, email, phone number, or location accompanies an AI request.
These providers may retain the submitted text for a period to monitor for abuse, under their own terms. MadMacros asks for your explicit consent before the first AI request is sent, and every AI estimate is labelled as approximate. AI output is not medical or dietary advice.
The camera is used only for on-device barcode scanning. Camera images are never stored or uploaded.
To enforce fair-use limits on the AI features, we keep a small server-side counter of how many AI requests your anonymous ID makes per day. These counters hold request counts and dates only, with no health data attached. As described in Section 4, they are retained after you delete your data, so the daily limit cannot be reset by deleting and re-creating data.
The services and providers that process data on our behalf do so under their own privacy terms, which provide equal or better protection of the limited data described above. We credit and link the data sources the app relies on.
We hold as little data as possible, which limits what could ever be exposed. Beyond that:
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your data, we will notify affected users and any regulators as required by applicable law.
You can delete everything from inside the app at any time.
This removes your synced rows from our backend (meal timestamps, body metrics, and goal targets), clears the app's local database (meals, workouts, weight history, presets, and saved restaurants), and signs you out of your anonymous session.
Some local convenience state sits outside that database and is not cleared by this action: your recently used fast-food items and how often you have opened each chain, your unit and prompt-dismissal preferences, the AI quota remaining for the day, and your device's temporary network cache of dining-hall menus and scanned barcode results. None of it leaves your device, none of it contains account or identity information, and all of it is removed when you delete the app from your iPhone.
Because the account is anonymous and holds no personal identity, this deletes your data and signs you out rather than deleting an "account" in the traditional sense. The empty authentication stub left behind holds no personal data. The one exception is the fair-use AI usage counters described above, which are retained server-side and contain no health or identity data.
You can revoke your consent to the AI features at any time by not using them. Declining the consent prompt cancels the request, and nothing is sent.
Depending on where you live, you may have rights over your personal information under state privacy laws such as the California Consumer Privacy Act (CCPA/CPRA) and comparable laws in Colorado, Connecticut, Virginia, Utah, Texas, and Oregon. We extend the rights below to every user, regardless of state.
We have never sold personal information, and we do not "share" it for cross-context behavioral advertising, as the CCPA and CPRA define those terms. We do not use your health, nutrition, or fitness data for advertising, marketing, or data mining, and we do not disclose it to data brokers. There is no opt-out to exercise here, because none of these things happen.
Section 1 describes what we handle. In the vocabulary of these laws:
One limitation follows from the anonymous design. Because we hold no name, email, or other identifier, we cannot verify that a given anonymous ID belongs to you, so we cannot safely act on an individual access, correction, or deletion request sent by email. Doing so could expose one person's data to another. That is why each of these rights is built into the app instead, where you already control the data. The CCPA and similar laws do not require a business to re-identify information in order to respond to a request. For a privacy question we can answer without identifying you, or to appeal a decision, email austinkyuhan@gmail.com. You may also designate an authorized agent, and California residents may contact the California Attorney General or the California Privacy Protection Agency.
MadMacros is operated from the United States, and the limited synced data described in Section 1 is processed and stored on servers there. If you use the app from outside the U.S., your information will be transferred to and processed in the U.S., where data-protection laws may differ from those in your country.
The app is currently offered in the United States, the United Kingdom, Canada, Japan, Australia, and other App Store territories. It is not offered in the European Union or the European Economic Area.
If you are in the UK, the UK GDPR and the Data Protection Act 2018 apply to our handling of your personal data. Austin Han, trading as MadMacros, is the data controller. Our legal bases are:
You have the rights of access, rectification, erasure, restriction, objection, and data portability. As explained in Section 5, these are built into the app because we cannot verify identity for an anonymous account. Transfers to the U.S. rely on your explicit consent and on the necessity of the transfer to perform the service you requested. You also have the right to lodge a complaint with the UK Information Commissioner's Office at ico.org.uk or 0303 123 1113.
We handle your data consistently with the principles of Canada's PIPEDA, Australia's Privacy Act and Australian Privacy Principles, and Japan's APPI. We collect only what is needed, tell you what we collect, obtain consent before AI processing, keep the data out of advertising, and provide a deletion path that works. Australian users may complain to the OAIC, and Canadian users to the Office of the Privacy Commissioner.
MadMacros is a general-audience wellness app and is not directed at children under 13. It does not knowingly collect personal information from them, and our Terms of Service require users to be at least 13 years old. If you believe a child under 13 has provided us information, contact austinkyuhan@gmail.com and we will delete it. Because the app collects no name, email, or contact details, we have no practical means of determining a user's age on our own.
If this policy changes materially, the updated version will be posted at this URL with a new "last updated" date.
Questions about this policy or your data: