Effective date: 26 July 2026
MacroTracker estimates the calories and macronutrients in a meal from a photograph. This policy describes what the app does with your information.
All of it, unless it is named in the next section.
Every meal you log, its photos, your daily goals, your height, weight, age and activity level, your location history, and any API key you enter are stored on your device. They are not uploaded, backed up to us, or shared. We do not operate a database of users, because there are no users to put in one.
Your log is also mirrored into your device's Keychain so that deleting and reinstalling the app does not lose it. That mirror is part of your device's own encrypted storage and, if you use encrypted iCloud or computer backups, it travels with those backups under Apple's protection rather than ours.
When you photograph or describe a meal and ask for an estimate, the app sends a single request containing:
Nothing else accompanies that request. No name, no email, no account, no device identifier, no advertising identifier, and no GPS coordinates. The service receiving it has no way to connect one request to another, or to you.
The request goes to one of the following, depending on how the app is configured and which providers are available:
Their handling of that request is governed by their own privacy policies and their terms for API traffic. We do not control how long they retain it.
Requests reach those services through a relay we run on Cloudflare Workers. It holds the provider API key so that the app does not have to carry one, forwards your request, and passes the answer back. It does not store your photo or the text you sent. Neither is written to disk or to a database, and nothing is kept that could reconstruct a request after it has been answered.
Two things about the relay are worth stating plainly rather than leaving you to assume:
This page and the support page are served by that same relay.
If you supply your own API key in Settings, the app talks to that provider directly using your key, and requests do not pass through the relay at all.
Location tagging is off until you turn it on, in Settings → Location.
With it on, the app takes a location fix and uses Apple's Maps services to work out which restaurant or cafe you are in. Your coordinates are used on your device to place a meal on a map and are stored with that meal locally. They are never sent to the analysis service — only the venue name, its category, the district and the city are, as described above.
Reverse geocoding and the nearby-venue search are performed by Apple's Maps services, which necessarily receive an approximate location to answer the query. That is Apple's system service, handled under Apple's privacy policy, not ours.
Turning location tagging off stops the app requesting a fix at all.
If you allow it, photos you take inside the app are saved to your photo library at full resolution — the same thing the Camera app does. The app has add-only access: it can put a photo into your library and cannot read what is already there. Photos you pick from your library are not copied back.
The app can let the analysis service search the web mid-estimate for a packaged product's label or a named restaurant's published figures. Only the food is searched for — never you, and never a venue's address. This can be switched off in Settings → Photo analysis.
MacroTracker is not directed at children under 13, and we do not knowingly collect information from them. It is rated 4+ because it contains no objectionable content, not because it is designed for young children. Calorie tracking is not appropriate for everyone.
Because there is no account, there is nothing held on our side to request, correct or delete. Requests you have already sent for analysis are held, if at all, by the provider that received them, under their policy.
Everything sent to a provider goes over HTTPS. API keys you enter are stored in your device's Keychain, marked so that they never leave the device and are never included in a backup.
No system is perfect, and an estimate request is only as private as the service answering it. If that matters to you, supply your own API key so your requests go directly to a provider you have your own agreement with.
If this policy changes, the effective date above changes with it, and material changes will be noted in the app's release notes.
Questions about this policy, or about anything the app does with your information: xtde8in7o@relay.firefox.com.