Privacy Policy
Last updated: July 31, 2026
This Privacy Policy describes how Filip Piotr Kowalski, the developer of MacroLog (Google Play developer name: Melted Butter; "MacroLog", "we", "us", or "our"), collects, uses, and shares information when you use the MacroLog mobile app, its public profile pages, and macrolog.co (collectively, the "Services"). We are the data controller. Our address is CARRER Ferrers, 1, c/o Coworking Minds Sineu, 07510 Sineu, Illes Balears, Spain. You can contact us at [email protected].
We are committed to protecting your privacy and ensuring you understand how your data is handled. Please read this policy carefully.
1. Information We Collect
1.1 Information You Provide
We collect information you provide directly to us, including:
- Profile Information: Gender, date of birth, height, weight, activity level, and fitness goals (for calorie and macro calculations)
- Food and Nutrition Data: Food entries, custom foods, meal times, notes, calorie and nutrient intake, water intake, weight history, dietary preferences, recipe requests, and the information you include in photos, voice recordings, or text meal descriptions
- Voice Recordings: When using voice logging (Pro feature), your voice is temporarily processed to transcribe and identify foods
- Public Profile Information: If you publish a profile page, its username, optional display name, visibility choices, and the nutrition, profile, weight, or note data you choose to make public
- Support Communications: Feedback, diagnostic context, your message, and your email address if you choose to provide it
1.2 Information Collected Automatically
When you use our Services, we automatically collect:
- App Identifier: A randomly generated, pseudonymous device or installation ID used to authenticate sync and backup requests, join data belonging to the same installation, provide analytics, and prevent abuse. It is not your hardware serial number
- Advertising Attribution: On Android, Google Play provides the install-referrer data associated with the installation. We keep only recognized campaign parameters and ad-click identifiers, such as UTM values, gclid, gbraid, wbraid, fbclid, ttclid, and similar network click IDs, and send them to RevenueCat. Depending on the Android version installed, Google Analytics may also receive the Android Advertising ID when it is available; newer MacroLog builds remove advertising-ID and Privacy Sandbox advertising permissions because the App does not display ads. On iOS, Apple's AdServices framework provides Apple Ads attribution. MacroLog does not request the IDFA or permission to track you across other companies' apps and websites
- Usage and Search Data: App opens, screens and features used, interactions, session IDs and duration, searches performed in the app, trial usage, exports, public-page actions, and subscription events
- Technical and Diagnostic Data: App version and build, operating system, device model, locale, country setting, time zone, subscription status, limited error details, stack traces, and a shortened app identifier
1.3 Information from Third Parties
We may receive information from:
- Food Databases: OpenFoodFacts and USDA FoodData Central for nutritional information when you scan barcodes or search foods
- Payment Processors: Apple App Store and Google Play Store manage subscriptions; we receive subscription status but not payment details
- Subscription and Store Services: RevenueCat, Apple, and Google provide subscription status, product, transaction, store, price, currency, and related purchase information
- AI Services: Google Gemini and, when the primary service is unavailable, OpenAI process AI requests as described in Section 3
1.4 Health and Fitness Data (Apple Health & Google Health Connect)
If you choose to connect MacroLog to Apple Health (iOS) or Google Health Connect (Android), we access health and fitness data solely to keep your nutrition and body-weight records in sync. This integration is optional, turned off by default, and you control it entirely from the app's Settings and from Apple Health or Health Connect:
- Data we write to Apple Health / Health Connect: the nutrition of the meals you log — calories, protein, carbohydrates, and fat, plus, where the nutrient is known for that food, fiber, sugar, saturated fat, sodium, cholesterol, potassium, calcium, iron, magnesium, vitamin C, vitamin D, and vitamin B12 — along with the water you log and your body weight.
- Data we read from Apple Health / Health Connect: your body weight (to display and import your weight history) and, for information only, your daily steps and active energy burned. Steps and active energy are shown for context and are never added to your calorie budget.
Body weight — including readings imported from Apple Health or Health Connect — is synced to our servers so it is available across your devices and in your MacroLog web data portal. Steps and active energy are used only on your device and are not sent to our servers. We never share health and fitness data with any third party, use it for advertising or marketing, or sell it. You can revoke access at any time in Apple Health or Google Health Connect, or by disconnecting the integration in the app's Settings — revoking access stops all future syncing. Our use of this data complies with Apple's HealthKit terms and Google's Health Connect Permissions policy.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our Services
- Calculate your personalized calorie and macro goals
- Process and analyze food photos and voice recordings for meal logging
- Track your nutrition progress and streaks
- Sync your diary and profile, keep automatic cloud backups, and restore data on another installation
- Create a public profile page when you ask us to publish one
- Sync your logged nutrition and body weight with Apple Health or Google Health Connect when you enable the integration
- Process subscriptions and manage your installation profile
- Respond to your support requests
- Send service-related communications
- Detect, prevent, and address technical issues and abuse
- Analyze usage patterns to improve user experience
3. AI-Powered Features and Data Processing
Our AI features use Google Gemini as the primary processor and may use OpenAI as a fallback. Requests may include the photo, audio, or text you submit, your language, relevant profile context, daily nutrition totals, and, for recipe suggestions, a client-generated summary of recent meals and goals.
- Photo Analysis: Meal photos are sent through our backend to an AI processor for food identification. We do not save the image as a file or database record on our backend
- Voice Processing: Voice recordings are sent through our backend for transcription and food analysis. We do not save the audio as a file or database record on our backend
- Text Analysis: Text meal descriptions are processed to identify individual food items and estimate portions.
The transfer through our backend is real-time, but the AI provider may retain request content and technical metadata for a limited period for abuse monitoring, security, or legal compliance under its business/API terms. Paid Gemini and OpenAI API content is not used to train their models by default.
4. Data Storage and Security
4.1 Local Storage and Sync
Your food diary, profile, weight, and nutrition data are stored locally on your device using SQLite. Core diary features work offline. AI, online food search, subscription checks, sync, backup, feedback, and public profile pages require an internet connection. When you are online:
- Your data works offline and lives on your device
- Your diary, weight, profile, saved meals, and related nutrition data sync to our servers
- Automatic cloud backup is enabled by default after you create data. It uploads compressed snapshots tied to your pseudonymous app identifier; you can turn it off in Settings
- If you publish a public profile, anyone with its link or username can view and export the information you chose to show. Revoking the link prevents future access but cannot recall copies already made by others
- Uninstalling the app removes local data; data already synced to our servers remains until you request deletion (see Section 6.2)
4.2 Server Processing
For AI features, data is temporarily sent to our servers:
- Our backend is hosted on secure servers in the United States (Ashburn, Virginia)
- Photos and voice recordings are processed in real-time and not stored
- Device IDs are used to enforce usage limits and prevent abuse
4.3 Security Measures
We implement appropriate technical and organizational measures to protect your data, including:
- HTTPS encryption for all data in transit
- Secure storage on your device
- Rate limiting to prevent abuse
- Regular security reviews
5. Data Sharing and Disclosure
We do not sell your personal information. We do not use health or fitness data obtained through Apple Health or Health Connect for advertising, marketing, or data mining, and we do not disclose it except as needed to provide user-requested sync/backup or as required by law. We use the following service providers:
- Analytics: Google Firebase Analytics and our self-hosted analytics service — app identifiers, product interactions, device/app context, approximate location derived by Google from a masked IP address, subscription status, and, on older Android versions where available, the Advertising ID, for analytics, product improvement, and campaign measurement
- Subscription Management and Attribution: RevenueCat — pseudonymous subscriber identifiers, Firebase app instance ID, subscription and purchase information, and campaign parameters or ad-click identifiers from the Play install referrer or Apple Ads attribution. We do not send the Android Advertising ID or Apple's IDFA to RevenueCat
- AI Processing: Google Gemini and OpenAI — the inputs and context described in Section 3
- Error Monitoring and Feedback: our Telegram relay — redacted error details, limited device/app context, feedback content, and an email address if you provide one
- App Distribution: Apple App Store and Google Play Store for app distribution and in-app purchases
- Legal Requirements: When required by law, legal process, or to protect rights and safety
- Business Transfers: In connection with a merger, acquisition, or sale of assets (with notice)
6. Your Rights and Choices
6.1 Access and Portability
You can access your diary data in the app and export it from Settings in CSV or Markdown format. Public profile pages also offer CSV and Markdown exports for information the owner has chosen to publish.
6.2 Deletion
You can delete your data at any time:
- Individual Entries: Delete specific food entries from your diary
- Local Data: The sign-out/clear-data action removes the local database. It does not by itself delete data already synced or backed up on our servers
- Public Page: Turn off your public page in the app to revoke its link
- Server-Side Data: Use our support form or email [email protected] to request deletion. Because the App does not use an email login, we may ask you to complete a verification step from the installation that owns the data
6.3 Advertising and Analytics Choices
You can control platform-level advertising and analytics settings:
- Android: MacroLog does not display personalized ads. You can reset or delete the Android Advertising ID in system privacy settings. Google Play install attribution is collected automatically; you may ask us to delete attribution records from RevenueCat
- iOS: MacroLog does not request permission to track you across other companies' apps or websites and does not access the IDFA. Apple Search Ads attribution uses Apple's privacy-preserving AdServices framework.
You can also use the app without AI features by using only barcode scanning and manual search (included in the free tier).
7. GDPR Compliance (European Users)
If you are located in the European Economic Area (EEA), you have additional rights under GDPR:
- Legal Bases: We process data to perform our contract with you (app features, sync, backup, purchases, and support), with your consent (Health connections and publishing a public profile), and for our legitimate interests (security, abuse prevention, diagnostics, service analytics, and non-personalized campaign measurement). Where local law requires consent for analytics or attribution, consent is the basis
- Data Controller: The controller is identified at the beginning of this policy
- Your Rights: Access, rectification, erasure, restriction, portability, and objection
- Supervisory Authority: You have the right to lodge a complaint with your local data protection authority
- Data Transfers: Data may be transferred to the US for processing; we rely on standard contractual clauses where applicable
To exercise your GDPR rights, contact us at [email protected].
8. California Privacy Rights
If you are a California resident, you may have rights under the CCPA/CPRA:
- Right to Know: What personal information we collect, use, and disclose
- Right to Delete: Request deletion of your personal information
- Right to Opt-Out: We do not sell personal information. You may contact us about any processing that applicable law treats as sharing or targeted advertising
- Non-Discrimination: We will not discriminate against you for exercising your rights
To exercise your CCPA rights, contact us at [email protected].
9. Children's Privacy
Our Services are intended for adults aged 18 or older and are not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has used the Services, contact us so we can delete the data.
10. Data Retention
We retain your data as follows:
- Local Data: Retained on your device until you delete it or uninstall the app
- Synced App Data: Retained until you request deletion. Deleted diary rows may remain as sync tombstones long enough to propagate deletion across installations
- Cloud Backups: We keep up to the 10 newest snapshots and delete older snapshots when a new one is uploaded. Turning backup off stops new uploads but does not delete existing snapshots; contact us to delete them
- Analytics Data: Firebase event-level data is retained for up to 14 months. First-party analytics and search-query logs are retained until deleted under our operational schedule or when you request deletion
- Website app-prompt preference: If you dismiss the app-download banner on macrolog.co, we store the first-party localStorage key
macrolog_app_upsell_dismissed_at_v1for seven days so the banner does not reappear during that period. This local display preference is not sent to Google Analytics - AI Processing: We do not persist raw photo or audio files in our backend database. AI providers may keep limited abuse-monitoring logs under their API terms
- App Identifiers: Retained for authentication, sync, analytics, and abuse prevention. On iOS, secure system storage may preserve the identifier after reinstalling the app; reinstalling is not a deletion method
- Attribution Data: Install-referrer data is retained by RevenueCat with the pseudonymous subscriber record until deletion. Google controls retention of Firebase Analytics identifiers and campaign data under our Analytics settings
- Support Communications: Retained for customer service purposes
- Public Shares: Revoked share records and aggregate view counts may be retained for security and audit purposes, while the public content becomes unavailable
- Health & Fitness Data: Weight synced from Apple Health / Google Health Connect is retained until you delete it (on your device and on our servers); steps and active energy are shown only on-device and not stored. Revoke access anytime in those apps or in MacroLog's Settings
11. Third-Party Services
Our app integrates with the following third-party services:
- Google Firebase Analytics: App usage analytics and advertising campaign measurement — Privacy Policy
- Google Gemini: AI processing for food and recipe features — API Terms
- OpenAI: fallback AI processing — Privacy Policy
- RevenueCat: Subscription management and analytics — Privacy Policy
- OpenFoodFacts: Food database for barcode scanning
- USDA FoodData Central: Nutritional information database
- Apple Health (HealthKit): Optional on-device sync of your nutrition and weight on iOS — governed by Apple's Privacy Policy
- Google Health Connect: Optional on-device sync of your nutrition and weight on Android — see Health Connect
- Apple App Store: App distribution and in-app purchases (iOS)
- Google Play Store: App distribution and in-app purchases (Android)
- Telegram relay: operational error reports and user-submitted feedback
Each service has its own privacy policy governing their data practices.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Updating the "Last updated" date at the top of this policy
- Posting a notice in the app for significant changes
We encourage you to review this policy periodically.
13. Contact Us
If you have questions about this Privacy Policy or our data practices, please contact us:
- Email: [email protected]
- Support Form: macrolog.co/support
We will respond to your inquiry within 30 days.