Macromaat Privacy Policy
Effective Date: 03-12-2025
Welcome to Macromaat (“Macromaat,” “we,” “our,” or “us”).
Macromaat is designed to help you understand your nutrition, log your meals, plan your week, and achieve your health goals through powerful AI-driven tools, including an AI food scanner and an AI chat assistant. Because this is a personal journey, we are committed to protecting your privacy and handling your data with care, transparency, and in full compliance with the GDPR.
This Privacy Policy describes how we collect, use, store, and protect your personal data when you use our mobile application, website, and related services (“Services”).
This Policy forms part of our Terms of Service.
MacromaatDe Klaverzuring 7
7701 MR Dedemsvaart
The Netherlands
Email: info@macromaat.nl
1. Age Requirement
You must be at least 18 years old to use Macromaat.
Our Services are not intended for children under 18, and we do not knowingly collect data from them. If we discover or are informed that a user is under 18, we will delete the account and associated data without undue delay.
2. What Personal Data We Collect
We collect information directly from you, and automatically through your use of the app.
We do not collect data for advertising, and we do not sell your personal data.
2.1. Data You Provide During Account Setup
When you create a Macromaat account, we may collect:
- Name
- Email address
- Date of birth
- Gender
- Country of residence
- Height and weight
- Dietary preferences and restrictions (e.g. vegetarian, allergies)
- Activity level
- Health or body composition goals (e.g. weight goal)
- Password (stored using industry-standard hashing)
2.2. Data You Provide While Using the App
When you use the core features of Macromaat, we may process:
- Food and meal logs (what you eat and drink, when, and in what quantity)
- Photos of food used in the AI food scanner
- Barcode scans and selected products
- Macronutrient and calorie data logged or calculated from your entries
- Body measurements and progress data (e.g. weight, measurements over time)
- Fasting schedules and fasting timers (if you use this feature)
- Hydration logs (if used)
- Recipes you save or create, and meals you favourite
- Meal plans and grocery lists you generate
- Notes, tags, and personal comments you add to entries
These data points can qualify as health data under the GDPR. We only process them with your explicit consent, which you provide during onboarding and when using the relevant features.
2.3. AI Chat and AI Food Scan Data
Macromaat includes:
- An AI food scan: you can upload a photo of your meal, which is analyzed by our AI to estimate nutritional information and help you log the meal.
- An AI chat assistant: you can ask questions, request advice based on your logged data, and request recipes or plans.
When using these AI features we may process:
- The content of your messages to the AI chat
- The context from your account and logs (e.g. goals, dietary prefs, recent meals) to personalize responses
- Images you upload for food scanning
We use this information to generate answers and suggestions, and to improve the relevance and quality of our Service. Where possible, we use pseudonymization or anonymization to protect your identity when performing analyses and technical improvements.
We do not use your AI chat or scan content for advertising or to build marketing profiles.
2.4. Communications With Us
If you contact us directly, we may process:
- Your name
- Email address
- The content of your message(s)
- Support-related metadata (timestamps, ticket ID, internal notes)
2.5. Automatically Collected Data
To maintain and improve our Services, we may collect certain technical and usage data, such as:
- Device type, operating system, and app version
- IP address (where possible anonymized or truncated)
- Crash logs and error reports
- General usage data (e.g. which features are used, frequency of use, session duration)
We use this information to:
- Keep the app functional and stable
- Diagnose errors and performance issues
- Understand which features are most helpful and where improvement is needed
We do not use this technical data to display third-party ads or track you across other apps or websites.
3. No External Health Integrations
Macromaat currently does not integrate with external health platforms such as:
- Apple Health / HealthKit
- Google Health Connect
- Samsung Health
- Fitbit, Garmin, or similar devices
We do not read or write data from/to such services. If we introduce such integrations in the future, we will clearly inform you and update this Privacy Policy and our in-app consent flows.
4. How We Use Your Personal Data
We use your data only for clearly defined purposes, and never for third-party advertising or data selling.
4.1. To Provide and Operate the Services
- Creating and managing your account
- Calculating your daily and weekly nutritional values and targets
- Logging your meals and tracking your progress
- Powering the AI food scanner and AI chat assistant
- Providing recipe suggestions and meal planning
- Operating fasting timers and schedules (if you use them)
- Supporting features like favourites, history, and search
4.2. To Personalize Your Experience
- Tailoring suggestions to your goals and preferences
- Offering recipe and meal ideas that fit your dietary profile
- Highlighting relevant features and content based on your use of the app
4.3. To Communicate With You
- Responding to your support requests
- Sending important service messages (e.g. security updates, changes to terms or policy)
- With your consent, sending product updates, tips, or newsletters
You can opt out of non-essential emails at any time by using the unsubscribe link or your in-app preferences.
4.4. To Ensure Security and Prevent Misuse
- Detecting suspicious logins and activity
- Monitoring for abuse or misuse of the platform
- Protecting our infrastructure and other users
4.5. For Analytics and Product Improvement
We use aggregated and/or pseudonymized data to:
- Understand how users interact with certain features
- Improve our AI models, user flows, and experience
- Debug technical problems and crashes
- Plan new features and improvements
Where technically possible, we avoid processing directly identifiable information for analytics.
4.6. To Comply With Legal Obligations
- Accounting and tax obligations under Dutch and EU law
- Responding to lawful requests from regulators or law enforcement, where required
5. Legal Bases for Processing (GDPR)
We process your personal data based on the following legal grounds:
- Consent – especially for health-related data, AI features, and optional communications.
- Contractual necessity – to provide the app and its core functionalities once you create an account.
- Legitimate interests – to secure our platform, prevent abuse, support users, and improve our product, in ways that do not override your fundamental rights and freedoms.
- Legal obligations – for compliance with Dutch and EU law (e.g. tax and accounting).
You can withdraw your consent at any time in the app or by contacting us at info@macromaat.nl. This will not affect processing that took place before the withdrawal.
6. Where and How Your Data Is Stored
6.1. Data Location – Within the European Union
Macromaat is a Dutch company, and we are committed to keeping your personal data within the European Union.
We configure our infrastructure so that your personal data is stored and processed on servers located in the EU/EEA.
6.2. Use of Firebase / Firestore
We use Google Cloud Firebase, including services such as:
- Firestore (database)
- Authentication (for account sign-in)
- Cloud Storage (for storing images, e.g. meal photos)
- Other Firebase components required to provide and secure the app
These services act as our data processors and are configured to store your personal data in EU data centers, where technically possible.
Firebase is contractually bound by data processing agreements and must implement appropriate security measures and cannot use your data for their own independent purposes.
7. How We Share Your Personal Data
We do not sell or rent your personal data. We share it only when necessary and under strict conditions.
7.1. Service Providers (Processors)
We may share your data with carefully selected service providers who help us operate the app, such as:
- Cloud hosting and database providers (e.g. Firebase / Firestore)
- Logging and error monitoring tools
- Email delivery tools
- Analytics tools (privacy-friendly and EU-compliant where possible)
These processors are bound by data processing agreements and may only handle your data according to our documented instructions.
7.2. Legal and Regulatory Disclosures
We may disclose your data when required to:
- Comply with a legal obligation under Dutch or EU law
- Respond to lawful requests from law enforcement or regulators
- Protect our rights, property, or safety or that of our users
7.3. Business Transfers
If Macromaat is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction, but always under conditions consistent with this Privacy Policy and applicable law.
8. How We Protect Your Data
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption of data in transit (e.g. HTTPS)
- Encryption of data at rest where supported by our infrastructure
- Restricted access to production systems (access only for authorized personnel)
- Regular updates and security patches
- Monitoring and logging of access for security purposes
Although no system is completely risk-free, we strive to follow industry best practices to minimize security risks.
9. Data Retention
We keep your personal data only as long as necessary for the purposes described in this Policy.
As a guideline:
- Your account and associated data are kept for as long as your account is active.
- If your account is inactive for an extended period (e.g. 3 years), we may anonymize or delete your personal data.
- Some data may be kept longer if required by law (e.g. accounting records, up to 7 years under Dutch law).
- Backups may retain data for a limited period (e.g. up to 90 days) before being fully overwritten.
When you delete your account or ask us to erase your data, we will delete or irreversibly anonymize your personal data, unless we are legally obliged to keep certain information for a longer period.
10. Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights:
- Right of access – Request confirmation whether we process your data and obtain a copy of your personal data.
- Right to rectification – Have inaccurate or incomplete data corrected.
- Right to erasure (“right to be forgotten”) – Have your personal data deleted in certain circumstances.
- Right to restriction of processing – Ask us to limit the processing of your data in certain situations.
- Right to data portability – Receive your data in a structured, commonly used, machine-readable format and transmit it to another controller where technically feasible.
- Right to object – Object to certain processing activities based on our legitimate interests.
- Right to withdraw consent – Withdraw your consent at any time, without affecting past processing.
- Right to lodge a complaint – With the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority.
To exercise your rights, you can:
- Use the privacy and account settings in the app (e.g. account deletion), or
- Contact us via info@macromaat.nl
We may need to verify your identity before fulfilling certain requests.
11. No Advertising, No Data Selling
Macromaat:
- Does not display third-party ads in the app
- Does not sell, rent, or trade your personal data
- Does not share your data with advertisers or data brokers
- Does not perform cross-app or cross-site advertising tracking
Our business model is based on providing a paid product and not on monetizing your personal data.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will:
- Notify you within the app or by email (where appropriate), and
- Update the “Effective Date” at the top of this document.
Your continued use of the Services after such changes means you accept the updated Policy.
13. Contact Us
If you have questions, concerns, or requests related to this Privacy Policy or your personal data, you can contact us at:
MacromaatDe Klaverzuring 7
7701 MR Dedemsvaart
The Netherlands
Email: info@macromaat.nl
We will do our best to respond in a timely and transparent manner.
