Privacy Policy
Privacy Policy
Effective Date: [Month Day, Year]
Last Updated: [Month Day, Year]
This Privacy Policy explains how [Legal Company Name] ("MacroIndex," "we," "us") collects, uses, discloses, and protects information when you use MacroIndex (the "Service").
1) Information We Collect
A) Information you provide
- Account information: email address, password (stored as a secure hash), and authentication data for OAuth sign-in (the provider name and the provider's account identifier).
- Nutrition and tracking information: foods you create, foods you log, meals, macro totals, goals, weight entries and goals, water entries and goals, supplements and supplement logs.
- Images for scanning: if you upload a nutrition label image, we process it to extract nutrition values. Scan images are not stored — they are held only for the moments required to process them and are then deleted.
- AI inputs: if you use AI-powered features, we process the text you submit (typed requests or voice transcripts) to generate a response. See Section 3.
- Feedback and bug reports: the description you write, the page you were on, your browser user agent, the app version, and any screenshot you choose to attach. Screenshots are stored in our database and are visible to administrators.
B) Information collected automatically
- Device and usage data: IP address, user agent, timestamps, and server logs for security and reliability.
- Cookies/session data: used to keep you signed in and to protect against security threats such as CSRF. See our Cookie Notice.
- Agreement records: when you accept these policies, we record the date and time, the policy version, your IP address, and your user agent, as evidence of consent.
- Usage counters: short-lived counters used to enforce rate limits and daily usage allowances.
- Abuse enforcement records: see Section 4.
- Plan and subscription identifiers: your plan level and, if you subscribe, identifiers issued by our payment processor. See Section 6.
2) How We Use Information
We use information to: - provide the Service (logging, goals, scanning, and AI features), - secure accounts, enforce usage limits, and prevent abuse and fraud, - send essential emails (for example, password reset), - maintain and improve reliability, quality, and user experience, - process payments if you subscribe, - comply with law and enforce our Terms.
3) AI and OCR Processing
OCR (label scanning)
Label scanning may be performed by software running on our servers or by a configured cloud OCR provider (currently Google Cloud Vision). When a cloud provider is used, the image is transmitted to that provider for processing. We do not retain scan images in either case.
Before processing, uploaded images may be screened automatically for prohibited content (see Section 4). OCR can be inaccurate; you are responsible for verifying extracted values.
AI features
AI features send the text you submit to an AI provider (currently OpenAI) to generate a response.
- Safety screening: before your text is sent to a paid AI model, it is first screened by the provider's content moderation service. Text that is flagged is refused and is not processed further.
- Safety identifier: requests we send to the AI provider include a one-way hashed identifier derived from your account ID. This lets the provider attribute misuse to an individual account rather than to the Service as a whole. It does not contain your email address or any other directly identifying information.
- Shared lookup cache: to avoid repeating identical lookups, the normalized text of a nutrition query may be stored alongside its result in a cache shared across the Service. Do not include personal or sensitive information in AI requests.
- Diagnostic logs are metadata only. We record the outcome of AI and OCR operations — such as status, model name, response time, data sizes, token counts, and error messages — but we do not store the content of your AI requests or the provider's responses, and we do not store scan images.
AI output may be inaccurate, incomplete, or outdated. Verify nutrition values against product labels and official sources.
4) Abuse Prevention and Enforcement
To protect the Service, other users, and the third-party accounts the Service depends on, we operate automated abuse controls.
- What triggers a record: when submitted text or an uploaded image is flagged by an automated content-safety system, we block the request and record the event.
- What we record: your account ID, the date and time, and the category reported by the safety system. We do not store the flagged content itself.
- What we record when an account is suspended: the date and time, the IP address and user agent of the request that caused the suspension, and the violation category. We use this to enforce suspensions, detect repeat sign-ups from the same source, and, where legally required, support reporting obligations.
- Counts: we maintain a per-account count of flagged events, which determines whether an account is suspended. See our Terms of Service for the enforcement policy.
- Support instead of enforcement: requests flagged as relating to self-harm are blocked and answered with support resources. They are not counted as violations and do not contribute to suspension.
5) How We Share Information
We share information only as needed to operate the Service, including: - Service providers (processors): - Hosting and database: our cloud hosting provider (currently Render). - AI provider (currently OpenAI): for AI nutrition lookup, voice command interpretation, and content-safety screening. - OCR provider (currently Google Cloud Vision): for label scanning and image content screening, when enabled. - Payment processor (currently Stripe): for subscription billing, if you subscribe. - Email delivery (currently Resend): for essential transactional email such as password resets. - OAuth providers (Google, Apple): for sign-in, if you choose it. - Error monitoring (currently Sentry): for diagnosing faults. Reports are automatically scrubbed to remove email addresses, credentials, tokens, and the content of AI requests. - Legal and safety: if required by law, or to protect rights, safety, and security. This includes reporting apparent child sexual abuse material to the appropriate authorities as required by law. - Business transfers: if we are involved in a merger, acquisition, or asset sale.
We do not sell your personal information, and we do not use it for third-party advertising.
6) Payments
If you subscribe to a paid plan, payment is processed by our payment processor. We never receive or store your full card number, CVC, or bank details — those are collected directly by the processor. We store your plan level, the processor's customer and subscription identifiers, and the current status and renewal date of your subscription.
7) Data Retention
- Account and tracking data: retained until you delete your account. Deletion removes your profile, logs, foods, meals, supplements, goals, feedback, scan and AI diagnostic records, and linked sign-in identities.
- Scan images: not retained.
- AI request and response content: not retained (see Section 3).
- Usage counters: automatically deleted after a short period (currently about seven days).
- Abuse enforcement records: retained while the account exists, and where necessary for abuse prevention, legal compliance, or the enforcement of suspensions. Records are cleared if a suspension is reviewed and reversed.
- Server and security logs: retained for a limited period.
- Shared lookup cache: cached nutrition results are not tied to your account and may persist independently of it.
8) Your Choices and Rights
Depending on where you live, you may have rights to access, correct, delete, or obtain a copy of your information, or to object to or restrict certain processing.
Two of these are available to you directly in the Service, on your Profile page: - Export: download a complete copy of your data as JSON. - Deletion: permanently delete your account and associated data.
For anything else, contact us at [support@yourdomain.com].
9) Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information, including encrypted transport (HTTPS), hashed passwords, hashed API credentials, scoped access controls, and rate limiting. However, no method of transmission or storage is 100% secure.
10) Children's Privacy
MacroIndex is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
11) International Users
If you access the Service from outside the United States, you understand your information may be processed in the United States and other locations where our service providers operate.
12) Changes to This Policy
We may update this Privacy Policy from time to time. We will update the "Last Updated" date and may provide additional notice within the Service.
13) Contact
[Legal Company Name]
Email: [support@yourdomain.com]
Address: [Address]