MacroMotive Privacy Policy
Last updated: July 19, 2026
MacroMotive ("we," "us") is a nutrition and fitness coaching app. This policy explains exactly what data we collect, why, who (if anyone) we share it with, how long we keep it, and how you can access, correct, or delete it. We wrote this to be read, not skimmed past — if anything here is unclear, contact us at support@macromotive.app.
The short version: MacroMotive reads (never writes) a small set of Apple Health metrics to power your coaching; it sends meal photos and coach conversations to Anthropic (Claude) only to generate your nutrition analysis and coaching replies, under Anthropic's standard commercial terms of no training on your data and limited retention; it never shows ads, never sells or shares data with data brokers or advertisers, and never uses your health data for anything other than giving you coaching inside this app. You can delete your entire account and all associated data at any time from Profile → Delete account & data.
1. Data We Collect and Why
Account & sign-in. When you sign in with Apple, we store an
opaque identifier for your account (Apple's sub value — not your Apple
ID or email, since MacroMotive does not request either). We do not store your
name on our servers — the display name you enter once at first sign-in is kept
only on your device. Your app session is represented by a signed token stored in your
device's Keychain, not persisted by our servers. We retain Apple's opaque refresh token,
encrypted and inaccessible to the app, solely so we can revoke MacroMotive's Sign in with
Apple authorization if you delete your account. Purpose: identify your account, keep
you signed in, and remove Apple authorization during account deletion.
Apple Health data (read-only). With your permission, MacroMotive reads: workouts, heart-rate variability (HRV/SDNN), resting heart rate, respiratory rate, VO2 max, body weight, and sleep analysis. MacroMotive never writes to Apple Health and never requests write permission — the read-only Health permission prompt on your device accurately reflects everything this app does with Health data. Purpose: this data is used exclusively to make your in-app coaching specific to you — e.g., adjusting recommendations around a poor night's sleep or a hard workout. It is never used for advertising, never sold, never shared with data brokers, and never used to build any profile of you outside of the coaching you receive in this app. You can revoke this access at any time in iOS Settings → Privacy & Security → Health → MacroMotive.
Meal photos. When you photograph a meal, scan a recipe, or scan a nutrition label, the full-resolution image is sent once to our nutrition-analysis service and is not stored on our servers afterward. A small thumbnail (capped at 200KB) is kept so the meal shows a picture in your timeline. Purpose: identify foods and estimate calories/macros; display your logged meals.
Coach conversations. Your chat messages with the AI coach — and the coach's replies — are stored so your conversation history persists across sessions. A low-resolution thumbnail of any photo you send in chat is stored for display purposes only and is never re-sent to any AI model. Purpose: maintain conversation continuity and let you review past coaching advice. You can delete your entire chat history at any time (see Section 5).
Coaching profile ("coach memory"). To give useful advice, MacroMotive remembers a small set of facts you've told your coach or that it's inferred from your logs — for example dietary restrictions, allergies, injuries, and macro/calorie targets. Purpose: this exists solely so your coach doesn't need to re-ask things you've already told it, and so its advice accounts for injuries or allergies. This is never used for advertising or shared outside the direct coaching purpose described here.
Meals, nutrition, and activity timeline. Logged meals (name, items, macros) and workout/cardio/recovery entries you save or that sync from Health are stored so you can review your history and trends. Purpose: core app functionality — your timeline and progress.
Saved foods. Meals you explicitly save for reuse are stored under your account. Purpose: quick re-logging of foods you eat often.
Shared meal links. If you choose to share a meal, we generate a private link that shows that meal's nutrition info to whoever has the link — no account or identifying information about the viewer is collected. These links expire automatically 90 days after creation. Purpose: let you share a meal's nutrition facts with someone, e.g. over text.
Barcode and food-name lookups. When you scan a barcode or search for a food by name, we look that up against public nutrition databases (see Section 2). These lookups do not include any information that identifies you.
Usage/cost metrics. We record which AI features you used and their approximate computational cost, linked to your account, for the operational purpose of managing service costs. We do not store the content of your prompts or the AI's responses in these records — only counts and cost figures.
What we do not collect: MacroMotive collects no location data, no advertising identifiers, no analytics or crash-reporting data, and includes no third-party advertising, analytics, or tracking SDKs of any kind. We do not use the App Tracking Transparency framework because we do not track you.
2. Who We Share Data With, and Why
We share data with exactly three categories of outside service, and only what's strictly necessary for each to do its job:
Anthropic (the maker of the Claude AI models). We send meal/recipe/nutrition-label photos, your coach chat messages, and the relevant slice of your coaching profile and recent activity to Anthropic's API so it can analyze your food photos and generate your coach's replies. This is the only third party that receives anything resembling health-related content, and we hold it to the same bar we hold ourselves to: under Anthropic's commercial API terms, your data is not used to train Anthropic's models. Anthropic retains API inputs and outputs for a limited period — up to 30 days under its standard commercial data-retention policy — after which they are deleted, except where Anthropic is required to retain them longer to meet legal obligations or to enforce its usage policies (for example, content flagged by its trust-and-safety systems). We do not have a zero-retention agreement with Anthropic, so we cannot guarantee that a given prompt is deleted from Anthropic immediately on request; deletion follows Anthropic's own schedule. MacroMotive's backend restricts AI processing to providers we have vetted for these terms — today that is Anthropic only. This allowlist is an engineering control over which providers may be used; it is not itself a contractual retention agreement. Anthropic does not use your data for advertising, does not sell it, and does not use it to build user profiles outside of providing the API response you requested.
USDA FoodData Central (a U.S. government nutrition database). When you search for a food by name, we send only the search text — no account identifier, no device identifier, nothing that could identify you — to retrieve nutrition facts.
OpenFoodFacts (an open, crowd-sourced barcode database). When you scan a barcode, we send only the barcode number — again, nothing that identifies you — to look up the product. Results are cached for all users, not tied to any individual.
Because USDA and OpenFoodFacts never receive anything that identifies you, they fall outside the scope of the "equal protection" commitment above by construction — there is no personal or health data for them to mishandle.
Apple. Sign in with Apple is verified directly with Apple as part of authentication. We also exchange Apple's one-time authorization code for a refresh token and send that token back to Apple for revocation when you delete your account; Apple's own privacy policy governs those exchanges.
Infrastructure providers. Our application runs on Cloudflare (which hosts our backend and routes API traffic) and stores data in a Neon-hosted PostgreSQL database. These providers process and store your data on our behalf, as sub-processors, solely to operate the service; they do not use it for their own purposes, and the health, meal, and coaching records they store are encrypted at rest as described in Section 4. Cloudflare also processes basic operational request metadata needed to run and protect the service.
We do not use any advertising network, analytics platform, data broker, or marketing partner. We have never sold personal data and never will.
3. How Long We Keep Data
| Data | Retention |
|---|---|
| Account (Apple sign-in identifier and encrypted revocation credential) | Until you delete your account. The credential is used only to revoke Sign in with Apple during deletion and is then removed with the account. We do not store your name — it stays on your device. |
| Recovery vitals from Apple Health (heart rate, resting heart rate, HRV, respiratory rate, sleep, blood oxygen, VO₂max) | Kept only for a short rolling window (currently about 60 days) and then automatically deleted from our servers — Apple Health remains the source of truth and the app reloads them as needed. |
| Workouts, body-weight entries, and logged meals | Kept for the life of your account so your trends, history, and coaching stay accurate. Deleted when you delete the individual entry or your account (see below on deletion timing). |
| Full-resolution meal/recipe/label photos | Not retained — used once for analysis, then discarded |
| Meal thumbnails | Until the meal is deleted or account is deleted |
| Coach chat messages | Until you clear your chat history or delete your account |
| Reported AI coach replies (safety review) | When you report an AI reply as objectionable, an encrypted copy of that reply is stored separately from your conversation so our team can review it. This copy is kept even if you later clear your chat history, and is retained until your report has been reviewed and for a limited safety-review period afterward. It is deleted when you delete your account. |
| Coaching profile facts (goals, allergies, injuries, preferences) | Until you delete your account. Clearing your chat history does not clear these facts individually — they persist so your coach keeps functioning correctly across a cleared conversation. You can remove individual facts one at a time in-app; full removal happens automatically on account deletion. |
| Saved foods and other timeline/activity entries | Until deleted or account deletion |
| Shared meal links | No longer accessible 90 days after creation; the underlying record may be retained for a period after expiry until removed as part of routine maintenance. Deleted immediately if you delete your account. |
| Usage/cost metrics (no content) | Until account deletion |
When you delete an entry (a meal, workout, or a sample removed in Apple Health), it is hidden from the app immediately and permanently erased from our servers within about 30 days. The short delay lets the deletion sync reliably across your devices; after it, the record is gone.
We do not keep data "just in case" beyond the purposes above, and everything on this list is permanently removed when you delete your account.
4. Health Data — Extra Protections
We treat Health data as sensitive. It is used only to make your coaching more specific and useful to you — never for advertising, marketing, or data mining, and never shared with data brokers or any third party for purposes unrelated to providing your coaching. The only outside processor that ever sees Health-derived context is Anthropic, under the no-training/limited-retention terms described in Section 2, and only for the purpose of generating your coaching response.
Health data read from Apple Health is never stored in or synced to iCloud. MacroMotive does not use iCloud, CloudKit, or any Apple cloud-sync mechanism for your Health data or any data derived from it.
The sensitive content of your health and meal information and your coaching conversations is encrypted at rest on our servers: each record's payload is individually encrypted, and the keys are held separately from the database, so the stored content is unreadable on its own. Certain non-content metadata needed to organize and query your data — such as timestamps, record types and subtypes, and internal identifiers — is stored in plaintext alongside the encrypted payload.
5. Your Choices: Consent, Access, and Deletion
- Apple Health access: Grant or revoke at any time in iOS Settings → Privacy & Security → Health → MacroMotive. This is controlled entirely by iOS, not by us.
- Clear your coach conversation: In the Coach tab, you can delete your chat history at any time; this removes the stored conversation text and message thumbnails.
- Delete your entire account and all data: Open the app, go to Profile → "Delete account & data", and confirm. This immediately and permanently deletes your account, timeline, coach conversations and coaching profile, saved foods, shared meal links, and every other record described in this policy. We also ask Apple to revoke MacroMotive's Sign in with Apple authorization. If Apple revocation cannot be completed automatically, the app gives you the iOS Settings steps to remove it manually. This action cannot be undone and there is no recovery period.
- Questions, access requests, or anything not covered above: email support@macromotive.app.
6. Children
MacroMotive is not directed to children under 13, and we do not knowingly collect data from children under 13.
7. Changes to This Policy
If this policy changes, we'll update the "Last updated" date above. Material changes affecting how health data is used will be communicated in-app.