Privacy Policy

MacroDish — com.macrodish.app

Last updated: 8 August 2026

This Privacy Policy explains how Syed Shahbaz Husain ("we", "us", "our"), the developer of the MacroDish mobile application (the "App"), collects, uses, shares, and protects your information. By creating an account or using the App you agree to the practices described here.

If you have any questions or wish to exercise your privacy rights, contact us at sharp.applications2026@outlook.com.

1. Who we are (Data Controller)

The data controller responsible for your personal data is Syed Shahbaz Husain, an individual developer based in India. Contact: sharp.applications2026@outlook.com.

2. Information we collect

a. Account information

b. Profile and health-related information you provide

During onboarding and in your profile you may provide:

Height, weight, age, and dietary information are health-related data. We use them only to personalize your nutrition insights and comparisons. We do not sell this data, and we do not use it for advertising targeting.

c. Food and meal logs

d. Restaurant name and approximate location (optional)

When logging a meal you may optionally name the restaurant you ate at, by typing it as part of the entry (for example "chicken wings from Empire"). If you do, the App asks for permission to read your device's approximate location so it can work out which city you are in and match the restaurant to the right regional menu.

e. Device identifier (abuse prevention)

When you create a new account, the App sends a device identifier to our servers so we can limit how many accounts may be created from a single device. This prevents people from bypassing free-tier daily limits by signing up repeatedly with disposable email addresses. On Android this identifier is the system-provided Android ID, which is unique to this app on this device and cannot be used to recognise you in other apps; on iOS it is a random value the App generates and stores on your device.

We store only this identifier alongside the accounts created on that device. It is not used for advertising, analytics, profiling or tracking you across apps or websites, and it is not shared with third parties. If you simply sign in to an account you already have, no device identifier is collected at all. The record is deleted when the associated account is deleted.

f. Advertising and technical data

The current version of the App does not show advertising. It does not collect or share an advertising identifier, and it does not request access to one.

If we introduce advertising in a future version, we will update this policy and our Google Play Data safety declaration before that version is released, and — where required by law — ask for your consent in the App. At that point our advertising provider (Google AdMob) may collect:

g. Subscription and purchase data

If and when paid subscriptions are enabled, purchase and entitlement data (product, status, expiry) is processed through Google Play / the Apple App Store and our subscription manager (RevenueCat). We do not receive or store your full payment card details — those are handled by the app stores.

3. How we use your information

Comparison statistics shown in the App are aggregated across all users and never expose any individual user's personal data to another user.

4. Third-party services we share data with

We use the following service providers ("sub-processors") to operate the App. Each processes only the data needed for its function:

ProviderPurposeData involved
Supabase (hosting, database, authentication) Stores your account, profile, and meal data; handles sign-in. Account, profile/health fields, meal logs. Data is hosted in the Asia-Pacific (Seoul) region.
OpenRouter (AI model gateway) Resolves foods it doesn't already recognize into nutrient information. The food text you type (plus your country/dietary context) is sent server-side to an AI model for nutrition estimation. If you name a restaurant, that name and your city are included so the model can return that venue's menu values. Precise coordinates are never sent.
Google AdMob (not in use) Would display advertising to free-tier users. Not enabled in the current version — no data is sent to AdMob. If enabled in a future version: advertising ID, device and ad-interaction data. See Google's policy.
RevenueCat + Google Play / Apple App Store Processes subscriptions and manages entitlements (when enabled). Purchase, subscription status, and store account identifiers. Payment details are handled by the app stores, not by us.
Resend (email delivery) Sends sign-in one-time passcodes and transactional email. Your email address and the message content.

We do not sell your personal data. We only share data with these providers to run the App, or where required by law.

5. Advertising and your consent choices

The App currently shows no advertising, so there is nothing to consent to and no advertising identifier is read.

If advertising is introduced in a future version, ads would be served by Google AdMob to free-tier users. Where required by law (for example under the EU/EEA GDPR or India's Digital Personal Data Protection Act), we would present a consent prompt (via Google's User Messaging Platform) before personalized ads are shown, and you could choose non-personalized ads. You can reset your advertising ID or opt out of ad personalization in your device settings at any time.

6. Legal bases for processing (EEA/UK users)

7. Data retention

We keep your account, profile, and meal data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within a reasonable period, except where we must retain limited records to comply with legal obligations or resolve disputes. Aggregated, anonymized statistics that cannot identify you may be retained.

8. Your rights

Depending on your jurisdiction, you may have the right to:

To exercise any of these rights, email sharp.applications2026@outlook.com. We will respond within the timeframe required by applicable law.

9. Account and data deletion

You may request deletion of your account and associated data at any time by emailing sharp.applications2026@outlook.com from the email address associated with your account, with the subject line "Delete my MacroDish account". We verify the request, action it within 30 days, and confirm by email when it is done.

Our account deletion page sets out exactly what is deleted, what is retained in anonymous form, and why.

10. Children's privacy

MacroDish is not directed to children under the age of 13 (or the minimum age of digital consent in your country, such as 16 in parts of the EEA). We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

11. International data transfers

Your data may be stored and processed in countries other than your own — including the Asia-Pacific (Seoul) region where our backend is hosted, and the locations of our sub-processors. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for these transfers.

12. Security

We use industry-standard measures to protect your data, including encrypted transport (HTTPS), row-level access controls so you can only access your own records, and secure credential storage on your device. No method of transmission or storage is 100% secure, but we work to protect your information.

13. Changes to this policy

We may update this Privacy Policy from time to time. We will revise the "Last updated" date above and, where changes are significant, provide a more prominent notice. Continued use of the App after changes take effect constitutes acceptance of the updated policy.

14. Contact us

Syed Shahbaz Husain
Email: sharp.applications2026@outlook.com