Skip to content

Instantly share code, notes, and snippets.

@warrenday
Created August 16, 2026 20:12
Show Gist options
  • Select an option

  • Save warrenday/ebf3285499d33131dccf7c34754fd367 to your computer and use it in GitHub Desktop.

Select an option

Save warrenday/ebf3285499d33131dccf7c34754fd367 to your computer and use it in GitHub Desktop.
Macro Notes Privacy Policy
# Privacy Policy — Macro Notes
**Last updated: 16 August 2026**
Macro Notes is a food diary for iPhone, developed by Warren Day ("we", "us"). This policy
explains exactly what the app collects, what leaves your phone, who else touches it, and what
you can do about it.
Contact: **warren@overstacked.io**
---
## The short version
- **Your diary stays on your phone.** What you eat, your targets and your notes are stored
locally on your device. We do not have a copy and cannot read them.
- **We ask for no personal details.** No name, no email address, no date of birth, no weight.
Sign in with Apple is used, and we deliberately request _no_ scopes from it.
- **There is no analytics, no advertising and no tracking.** The app contains no analytics
SDK, no ad network, no crash reporter and no third-party tracker. We do not track you across
apps or websites, and we do not sell or share personal data with anyone for advertising.
- **We never sell your data.**
The rest of this document is the detail behind those four lines.
---
## What stays on your device
The following is held in a private database inside the app on your iPhone and is **not**
uploaded to us:
- your daily diary — every line of text you type, the meals you organise it into, and the
calorie and macro figures worked out for each line;
- your calorie and macro targets, and your meal-time settings;
- your pantry list and the foods you use most often;
- links you make between a line and a specific food, and a local cache of food data so the
app keeps working offline.
Deleting the app deletes this data from your device.
## What your phone syncs to your own iCloud
Foods **you** create or save yourself are synced through Apple's CloudKit to the private
iCloud database of your own Apple Account, so they follow you to a new phone. This is storage
Apple provides to you, under
[Apple's privacy policy](https://www.apple.com/legal/privacy/). We have no access to it and no
ability to read it. You can turn it off by disabling iCloud for Macro Notes in iOS Settings.
---
## What is sent to our server, and why
Our server exists to hold a food composition database and price the lines you type. Here is
every case in which your phone talks to it.
### 1. Looking up food
When you type a line, the text of that line is sent to our service so it can be matched
against the food database and priced. This request carries **no account identifier and no
device identifier**, and the text is not stored against you — it is used to answer the request
and then discarded.
One narrow exception: if the text names a food our catalogue does not yet cover, the **food
term alone** is added to a review queue so we know what to add. That row is the term, a count,
and the dates it was first and last seen. It carries no user identifier, no link between one
line and another, and nothing that could reconstruct a day.
### 2. The assistant (premium feature)
If you use the AI assistant, the following is sent to our server and passed on to the AI model
provider so the assistant can answer:
- the message you typed and the earlier messages in that conversation;
- the day you are looking at — its meals, its lines, and the calorie and protein figures for
each;
- your calorie and macro targets, your pantry, the foods you commonly eat, and roughly the
last two weeks of your diary as plain text;
- your locale (for example, `en-GB`).
**We do not store any of it.** It is held in memory for the length of the request and then
gone. The only thing written down is a usage counter — an identifier, the month, how many
turns you used, and what they cost — which is what enforces the monthly allowance. It contains
no message content and no diary content.
The model is operated by Google and reached through OpenRouter. **No account identifier, name
or email is sent with the request** — the provider receives the text above and nothing that
identifies you to them. Their handling is governed by
[OpenRouter's privacy policy](https://openrouter.ai/privacy) and
[Google's privacy policy](https://policies.google.com/privacy).
If you never open the assistant, none of this ever happens.
### 3. Your account
Signing in is required before the assistant and food submissions can be used. We use **Sign in
with Apple** and request **no scopes at all** — not your name, not your email address. Your
account record is:
- Apple's opaque identifier for you against this app (a random-looking string that means
nothing anywhere else);
- the date the account was created;
- a private-relay email address, _only_ in the case where Apple volunteers one without being
asked. Where present it is stored and never read or used to contact you.
That is the entirety of what we know about a person.
### 4. Subscriptions
Purchases are made through Apple; **we never see your payment details**. Subscriptions are
managed by [RevenueCat](https://www.revenuecat.com/privacy/), who tell our server when a
subscription starts, renews, or ends. We store the date your access runs until, which store
the purchase came from, and the event history RevenueCat sends us so we can answer questions
about your access.
### 5. Food label submissions
If you scan a barcode for a product we do not have and choose to submit it, we store the
barcode, the product name, the serving size and the nutrition figures from the packet, along
with your account identifier — the identifier is there so that repeated submissions of the
same packet from the same person count once. When enough people independently agree on a
label, the food joins the shared catalogue **without any personal data attached**.
### 6. The camera
Barcode scanning and nutrition-label reading happen **entirely on your device** using Apple's
on-device Vision framework. **No photograph or camera image is ever uploaded, stored or seen by
us.** Only the resulting numbers leave your phone, and only if you choose to submit them.
---
## Who else is involved
| Who | What they do | What they get |
| ------------------- | ---------------------------------------------------- | --------------------------------------------------------------------------------- |
| Apple | Sign in with Apple, iCloud sync, App Store purchases | Your account identity; your own iCloud data; payment details (we never see these) |
| RevenueCat | Subscription management | Your account identifier and subscription status |
| OpenRouter + Google | The AI assistant model | The assistant request described above, with no identifier attached |
| Heroku (Salesforce) | Hosting for our service and database | Hosts everything described above, in the EU |
We use no other processors. There is no analytics provider, no advertising network and no
crash-reporting service.
## Where your data is stored
Our service and its database run on Heroku in the **European Union (Ireland)**. Apple and our
other providers may process data elsewhere, including the United States, under their own
published safeguards.
## How long we keep it
- **Diary content:** never stored by us at all.
- **Assistant messages:** never stored — discarded at the end of the request.
- **Usage counters:** one row per month, kept while your account exists.
- **Account and subscription records:** kept while your account exists.
- **Food terms in the review queue:** kept indefinitely; they identify nobody.
- **Submitted food labels:** kept as the record of how a shared food entered the catalogue.
## Your rights
You can, at any time:
- **Delete your account and everything attached to it**, from within the app. This removes your
account record, your subscription history, your usage counters and the link between you and
anything you submitted. Foods already added to the shared catalogue remain, because they
contain no personal data and other people rely on them.
- **Delete everything on your device** by deleting the app, and remove the synced copy through
iCloud settings.
- **Ask us for a copy of what we hold**, ask for it to be corrected, ask us to restrict or stop
processing it, or object to that processing. Write to warren@overstacked.io and we will
respond within one month.
If you are in the UK or the EEA, we are the data controller for the information described here
and process it on the basis of performing the service you asked for and our legitimate interest
in keeping the food catalogue accurate. You have the right to complain to a supervisory
authority — in the UK, the [Information Commissioner's Office](https://ico.org.uk/).
If you are a California resident: we do not sell or share personal information, and we do not
use it for cross-context behavioural advertising. You have the right to know what we hold, to
delete it and not to be discriminated against for exercising those rights.
## A note on health information
What you eat can reveal something about your health, so we treat your diary as sensitive. That
is the reason it is designed to stay on your device rather than in an account with us.
## Children
Macro Notes is not directed at children under 13, and we do not knowingly collect information
from them. If you believe a child has provided us with information, contact us and we will
delete it.
## Security
Traffic between the app and our service is encrypted in transit (HTTPS). Sign-in tokens are
verified against Apple's published keys rather than trusted from the app. Access to our
database is restricted to the service itself. No system is perfectly secure, but the strongest
protection here is structural: most of what a food diary knows about you never leaves your
phone.
## Changes to this policy
If this policy changes materially, we will update the date at the top and, where the change
matters, say so in the app.
## Contact
Questions, requests, or anything else: **warren@overstacked.io**
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment