Last updated: 14 August 2026
Macro Masala is built and operated by Pratik Juta (“we”, “us”). This policy explains what the app collects, where it goes, and what we do not do.
We have tried to write this in plain language. If anything is unclear, email us at the address at the bottom and we will explain it.
When you first open the app, we generate a random identifier and store it in the iOS Keychain on your phone. It is not linked to your name, email, phone number, Apple ID, or any advertising identifier. It exists only so your meals appear on your device when you reopen the app.
We cannot use this identifier to work out who you are.
When you log a meal we store the dishes identified, the portions, any corrections you make, the calculated calorie and macronutrient ranges, whether the meal was marked home or restaurant, and the meal type and time.
If you enter your weight, we store the weight and the date. This is health information and we treat it accordingly. It is stored against your anonymous device identifier only.
Height, weight, age, sex, activity level and target, if you enter them during setup. These are used to calculate your daily calorie target. Your height, age and sex are stored on your device and are not sent to our servers.
We record which screens you view, which features you use, whether you granted or denied a permission, and when the app is opened. Each event carries your anonymous device identifier, the app version, your iOS version, and your country as reported by your device’s language settings — not your IP address or GPS location.
We use this to understand where the app is confusing or broken. It contains no food names, no photos, and no personal identifiers.
If you save a custom food, it is stored in the iOS Keychain on your device. It is not sent to our servers.
This is worth being specific about, because it is the question people ask most.
When you photograph a meal or select an existing photo:
We never store your photos. They are not written to our database, our logs, or any file storage. There is no photo column in our database and no image bucket. Only the resulting text is kept.
Anthropic’s commercial API terms state that inputs are not used to train their models and are deleted within 30 days.
When you speak a meal, the speech-to-text conversion happens on your device, using Apple’s built-in Speech framework. The audio recording never leaves your phone.
Only the resulting text — for example, “two rotis and a katori of dal” — is sent to be interpreted. That text is processed and the result returned; we do not store the raw utterance.
Apple’s own privacy policy governs the on-device speech recognition. Note that iOS may in some circumstances send audio to Apple’s servers for recognition; that is between you and Apple and is described in Apple’s privacy policy and your device settings.
We use a small number of services to make the app work. None of them receive your name or contact details, because we do not have them.
Anthropic PBC — receives meal photos and the text of what you said or typed, in order to identify foods. Under their commercial terms this data is not used for model training and is deleted within 30 days.
Supabase — provides the database where your meals, weigh-ins and usage events are stored. Data is stored in Canada.
USDA FoodData Central — receives food search terms, for example “kraft cheddar”. This is a United States government nutrition database. It receives no identifier and no meal data.
Open Food Facts — receives barcode numbers when you scan a packaged product. It receives no identifier and no meal data.
RevenueCat and Apple — handle subscriptions. Apple processes all payments. We never see your card details, billing address, or Apple ID. RevenueCat tells us only whether a device has an active subscription.
We do not sell your data to anyone, and we do not share it with advertisers or data brokers.
Meals, weigh-ins and usage events are kept until you delete them or ask us to delete your data.
You can delete an individual meal in the app at any time, which removes it from our database.
If you delete the app without asking us to delete your data, the data remains associated with your anonymous device identifier. Because we have no way to contact you or identify you, we cannot delete it proactively — you would need to email us, and we will explain how to supply your device identifier so we can find and remove it.
Depending on where you live, you may have the right to access, correct, delete, or export your data, and to object to how it is used.
Because we hold no personal identifiers, we can only act on these requests if you can supply your device identifier. Email us and we will tell you how to find it and verify it.
If you are in Canada, this policy is written with PIPEDA in mind. If you are in the UK or EU, we process your data on the basis of legitimate interest in providing the app you have asked us for, and you may lodge a complaint with your local data protection authority. If you are in California, we do not sell or share personal information as those terms are defined by the CCPA.
Macro Masala is not intended for anyone under 13, and we do not knowingly collect data from children. If you believe a child has used the app and provided data, email us and we will delete it.
All data is transmitted over encrypted connections. Your device identifier is stored in the iOS Keychain, which is encrypted by the operating system.
We should be honest about the limits: no system is perfectly secure, and we are a small operation. The mitigation is that we hold very little worth stealing — no names, no emails, no payment details, no photos.
If we change how the app handles data, we will update this page and change the date at the top. If a change is significant, we will make it visible in the app rather than relying on you to check here.
Questions, requests, or complaints:
We are a one-person operation, so replies may take a few days, but every message is read.