Privacy Policy
Last updated: 22 June 2026
This policy explains what data macroBody collects across the app and the macrobody.fr website, why we collect it, how we protect and anonymise it, and the rights you have. In plain terms: we collect what we need to coach you, we protect it, and we never sell it.
1. Who we are (data controller)
The controller of your personal data is Amine EL KERZAZI, an individual established at 90 rue Abbé Pierre Arnaud, APT 1, 85000 La Roche-sur-Yon, France (operating as “macroBody”, “we”, “us”). For any privacy request, contact contact@macrobody.fr. See also our legal notice.
2. Scope
This policy covers both the macroBody mobile app and the website. By creating an account you confirm you have read this policy; some processing (see “special category data” and analytics) relies on your explicit consent, which you can withdraw at any time.
3. What we collect
- Account data: your email address, a securely hashed password, and — if you sign in with Google — your Google account identifier and basic profile (name, email). We never see or store your Google password.
- Profile & health-related data: the figures you enter to power coaching — sex, date of birth/age, height, body weight and weigh-ins, activity level, goals, and your food log (foods, quantities, meal times). Because weight and dietary data can reveal information about your health, we treat them as special-category data and process them only on the basis of your explicit consent (see §5).
- Food photos (AI logging): if you use AI photo logging, the image is sent to our AI provider to identify foods and estimate portions. We use the photo only to generate that estimate; we do not use your photos to identify you or to build advertising profiles.
- Food searches & barcodes: search terms and scanned barcodes are sent to third-party food databases to return results (see §8 and §9).
- Subscription status: whether you have an active trial or plan. Payments are processed by the Apple App Store or Google Play — we do not receive or store your payment-card details.
- Technical data: basic information needed to run and secure the Service, such as IP address, device/app version, and server logs.
- Website analytics: if you consent on the website, Google Analytics 4 collects anonymous, aggregated usage (pages, approximate region, device, a few interactions). Your IP is anonymised. See §11 for cookies.
- Local preferences: your language, theme and cookie choice are stored on your device and are not used for tracking.
4. How we use your data
- To provide the Service: create and secure your account, verify your email, and run the adaptive calculations that produce your calorie and macro targets.
- To sync your logs across your devices.
- To operate the shared food database (see §6).
- To maintain security, prevent abuse, and enforce usage/entitlement limits.
- To improve the Service using aggregated and anonymised data (see §7).
- To comply with legal obligations and respond to your requests.
We do not use your personal logs or health data for advertising, and we do not sell your data to anyone.
5. Legal bases (GDPR)
- Performance of a contract — to provide the app you asked for (account, logging, sync, targets).
- Explicit consent — for special-category (health-related) data such as weight and dietary information, for AI photo processing, and for website analytics cookies. You can withdraw consent at any time without affecting prior processing.
- Legitimate interests — to keep the Service secure and prevent abuse (balanced against your rights).
- Legal obligation — where the law requires us to retain or disclose data.
6. The shared food database (your contributions)
macroBody works better when foods only need to be entered once. When you scan a barcode or create a food that isn’t yet in our catalog, the product information — the barcode, product name, brand and nutrition facts — is saved to our shared food database so that you and other users can log that product later without re-entering it.
This contributed information is product data, not personal data: it describes a food, not you, and it is not labelled with your identity or shown as “yours” to other users. Because it is part of the community catalog, it may be retained even after you delete your account, in a form that is not linked to you.
7. Anonymisation & aggregation
To understand trends and improve features, we may aggregate data (combine it across many users) and de-identify / anonymise it so that it can no longer reasonably be linked back to you. Once data is truly anonymised it is no longer personal data under the GDPR. We use pseudonymisation (e.g., internal identifiers rather than your name) wherever possible in our processing.
8. We do not sell your data
We never sell, rent, or trade your personal data, and we don’t share it with advertisers. We only share data with the service providers listed in §9, who act on our behalf, and only as needed to run the Service or where the law requires.
9. Service providers (sub-processors)
We use carefully selected providers who process data on our instructions under data-processing agreements:
- Hosting & database — to store your account and logs.
- Google — sign-in (Google Sign-In), AI food recognition (the photo-logging provider), and website analytics (Google Analytics 4).
- Resend — to send account emails such as your verification code.
- Food databases — USDA FoodData Central, Open Food Facts, and FatSecret receive your search terms / barcodes to return food results.
- Apple App Store / Google Play — to process subscriptions and payments.
10. International transfers
Some providers (for example, Google and US-based food databases) may process data outside the European Economic Area. Where that happens, we rely on appropriate safeguards such as the European Commission’s adequacy decisions or Standard Contractual Clauses.
11. Cookies & analytics
On the website, analytics are off by default. A banner lets you Accept or Decline, and we use Google Consent Mode v2 so no analytics cookies are set until you accept. You can change your choice anytime:
You can also install Google’s Analytics opt-out add-on. See Google’s Privacy Policy for how Google processes data.
12. How long we keep your data
We keep your account and logs for as long as your account is active. If you delete your account, we delete or anonymise your personal data within a reasonable period, except where we must keep certain records to meet legal obligations or resolve disputes. Website analytics data is retained for up to 14 months. Contributed product data in the shared food catalog (§6) may be retained as it is not personal to you.
13. How we protect your data
We use industry-standard safeguards: encryption in transit (HTTPS), hashed passwords, access controls, and server-side enforcement of permissions. No system is perfectly secure, but we work to protect your data and will notify you and the authorities of a breach where the law requires.
14. Your rights
Under the GDPR you can: access your data; correct it; delete it (“right to be forgotten”); restrict or object to processing; receive a copy in a portable format; and withdraw consent at any time. You can edit much of your data directly in the app, delete your account and associated data (in the app or by request), or email contact@macrobody.fr. You also have the right to complain to your data-protection authority — in France, the CNIL.
15. Children
The Service is not directed to children under 16 and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
16. Changes to this policy
We may update this policy; we’ll change the “last updated” date and, for material changes, give notice in the app or reset your cookie banner so you can review your choice.
17. Contact
Privacy questions or requests: contact@macrobody.fr. See also our Terms of Service.
