Last updated: August 26, 2026
MacroDrop ("we", "our", "the app") is a nutrition and macro tracking application operated by Denis Nesterenko, an individual developer (the "Developer", acting as data controller). This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data. By using MacroDrop you also agree to our Terms of Service.
| Data type | Purpose | Required? |
|---|---|---|
| Email address, name (via Google/Apple Sign-In) | Account creation, authentication | Only for AI features |
| Photos of food | AI-powered food recognition (sent to Google Gemini for analysis) | Only when using photo logging |
| Voice recordings / transcribed speech | AI-powered food logging via voice (converted to text on-device, then sent to Gemini for analysis) | Only when using voice logging |
| Body metrics (sex, age, height, weight, activity level) | Calculating calorie and macro targets using standard published formulas — processed on your device | Yes, during onboarding |
| Food and meal logs | Core app functionality — stored locally on your device | Yes |
| Barcode scans | Looking up product nutrition info via Open Food Facts | Only when using barcode scanning |
| Apple Health / Health Connect data — the nutrition you log, active energy burned, body weight | Writing your logged meals to your device's health app, and showing calories burned and body weight next to your intake on the Progress screen | No — off by default, and only if you turn the sync on |
| Usage analytics (app opens, feature usage, screen views, approximate device info: model, OS version, language, country) | Understanding how the app is used to improve it (Firebase Analytics) | Collected automatically |
| Crash and diagnostic data (stack traces, device state at time of crash) | Detecting and fixing bugs and crashes (Firebase Crashlytics) | Collected automatically |
| Advertising attribution data (device advertising identifier, install and in-app events) | Measuring the effectiveness of our advertising campaigns (Meta SDK / SKAdNetwork) | On iOS — only with your consent via the App Tracking Transparency prompt; you can decline and the app works fully |
We do not collect: your precise location, your contacts, or the content of your locally stored meal history.
Most of your data — meals, foods, body metrics, and daily goals — is stored locally on your device using an on-device SQLite database. It is not uploaded to our servers except as described below.
Account data (email, authentication tokens, AI usage counters) is stored with Supabase, our backend provider, secured via row-level security so only you can access your own data.
Photos and voice transcripts sent for AI analysis are processed transiently and are not permanently stored on our servers.
Data read from or written to Apple Health or Health Connect stays on your device. The values MacroDrop reads are kept in the app's own local database alongside your other data, and the meals it writes are held by your device's health app, under your control there. Neither is ever uploaded to our servers. Section 4 describes this sync in full.
| Service | What we share | Purpose |
|---|---|---|
| Supabase | Email, authentication tokens, AI usage counters | Account management, backend infrastructure |
| Google Gemini API | Food photos and transcribed voice input (only when you use these features) | AI food recognition |
| Google / Apple Sign-In | Basic profile info (email, name) via OAuth | Authentication |
| Google Firebase (Analytics & Crashlytics) | Usage events, device and diagnostic information, pseudonymous app-instance identifiers | Product analytics, crash reporting |
| Meta Platforms (Meta SDK) | App install and in-app events, device advertising identifier (on iOS only if you allow tracking via the ATT prompt) | Advertising attribution and campaign measurement |
| Open Food Facts | Barcode number, IP address (request sent directly from your device to Open Food Facts' servers) | Product nutrition lookup |
We do not sell your personal data. We share limited data with Meta solely to measure our own advertising campaigns; under some US state laws (e.g., California's CCPA/CPRA) this may qualify as "sharing" for cross-context behavioral advertising — you can opt out at any time as described in Section 8. We do not display third-party ads inside the app.
None of the processors above receive your Apple Health or Health Connect data. The health sync runs only between MacroDrop and your device's health app — see Section 4.
MacroDrop can sync with Apple Health on iOS and with Health Connect on Android. This is off by default. It begins only after you turn it on in Settings and grant permission on your device's system permission screen.
While the sync is on, each meal you log is written as a single entry carrying its name and the time you ate, with up to 17 nutrient values: calories, protein, carbohydrates, fat, fiber, sugar, saturated fat, sodium, potassium, magnesium, calcium, iron, zinc, vitamin D, vitamin B12, vitamin C, and caffeine.
Turning the sync on does not upload your history. Only the meals you log or change from that point onward are written.
MacroDrop does not read your health data in the background. It reads only while you are using the app.
Nowhere. Your health data stays on your device. It is never sent to our servers, never sent to the AI service that analyses your meal photos and voice notes, and never reaches the analytics or advertising SDKs listed in section 3.
We do not use health data for advertising, marketing, or any form of data mining, and we do not sell it or share it with anyone. The analytics events recorded for this feature note only whether the sync is switched on or off — never any value read from or written to your health app.
You can turn the sync off at any time in Settings. MacroDrop will ask whether you also want to delete the entries it has written to your health app:
Either way, the active energy and body weight readings MacroDrop pulled in are removed from the app. Weights you entered yourself are your own data and remain.
You can also revoke access from outside the app — on iOS in Settings › Health › Data Access & Devices › MacroDrop, and on Android in the Health Connect app under App permissions. If you do, MacroDrop notices the next time you open it and switches the sync off itself.
If you delete all of your MacroDrop data, the entries MacroDrop wrote to your health app are removed as well.
Where the GDPR or UK GDPR applies, we process your data on the following bases:
| Processing | Legal basis |
|---|---|
| Account creation, authentication, AI quota enforcement | Performance of a contract (Art. 6(1)(b)) |
| AI photo/voice analysis | Performance of a contract — you actively initiate each analysis |
| Analytics and crash reporting | Legitimate interest in improving and maintaining the app (Art. 6(1)(f)) |
| Advertising attribution (Meta SDK with device identifier) | Consent (Art. 6(1)(a)) — via the tracking permission prompt; you may withdraw at any time |
Our service providers (Supabase, Google, Meta) may process data on servers located outside your country, including in the United States. Where required, such transfers are protected by appropriate safeguards, such as the EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework, to which Google and Meta are certified.
You can delete your account at any time from Settings → Delete Account. This permanently removes your account and associated usage data from our servers. Locally stored meal data remains on your device until you uninstall the app or clear its data.
Analytics and crash data is retained by Firebase for a limited period (up to 14 months for user-level analytics data) and then deleted or aggregated. Attribution data is retained only as long as needed for campaign measurement.
Depending on your location, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict certain processing, and to withdraw consent (GDPR — EU/EEA/UK; CCPA/CPRA and similar laws — US states). You also have the right to lodge a complaint with your local data protection authority. We do not discriminate against you for exercising any of these rights.
Your choices in the app and on your device:
All data transmitted between the app and our servers is encrypted in transit via HTTPS/TLS. AI API keys are never stored on your device — all AI processing is proxied through our secured backend with per-user authentication and rate limiting.
MacroDrop is not directed at children under 13 (or the higher minimum age required in your jurisdiction, e.g., 16 in parts of the EU). We do not knowingly collect data from children. If you believe a child has provided us personal data, contact us and we will delete it.
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above and, where appropriate, notified in the app.
If you have questions about this Privacy Policy or your data, or wish to exercise your rights, contact us at: support@macrodrop.app