← MacroMatch

Privacy Policy

Last updated: August 27, 2026

What we collect

When you use MacroMatch — with or without an account — we collect the following information:

  • Account info: on the web, from Clerk (our authentication provider) — email address, name, and any identity you connect via Google or other OAuth providers. In the iOS app, you sign in with Apple or Google; we receive an account identifier and your email address from that provider, plus your name if you share it, and store them in our own database.
  • Profile info you provide directly: birth date (used to calculate your basal metabolic rate), sex assigned at birth, height, weight, activity level, dietary goal, location (city or ZIP), and any dietary preferences, allergies, or avoidances you set.
  • Usage data: meals you log in your diary, searches you run, meals you save or order, and the preferences you set in the app.
  • Technical data: standard server logs (IP address, user agent, request timestamps) from our hosting provider (Vercel).

What we don't collect

  • We do not collect payment card details. The MacroMatch web app is free and has no payments. Any MacroMatch Pro subscription in our iOS app is purchased through Apple’s App Store in-app purchase system — Apple processes the payment, and your card details never touch our servers.
  • We do not access your device's contacts, photos, microphone, or camera.
  • We do not store your precise location. By default, we approximate your location from your IP address (via a third-party IP lookup service) or a ZIP code you enter manually. If you tap “detect my location” and grant your browser’s location permission, your device’s coordinates are sent through our server to a reverse-geocoding service (OpenStreetMap Nominatim) solely to determine your city and state; we keep only the resulting city and state, not the coordinates.
  • We do not sell your personal data. Ever.

How we use your data

  • To calculate your personal calorie and macro targets.
  • To rank restaurant meals against your targets and preferences.
  • To sync your profile and diary across devices when you sign in.
  • To improve the product — we look at anonymized usage trends (e.g. which search prompts return zero results) to fix gaps.

Third-party services we use

MacroMatch sends limited data to these services to provide functionality. Each one has its own privacy policy:

  • Clerk — account authentication and session management. They receive your email and any profile metadata we store with them.
  • Anthropic (Claude API) — powers our AI features (natural-language search, meal estimation, the consultant). Your search prompts and meal descriptions are sent to Claude. Anthropic does not train their models on this data.
  • Nutritionix — restaurant nutrition database. For some searches (when our own curated catalog can’t answer), we send the food-related search terms (e.g. “chicken bowl”) to Nutritionix to look up matching menu items. Your name, email, account identity, and macro profile are never included in these requests.
  • FatSecret — restaurant nutrition database, used the same way as Nutritionix: it receives only food-related search terms, never your identity or profile data.
  • Supabase — our database. Stores your profile, diary, and saved meals so they sync across devices.
  • PostHog — product analytics. Records how the app is used (pages viewed, searches run, meals selected) and, on the web app for a sample of sessions, a session replay (a reproduction of your in-app interactions) so we can fix what isn’t working. If you’re signed in, these events are linked to your account identifier so we can understand usage across sessions; they are never sold or shared for advertising.
  • Sentry — error monitoring. If the app crashes or hits a bug, technical details (including your IP address and, in a sample of sessions, a replay of the in-app interaction that led to the error) are sent to Sentry so we can reproduce and fix it.
  • Vercel — hosting and infrastructure. Server logs pass through their network.
  • OpenStreetMap Nominatim — reverse-geocoding. If you grant location permission, we send your coordinates (via our server, so your IP address is not shared with them) to determine your city and state; nothing else about you is sent.
  • ipapi.co — IP-based location. If location permission is unavailable or denied, we send your IP address to approximate your city and state.
  • Apple and Google — sign-in providers for the iOS app. When you sign in on iOS, they authenticate you and we receive your name, email address (Apple lets you hide it behind a private relay address), and an account identifier. Apple also processes iOS subscription payments — we never see your payment details.
  • Resend — transactional email. If you join the waitlist, we use Resend to send a confirmation email to the address you provide.

Your rights

  • Access: you can see your profile and diary at any time inside the app.
  • Edit: you can update your profile, dietary preferences, and diary entries directly.
  • Delete: in the iOS app, go to the You tab and tap Delete account to immediately and permanently delete your account and its data. For web accounts, email us (see below) and we will remove your account and associated data from our systems, including asking Clerk (our web authentication provider) to delete your authentication record. Some anonymized usage data may persist in aggregated form.
  • Export: email us to request a copy of your data.

Cookies and tracking

We use cookies set by Clerk to keep you signed in on the web, and PostHog stores a device identifier (cookie/local storage) to distinguish visitors. We do not use third-party advertising cookies or cross-site tracking. We use PostHog, an analytics service (data is processed on PostHog’s US cloud), to understand how users move through the app. For visitors who aren’t signed in, this data is not linked to a name or email; for signed-in users, events are associated with your account identifier (see “Third-party services” above). We never use this data for advertising, and we never sell it.

Children

MacroMatch is not intended for users under 13. If you are under 13, do not use this app. We do not knowingly collect data from children under 13; if we learn we have, we will delete it.

Data security

Your data is stored with industry-standard providers (Supabase, Clerk, Vercel) that encrypt data in transit (TLS) and at rest. No system is perfect; in the event of a breach affecting your data, we will notify affected users within 72 hours of discovery, in line with applicable law.

Changes to this policy

We may update this policy as the product evolves. Material changes will be communicated via email or an in-app notice. The "Last updated" date at the top of this page always reflects the current version.

Contact

Questions, requests, or concerns about your data? Email hello@macro-match.com.

MacroMatch is operated by MacroMatch LLC, a Florida limited liability company, 7901 4th St N Ste 300, St. Petersburg, FL 33702, USA. MacroMatch LLC is the controller of the personal data described in this policy.