Sensitive data
Consumer Health Data Privacy Policy
Extra detail about how Makro handles nutrition, weight, goals, meal content, and related data that may be treated as consumer health data.
Effective August 5, 2026
1. Scope and data covered
This Consumer Health Data Privacy Policy supplements the Makro Privacy Policy where consumer health privacy laws apply. “Consumer health data” means personal information that identifies or can reasonably be linked to a consumer and that identifies past, present, or future physical or mental health status.
Makro may process nutrition goals, meal and ingredient records, calories and macronutrients, weight check-ins and trends, activity level, goal direction, optional meal photos or descriptions submitted for analysis, Coach questions, and progress summaries. Makro does not currently request records from HealthKit, healthcare providers, insurers, pharmacies, or medical devices.
2. Sources of consumer health data
Consumer health data comes primarily from information you enter or submit, your actions in Makro, and calculations Makro performs from those entries. Food details can also come from USDA FoodData Central or Open Food Facts when you select a search or barcode result. Apple or Google sign-in provides account information, not health records.
3. Why Makro collects and uses it
Makro collects and uses consumer health data to provide features you request, including:
- meal, calorie, and macronutrient logging;
- editable starting goals and target ranges;
- saved meals, progress summaries, adherence scores, and weight trends;
- optional AI meal estimates and optional Makro Coach responses;
- data export, correction, and account deletion tools; and
- security, fraud prevention, support, and legal compliance.
Makro does not use consumer health data for targeted advertising or to determine eligibility for employment, housing, insurance, credit, or healthcare.
4. Consumer health data sharing
Makro does not sell consumer health data. We share it only as needed to provide a feature you request, with your direction or authorization, or as permitted or required by law.
- Supabase hosts authenticated account, nutrition, weight, progress, and Coach records and runs server functions.
- OpenAI receives meal text or an image when you intentionally request an AI estimate, or a Coach question and relevant progress context when you intentionally use Makro Coach.
- USDA FoodData Central and Open Food Facts receive a food search or barcode needed to return a database result. These requests generally do not require your Makro account or health profile.
Makro deliberately filters meal content, nutrition values, weight, photos, searches, barcodes, and Coach questions from PostHog product analytics and deliberately filters that content from Sentry diagnostic payloads attached by Makro. See the main Privacy Policy for the limited device, identifier, interaction, and diagnostic information those providers may receive.
5. Consent and authorization
You choose whether to enter nutrition or weight data and whether to enable optional AI processing. You can withdraw AI consent at any time in Settings → Privacy and data; doing so stops new AI requests but does not automatically delete results or Coach records already stored. If Makro seeks to sell consumer health data or share it for a purpose not described here, Makro will first obtain any separate authorization required by law.
6. Your consumer health data rights
Subject to applicable law, you may request to confirm whether Makro collects or shares consumer health data, access that data, receive a list of relevant third parties, withdraw consent, or have the data deleted. You may export your current Makro records in the app and delete your account from Settings.
Email nomofoway@gmail.com for a request that cannot be completed in the app. We may verify your identity and will respond within the period required by applicable law. If we deny a request, you may appeal by replying with the subject “Privacy appeal.” You may also contact the regulator or attorney general in your jurisdiction.
7. Security and retention
Makro uses authenticated requests, row-level database rules, secure native session storage, server-side limits, and data-minimization controls. We generally retain consumer health data while your account is active and delete user-owned database records when your account is deleted, subject to limited legal, security, backup, and fraud-prevention exceptions. No security measure can eliminate every risk.
8. Changes and contact
We will post updates to this policy here and change the effective date. Material changes will receive any additional notice or consent required by law.
Contact nomofoway@gmail.com with questions or requests.
Launch note: this policy is a product-grounded draft and must be reviewed by qualified counsel before public distribution.