DailyMacros Privacy Policy

Last updated July 31, 2026

Optional progress check-in notes and dates are stored with your account. Progress photos are stored privately in Amazon S3 after location metadata is removed and the image is resized. Photos are not sent to AI services. Authenticated access provides short-lived download links. Export photos from their check-in; account exports include check-in records and photo identifiers. Deleting a photo, check-in, or account deletes its stored photo files.

DailyMacros is a private friends and family beta for nutrition, workout, weight, waist measurements, sleep, and wellness tracking. This policy explains what the app collects, why it is collected, and the controls available to you.

Data We Collect

Apple Health

HealthKit permissions are optional. Before DailyMacros requests HealthKit access, you choose Read and Write separately for each supported data type: weight, workouts, sleep, and sexual activity where enabled. A missing choice defaults to no access. These in-app choices control whether DailyMacros imports from or adds new entries to Apple Health; Apple's system permission remains an additional device-level control. Turning a direction off stops future transfers in that direction and does not delete records already imported or samples already written. You can change both the in-app choices and Apple's Health permissions at any time.

Oura

Connecting Oura is optional and uses Oura's authorization screen. DailyMacros requests daily-data access plus the minimum personal scope needed to obtain Oura's opaque user identifier and route signed webhook updates to your account. After connection, you choose which supported Oura aggregate categories DailyMacros may read. No aggregate backfill, reconciliation, or webhook document fetch begins until those choices are saved, and a missing choice defaults to no access. Oura does not support writes from this integration. Oura profile fields such as age, height, weight, biological sex, and Oura email are discarded.

Oura access and refresh tokens are encrypted on the DailyMacros server. DailyMacros stores allowlisted aggregate Oura metrics and does not retain raw heart-rate, HRV, movement, sleep-phase, or MET sample arrays. Imported aggregates remain stored until you choose Disconnect & Delete or delete your DailyMacros account. A minimal record of covered provider days and ignored record identifiers is retained after disconnect to prevent deleted history from being reimported through Apple Health; account deletion removes these markers. Sleep quality, perceived wake-ups, and notes are separate user annotations. Signed webhooks deliver Oura cloud updates after your ring syncs to Oura, with scheduled reconciliation for missed events.

DailyMacros may combine Oura aggregates with other app history for deterministic in-app trends and coaching. Oura API data and values derived from it are not provided to OpenAI, Apple Foundation Models, or any other AI or machine-learning model.

AI Processing

When you ask DailyMacros to parse or analyze a meal, workout, meal photo, report, or eligible connected health data, relevant content may be sent to OpenAI to produce estimates or analysis. Oura API data and values derived from it are always excluded. DailyMacros does not send other eligible content to OpenAI unless you use those AI features. OpenAI publishes its API data controls at platform.openai.com/docs/guides/your-data.

Barcode Data

Barcode lookups use Open Food Facts product data. DailyMacros sends the barcode value needed to look up the product and stores the nutrition entry only when you save it.

How We Use Data

Data is used for app functionality, account authentication, syncing across web and iOS, support, security, abuse prevention, beta reliability, billing when enabled, and account export or deletion. DailyMacros does not sell personal data and does not use third-party advertising or cross-app tracking.

Backups And Retention

Production data is backed up for operational recovery. Account data remains in the active database until you delete your account or request help deleting it, except for operational records with shorter limits. Optional browser diagnostics are retained for 30 days, operational usage counters for 90 days, and account audit events for 365 days. A scheduled server cleanup enforces those limits. Deleted account data is removed from the active database; encrypted production backup snapshots currently age out after 7 days, while transport or provider logs follow their providers' limited operational windows.

Your Controls

You can turn future optional browser diagnostic uploads on or off from Account & Privacy on the web or Settings on iOS. Turning them off does not disable essential server-side security records, audit events, abuse controls, or request references. You can manage per-source, per-data-type Read and Write choices from those settings, and explicit off choices are retained so they are not treated as missing consent. You can export a JSON copy of your account data, including these integration choices and safe diagnostic metadata, or permanently delete your account from those same settings. You can disconnect Oura and delete imported Oura data from either Settings surface, change or revoke HealthKit access, and sign out from the app.

Support

For support or privacy requests, contact the person who invited you. Include the request reference shown in any error message and the build information from Settings or Account & Privacy.