At a Glance
- You control your data: log meals, photos, weight, and Health activity only when you choose to.
- We share data only with the services needed to make the App work (AI, food databases, login, support).
- No advertising SDKs, no sale of personal data, no third-party data brokers.
- You can delete your account and all associated data anytime in Settings → Delete Account.
- Country is derived from your device timezone — we do not collect GPS or precise location.
This Privacy Policy describes how MacroLeaf AI ("we", "us", "our", or "the App"), operated by MacroLeaf, handles your information. By creating an account or using the App, you acknowledge that you have read and understood this Policy.
Contents
- Introduction & Scope
- Information We Collect
- How We Use Your Data
- Legal Bases (GDPR)
- Apple Health (HealthKit)
- AI & Automated Features
- Support & Feedback
- Anonymous Chatbot
- How We Share Data
- Storage & Security
- Diagnostic Telemetry
- Internal Access (Admin)
- Data Retention
- Your Privacy Rights
- Children's Privacy
- Permissions
- Local Storage
- International Transfers
- Data Breaches
- Medical Disclaimer
- Changes
- Contact
1.Introduction & Scope
MacroLeaf AI is a nutrition, calorie, and fitness tracking application offering AI-assisted food logging and general wellness guidance. This Policy applies to all data processed through the App, the support website (macroleafai.in/support), and connected services. It does not cover third-party services that operate under their own privacy policies (see Section 9).
2.Information We Collect
| Category | Examples | Why we collect it |
|---|---|---|
| Account & identity | Name, email, account ID, login method (email / Google / Apple) | To create and secure your account and sync your data |
| Profile & body metrics | Age, gender, height, current & goal weight, activity level, dietary preferences | To calculate personalized calorie and macro goals |
| Health & activity (HealthKit) | Steps, distance, flights climbed, active energy, exercise minutes | To display your daily activity and progress (with your permission) |
| Food, diary & progress | Logged meals/foods, calories, macros, water, exercises, weight history, saved recipes/meals | To track your nutrition and goals over time |
| Camera, photos & voice | Meal photos, voice descriptions, scanned barcodes (only when you use these features) | To identify foods and estimate nutrition via AI / databases |
| Support messages | Name, email, subject, message body, category (Question / Bug / Feature / Account / Other), source (web or app) | To respond to your support requests and improve the App |
| Diagnostic events | App version, session start / end, session duration, AI Coach usage count, food log count, device timezone | To monitor app health, fix bugs, measure performance |
| Derived country | Country name inferred from your device's time zone (e.g. "United States" from America/New_York) | For aggregate geography statistics — we do NOT collect GPS or precise location |
| Push notification preference | Boolean (on / off) | To respect your notification choice across reinstalls |
We do not use third-party advertising SDKs or sell data to data brokers.
3.How We Use Your Data
- Calculate personalized calorie, macro, water, and step goals.
- Record and display meals, water, exercise, weight, and Health activity.
- Power AI features — food photo/voice recognition and the AI Coach.
- Send optional local reminders and notifications.
- Sync your data securely across sessions and devices.
- Respond to your support messages and resolve issues you report.
- Monitor app stability, measure feature usage in aggregate, and improve the App.
- Maintain security, prevent abuse, and comply with our legal obligations.
4.Legal Bases for Processing (where GDPR applies)
- Consent — for health data, camera, microphone, and notifications (you grant these explicitly).
- Contract — to provide the core features you sign up for.
- Legitimate interests — to secure, monitor, and improve the App; respond to support requests.
You may withdraw consent at any time by disabling the relevant permission or deleting your account.
5.Apple Health (HealthKit)
- We will never use HealthKit data for advertising or marketing.
- We will never sell HealthKit data or disclose it to third parties for their own purposes.
- You can revoke access any time in iOS Settings → Privacy & Security → Health → MacroLeaf AI.
6.AI & Automated Features
AI providers we use
- Groq (Meta Llama models) — primary AI Coach chat. Groq Privacy Policy
- Google AI (Gemini models, via Google AI Studio) — fallback AI Coach chat. Google Privacy Policy
- OpenAI (GPT-4o-mini, GPT-4o for vision) — backup chat, photo scan, voice log. OpenAI Privacy Policy
- Google Cloud Vision — barcode reading from photos. Google Cloud Privacy Notice
Data sent to AI (only after consent)
- Your chat message text
- Today's logged meals (food names, calories, macros)
- Your dietary preferences and weight goal
- Profile context: age, gender, height, weight, activity level (self-reported, not from HealthKit)
- Food photos (only when you use Photo Scan)
- Voice transcript (only when you use Voice Log)
Data we never send to AI
- Apple HealthKit data (steps, active calories, heart rate, workouts) — kept on-device only, never transmitted to AI providers. This satisfies Apple Guideline 5.1.2(vi).
- Your name, email, phone number, or account identifier
- Your account password or auth tokens
- Location data (we don't collect any)
- Photos other than what you explicitly submit to Photo Scan
Equal Protection of Your Data (Apple Guideline 5.1.1(i))
All AI providers listed above provide protection of your data equal to or stronger than the protections in this Privacy Policy. Specifically, each provider contractually agrees not to:
- train AI models on your messages or chats,
- retain your data beyond what is necessary to generate a response,
- sell your data to any third party,
- use your data for advertising or tracking.
We send only the minimum data needed to answer your question. AI outputs are estimates and general wellness guidance only — not exact nutrition values and not medical advice.
How to revoke AI consent
- In the app: Settings → AI Coach & Data Sharing → toggle OFF. This immediately stops all data sharing with AI providers.
- Effect: AI Coach, Photo Scan, and Voice Log are disabled. All other app features (manual food logging, water, weight, search) continue to work normally.
- Re-enable: toggle ON; the consent screen is shown again.
Methodology & Sources for Health Data (Apple Guideline 1.4.1)
MacroLeaf AI displays calorie, macronutrient, BMR, TDEE, weight projection, and hydration values that are calculated using published, peer-reviewed equations. Every number shown in the app is traceable to a public source:
- Basal Metabolic Rate (BMR): Mifflin-St Jeor equation (1990) — Am J Clin Nutr 51:241-247.
- Total Daily Energy Expenditure (TDEE): Physical Activity Level (PAL) multipliers from WHO/FAO/UNU Human Energy Requirements (2001).
- Macronutrient targets: IOM Dietary Reference Intakes (2005) — Acceptable Macronutrient Distribution Ranges.
- Weight change projections: Hall et al. (2011) Lancet energy balance model.
- Food nutrition data: USDA FoodData Central, Open Food Facts, and Indian Food Composition Tables (NIN/ICMR).
- Activity calorie estimates: Compendium of Physical Activities (Ainsworth et al., 2011) and Apple HealthKit.
- Hydration targets: Institute of Medicine Adequate Intake (2005) and EFSA reference values (2010).
The full bibliography with clickable links and the exact formulas used is published at citations.html and is accessible inside the app via Settings → Legal → Sources & Citations, plus inline footers on the AI Coach, Diary, Progress, and Meals screens.
7.Support & Feedback
- What we collect: name, email, subject, message, category (Question / Bug Report / Feature Request / Account Help / Other), and source (web or app).
- AI Coach reports. If you tap the ⚠️ icon in the AI Coach header to report an inappropriate response, the report includes the quoted AI reply text (auto-attached for context), your description of the issue, your account name and email, and a timestamp. Reports are categorized as "Bug Report" and used to refine the AI's hardcoded safety rules.
- What we use it for: replying to you, fixing reported bugs, prioritizing feature work, improving AI safety rules, and detecting abuse.
- Retention: support tickets and AI Coach reports are retained for up to 12 months after resolution unless you ask us to delete them sooner.
- You may opt out of further contact at any time by emailing support@macroleafai.in.
8.Anonymous Chatbot
- Your question is sent to a secure server function which forwards it to Groq (LLM provider) to generate an answer.
- We do not store the conversation. Groq processes the query in real time and does not retain it beyond responding.
- If you ask the chatbot to send a support ticket, you'll be asked for your email so we can reply — at that point Section 7 applies.
- To stop using the chatbot, simply close it. No persistent identifier is set.
9.How We Share Data (Service Providers)
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Cloud database, authentication, edge functions | Account info, logs, profile, support messages, diagnostic events |
| Vercel | Web hosting (privacy policy, support page, admin panel) | Web request metadata only (no app account data) |
| Sign in with Apple | Optional login (Apple's privacy-preserving sign-in; supports anonymous email relay) | Email (real or Apple relay), name, auth token |
| Google OAuth | Optional login | Email, name, auth token |
| Groq (Meta Llama) | AI Coach chat — primary provider | Chat text, today's food log, profile context (no HealthKit, no name/email) |
| Google AI (Gemini) | AI Coach chat — fallback provider | Chat text, today's food log, profile context (no HealthKit, no name/email) |
| OpenAI (GPT-4o, GPT-4o-mini) | Photo Scan, Voice Log, backup chat, anonymous support chatbot | Food photos, voice transcript, chat text (no HealthKit, no name/email) |
| Google Cloud Vision | Barcode reading from photos | Photo data for barcode detection only |
| Open Food Facts / USDA | Public nutrition lookup | Search terms, barcodes |
| The HostMe (email hosting) | Receiving support emails sent to support@macroleafai.in | Email content you send to us |
We share only what is necessary for each function. We may also disclose data if required by law or to protect rights and safety.
10.Storage, Location & Security
- Data is stored in secure cloud infrastructure (Supabase) and cached on your device.
- Access is restricted to your own account through database-level Row Level Security (RLS) rules.
- All network traffic uses encrypted (HTTPS/TLS) connections.
- Edge functions sit behind authentication and CORS restrictions.
- While we apply reasonable safeguards, no system is 100% secure.
11.Diagnostic Telemetry & Analytics
- Events recorded: session start, session end (with duration), AI Coach message sent (length only — not content), food logged (count only), app version, opt-in status for notifications.
- What we do NOT record: message contents, individual food names tied to your identity for analytics, location coordinates, contacts, screen recordings.
- Aggregation: in admin dashboards, only aggregate counts are shown (e.g., "12 messages today"). Individual rows are not surfaced except support tickets.
- Retention: diagnostic events are retained for up to 90 days then deleted.
12.Internal Access (Admin Roles)
For day-to-day operation, a small number of authorized team members may access:
- Aggregate statistics (total users, daily/weekly active users, signup country breakdown).
- Individual support tickets you submit (to reply to them).
- Anonymized error and diagnostic event counts.
Administrative access is gated by a separate authenticated admin account and protected by database-level rules (only the admin email can read these tables). We log internal admin actions and use them only to provide and improve the service.
13.Data Retention & Deletion
- Profile, diary, weight, recipes: retained while your account is active.
- Diagnostic events: up to 90 days.
- Support tickets: up to 12 months after resolution.
- Logs / backups: rotated and overwritten within a limited period.
- Account deletion: you can delete your account and all associated data at any time in Settings → Delete Account. This permanently removes your profile, diary, recipes, meals, water, exercise, weight records, and diagnostic events tied to your user ID.
14.Your Privacy Rights
Depending on your location (including under GDPR and CCPA), you may have the right to:
- Access the personal data we hold about you.
- Correct or update inaccurate data.
- Delete your data ("right to be forgotten").
- Export/port your data.
- Object to or restrict certain processing, and withdraw consent.
- Not be discriminated against for exercising these rights.
To exercise any right, use the in-app controls or contact us (Section 22). We do not sell personal information.
15.Children's Privacy
MacroLeaf AI is not directed to children under 13 (or the minimum age in your country). We do not knowingly collect their data. If you believe a child has provided us information, contact us and we will delete it.
16.Permissions & Notifications
The App requests the following iOS permissions only when you use the related features. You may grant or revoke each at any time in iOS Settings → Privacy & Security.
| Permission | Used for |
|---|---|
| Camera | Capturing meal photos for AI food identification, and scanning barcodes |
| Photo Library (Add) | Saving meal photos you take inside the App to your iPhone Photos (only when you choose to save) |
| Microphone | Recording your voice for voice-based meal logging |
| Speech Recognition | Transcribing your voice to text on-device (Apple's Speech framework) for voice logging |
| Health (HealthKit) | Reading steps, active energy, weight, workouts to show your activity (see Section 5) |
| Notifications | Local reminders for meals, water, and steps (scheduled on your device only) |
Location: We do NOT request iOS Location permission. The country shown in our aggregate geography statistics is derived from your device's time zone (e.g., America/New_York → United States), not from GPS, Wi-Fi triangulation, or IP geolocation.
Notifications: All notifications are local — scheduled on your device. We do not currently use remote push (APNs) to deliver notifications.
17.Local Storage / Cookies
The App stores certain settings and cached data locally on your device (e.g., your goals and recent logs) to work quickly and offline. The support website may use a brief sessionStorage value to keep your chatbot session ID. None of this is shared off-device until you submit a request.
18.International Data Transfers
Your data may be processed in countries other than your own, including where our service providers operate. We take steps to ensure appropriate safeguards for such transfers.
19.Data Breaches
If a data breach affecting your personal data occurs, we will take prompt action and notify affected users and authorities where required by applicable law.
20.Medical Disclaimer
21.Changes to This Policy
We may update this Policy periodically. Material changes will be reflected by the "Last updated" date above and, where appropriate, an in-app notice. Continued use after changes constitutes acceptance.
22.Contact Us
For privacy questions, data requests, or grievances, contact:
MacroLeaf
Email: support@macroleafai.in