FamilyMacro

Privacy Policy

How FamilyMacro protects household nutrition data

FamilyMacro is built for households, so the privacy policy needs to be plain about account data, family profiles, shared meals, child visibility, support requests, and AI-assisted logging.

Last updated: August 21, 2026

Information FamilyMacro may collect

  • Account details such as name, email address, password hash, family name, family membership, subscription status, and app sessions.
  • Household profile details such as names, age groups, nutrition goals, privacy settings, meal logs, shared-meal portions, recipes, plans, shopping-list items, and AI usage counts.
  • Optional food photos, nutrition-label photos, typed food descriptions, and voice meal descriptions when you choose AI-assisted logging.
  • When you use the Assistant, a separate product-quality ledger may keep the server-sanitised text of your question and limited operational labels, such as the route, provider, outcome, and a coarse response-time range. A server-sanitised AI reply is held separately only while a twice-daily quality review needs it; it is removed after resolution or at a 30-day safety limit. Before storage, FamilyMacro redacts obvious direct identifiers such as email addresses, phone numbers, links, access tokens, secrets, payment-card numbers, and long identifier strings.
  • Optional Health Connect exercise import details such as exercise sessions, activity calories, steps, distance, heart-rate summaries, provider/source-app labels, this phone's local Health Connect identity, FamilyMacro workout records written back to Health Connect when you choose to connect and sync them, and your own FamilyMacro meal nutrition records written to Health Connect when you allow nutrition write access.
  • Support, billing, purchase status, and operational security details when you contact us, manage a subscription, or use account features.
  • Public website analytics such as page path, referrer details, campaign or affiliate code, approximate country, user-agent family, and a pseudonymous visitor identifier.

How the data is used

We use household data to provide private login, family profiles, nutrition logs, shared meals, privacy controls, and billing access. Meal and nutrition entries stay editable so households can review and correct values before relying on them.

AI-assisted photo, voice, exercise, recipe, and insight features use the content you submit to return estimates, summaries, and editable draft entries. Every submitted Assistant text request uses OpenAI first, normally with the GPT-5.6 Luna model. If Luna requests FamilyMacro data, the server checks the signed-in person’s permissions and sends only the authorised, minimised tool results needed for that answer; Luna never receives direct database access, account tokens, or raw internal identifiers. Food-photo analysis normally uses Google Gemini. Where both providers are configured, the alternate provider is tried once only after the primary provider fails. OpenAI processes submitted meal audio for transcription. FamilyMacro starts this processing only after you choose an AI-assisted action.

The separate Assistant question ledger is used to improve product quality and app functionality and to produce aggregate usage and reliability analytics. Twice daily, FamilyMacro automatically flags delivery, formatting, fallback, and slow-response concerns. Only a flagged reply remains available to the owner-review surface until it is resolved; archiving removes the reply text. Its admin review does not expose IP addresses, user agents, account IDs, family IDs, profile IDs, or the keyed one-way account-deletion value. That server-only value is created with a secret and is used only to find and remove matching ledger entries during deletion.

Meal and favourite-food images are stored in private Cloudflare R2 object storage with authenticated, household-scoped access. The retention periods for those images are explained below.

Health Connect exercise and nutrition sync are optional. FamilyMacro asks for Android Health Connect access before reading activity data or writing records. It reads the selected activity data for review, can write reviewed Samsung workout records back to Health Connect when Samsung has not already shared them there, and can automatically write your own logged meal nutrition to Health Connect after you allow nutrition write access. FamilyMacro does not diagnose, treat, or give medical advice from Health Connect data.

Children and family privacy

Profiles under 16 stay guardian-visible for nutrition, vitamins, and meals. Parents can optionally give older children their own app login. Adults can choose Private, Shared totals, or Shared meals only. Family members only see what the selected privacy setting allows.

Sharing and advertising

We do not sell household nutrition data. FamilyMacro is designed as an ad-free paid household nutrition tracker, not an advertising profile builder. Service providers may process data only as needed to operate hosting, email, payments, app stores, analytics, support, security, and AI-assisted features.

Your privacy choices

You can edit or delete meal and exercise logs, update profile visibility, disconnect Health Connect permissions in Android settings, contact privacy support, and request account deletion.

Data retention

FamilyMacro keeps data only for the period needed to provide the service, meet the choices below, and satisfy limited security, accounting, fraud-prevention, or legal obligations:

  • Account and household records: login details, profiles, nutrition and exercise history, goals, favourites, recipes, plans, and household settings are kept while the account or household remains active. Individual records are removed earlier when you delete them. Account data is removed from active FamilyMacro systems when the relevant account or household is deleted.
  • Login sessions: app sessions expire after 30 days and are removed sooner when you sign out or delete the account.
  • Meal and favourite images: standard accounts keep an uploaded original for 7 days and its private thumbnail for 30 days. Extended or lifetime entitlements keep an original for 183 days and its thumbnail for 365 days. Images are removed sooner when the related record, profile, or household is deleted.
  • AI-assisted inputs: FamilyMacro does not keep a reusable copy of raw meal audio after sending it for the requested transcription. A transcript, estimate, or submitted image follows the retention period of the meal, exercise, favourite, or other record that you choose to save.
  • One-meal preview before registration: if you use this preview, its typed description, estimate and selected portion are available in local device storage for seven days. Expired drafts are cleared when FamilyMacro next opens; you can discard a draft sooner. Photos and recordings are processed for the requested estimate but are not stored as FamilyMacro meal records. A random request ID and daily salted network digest temporarily limit misuse; these contain no raw IP address or meal content. Only the current UTC day counts toward the request budget; older quota rows are pruned by later requests once their date is more than two days old. AI providers process submitted content under their own service terms. A household meal is saved only after account setup, valid access and your confirmation.
  • Product-use measurement: for signed-in app use, we record at most one activity day per person and household per UTC day. Reports use a 90-day window, and older activity rows are pruned when new activity is recorded. This record contains no meal details, precise activity time, IP address, device ID or visited screen. It helps us distinguish repeat use from sign-ins.
  • Assistant question ledger: server-sanitised question text and limited operational labels stop appearing in review after 90 days. Expired rows are physically removed during the next ledger write or review, and matching rows are removed sooner when the associated account, profile-owned login, profile, or household is deleted. A separate sanitised reply-review record exists only while the reply is pending or needs resolution; the twice-daily review removes reply text after resolution and no reply remains longer than 30 days.
  • Support, billing, security, and legal records: these are kept only as long as needed to resolve the request, administer the subscription, prevent abuse, meet accounting or other legal duties, or establish and defend legal claims. Payment providers and app stores may retain their own transaction records under their policies and legal obligations.
  • Public website analytics: pseudonymous page, referral, campaign, approximate-country, browser-family, and visitor-hash records are kept for trend reporting and service security. They are not joined to a FamilyMacro household profile and are deleted or anonymised when no longer needed for those purposes.

If a limited record must be retained after deletion for a legal, security, fraud-prevention, or dispute purpose, FamilyMacro restricts it to that purpose and removes it when the obligation ends. Deleted account content is not restored to the product from an operational backup.

How to request account and data deletion

  1. Inside FamilyMacro: sign in, open Settings, choose Delete account, type DELETE, and confirm. A household owner deletes the whole family account and its FamilyMacro data. A household member deletes that login and the member's profile-owned data; the household may retain a de-identified “Deleted member” placeholder so other people's shared records remain intact.
  2. If you cannot sign in: open the FamilyMacro account deletion page, follow its link to the support form, choose Privacy or deletion, enter the email address used for the account, and ask us to delete your FamilyMacro account and associated data.

We may ask for enough information to verify that the requester controls the account. We respond without undue delay and normally within one month. If a legal exception requires us to retain limited data or extend the response period, we will explain that to the requester. Deleting FamilyMacro does not by itself cancel every Google Play subscription or remove records already written to Android Health Connect; those can be managed separately in Google Play and Health Connect settings.